docs(merge-policy): explain why PR Governance / Canonical issue and evidence are absent from gate 2 - #1766
Merged
Merged
Conversation
Contributor
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Closed
3 tasks
…esolution (#1436) Co-authored-by: groupthinking <154503486+groupthinking@users.noreply.github.com>
Copilot
AI
changed the title
[WIP] Fix governance escape paths report success on job-level check
docs(merge-policy): explain why PR Governance / Canonical issue and evidence are absent from gate 2
Sep 8, 2026
groupthinking
approved these changes
Sep 12, 2026
groupthinking
marked this pull request as ready for review
September 12, 2026 09:46
Contributor
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Contributor
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.Snapshot WarningsEnsure that dependencies are being submitted on PR branches and consider enabling retry-on-snapshot-warnings. See the documentation for more information and troubleshooting advice. Scanned FilesNone |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Canonical issue
Outcome
Anyone auditing the escape-path topology described in the issue (job-level
Canonical issue and evidencereportingsuccesswhile only the customPR Governancecheck carried the honestneutral) now finds, directly inMERGE_POLICY.mdgate 2, why neither name appears in the required-checks list and what to do if a similar gate is ever reintroduced.Scope
MERGE_POLICY.mdgate 2.pr-governance.yml(the sole source of both check names) was already retired outright by Remove retired PR Governance gate #1665, so the reported defect can no longer occur in this repo.Investigation:
pr-governance.yml/Canonical issue and evidencehistory and confirmed the gate was removed entirely (not narrowed) by Remove retired PR Governance gate #1665, which also stripped both names fromMERGE_POLICY.mdgate 2 and deleted its test file.Change:
trivy/Trivycase-sensitivity trap in gate 2, explaining the original defect, why the omission is deliberate, and requiring that any future canonical-issue gate name its authoritative check here before it's added to branch protection.Risk
git revert, no migration or config impact.Verification
test_required_checks_match_merge_policy(regex-parses gate 2's required list — confirmed unaffected by the new paragraph) plus fulltest_dependabot_automation_workflow.pyandtest_gh_aw_workflow_governance.pysuites.Production evidence
Not applicable — documentation-only change to
MERGE_POLICY.md, no runtime or code surface touched.Agent handoff
successon the job-level check, not "not applicable" #1436