Repository navigation
ci(repo): fail CI until main's rules require every pull-request check - #78
Merged
Merged
Conversation
U3 and U4 of the gates-bind plan (R22, AE10). A rules job in ci.yml reads
GET /repos/{owner}/{repo}/rules/branches/main with the workflow's
GITHUB_TOKEN, decodes it with Effect Schema and fails while the active
rules do not require the six check legs, journeys, lint PR commits, the
changeset check and rules itself. .github/rulesets/gates.json is that
ruleset (active, no bypass actors, up-to-date branches required) and the
README's new Getting Started step installs it, per conductor rulings 13
and 14
…o tests pnpm test and pnpm gate:tasks wrap test:scripts in an outer sandbox that allowed only jsr.io, so Deno could not fetch npm:effect@4.0.1 on a cold cache: egress to registry.npmjs.org:443 refused, Failed caching npm package 'effect@4.0.1'. Both outer sandboxes now allow registry.npmjs.org, the one host test:scripts already declares
…o scripts Deno now resolves effect through nodeModulesDir manual from the root package's installed effect (catalog, 4.0.1, already in pnpm-lock.yaml), so test:scripts downloads nothing from the npm registry. The npm:effect import entry and its deno.lock lines are gone, and every sandbox is back to its earlier hosts, per conductor ruling 15
check-branch-rules.ts now takes effect from node_modules, and the rules job skipped the install, so Deno failed with 'Could not resolve effect' on run 37849660110. The dev-shell step's default install is offline from the Nix pnpm store
A ruleset created from gates.json through the REST API pins no app, so a required status check may come back with integration_id null. The decode refused that and would have kept rules red with the ruleset installed. The property now generates integer, null and absent ids, per conductor ruling 16
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Units U1, U3 and U4 of
docs/plans/2026-10-08-0705-feat-gates-bind-and-inline-suppression-plan.md(C1, R22, AE10). Conductor rulings 13, 14 and 15.Change
scripts/check-branch-rules.ts: a Deno script with the shebang--allow-net=api.github.com --allow-env=GITHUB_TOKEN,GITHUB_REPOSITORY, followingcheck-sfs-sources.ts. The shell readsGET /repos/{owner}/{repo}/rules/branches/mainwithGITHUB_TOKENand logs the HTTP status and the active rule types. Effect Schema decodes the response, witheffecttaken from the workspace's installednode_modules. The purebranchRulesVerdict(rules, requiredChecks)returns the required checks that norequired_status_checksrule requires, as data. The script exits 1 when any are missing, when the call fails, or when the response doesn't decode.scripts/check-branch-rules.test.ts: one property and two hand-written refusals. Expected values come from R22 and GitHub's documented "Get rules for a branch" response, not from the code's output.deletion,non_fast_forward,pull_requestand an unrelated status check mixed in.integration_id,integration_id: nullor nointegration_idat all, so the schema must accept all three (ruling 16, F1). A ruleset created fromgates.jsonthrough the REST API pins no app, and the decode can't strand it red. Sabotage: reverting the schema to integer-only turns the property red.deletion+non_fast_forward+pull_request) name every required check..github/workflows/ci.yml: onerulesjob onubuntu-latestwithpermissions: contents: read. It installs the workspace through the dev-shell action's default offlinepnpm bootstrapfrom the Nix pnpm store, sonode_modules/effectexists, then runspnpm check:branch-rules. It has nocontinue-on-errorand noif:. (Onf5a8352the job skipped the install and failed withCould not resolve "effect"before it made the request;adfa340fixes that.)package.json:check:branch-rules(sandbox egress:api.github.com,jsr.io).effectto the rootdevDependenciesascatalog:, which iseffect: 4.0.1inpnpm-workspace.yaml. The root package ownsscripts/, so pnpm installseffectthere from the existing lockfile store.pnpm-lock.yamlgains only that importer entry;effect@4.0.1was already locked.test:scriptsgains no network permission.scripts/deno.json:"nodeModulesDir": "manual", so Deno resolveseffectfrom the existingnode_modulesand downloads nothing from npm. There's nonpm:import entry, andscripts/deno.lockis unchanged frommain.DENO_DIRset to an empty directory,pnpm test:scriptsdownloads onlyjsr.iomodules and passes (ok | 9 passed | 0 failed). Nothing in the output mentionsregistry.npmjs.org.check (test)failed withFailed caching npm package 'effect@4.0.1'/unsuccessful tunnel, because Deno tried to downloadeffectfrom the npm registry inside the test sandbox..github/rulesets/gates.json: the "gates" repository ruleset forrefs/heads/main. It hasenforcement: active,bypass_actors: [],pull_request, andrequired_status_checkswith exactly the 10 names below, plusstrict_required_status_checks_policy: true.README.md: Getting Started gains "5. Make the Gates Block Merges", between "Run It Locally" and "Deploy". It gives the one install command,gh api -X POST repos/{owner}/{repo}/rulesets --input .github/rulesets/gates.json, and says therulescheck fails until it runs.Judgment surfaces changed (GATE1, conductor Q7):
.github/workflows/ci.yml,.github/rulesets/gates.json,package.json(scripts, plus theeffectdev dependency),scripts/check-branch-rules.ts,scripts/deno.json.Required checks (item 2)
These are the check names exactly as GitHub reported them on #77's head
9b4e918(CI run 37840842636, Commitlint run 37840842631, Changeset Check run 37840843669), plusrules:check (format)check (lint)check (typecheck)check (test)check (dist)check (sfs-sources)journeyslint PR commitschangeset · shared tooling / a publishable-package change needs an intentrulesU1: can
GITHUB_TOKENread branch rules?Answered by this PR's first
rulesrun, with no throwaway workflow or scratch branch: CI run 37845459980, jobrules(113545095569). The workflow'sGITHUB_TOKENran withpermissions: contents: read.deletion,non_fast_forward,pull_request. These match the 2026-10-08 read with a personal token.GET rulesets/{id}returnsbypass_actorstoGITHUB_TOKEN. Ruling 4 keeps bypass actors out of the check's reach.Predicate
rulesjob fails against the template's current rules, and every other check is green. That redrulesjob is the expected result.gates.jsonon the template, then re-runsrules. This PR doesn't install it.Must not count
required_status_checkscontexts. The template's current ruleset (three other rule types) is refused, both in the test and in the PR run.rulesmissing from its own required list. It's in bothREQUIRED_CHECKSandgates.json.GITHUB_TOKEN.continue-on-errororif:makingrulesgreen,--no-verify, or a weakened threshold. None is used.Evidence
pnpm format:check,pnpm lint,pnpm typecheckandpnpm test(includestest:scripts:ok | 9 passed | 0 failed) all exit 0.[]turns all three tests red.Note
ci.ymlis also changed by #77, and this branch is cut frommainas ruling 13 directs. #77 drops the push trigger at the top of the file; this PR appends therulesjob at the end.git merge-tree origin/gates/u2-deploy-waits HEADreports no conflict.