Repository navigation
Unblock required-workflow source repository PRs without weakening organization gates #732
Description
Activity
seonghobae commented
on Aug 4, 2026 ContributorAuthorMore actionsFresh evidence on 2026-08-04: #731 is back on its clean exact source head
c73ee47861fca21e6959ce80fdf57b434c715c9d. Seven of the eight direct PR workflows have a fresh successful run; the remaining CodeQL run is queued, while earlier exact-head CodeQL runs are successful. A guarded merge still reportsNew changes require approval from someone other than the last pusherplus four unsatisfied required contexts, including one expected ruleset workflow. GitHub's ruleset troubleshooting guidance also says ruleset workflows should not usecancel-in-progress; both current OpenCode and Noema entrypoints do. The source-repository configuration/evaluate-mode decision remains necessary before the clean bootstrap can merge without synthesizing statuses.- addedarea: apiAPI, protocol, event, or external contractAPI, protocol, event, or external contractarea: authAuthentication, authorization, identity, or tenant isolationAuthentication, authorization, identity, or tenant isolationarea: ci-cdCI, GitHub Actions, checks, release, or supply chainCI, GitHub Actions, checks, release, or supply chainarea: securitySecurity boundary, hardening, or vulnerability preventionSecurity boundary, hardening, or vulnerability preventionpriority: mediumNormal-priority or P2 workNormal-priority or P2 workstatus: triagedOpen issue has an organization taxonomy assignmentOpen issue has an organization taxonomy assignmenttype: featureNew or expanded product capabilityNew or expanded product capability
on Aug 22, 2026 seonghobae commented
on Aug 28, 2026 ContributorAuthorMore actionsFresh source-repository canary for the existing bootstrap/review deadlock, without changing ownership or requesting bypass.
Current protected central source:
.github/main@24ee38b097dbfc1a895e1199ade48cff36431d05.
Current repair consumer:.github#897@4553da875f2799b39e1c89aeb89f552d9fb92564, Ready and mechanically mergeable against that exact base.The product/security repair itself is exact-head GREEN: Security Scan
33141727347, dependency-review job98753825077, checked out and verified the submitted head, the support probe succeeded, and the pinnedDependency reviewaction executedsuccessrather than being skipped.The first remaining causal boundary is now the source-repository review path: required OpenCode run
33141725355, job98755817116, fails closed because no authenticatedAPPROVEDorCHANGES_REQUESTEDOpenCode review is anchored to current head4553da8.... The formal review inventory contains only predecessor-head OpenCode verdicts; none may transfer. A fresh@opencode-agentexact-head request has been posted on #897 and has not yet produced a current-head formal verdict.RED acceptance for #732: an unchanged, technically clean
.githubsource-repository PR can still reach the required OpenCode workflow with no current-head Reviews-API verdict, leaving the bootstrap repair non-integrable.Smallest safe remedy/GREEN: make the supported central source-repository review/dispatch path emit a genuine exact-current-head formal verdict for
4553da8...(and the corresponding required context) under the existing reviewer identity and permissions. Do not synthesize a status, transfer a predecessor review, self-approve, use admin/ruleset bypass, or weaken the independent-review requirement. After that, refetch all current-head checks/reviews before any normal integration decision.- addedbugSomething isn't workingSomething isn't workingtype: bugDefect or incorrect behaviorDefect or incorrect behavior
on Sep 7, 2026
Incident
The organization ruleset requires the OpenCode and Noema workflows sourced from
ContextualWisdomLab/.github, and the ruleset also targets the.githubrepository's own default branch. A central bootstrap repair therefore cannot currently satisfy the two workflow contexts sourced from the same repository.Exact example: PR #731, head
c73ee47861fca21e6959ce80fdf57b434c715c9d.2 of 15 required status checks are expectedandNew changes require approval from someone other than the last pusher;GitHub's documented source-repository boundary
GitHub's ruleset troubleshooting documentation calls out required-workflow source repositories explicitly. For workflows intended to run through a ruleset, GitHub recommends choosing a deliberate source-repository configuration, such as adding an unconditional job condition, disabling the local workflow in the source repository, or disabling Actions there. It also recommends Evaluate mode or an authorized bypass for bootstrap situations where the required workflow cannot run.
Primary documentation:
Required administrative decision
Choose and implement one fail-closed pattern for the
.githubsource repository:ContextualWisdomLab/.githubfrom the organization required-workflow targets while keeping its direct CodeQL/Semgrep/Security/Python/OSV/Scorecard/Secret/SBOM checks plus independent review rules; or.githubPRs.Do not synthesize statuses, remove independent review, or weaken the organization rules for target application repositories.
Acceptance evidence
newsdom-api#467is then re-reviewed through the repaired central coverage path and merges without a manual bypass;docs/org-required-workflow-rollout.mdand covered by a contract test where repository-level configuration can be represented in source.