fix(ci): stop the skipped PR-run mirror from satisfying Required PR Check - #346
Merged
Merged
Conversation
…heck On an in-repo feature PR, the `pull_request` run of ci.yml skips the `required-check` job because the push run owns the status. A skipped job still posts a check run under its name, and GitHub treats a skipped required check as satisfied. The push run's real mirror is only created once `ci` finishes, so for the whole test window the only check named `✅ Required PR Check` on the head SHA was the skipped one — the ruleset (and auto-merge) let the PR merge while tests were still running, gated only by CodeQL. Seen on CLDMV/slothlet#553. Give the job a conditional name: the real name on the paths that run, `⏭️ Required PR Check (reported by the push run)` on the skipped path, so the required check stays pending until the push run reports. Applied to the consumer template and to this repo's local-ci.yml.
Shinrai
approved these changes
Oct 2, 2026
Shinrai
added a commit
that referenced
this pull request
Oct 2, 2026
) ## 🚀 What's Changed ### 💥 Breaking Changes _No breaking changes_ ### ✨ Features _No new features_ ### 🐛 Bug Fixes - #346 - fix(ci): stop the skipped PR-run mirror from satisfying Required PR Check (6bcf11d) ### 📦 Dependencies _No dependency updates_ ### 🔧 Other Changes - #346 - docs(ci): note that a skipped job's expression name is shown unevaluated (f8dcf5a) <details> <summary>👥 Contributors</summary> - @Shinrai </details> <!-- co-authors --> Co-authored-by: Shinrai <Shinrai@users.noreply.github.com> --------- Co-authored-by: Shinrai <Shinrai@users.noreply.github.com> Co-authored-by: Nathaniel H <7722267+Shinrai@users.noreply.github.com> Co-authored-by: cldmv-bot[bot] <230771808+cldmv-bot[bot]@users.noreply.github.com>
Shinrai
added a commit
to CLDMV/io-kasa-api
that referenced
this pull request
Oct 2, 2026
On an in-repo feature PR, the `pull_request` run skips the `required-check` job because the push run owns the status. A skipped job still posts a check run under its name, and GitHub treats a skipped required check as satisfied. The push run's mirror is only created once `ci` finishes, so for the whole test window the only `✅ Required PR Check` on the head SHA was the skipped one, and the PR could merge while tests were still running. Give the job a conditional name so the skipped path posts under a different name and the required check stays pending until the push run reports. Synced from CLDMV/.github#346.
cldmv-bot Bot
added a commit
to CLDMV/fix-headers
that referenced
this pull request
Oct 3, 2026
# @cldmv/fix-headers v2.1.3 Changelog **Release Date**: October 2026 **Release Type**: Patch **Branch**: `release/2.1.3` --- ## Overview Version 2.1.3 is a CI and tooling release with no runtime change. The `✅ Required PR Check` mirror job in `ci.yml` no longer satisfies the branch ruleset while it is skipped, which closes a window in which an in-repo pull request could be merged before its tests had finished. Four development dependencies move to their current releases through the lockfile; `ignore`, the only runtime dependency, is unchanged. No source file changes, so `dist/`, `bin/` and the `fixHeaders` API are the same as in v2.1.2. The two patch releases before this one, [v2.1.1](https://github.com/CLDMV/fix-headers/releases/tag/v2.1.1) (a header-only file ends with the header instead of trailing margin lines; `esbuild` 0.28.2) and [v2.1.2](https://github.com/CLDMV/fix-headers/releases/tag/v2.1.2) (the repository adopts the shared CLDMV fix-headers config and stamps uniform file headers), shipped without a changelog file; their notes are on their GitHub Releases. --- ## 🔧 CI & tooling ### The skipped PR-run mirror no longer satisfies `✅ Required PR Check` ([#111](#111)) An in-repo feature PR gets two `ci.yml` runs on the same commit: a `push` run on the head branch and a `pull_request` run. The `pull_request` run skips the `required-check` job, because the push run owns the status on that SHA, but a skipped job still posts a check run under its name, and GitHub treats a skipped required check as satisfied. The push run's real mirror is only created once `ci` finishes, so for the whole test window the only `✅ Required PR Check` on the head SHA was the skipped one: the ruleset read green, and a PR with auto-merge enabled could merge while its tests were still running, or over a red result. The job's `name:` is now an expression. On every path that actually runs (push events, fork PRs, and the `next` and `hotfixes` release PRs) it evaluates to `✅ Required PR Check`; on the skipped path it does not carry the required name, so the check stays pending until the push run reports. The condition in the name is written out to match the job's `if:` exactly. Synced from the `CLDMV/.github` template change in [CLDMV/.github#346](CLDMV/.github#346). ## 📚 Documentation - **NEW:** [docs/changelog/v2/v2.1.3.md](./v2.1.3.md) — this changelog. - README **What's New**: v2.1.3 is the new Latest, and the v2.1.1 and v2.1.2 releases, which shipped without a README entry, are listed under Recent Releases. ## 🔧 Dependencies Development dependencies only; each PR moves the resolved versions in `package-lock.json` and leaves the `package.json` ranges unchanged. - `@cldmv/eslint-plugin-jsonv` 1.0.10 → 1.0.13 and `@cldmv/jsonv` 1.0.9 → 1.1.1 ([#109](#109)). - `@cldmv/prettier-plugin-jsonv` 1.0.6 → 1.1.0 and `@cldmv/vitest-runner` 1.4.2 → 1.5.1 ([#114](#114)). The prettier plugin's 1.1.0 fixes lossy `.jsonv` formatting (identifier keys printed as `[object Object]`, comments dropped); this repository has no `.jsonv` files, so the bump only keeps the lint and format toolchain current. - `ignore`, the only runtime dependency, is unchanged. --- ## Upgrade notes - No breaking changes: drop-in for v2.1.2. No runtime code changed and no option was added or removed. <details> <summary>👥 Contributors</summary> - @Shinrai </details> --- <!-- coverage-start -->  | Metric | Coverage | |--------|----------| | Statements | 100.0% | | Branches | 100.0% | | Functions | 100.0% | | Lines | 100.0% | *Avg: **100.0%** · `7d71608` · Node lts/** <!-- coverage-end --> <!-- co-authors --> Co-authored-by: Shinrai <Shinrai@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
🚀 What's Changed
💥 Breaking Changes
No breaking changes
✨ Features
No new features
🐛 Bug Fixes
📦 Dependencies
No dependency updates
🔧 Other Changes
👥 Contributors