Repository navigation
Six repos require a PR but require nothing to be green; six carry a main-protection.json that was never applied #25
Description
Activity
Re-measured 2026-09-10. Still live, and the table has moved in three ways.
repo PR required required status checks doiget yes 6 QAtlas.jl yes 4 ExperimentalAPI.jl yes 3 TestShards.jl yes 3 AbstractQAtlas.jl yes 0 Archeion.jl yes 0 DataVault.jl yes 0 ParamIO.jl yes 0 Pinax.jl yes 0 SweepRunner.jl yes 0 .github yes 0 doiget-citation-check yes 0 QAtlasHub.github.io yes 0 QAtlasRegistry no 0 templateHPC.jl no 0 What changed since 2026-09-01:
ParallelManager.jlis nowSweepRunner.jl— same repo, renamed. Still zero.- Three repos joined the zero column that were not in the original table:
.github,doiget-citation-check,QAtlasHub.github.io. - ExperimentalAPI.jl's six contexts became three, and that was a fix rather than a loosening. It required each matrix leg by name — and
julia 1.12 — macos-latestwas not among them, so macOS had been ungated since it was added. It now requires the aggregateAll tests passed, which isneeds: testwithif: always(): it fails when any leg fails, stays green for a failingnightly(continue-on-errorkeeps it out ofneeds.test.result), and gates a new Julia version automatically.
That third row is the shape worth copying to the nine: require the aggregate, not the legs. Requiring legs by name is how a matrix silently grows past its gate.
[noblock]
- added a commit that references this issue
on Sep 29, 2026 Re-measured 2026-09-29 and closed out.
Required checks
Since the 2026-09-10 re-measure, DataVault, SweepRunner, ParamIO, Pinax, Archeion and AbstractQAtlas had each gained an aggregate required check (
test / All shards passed, orci/ci-ltsfor AbstractQAtlas). Two repos still required nothing:repo change now required .githubactionlintran only on PRs touching workflows, so a README-only PR (#28) reported no check; it now runs on every PR (#31)actionlintdoiget-citation-checkadded an aggregate All checks passed(needs: [smoke, encoding, titles],if: always()) rather than requiring the three jobs by name (QAtlasHub/doiget-citation-check#5)All checks passedBoth were set with the rest of the existing protection (PR required, enforce_admins, no force-push or deletion) left as it was.
QAtlasHub.github.iohas no workflows at all, so there is nothing to require there yet.Dead template files — removed
.github/rulesets/main-protection.json(never applied) and.github/scripts/setup_project.jl(template scaffold) were removed from every repo that had them, which by now was seven: AbstractQAtlas#165, Archeion#88 (JSON only), DataVault#76, ParamIO#41, Pinax#156 (also.github/workflows/init.yml, the template's one-shot init job that has been skipped on every run since the first), QAtlas#858, SweepRunner#62. Each was checked withgit grepfor references first.required_linear_historyLeft as it is (
trueon TestShards and ExperimentalAPI,falseelsewhere). The other repos merge with merge commits (Merge pull request #…), which linear history would forbid, so turning it on is a change of merge policy rather than a gap in protection.Not done here
doiget requires
test (windows-latest),test (ubuntu-latest)andtest (slow)by name, whiletest (macos-latest),test (citation feature)andtest (tdm features)also run but are not required: the matrix has grown past its gate, which is exactly the failure mode described above. The fix is an aggregate job in doiget's CI, which has to follow its own DCO and ADR-0033 process, so it is on hold for now.
What was measured
Every QAtlasHub package repo, 2026-09-01:
build,All tests passed,INVENTORY drift guard,format-checkversion / check-version,format / format-check,test / All shards passedThe gap
Six repos require a pull request and enforce it on admins — that part is right and already in
place. What they do not require is that anything be green.
A PR whose CI is fully red is mergeable in those six. The gate reads as protection and is only
half of one: it stops an unreviewed direct push, and stops nothing about correctness. QAtlas.jl
and TestShards.jl show the intended shape, so this is drift rather than a decision.
Fixing it is per-repo, because the context names differ: each repo's required set has to be read
off its own recent PR (
gh api repos/OWNER/REPO/commits/SHA/check-runs) rather than copied, anda required context that never runs leaves the branch permanently unmergeable — the failure mode
already documented for
paths:-filtered required checks.Worth deciding at the same time:
required_linear_historyistrueonly on TestShards.jl andExperimentalAPI.jl,
falseon the other seven.Dead template files
Six repos carry
.github/rulesets/main-protection.json:None of them has a ruleset applied (all report zero), so the file has never been in effect. It
requires a status check named
build, which exists in QAtlas.jl but not in the others — soapplying it as written would make five repos unmergeable.
Five of those also carry
.github/scripts/setup_project.jl, which still renamesMyModuleandis scaffolding from the template these repos were generated from.
Both read as configuration to anyone opening the directory. A file that looks like branch
protection and has never been applied is worse than no file, because it answers the question
"is this repo protected?" wrongly.
Proposal: delete both from all six, and keep protection where it is actually enforced — the
repository settings — rather than in a JSON nobody applies.
Note
This corrects an earlier reading in which these repos looked unprotected. They are protected;
gh api .../rulesetsreturns empty for them because the protection is classic branch protection,not a ruleset, and checking only the ruleset endpoint answered a different question than the one
being asked.