ci: gate pull requests on an accepted issue and signed commits - #744
Merged
Merged
Conversation
The canary only fires when an agent both reads the instructions and follows a request to self-incriminate, so it catches nothing an adversary does and little an honest contributor does. The attribution patterns in pr-hygiene cover the same ground with signals nobody opts into.
Contributor
|
Two new pr-hygiene jobs. The first requires the description to reference an issue a maintainer has labelled `accepted`, so scope is agreed before anyone writes code. A pull request without one is labelled `needs-issue`, commented on once and closed. Once the issue is accepted and linked, reopening the pull request runs the check again and clears the label. Typos, broken links and comment-only fixes declare `Linked issue: trivial` instead, and bots and collaborators with write, maintain or admin access are exempt. The second enforces the signature requirement CONTRIBUTING already states. Any unverified commit gets one changes-requested review listing the offending shas, carrying a marker that names the digest of that list, so the job only ever dismisses or supersedes a review it wrote itself. The review is dismissed once every commit verifies, and replaced when a force-push changes which commits are unsigned. A failing status check would clear itself on push, but it would not block the merge, and stale review dismissal only applies to approvals. Both jobs run under a per-pull-request concurrency group so overlapping runs cannot race on the label or file duplicate reviews.
dev-jodee
force-pushed
the
ci/require-accepted-issue-and-signed-commits
branch
from
September 21, 2026 15:25
6061a48 to
de9b2c7
Compare
amilz
approved these changes
Sep 21, 2026
amilz
left a comment
Collaborator
There was a problem hiding this comment.
CI hardening: adds accepted-issue + signed-commits gates to pr-hygiene, retires marzipan canary. LGTM.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Linked issue
Linked issue: trivial
What and why
Replaces the contributor canary word with checks that do not depend on an agent opting into them, and adds the issue-first gate from solana-mobile/templates#64.
CLAUDE.mdand follows a request to self-incriminate. It catches nothing adversarial and little honest. Removed fromCLAUDE.md,AGENTS.mdand the hygiene patterns. The rest of the attribution scan is untouched and still labelsai-unreviewed, comments and fails the check without closing anything.Accepted issue linkedjob: the description must reference an issue a maintainer has labelledaccepted. Without one the PR is labelledneeds-issue, commented on once and closed. Once the issue is accepted and linked, reopening the PR reruns the check and clears the label.Linked issue: trivialexempts typos, broken links and comment-only fixes. Bots and authors with write, maintain or admin access skip.Commits signedjob: an unverified commit gets one changes-requested review naming the shas, dismissed automatically once all commits verify and replaced when a force-push changes which commits are unsigned. The review carries a marker with the digest of that list, so the job only ever dismisses a review it wrote itself. This enforces a rule CONTRIBUTING already stated but nothing checked.Both jobs run under a per-PR concurrency group, so overlapping
opened/edited/synchronizeruns cannot race on the label or file duplicate reviews. No third-party action is involved:pull_request_targetwithpull-requests: writeis the worst place to carry one, and the logic is a handful ofghcalls.Testing
bash -non both new job scripts, YAML parsed. The jobs themselves only run once this is onmain, sincepull_request_targetreads the workflow from the base branch.AI disclosure