Skip to content

feat(github): require a required gate check by default - #294

Merged
UnstoppableMango merged 1 commit into
mainfrom
claude/project-thread-dtaqun
Oct 7, 2026
Merged

UnstoppableMango merged 1 commit into
mainfrom
claude/project-thread-dtaqun

Conversation

@UnstoppableMango

@UnstoppableMango UnstoppableMango commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Requested by Erik · project thread

Before: a PublicRepo with neither githubChecks nor requiredChecks required nothing, and an empty list sent a rule with no checks in it.

After: such a repository requires one check named required, a gate job at the end of its CI whose needs decide what blocks a merge. An empty list requires nothing and omits the rule. terraform2crd, the only repository here with no checks, sets githubChecks: [] so it keeps requiring nothing. This mirrors UnstoppableMango/pulumi-components's new default; folding this local component into pulumi-components is a separate, larger change.

Expected preview: no changes. Every other repository lists its own checks, and terraform2crd's opt-out reproduces what it has today. If pulumi preview shows any ruleset diff, this PR is wrong.

How: when requiredChecks is absent, githubChecks falls back to ['required'], and getRequiredStatusChecks resolves to undefined for an empty list. requiredChecks now wins over githubChecks when both are given; no repository sets both. Checked locally with tsc --noEmit and eslint .; dprint couldn't download its plugins here, so CI's dprint step is the format check.

🤖 Generated with Claude Code

https://claude.ai/code/session_01KMdNARLiCQSWqzHj8WmhQu


Generated by Claude Code

Summary by CodeRabbit

  • Bug Fixes
    • Required status checks now follow a consistent precedence: explicitly configured checks take priority, and otherwise the default required check is used.
    • An explicitly empty check list now means no checks are required, rather than applying the default check.
    • The terraform2crd repository is now configured to require no status checks.

A PublicRepo with neither githubChecks nor requiredChecks now requires one
check named `required`, a gate job at the end of the repository's CI that
fails when any job it needs did. The repository decides what blocks a
merge by editing that job's needs, with no change to this stack. This
mirrors the default in pulumi-components.

An empty list now requires nothing and omits the rule. terraform2crd,
the one repository that requires no checks, sets githubChecks: [] so it
keeps requiring nothing.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KMdNARLiCQSWqzHj8WmhQu
@UnstoppableMango UnstoppableMango self-assigned this Oct 7, 2026
@coderabbitai

coderabbitai Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: d8a8c499-b622-4b59-b546-439e710b7d0a
📥 Commits

Reviewing files that changed from the base of the PR and between e2aa1cd and e0cdc2b.

📒 Files selected for processing (2)
  • github/components/publicRepo.ts
  • github/repos.ts

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

Required status checks now use requiredChecks when provided, otherwise use githubChecks or the default required check. An empty list omits the required status checks rule. The terraform2crd configuration now sets an empty check list.

Changes

Required GitHub checks

Layer / File(s) Summary
Resolve required checks
github/components/publicRepo.ts, github/repos.ts
requiredChecks takes precedence over githubChecks. When neither is provided, the component uses the required check. An empty list omits the status checks rule. The terraform2crd configuration sets githubChecks to an empty list.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Feature

Merge Risk: ⚪ Minimal · up to e0cdc

The change makes a required gate check the default for repositories that configure no checks. All current repositories set their checks explicitly, so merge behavior should stay the same. The only remaining check is the CI preview, which should show no changes.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 2 functions across 2 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly identifies the main change: PublicRepo configurations now require a required gate check by default.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@pulumi

pulumi Bot commented Oct 7, 2026

Copy link
Copy Markdown

🍹 The Update (preview) for UnstoppableMango/unmango-github/prod (at e0cdc2b) was successful.

Resource Changes

    Name                     Type                                                                  Operation
+   RELEASE_APP_PRIVATE_KEY  github:index/actionsOrganizationSecret:ActionsOrganizationSecret      create
+   RELEASE_APP_CLIENT_ID    github:index/actionsOrganizationVariable:ActionsOrganizationVariable  create

@UnstoppableMango
UnstoppableMango merged commit 9a44de4 into main Oct 7, 2026
6 checks passed
@UnstoppableMango
UnstoppableMango deleted the claude/project-thread-dtaqun branch October 7, 2026 13:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants