Repository navigation
ci: add core product validation merge gate - #2477
Conversation
4d292be to
b463394
Compare
b463394 to
2fecaff
Compare
codeforester
left a comment
There was a problem hiding this comment.
Reviewed head 2fecaff against #2452 ("Partially addresses", so the issue stays open for the ruleset change). No blocking findings.
if: always()together with an explicit!= successcheck on each dependency is the right aggregate pattern: a failed, cancelled or skipped lane fails the gate, so the check can't go green when a lane didn't run. None of the five needed jobs has a job-levelif:, so docs-only PRs won't make the gate fail by default.needs.python.resultcovers the whole Python matrix, so any failing version fails the gate.- CI is green (22/22), including the new job.
One sequencing note is inline: the doc text describes repo configure behavior that only exists once #2478 lands.
| compatibility evidence outside this aggregate, while Project Intake remains | ||
| advisory. After the workflow has produced a trusted successful status, the | ||
| repository owner may explicitly add the exact `Core product validation` check | ||
| to the default-branch ruleset. `basectl repo configure` preserves that |
There was a problem hiding this comment.
Sequencing (non-blocking): "basectl repo configure preserves that additional required check" is only true after #2478 (preserve existing repository protections) merges. On current main, repo configure rebuilds the ruleset from Base's template, which is the bug #2451 tracks. Either merge #2478 first, or soften this sentence until it lands. Otherwise an owner who adds Core product validation to the ruleset and later runs repo configure would lose it.
## Summary - Fixes #2480 by documenting the ordering dependency around custom required checks. - Warns that older Base revisions can replace the named ruleset and remove a manually added check when `repo configure` is rerun. - Makes preservation a documented prerequisite while keeping `Core product validation` an explicit repository-owner decision. - Resolves the merge conflict with the current `main` documentation for the aggregate validation status. ## Issue Fixes #2480 Follow-up to #2477; the wording addresses the review comment about preserving `Core product validation` before ruleset reconciliation is available. ## Validation - `git diff --check` - `PYTHONPATH="$PWD/cli/python:/Users/rameshhp/work/base-cli/lib/python" /Users/rameshhp/.base.d/base/.venv/bin/python -m pytest -q tests/test_contract_hardening.py tests/test_github_workflows.py cli/python/base_github_projects/tests/test_project_rest.py` — 62 passed. - Verified the merge commit has `origin/main` as its second parent and no unmerged paths. ## Notes Documentation-only change; no runtime behavior changes. The PR remains open for hosted checks and review.
Partially addresses #2452
Summary
Core product validationjob to the existing Tests workflow.The live repository ruleset still needs a separately authorized settings change after this check has produced a trusted successful run. The exact check context is
Core product validation.Validation
pytest tests/test_github_workflows.py -q— 24 passedgit diff --checkThe issue remains open for the live ruleset update and readback.