Skip to content

ci: run the five gates on pull requests — the merge-gated regime's prerequisite - #8

Merged
ascalva merged 1 commit into
mainfrom
workflow/ci-on-prs
Jul 28, 2026
Merged

ci: run the five gates on pull requests — the merge-gated regime's prerequisite#8
ascalva merged 1 commit into
mainfrom
workflow/ci-on-prs

Conversation

@ascalva

@ascalva ascalva commented Jul 28, 2026

Copy link
Copy Markdown
Owner

What

Adds pull_request: (base: main) to ci.yml and retires the stale header comment that still cited the Item 11b park — its condition (the D4 origin re-point) landed 2026-07-12.

Why now

The owner's ruling this morning: many independent orchestrators produce PRs; auditors + owner at merge are THE gate, enforced externally; pushes to main become illegal on the GitHub side. Under that ruleset, merges are the only ingestion — so the verdict must exist on the PR surface, before landing. This is the sequencing prerequisite: CI-on-PRs first, then the ruleset (require PR + code-owner approval + required status checks + no bypass), then the identity split (finding-0276: a scoped credential so the ruleset cannot be edited by the thing it binds).

Notes

🤖 Generated with Claude Code

https://claude.ai/code/session_01GTYQT2QsWskJW4HmgobyrV

…d for the merge-gated regime

The park condition (the D4 origin re-point) landed 2026-07-12; the stale header
comment was misinformation in a load-bearing file. Under the coming main
ruleset (pushes illegal, merges the only ingestion), PR verdicts become
load-bearing: required status checks read the ratchet on the PR surface, so
every merge carries its verdict before landing. Same five mutually-independent
jobs, no paths filters, concurrency groups keyed per ref so PR runs never
cancel main runs.
@ascalva
ascalva force-pushed the workflow/ci-on-prs branch from 7d93f8f to 9aa0c95 Compare July 28, 2026 17:03
@ascalva
ascalva merged commit 2e19ced into main Jul 28, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant