Skip to content

feat: Configure draft pull request scanning across trigger modes - #113

Merged
julio-rocketchat merged 2 commits into
developfrom
feat/draft-scan-policy
Sep 26, 2026
Merged

julio-rocketchat merged 2 commits into
developfrom
feat/draft-scan-policy

Conversation

@julio-rocketchat

Copy link
Copy Markdown
Member

Summary

  • Add trigger.scanOnDraft with global and repository overrides.
  • Handle ready_for_review events.
  • Check live draft state before scans deferred to workflow_run/workflow_job.

Breaking default and migration

Draft PRs are skipped by default. Set trigger.scanOnDraft: true to preserve draft scanning. Deferred workflows must subscribe to ready_for_review to start their gate when a PR becomes ready. A major changeset records this default change.

Verification

  • Node 22: build, typecheck, lint, config validation, all 633 tests passed.
  • Regression tests cover draft/ready transitions, both deferred trigger modes, opt-in scanning, inheritance, and invalid config values.
  • Security review checked signature verification, live-state gating, queue admission and boolean validation. Gitleaks staged-patch scan passed.
  • Only this feature was extracted; the public configuration remains the baseline.

@julio-rocketchat

Copy link
Copy Markdown
Member Author

CI follow-up: the shared install failure was reproduced in an isolated Node 22 container. With maintainer approval, this branch now uses npm ci instead of deleting the lockfile and resolving a fresh dependency graph. This is the only CI change; GitHub checks are rerunning.

@julio-rocketchat
julio-rocketchat merged commit 2460a1d into develop Sep 26, 2026
3 checks passed
@github-actions github-actions Bot mentioned this pull request Sep 26, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant