ci: pin no-mistakes required-check to v1.80.1 - #142
Conversation
Restore the T2 trigger set and grant pull-requests: read so the live PR lookup can run, and add the canonical release-please paths-ignore and bot exemption.
|
Release-please node releases bump package.json, so omitting it from paths-ignore still starts the GITHUB_TOKEN run this filter is meant to prevent.
| paths-ignore: | ||
| - .release-please-manifest.json | ||
| - CHANGELOG.md | ||
| - package.json |
There was a problem hiding this comment.
Package manifest bypasses gate
Adding package.json to paths-ignore suppresses this workflow for every package.json-only PR, not just release-please PRs. A non-exempt author can therefore change scripts, engine constraints, or other manifest settings without the require-no-mistakes action validating the PR body and head-SHA attestation, contrary to the repository policy that human PRs must pass this gate. Restrict the exemption to release automation rather than using a path filter that also applies to human-authored PRs.
How this was verified: The pull-request path filter applies before the job-level author conditions, while package.json contains ordinary developer-editable configuration and the repository identifies this workflow as the enforcement point for head-SHA-bound attestations.
There was a problem hiding this comment.
Keeping package.json in this paths-ignore.
That matches the repo's other release ignore lists (ci.yml and guard-generated-files.yml). A human pull request that only touches package.json skipping this gate is accepted: release-please node releases always bump the manifest, so omitting it would still create the GITHUB_TOKEN action_required run this filter is meant to prevent.
There was a problem hiding this comment.
That context resolves the concern. Keeping package.json is an intentional repository-wide policy choice, consistent with ci.yml and guard-generated-files.yml: release-please Node releases modify it, and omitting it would recreate the action_required run this filter is intended to prevent. I’ll consider this acceptable and won’t block the PR on that path filter, with the acknowledged trade-off that human PRs touching only package.json also skip this gate.
Tip: You can customize Greptile's behavior for this repo with .greptile/rules.md and .greptile/config.json.
Summary
kunchenguid/no-mistakes/.github/actions/require-no-mistakes@f6441c96c352a18b9cadcaef6b6c7017e9ac3970(v1.80.1).permissions.pull-requests: readso the v1.80.1 verifier can look up the live PR instead of failing closed.opened,edited,synchronize,reopened) and add the canonical release-pleasepaths-ignoreplusrelease-please[bot]exemption.Test plan
PR must be raised via no-mistakes.pull-requests: read, and T2 types landed in the same commit.github-actions[bot]anddependabot[bot]exemptions remain.