-
-
Notifications
You must be signed in to change notification settings - Fork 0
[estate] audit Base ruleset across repos for unsatisfiable rules that force bypass merges #473
Copy link
Copy link
Open
Labels
cicdCI/CD: workflows, actions, lockfiles, pins, runners, release gatesCI/CD: workflows, actions, lockfiles, pins, runners, release gatespriority:p1High - schedule nextHigh - schedule nextscope:estateAffects many or all repos across the estateAffects many or all repos across the estatestatus:readyFully specified and ready to be picked upFully specified and ready to be picked uptri/controlSafety triangle — gate it so it cannot regressSafety triangle — gate it so it cannot regress
Description
Activity
Metadata
Metadata
Assignees
Labels
cicdCI/CD: workflows, actions, lockfiles, pins, runners, release gatesCI/CD: workflows, actions, lockfiles, pins, runners, release gatespriority:p1High - schedule nextHigh - schedule nextscope:estateAffects many or all repos across the estateAffects many or all repos across the estatestatus:readyFully specified and ready to be picked upFully specified and ready to be picked uptri/controlSafety triangle — gate it so it cannot regressSafety triangle — gate it so it cannot regress
Context (estate-scope)
hypatia's
Baseruleset was found to be 100% bypassed on every merge (decorative) because it contained several structurally-unsatisfiable rules that blocked normal PRs, so everything was force-merged via bypass. Fixed in hypatia today by pruning/replacing those rules; first genuine non-bypass merge confirmed (#469).The same
Baseruleset pattern is very likely replicated across many estate repos. Each unsatisfiable rule forces bypass merges, which silently defeats the ruleset's protection.Unsatisfiable-rule patterns to audit per repo
required_deployments: [github-pages]— the pages deploy only runs post-merge, so it can never be satisfied pre-merge → blocks all PRs.code_scanningrule requiring a tool that producesneutralon non-code PRs (CodeQL) → blocks all docs/config PRs. Prefer gating viarequired_status_checkscontexts.code_scanningrequiring Scorecard — Scorecard uploads 0 analyses (estate-wide startup_failure).copilot_code_review— only satisfiable if Copilot code review actually runs.code_quality(preview) — only if it emits results.Action
Audit each repo's active rulesets for the above; remediate per-repo with owner sign-off (this is governance config — do not blanket-change). Track which repos were 100%-bypass before/after via the rule-suites API (
result: bypassvspass).