Skip to content

ci: a commit speaks for its author alone, and CI reads it - #97

Merged
rodrigoteamx merged 3 commits into
mainfrom
ci/message-gate
Oct 7, 2026
Merged

rodrigoteamx merged 3 commits into
mainfrom
ci/message-gate

Conversation

@rodrigoteamx

@rodrigoteamx rodrigoteamx commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

CI read the code and never the words that travel with it: a commit
message, and the title and body of a pull request. The title becomes
the commit when the pull request is squashed, and the body stays
public beside it. The message gate now reads them, as a step of the
job that branch protection already requires, so a refused text blocks
the merge the way a failing test does.

The gate is the family's one copy and lives in getmilpa/devtools. It
refuses a co-author trailer for an identity the house does not list, a
generator signature and a session reference, and it ends red when it
cannot read.

Two things change around it. CI also runs when a pull request is
edited, because its text can change after the last push. And the token
may read pull requests.

CI read the code and never the words that travel with it: a commit
message, and the title and body of a pull request, which become the
commit when it is squashed. The message gate now reads them, as a step
of the job that branch protection already requires, so a refused text
blocks the merge the way a failing test does.

The gate is the family's one copy and lives in getmilpa/devtools. It
refuses a co-author trailer for an identity the house does not list, a
generator signature and a session reference, and it ends red when it
cannot read.

Three things change around it. CI also runs when a pull request is
edited, because its text can change after the last push. The token may
read pull requests. And there is one run per pull request, so a newer
event replaces the run it makes stale.
… squash carries

Grouping runs by pull request let a run for an older commit, started
later by a re-run or an approval, cancel the run of the newest commit
and leave its checks cancelled. The group is now the pull request and
its head commit: an edit of the title or the body still replaces the
run it makes stale, and a run for another commit is left alone.

The comment on `edited` said the body becomes the squashed commit. It
no longer does: the title does, and the body stays public beside it,
which is why the gate still reads both.
…ys finishes

Branch protection takes, for each check, the run of the latest event on
a commit. Grouping runs to cancel the stale one could cancel that very
run: when two events reached the same commit within a second, the run
of the earlier one sometimes survived, and the pull request stayed
blocked with a green run on its head. It happened in 2 of the 37 pull
requests of this change. Without the group every run finishes and the
latest event decides, which is what was wanted in the first place.
@rodrigoteamx
rodrigoteamx merged commit 232cd0c into main Oct 7, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant