From 0b8d8ae629c1303769d898aa2ed3ca5b34f42fb4 Mon Sep 17 00:00:00 2001 From: kunchenguid Date: Mon, 21 Sep 2026 14:31:41 -0700 Subject: [PATCH 1/2] ci: pin no-mistakes required-check to v1.80.1 Restore the T2 trigger set and grant pull-requests: read so the live PR lookup can run, and add the canonical release-please paths-ignore and bot exemption. --- .github/workflows/no-mistakes-required.yml | 32 ++++++++++++++++------ 1 file changed, 23 insertions(+), 9 deletions(-) diff --git a/.github/workflows/no-mistakes-required.yml b/.github/workflows/no-mistakes-required.yml index 88b9733f..529de840 100644 --- a/.github/workflows/no-mistakes-required.yml +++ b/.github/workflows/no-mistakes-required.yml @@ -3,18 +3,30 @@ run-name: "PR #${{ github.event.pull_request.number }} body compliance - ${{ git on: pull_request: - # The gate validates the head SHA recorded in pull_request.body. The - # pipeline pushes first, then rewrites that attestation, so the edited event - # checks the final body against the new head. A synchronize run would judge - # the old body in between and leave a same-named failure beside the later - # success. This check is not required by a ruleset or branch protection, so - # omitting synchronize cannot leave an expected check pending. - types: [opened, edited, reopened] + # T2: opened, edited, synchronize, reopened. #773 dropped synchronize + # because a pipeline push pinned a FAILURE check run to the new head + # before the PR step rewrote the body, and GitHub kept that failure + # next to the later edited SUCCESS. Since the pre-push attestation + # change (#994), synchronize is the event that judges a pipeline-pushed + # head, so it is restored. + types: [opened, edited, synchronize, reopened] branches: - main + # Never create a run for a release-please PR. The job-level author exemption + # below cannot do this: it is evaluated inside a run, and a GITHUB_TOKEN PR's + # run is created in action_required and never starts. + paths-ignore: + - .release-please-manifest.json + - CHANGELOG.md permissions: contents: read + # Lets require-no-mistakes read this PR's LIVE body/head SHA instead of the + # workflow's own cached event payload, which a job rerun replays verbatim + # from its original trigger. Without this the gate fails closed rather than + # certifying from the possibly-stale event payload. See + # .github/actions/require-no-mistakes/README.md. + pull-requests: read # GitHub concurrency groups retain at most one pending run, replacing older # pending runs even when cancel-in-progress is false. Give body-bearing events @@ -31,6 +43,7 @@ jobs: # Known automation accounts are exempt so automation keeps working: # - github-actions[bot] opens PRs via GITHUB_TOKEN (release-please) # - dependabot[bot] opens dependency update PRs + # - release-please[bot] opens the release PR when it uses its own app token # Other authors (human or bot) must raise PRs through `git push no-mistakes`. # # These stay job-level rather than moving to the action's `exempt-authors` @@ -40,7 +53,8 @@ jobs: # repository's gate already produces for those authors. if: >- github.event.pull_request.user.login != 'github-actions[bot]' && - github.event.pull_request.user.login != 'dependabot[bot]' + github.event.pull_request.user.login != 'dependabot[bot]' && + github.event.pull_request.user.login != 'release-please[bot]' steps: # The enforcement itself lives in the shared composite action in the # no-mistakes repository, so this repository no longer carries its own @@ -50,4 +64,4 @@ jobs: # pull request this gate is judging. Bumping the pin is a separate, # deliberate pull request. - name: Verify no-mistakes signature and pipeline attestation in PR body - uses: kunchenguid/no-mistakes/.github/actions/require-no-mistakes@32d396ac0f29135daf7fcb9964aba9d5f4e796d6 # post-v1.57.1, untagged (action added in #819) + uses: kunchenguid/no-mistakes/.github/actions/require-no-mistakes@f6441c96c352a18b9cadcaef6b6c7017e9ac3970 # v1.80.1 From c16b85e62d180fc5c0943eb73c86c62370a4696b Mon Sep 17 00:00:00 2001 From: kunchenguid Date: Mon, 21 Sep 2026 16:47:03 -0700 Subject: [PATCH 2/2] ci: ignore package.json on the no-mistakes required check Release-please node releases bump package.json, so omitting it from paths-ignore still starts the GITHUB_TOKEN run this filter is meant to prevent. --- .github/workflows/no-mistakes-required.yml | 1 + 1 file changed, 1 insertion(+) diff --git a/.github/workflows/no-mistakes-required.yml b/.github/workflows/no-mistakes-required.yml index 529de840..98e2267b 100644 --- a/.github/workflows/no-mistakes-required.yml +++ b/.github/workflows/no-mistakes-required.yml @@ -18,6 +18,7 @@ on: paths-ignore: - .release-please-manifest.json - CHANGELOG.md + - package.json permissions: contents: read