Skip to content

ci: pin no-mistakes required-check to v1.80.1 - #142

Merged
kunchenguid merged 2 commits into
mainfrom
fm/nm-gate-rollout-backpass-r1
Sep 22, 2026
Merged

kunchenguid merged 2 commits into
mainfrom
fm/nm-gate-rollout-backpass-r1

Conversation

@kunchenguid

Copy link
Copy Markdown
Owner

Summary

  • Pin the required-check caller to kunchenguid/no-mistakes/.github/actions/require-no-mistakes@f6441c96c352a18b9cadcaef6b6c7017e9ac3970 (v1.80.1).
  • Add permissions.pull-requests: read so the v1.80.1 verifier can look up the live PR instead of failing closed.
  • Restore the T2 trigger set (opened, edited, synchronize, reopened) and add the canonical release-please paths-ignore plus release-please[bot] exemption.

Test plan

  • Confirm the job name is still PR must be raised via no-mistakes.
  • Confirm the action pin, pull-requests: read, and T2 types landed in the same commit.
  • Confirm existing github-actions[bot] and dependabot[bot] exemptions remain.

Restore the T2 trigger set and grant pull-requests: read so the live
PR lookup can run, and add the canonical release-please paths-ignore
and bot exemption.
@greptile-apps

greptile-apps Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 3/5

The PR is not yet safe to merge because package.json-only human PRs can avoid creation of the no-mistakes verification workflow.

Reviews (2) · Last reviewed commit: "ci: ignore package.json on the no-mistak..."

Comment thread .github/workflows/no-mistakes-required.yml
Release-please node releases bump package.json, so omitting it from
paths-ignore still starts the GITHUB_TOKEN run this filter is meant
to prevent.
paths-ignore:
- .release-please-manifest.json
- CHANGELOG.md
- package.json

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 security Package manifest bypasses gate

Adding package.json to paths-ignore suppresses this workflow for every package.json-only PR, not just release-please PRs. A non-exempt author can therefore change scripts, engine constraints, or other manifest settings without the require-no-mistakes action validating the PR body and head-SHA attestation, contrary to the repository policy that human PRs must pass this gate. Restrict the exemption to release automation rather than using a path filter that also applies to human-authored PRs.

How this was verified: The pull-request path filter applies before the job-level author conditions, while package.json contains ordinary developer-editable configuration and the repository identifies this workflow as the enforcement point for head-SHA-bound attestations.

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Keeping package.json in this paths-ignore.

That matches the repo's other release ignore lists (ci.yml and guard-generated-files.yml). A human pull request that only touches package.json skipping this gate is accepted: release-please node releases always bump the manifest, so omitting it would still create the GITHUB_TOKEN action_required run this filter is meant to prevent.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

That context resolves the concern. Keeping package.json is an intentional repository-wide policy choice, consistent with ci.yml and guard-generated-files.yml: release-please Node releases modify it, and omitting it would recreate the action_required run this filter is intended to prevent. I’ll consider this acceptable and won’t block the PR on that path filter, with the acknowledged trade-off that human PRs touching only package.json also skip this gate.

Tip: You can customize Greptile's behavior for this repo with .greptile/rules.md and .greptile/config.json.

@kunchenguid
kunchenguid merged commit 02af5b8 into main Sep 22, 2026
3 of 5 checks passed
@kunchenguid
kunchenguid deleted the fm/nm-gate-rollout-backpass-r1 branch September 22, 2026 01:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant