From 56a04403dc1400f0cd3d1e2427d78789f70e76db Mon Sep 17 00:00:00 2001 From: Adam Wright Date: Wed, 9 Sep 2026 13:35:54 +0000 Subject: [PATCH] Run poetry-check on push to main, so main stops showing 6/8 poetry-check carried `if: github.event_name == 'pull_request' || 'workflow_dispatch'`, so a push to main skipped it. GitHub counts a skipped required check as not-passing, and `poetry-check (ubuntu-latest)` is one of the four required contexts -- so main has been showing 6/8 ever since. A main branch that always looks amber is a main branch nobody reads, which defeats the point of the gate. Removing the filter alone would have made the job expensive on every push: with no base_ref, the lockfile diff fell through to the "no base to compare against, so always verify" branch and would have run the full install-and-verify on every commit to main. A push does have something to compare against -- the commit before it -- so it now diffs HEAD^..HEAD and stays as cheap as it is on a PR. Simulated against real commits before pushing: push with a lock-changing commit -> true, push without -> false, workflow_dispatch -> true, pull_request base=main -> false. --- .github/workflows/ci.yml | 19 ++++++++++++++++--- 1 file changed, 16 insertions(+), 3 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 2c6bf08a..c332cd50 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -53,7 +53,12 @@ jobs: run: poetry run pytest poetry-check: - if: ${{ github.event_name == 'pull_request' || github.event_name == 'workflow_dispatch' }} + # No event filter. It used to run only on pull_request and + # workflow_dispatch, so every push to main skipped it -- and GitHub counts + # a skipped required check as not-passing, leaving main permanently + # showing 6/8. A main branch that always looks amber is a main branch + # nobody reads. The expensive steps stay gated on poetry.lock actually + # having changed, which on a push means comparing against HEAD^. runs-on: ${{ matrix.os }} strategy: matrix: @@ -71,8 +76,16 @@ jobs: shell: bash run: | base="${{ github.base_ref }}" - if [ -z "$base" ]; then - # manual run: no base to compare against, so always verify + if [ -z "$base" ] && [ "${{ github.event_name }}" = "push" ]; then + # A push has no base branch; compare against what main was + # before it, so this stays as cheap here as it is on a PR. + if git diff --name-only HEAD^ HEAD -- poetry.lock | grep -q .; then + echo "changed=true" >> "$GITHUB_OUTPUT" + else + echo "changed=false" >> "$GITHUB_OUTPUT" + fi + elif [ -z "$base" ]; then + # workflow_dispatch: nothing to compare against, so verify. echo "changed=true" >> "$GITHUB_OUTPUT" elif git diff --name-only "origin/$base...HEAD" -- poetry.lock | grep -q .; then echo "changed=true" >> "$GITHUB_OUTPUT"