Skip to content

Phase 2: nothing checks a pull request #191

Description

@DZPM

Approved by the Permanent Committee on 2026-09-30. This is the issue that explains why #190 exists.

A pull request to this repository runs no checks at all. Not a build, not a link check, nothing. Every item in #190 landed and stayed because nothing looked.

  • Build the site on every pull request
  • Check the content: front matter parses, a person id matches its filename, ids are unique, declared photos exist, and every person and sponsor id an event references resolves. This finds 6 errors on the current content, two of them visible on the live site
  • Check links, reporting without blocking, because external sites rate-limit
  • Update the deploy actions. actions/checkout@v3 is four majors behind and runs on a deprecated Node runtime, the other two are one major each, and the runner image is deprecated
  • Scope the workflow token to what the deploy needs, instead of the repository default of write
  • Pin the actions to a commit SHA rather than a mutable tag

Ordering: the content check cannot go green until the phase 1 fixes land, so these arrive in that order.

Activity

  1. self-assigned this
    on Oct 1, 2026
  2. DZPM commented on Oct 5, 2026

    @DZPM
    MemberAuthor

    All six items landed with #193, and the boxes above are ticked.

    The protection on edition is now set, which is the half that code cannot express. Until today the checks ran on every pull request but blocked nothing: one approving review was enough to merge with all three of them red.

    What is required now:

    Setting State
    Approving reviews required 1
    Required status checks Build the site, Check the content, Check the links
    Code owner review required yes
    Enforced on administrators no

    The link check reports without failing, so a rate-limited external site does not block a merge. The rule is not enforced on administrators, so an organizer can still unblock the repository if something goes wrong with the checks themselves.

    A branch protection setting lives only in the repository settings: it is in no file, appears in no diff, and nothing records who changed it or why. This comment is its history, which is why it is here and not in a pull request.

    Closing.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions