Skip to content

ci: add single 'gate' check context for the upcoming PR-gated main - #3

Merged
bytesnail merged 1 commit into
mainfrom
ci/pr-based-workflow
Oct 4, 2026
Merged

bytesnail merged 1 commit into
mainfrom
ci/pr-based-workflow

Conversation

@bytesnail

Copy link
Copy Markdown
Owner

Why

Switching this repo's development flow from direct pushes on main to a PR-based flow (strict: no bypass actors, admins included). A PR-gated ruleset needs required status checks — and requiring individual matrix cells (test (ubuntu-latest, 22.18), …) in the ruleset would silently drift every time the matrix changes.

What

  • .github/workflows/ci.yml: new gate job that aggregates the test + e2e matrices into one stable check context (if: always(), fails unless both need-jobs succeed). The ruleset will require gate + CodeQL's analyze.
  • AGENTS.md / CONTRIBUTING.md: document the PR-based workflow; release commits now land via release PRs.

After merge

Flip the protect main ruleset: add pull_request (squash+merge allowed, 0 required approvals) + required_status_checks (gate, analyze; up-to-date branch required), and remove the admin bypass actor.

The 'protect main' ruleset will require one stable check name instead of
enumerating matrix cells: 'gate' aggregates the test+e2e matrices (plus
CodeQL's 'analyze' is required separately). Docs (AGENTS.md,
CONTRIBUTING.md) switch to the PR-based workflow: direct pushes to main
rejected for everyone, release commits land via release PRs.
@bytesnail
bytesnail merged commit 301f1d2 into main Oct 4, 2026
15 checks passed
@bytesnail
bytesnail deleted the ci/pr-based-workflow branch October 4, 2026 19:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant