Skip to content

ci: gate pull requests on an accepted issue and signed commits - #744

Merged
dev-jodee merged 2 commits into
mainfrom
ci/require-accepted-issue-and-signed-commits
Sep 21, 2026
Merged

dev-jodee merged 2 commits into
mainfrom
ci/require-accepted-issue-and-signed-commits

Conversation

@dev-jodee

@dev-jodee dev-jodee commented Sep 21, 2026 •

Copy link
Copy Markdown
Collaborator

Linked issue

Linked issue: trivial

What and why

Replaces the contributor canary word with checks that do not depend on an agent opting into them, and adds the issue-first gate from solana-mobile/templates#64.

  • The canary only fires when an agent both reads CLAUDE.md and follows a request to self-incriminate. It catches nothing adversarial and little honest. Removed from CLAUDE.md, AGENTS.md and the hygiene patterns. The rest of the attribution scan is untouched and still labels ai-unreviewed, comments and fails the check without closing anything.
  • New Accepted issue linked job: the description must reference an issue a maintainer has labelled accepted. Without one the PR is labelled needs-issue, commented on once and closed. Once the issue is accepted and linked, reopening the PR reruns the check and clears the label. Linked issue: trivial exempts typos, broken links and comment-only fixes. Bots and authors with write, maintain or admin access skip.
  • New Commits signed job: an unverified commit gets one changes-requested review naming the shas, dismissed automatically once all commits verify and replaced when a force-push changes which commits are unsigned. The review carries a marker with the digest of that list, so the job only ever dismisses a review it wrote itself. This enforces a rule CONTRIBUTING already stated but nothing checked.
  • PR template gains the required Linked issue field.

Both jobs run under a per-PR concurrency group, so overlapping opened/edited/synchronize runs cannot race on the label or file duplicate reviews. No third-party action is involved: pull_request_target with pull-requests: write is the worst place to carry one, and the logic is a handful of gh calls.

Testing

bash -n on both new job scripts, YAML parsed. The jobs themselves only run once this is on main, since pull_request_target reads the workflow from the base branch.

AI disclosure

  • No AI tooling was used beyond editor autocomplete.
  • AI tooling was used. Tool and extent: Claude Code drafted the two jobs and the label config, I reviewed and edited before opening.

The canary only fires when an agent both reads the instructions and follows a request to self-incriminate, so it catches nothing an adversary does and little an honest contributor does. The attribution patterns in pr-hygiene cover the same ground with signals nobody opts into.
@greptile-apps

greptile-apps Bot commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

The PR appears safe to merge; no outstanding correctness or repository-rule violations remain.

Findings

  1. P1 Reopening bypasses automatic closure ▶
  2. P2 Review ownership is ambiguous ▶

Summary

The PR replaces the contributor canary with enforceable pull-request hygiene checks.

  • Requires external contributors to reference an accepted issue or declare an eligible trivial change.
  • Labels, comments on, and closes noncompliant pull requests directly from the hygiene workflow.
  • Requests changes for unsigned commits and identifies its own reviews with a durable marker.
  • Updates the pull-request template and contribution guidance to document the new requirements.
  • Since the previous review, the workflow now closes reopened noncompliant PRs directly and scopes signing-review dismissal to reviews created by this gate.

Reviews (2) · Last reviewed commit: "ci: gate pull requests on an accepted is..."

Comment thread .github/workflows/pr-hygiene.yml Outdated
Comment thread .github/workflows/pr-hygiene.yml Outdated
Two new pr-hygiene jobs.

The first requires the description to reference an issue a maintainer has
labelled `accepted`, so scope is agreed before anyone writes code. A pull
request without one is labelled `needs-issue`, commented on once and closed.
Once the issue is accepted and linked, reopening the pull request runs the
check again and clears the label. Typos, broken links and comment-only fixes
declare `Linked issue: trivial` instead, and bots and collaborators with
write, maintain or admin access are exempt.

The second enforces the signature requirement CONTRIBUTING already states. Any
unverified commit gets one changes-requested review listing the offending
shas, carrying a marker that names the digest of that list, so the job only
ever dismisses or supersedes a review it wrote itself. The review is dismissed
once every commit verifies, and replaced when a force-push changes which
commits are unsigned. A failing status check would clear itself on push, but
it would not block the merge, and stale review dismissal only applies to
approvals.

Both jobs run under a per-pull-request concurrency group so overlapping runs
cannot race on the label or file duplicate reviews.
@dev-jodee
dev-jodee force-pushed the ci/require-accepted-issue-and-signed-commits branch from 6061a48 to de9b2c7 Compare September 21, 2026 15:25

@amilz amilz left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

CI hardening: adds accepted-issue + signed-commits gates to pr-hygiene, retires marzipan canary. LGTM.

@dev-jodee
dev-jodee merged commit df283ae into main Sep 21, 2026
28 checks passed
@dev-jodee
dev-jodee deleted the ci/require-accepted-issue-and-signed-commits branch September 21, 2026 16:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants