Skip to content

The required-checks guard reads rulesets as well as branch protection - #847

Merged
irparent merged 1 commit into
mainfrom
ci/required-checks-rulesets
Oct 5, 2026
Merged

irparent merged 1 commit into
mainfrom
ci/required-checks-rulesets

Conversation

@irparent

@irparent irparent commented Oct 5, 2026

Copy link
Copy Markdown
Member

What changes

The checks a merge to main waits for are set in two places, and today they disagree:

Layer Checks it requires
Classic branch protection the 21 in .github/required-checks.json
The "main branch protection" ruleset 5: lint-and-typecheck, test (22), build, security-exposure, and CodeQL (code scanning's own result), which was in no document

scripts/ci/check-required-checks.mjs read only the classic layer, so a change to the ruleset was invisible to it, and moving protection to rulesets would have turned main red. It now holds the file to the union of both layers (classic protection from the branch endpoint, every active ruleset rule from rules/branches/main), and fails if neither requires anything.

CodeQL joins .github/required-checks.json and the CONTRIBUTING table, since a merge already waits for it.

Tests

  • tests/required-checks-documented.test.ts: the union of classic contexts and ruleset rules, once each; GitHub's own CodeQL context is recognised as not being one of our jobs.
  • The guard run against the live settings: OK — .github/required-checks.json lists the 22 contexts iris-eval/mcp-server@main requires (branch protection and rulesets together).
  • npm run preflight passed on this commit.

🤖 Generated with Claude Code

…tion

The setting lives in two places, and they disagree: classic branch
protection requires 21 checks, and the "main branch protection" ruleset
requires 5, one of which (`CodeQL`, code scanning's own result) was in
no document. The guard read only the classic rule, so a ruleset change
was invisible to it, and moving protection to rulesets would have
turned main red. It now holds .github/required-checks.json to the union
of both layers, and fails if neither requires anything.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@vercel

vercel Bot commented Oct 5, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
website Ignored Ignored Oct 5, 2026 10:13pm UTC

@github-actions

github-actions Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Iris gate — 1 of 2 tripped --fail-on detector_veto

iris-eval ingest: 3 stored, 1 tripped --fail-on detector_veto (2 of 3 evaluated in dataset "release-gate")

Trace Verdict Basis Rules, classes or missing inputs Evidence
ee094df25f7a0b3134bcbd1b7adc3fa4 failed detector_veto + risk_over_loss no_pii, pii_leak, credential_leak no_pii: AWS Access Key (output 45–65)
Verdict basis Traces
detector_veto 2
clean 1

Unjudged questions: task_completed (3), tool_use_correct (3) — a trace that did not carry what a rule needs.

tests/fixtures/ci-gate/traces.ndjson · 3 evaluated · dataset release-gate: 2 in the gate · exit 1 · what the bases mean

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown

Iris gate — 1 stored, nothing tripped --fail-on any

iris-eval ingest: 1 stored, 0 tripped --fail-on any

Verdict basis Traces
clean 1

Unjudged questions: task_completed (1), tool_use_correct (1) — a trace that did not carry what a rule needs.

tests/fixtures/ci-gate/clean.ndjson · 1 evaluated · exit 0 · what the bases mean

@irparent
irparent merged commit 1fb5407 into main Oct 5, 2026
74 checks passed
@irparent
irparent deleted the ci/required-checks-rulesets branch October 5, 2026 22:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant