Skip to content

Six repos require a PR but require nothing to be green; six carry a main-protection.json that was never applied #25

Description

@sotashimozono

What was measured

Every QAtlasHub package repo, 2026-09-01:

repo enforce_admins PR required required status checks
QAtlas.jl true true build, All tests passed, INVENTORY drift guard, format-check
TestShards.jl true true version / check-version, format / format-check, test / All shards passed
ExperimentalAPI.jl true true 6 contexts (version, format, 3 julia legs, docs)
Pinax.jl true true none
DataVault.jl true true none
ParamIO.jl true true none
Archeion.jl true true none
AbstractQAtlas.jl true true none
ParallelManager.jl true true none

The gap

Six repos require a pull request and enforce it on admins — that part is right and already in
place. What they do not require is that anything be green.

A PR whose CI is fully red is mergeable in those six. The gate reads as protection and is only
half of one: it stops an unreviewed direct push, and stops nothing about correctness. QAtlas.jl
and TestShards.jl show the intended shape, so this is drift rather than a decision.

Fixing it is per-repo, because the context names differ: each repo's required set has to be read
off its own recent PR (gh api repos/OWNER/REPO/commits/SHA/check-runs) rather than copied, and
a required context that never runs leaves the branch permanently unmergeable — the failure mode
already documented for paths:-filtered required checks.

Worth deciding at the same time: required_linear_history is true only on TestShards.jl and
ExperimentalAPI.jl, false on the other seven.

Dead template files

Six repos carry .github/rulesets/main-protection.json:

  • AbstractQAtlas.jl, DataVault.jl, ParallelManager.jl, ParamIO.jl, Pinax.jl, QAtlas.jl

None of them has a ruleset applied (all report zero), so the file has never been in effect. It
requires a status check named build, which exists in QAtlas.jl but not in the others — so
applying it as written would make five repos unmergeable.

Five of those also carry .github/scripts/setup_project.jl, which still renames MyModule and
is scaffolding from the template these repos were generated from.

Both read as configuration to anyone opening the directory. A file that looks like branch
protection and has never been applied is worse than no file, because it answers the question
"is this repo protected?" wrongly.

Proposal: delete both from all six, and keep protection where it is actually enforced — the
repository settings — rather than in a JSON nobody applies.

Note

This corrects an earlier reading in which these repos looked unprotected. They are protected;
gh api .../rulesets returns empty for them because the protection is classic branch protection,
not a ruleset, and checking only the ruleset endpoint answered a different question than the one
being asked.

Activity

  1. sotashimozono commented on Sep 10, 2026

    @sotashimozono
    MemberAuthor

    Re-measured 2026-09-10. Still live, and the table has moved in three ways.

    repo PR required required status checks
    doiget yes 6
    QAtlas.jl yes 4
    ExperimentalAPI.jl yes 3
    TestShards.jl yes 3
    AbstractQAtlas.jl yes 0
    Archeion.jl yes 0
    DataVault.jl yes 0
    ParamIO.jl yes 0
    Pinax.jl yes 0
    SweepRunner.jl yes 0
    .github yes 0
    doiget-citation-check yes 0
    QAtlasHub.github.io yes 0
    QAtlasRegistry no 0
    templateHPC.jl no 0

    What changed since 2026-09-01:

    1. ParallelManager.jl is now SweepRunner.jl — same repo, renamed. Still zero.
    2. Three repos joined the zero column that were not in the original table: .github, doiget-citation-check, QAtlasHub.github.io.
    3. ExperimentalAPI.jl's six contexts became three, and that was a fix rather than a loosening. It required each matrix leg by name — and julia 1.12 — macos-latest was not among them, so macOS had been ungated since it was added. It now requires the aggregate All tests passed, which is needs: test with if: always(): it fails when any leg fails, stays green for a failing nightly (continue-on-error keeps it out of needs.test.result), and gates a new Julia version automatically.

    That third row is the shape worth copying to the nine: require the aggregate, not the legs. Requiring legs by name is how a matrix silently grows past its gate.

    [noblock]

  2. sotashimozono commented on Sep 29, 2026

    @sotashimozono
    MemberAuthor

    Re-measured 2026-09-29 and closed out.

    Required checks

    Since the 2026-09-10 re-measure, DataVault, SweepRunner, ParamIO, Pinax, Archeion and AbstractQAtlas had each gained an aggregate required check (test / All shards passed, or ci / ci-lts for AbstractQAtlas). Two repos still required nothing:

    repo change now required
    .github actionlint ran only on PRs touching workflows, so a README-only PR (#28) reported no check; it now runs on every PR (#31) actionlint
    doiget-citation-check added an aggregate All checks passed (needs: [smoke, encoding, titles], if: always()) rather than requiring the three jobs by name (QAtlasHub/doiget-citation-check#5) All checks passed

    Both were set with the rest of the existing protection (PR required, enforce_admins, no force-push or deletion) left as it was. QAtlasHub.github.io has no workflows at all, so there is nothing to require there yet.

    Dead template files — removed

    .github/rulesets/main-protection.json (never applied) and .github/scripts/setup_project.jl (template scaffold) were removed from every repo that had them, which by now was seven: AbstractQAtlas#165, Archeion#88 (JSON only), DataVault#76, ParamIO#41, Pinax#156 (also .github/workflows/init.yml, the template's one-shot init job that has been skipped on every run since the first), QAtlas#858, SweepRunner#62. Each was checked with git grep for references first.

    required_linear_history

    Left as it is (true on TestShards and ExperimentalAPI, false elsewhere). The other repos merge with merge commits (Merge pull request #…), which linear history would forbid, so turning it on is a change of merge policy rather than a gap in protection.

    Not done here

    doiget requires test (windows-latest), test (ubuntu-latest) and test (slow) by name, while test (macos-latest), test (citation feature) and test (tdm features) also run but are not required: the matrix has grown past its gate, which is exactly the failure mode described above. The fix is an aggregate job in doiget's CI, which has to follow its own DCO and ADR-0033 process, so it is on hold for now.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions