ci(dependabot): require successful Pages PR checks - #144
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Root cause
Dependabot #143 at
addbc164863be1a8e0934099ecb31af4836403b5has a successfulBuild Pagescheck but a skippeddeploycheck. The existing strict gate succeeded because it exempted that skipped check. A skipped applicable check must not be accepted for dependency auto-merge.Repair
.github/workflows/pages.yml: keep the release-only Pages deployment on main, without creating a skipped deploy check on PRs..github/workflows/pages-check.yml: run the same Pages build and artifact validation on PRs; retain theBuild Pagescheck..github/workflows/dependabot-automerge.yml: require every observed exact-head check to succeed and fix the jq grouping so it evaluates the check-run array, not a boolean.Commit:
ci(dependabot): require successful Pages PR checks(28946e201f643fde22e94428785a78dea0619b2e). No release or check bypass.Local validation
All commands exited 0 in an isolated clone, using external-drive storage at
/Volumes/Code/Sources/.dev-storage/mathematic-inc-monitor/2026-09-26T1500Z-full.Hca07d:mise installlogs/ts-japi-mise-install.logpnpm install --frozen-lockfilelogs/ts-japi-pnpm-install.loghk check --all --slowlogs/ts-japi-hk-full.logpnpm typechecklogs/ts-japi-typecheck.logpnpm buildlogs/ts-japi-build.logpnpm testlogs/ts-japi-test.logpnpm pack --dry-runlogs/ts-japi-pnpm-pack-dryrun.logpnpm audit --audit-level highlogs/ts-japi-audit.logmise exec node@20.0.0 -- node --input-type=module -e "const api = (await import('./lib/index.js')).default; const document = await new api.Serializer('users').serialize({ id: '1', name: 'Ada' }); if (document.data?.type !== 'users' \|\| document.data?.id !== '1') process.exit(1);"logs/ts-japi-node20-runtime.logmise exec node@20.0.0 -- npm pack --dry-runlogs/ts-japi-node20-npm-pack-dryrun.logactionlinton the three changed workflowslogs/ts-japi-actionlint.logThe gate's jq filter was tested against the live #143 check-run payload: a skipped
deployreturned false; changing only that conclusion to success returned true. The PR must still pass every exact-head check and repository rule before merging.