Skip to content

ci: add core product validation merge gate - #2477

Merged
codeforester merged 2 commits into
mainfrom
ci/2452-20261005-core-product-merge-gate
Oct 6, 2026
Merged

codeforester merged 2 commits into
mainfrom
ci/2452-20261005-core-product-merge-gate

Conversation

@codeforester

@codeforester codeforester commented Oct 5, 2026 •

Copy link
Copy Markdown
Collaborator

Partially addresses #2452

Summary

  • Add an always-reported Core product validation job to the existing Tests workflow.
  • Require representative Python, BATS, integration, stable-compatibility, and security lanes; failed, cancelled, or skipped dependencies fail the aggregate.
  • Document the platform lanes that remain outside the aggregate and preserve the existing human-approval policy.

The live repository ruleset still needs a separately authorized settings change after this check has produced a trusted successful run. The exact check context is Core product validation.

Validation

  • pytest tests/test_github_workflows.py -q — 24 passed
  • git diff --check

The issue remains open for the live ruleset update and readback.

@codeforester
codeforester requested a review from a team as a code owner October 5, 2026 14:06
@codeforester
codeforester force-pushed the ci/2452-20261005-core-product-merge-gate branch from 4d292be to b463394 Compare October 5, 2026 14:12
@codeforester
codeforester force-pushed the ci/2452-20261005-core-product-merge-gate branch from b463394 to 2fecaff Compare October 5, 2026 14:12

@codeforester codeforester left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed head 2fecaff against #2452 ("Partially addresses", so the issue stays open for the ruleset change). No blocking findings.

  • if: always() together with an explicit != success check on each dependency is the right aggregate pattern: a failed, cancelled or skipped lane fails the gate, so the check can't go green when a lane didn't run. None of the five needed jobs has a job-level if:, so docs-only PRs won't make the gate fail by default.
  • needs.python.result covers the whole Python matrix, so any failing version fails the gate.
  • CI is green (22/22), including the new job.

One sequencing note is inline: the doc text describes repo configure behavior that only exists once #2478 lands.

Comment thread docs/repo-baseline.md
compatibility evidence outside this aggregate, while Project Intake remains
advisory. After the workflow has produced a trusted successful status, the
repository owner may explicitly add the exact `Core product validation` check
to the default-branch ruleset. `basectl repo configure` preserves that

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sequencing (non-blocking): "basectl repo configure preserves that additional required check" is only true after #2478 (preserve existing repository protections) merges. On current main, repo configure rebuilds the ruleset from Base's template, which is the bug #2451 tracks. Either merge #2478 first, or soften this sentence until it lands. Otherwise an owner who adds Core product validation to the ruleset and later runs repo configure would lose it.

@codeforester
codeforester merged commit cc800eb into main Oct 6, 2026
23 checks passed
@codeforester
codeforester deleted the ci/2452-20261005-core-product-merge-gate branch October 6, 2026 08:08
codeforester added a commit that referenced this pull request Oct 6, 2026
## Summary

- Fixes #2480 by documenting the ordering dependency around custom
required checks.
- Warns that older Base revisions can replace the named ruleset and
remove a manually added check when `repo configure` is rerun.
- Makes preservation a documented prerequisite while keeping `Core
product validation` an explicit repository-owner decision.
- Resolves the merge conflict with the current `main` documentation for
the aggregate validation status.

## Issue

Fixes #2480

Follow-up to #2477; the wording addresses the review comment about
preserving `Core product validation` before ruleset reconciliation is
available.

## Validation

- `git diff --check`
- `PYTHONPATH="$PWD/cli/python:/Users/rameshhp/work/base-cli/lib/python"
/Users/rameshhp/.base.d/base/.venv/bin/python -m pytest -q
tests/test_contract_hardening.py tests/test_github_workflows.py
cli/python/base_github_projects/tests/test_project_rest.py` — 62 passed.
- Verified the merge commit has `origin/main` as its second parent and
no unmerged paths.

## Notes

Documentation-only change; no runtime behavior changes. The PR remains
open for hosted checks and review.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant