Problem
Ruleset 23787415 ("main gate: append-only + required checks + signatures + scanning") required the SonarCloud Code Analysis context (integration 12526). It never reported. It was absent on #1060, #1061, #1062, #1063, #1064, #1067 and #1078.
Because one required context never arrived, every merge to main was a bypass. The owner account holds pull_requests_only bypass on this ruleset, so merges went through silently. The other 21 required checks were enforced only by convention, not by the platform.
Action already taken (2026-09-30, owner ruling)
SonarCloud Code Analysis was removed from 23787415's required_status_checks (22 → 21 contexts; enforcement stays active). The next merge, #1067, recorded rule suite 4296932589 with result: pass, not bypass. So the gate now genuinely enforces its 21 contexts.
What remains: why is SonarCloud silent?
Not yet diagnosed. Candidates to rule in or out:
- whether the SonarCloud GitHub App installation covers
hyperpolymath/standards
- automatic analysis vs a CI-driven scan: is anything actually triggering an analysis on PRs?
- the project binding / organisation key on the SonarCloud side
- whether any workflow runs a Sonar scan with
SONAR_TOKEN (a nonexistent secret resolves EMPTY silently)
Related: campaign #443 (parked).
Acceptance criteria
- The root cause of the silence is stated with evidence (app installation, binding, or trigger).
SonarCloud Code Analysis posts a check-run on at least one PR against main, as a positive control.
- Only after (2), the context is re-added to 23787415. A PR is then merged with rule-suite
result: pass (not bypass), which shows re-adding it did not reintroduce a vacuous gate.
- Alternatively, if SonarCloud is dropped for good, that decision is recorded here and this issue is closed as not-planned.
🤖 Generated with Claude Code
https://claude.ai/code/session_01WPSJ7fBhVAMcpSffCBWUDo
Problem
Ruleset 23787415 ("main gate: append-only + required checks + signatures + scanning") required the
SonarCloud Code Analysiscontext (integration 12526). It never reported. It was absent on #1060, #1061, #1062, #1063, #1064, #1067 and #1078.Because one required context never arrived, every merge to
mainwas a bypass. The owner account holdspull_requests_onlybypass on this ruleset, so merges went through silently. The other 21 required checks were enforced only by convention, not by the platform.Action already taken (2026-09-30, owner ruling)
SonarCloud Code Analysiswas removed from 23787415'srequired_status_checks(22 → 21 contexts; enforcement staysactive). The next merge, #1067, recorded rule suite4296932589withresult: pass, not bypass. So the gate now genuinely enforces its 21 contexts.What remains: why is SonarCloud silent?
Not yet diagnosed. Candidates to rule in or out:
hyperpolymath/standardsSONAR_TOKEN(a nonexistent secret resolves EMPTY silently)Related: campaign #443 (parked).
Acceptance criteria
SonarCloud Code Analysisposts a check-run on at least one PR againstmain, as a positive control.result: pass(notbypass), which shows re-adding it did not reintroduce a vacuous gate.🤖 Generated with Claude Code
https://claude.ai/code/session_01WPSJ7fBhVAMcpSffCBWUDo