From e4c67b9aeb392c560d47323ce31ad7b24295d417 Mon Sep 17 00:00:00 2001 From: Filip Masar Date: Thu, 24 Sep 2026 13:49:36 +0200 Subject: [PATCH] fix(agents-md): skip release, hotfix and back-merge PRs The gate only knew about drafts, forks and `[bot]` authors, so it ran on apify/apify-slack-app#146 (release/v0.27.0 -> master) and pushed a doc commit onto the release branch. Those PRs re-present commits already reviewed on the trunk: there is nothing to correct, and the commit ships unreviewed. Skips head branches prefixed release/, hotfix/ or sync-, and authors that are automation without the `[bot]` suffix. Both are workflow_call inputs, so a repo naming those branches differently can override them. Co-Authored-By: Claude Opus 5 --- .github/workflows/agents-md-maintenance.yml | 34 +++++++++++++++++++++ 1 file changed, 34 insertions(+) diff --git a/.github/workflows/agents-md-maintenance.yml b/.github/workflows/agents-md-maintenance.yml index b96d6fe0..157eda10 100644 --- a/.github/workflows/agents-md-maintenance.yml +++ b/.github/workflows/agents-md-maintenance.yml @@ -19,11 +19,29 @@ name: Keep AGENTS.md accurate (reusable) # secrets: # ANTHROPIC_API_KEY: ${{ secrets.YOUR_ANTHROPIC_API_KEY }} # +# It runs on topic branches only. A release or back-merge PR only moves commits that were already +# reviewed on the trunk, so there is nothing new to document, and a commit pushed to a release +# branch would ship without review. Those branches are skipped, as are automation accounts whose +# name doesn't end in `[bot]`. Both lists are inputs, below. +# # The repo must keep the doc in AGENTS.md, with CLAUDE.md a regular file whose first line is # `@AGENTS.md`. Anything else fails the run — see the Gate step. on: workflow_call: + inputs: + skip_head_ref_prefixes: + description: >- + Don't run on a pull request whose branch name starts with one of these. + Separate them with spaces or commas. + type: string + default: 'release/ hotfix/ sync-' + skip_authors: + description: >- + Don't run on a pull request opened by one of these users. Separate them with spaces or + commas. Accounts ending in `[bot]` are always skipped, whatever this is set to. + type: string + default: 'apify-service-account' secrets: ANTHROPIC_API_KEY: required: true @@ -61,6 +79,10 @@ jobs: id: gate env: HEAD_SHA: ${{ github.event.pull_request.head.sha }} + HEAD_REF: ${{ github.event.pull_request.head.ref }} + PR_AUTHOR: ${{ github.event.pull_request.user.login }} + SKIP_PREFIXES: ${{ inputs.skip_head_ref_prefixes }} + SKIP_AUTHORS: ${{ inputs.skip_authors }} run: | set -euo pipefail @@ -70,6 +92,18 @@ jobs: echo "run=false" >> "$GITHUB_OUTPUT"; exit 0 fi + # Before the layout check, so a PR we skip can't fail on a layout it didn't break. + for p in ${SKIP_PREFIXES//,/ }; do + case "$HEAD_REF" in "$p"*) skip="branch $HEAD_REF" ;; esac + done + for a in ${SKIP_AUTHORS//,/ }; do + case "$PR_AUTHOR" in "$a") skip="author $PR_AUTHOR" ;; esac + done + if [ -n "${skip-}" ]; then + echo "Skipping: $skip is on the skip list." + echo "run=false" >> "$GITHUB_OUTPUT"; exit 0 + fi + # checks the correct layout layout_ok=true if [ ! -f AGENTS.md ] || [ -L AGENTS.md ] || [ ! -s AGENTS.md ]; then