Finding
.github/workflows/ci.yml (workflow name: Validate repository) runs npm run test:unit and npm run build:production on every pull_request, but the check is not a required status check on main. A PR whose own unit tests fail is still reported as mergeable.
Evidence (2026-09-20, live API):
mergeStateStatus: UNSTABLE (rather than BLOCKED) means the failing check is non-required — if it were required, GitHub would report BLOCKED. Meanwhile main's own Validate repository runs are green (e.g. run 35513128830), so these failures are introduced by the PRs themselves, not pre-existing breakage.
Steps to Reproduce / Evidence
gh pr view 334 --repo cncf/endusers --json mergeable,mergeStateStatus,statusCheckRollup
# mergeable: MERGEABLE, mergeStateStatus: UNSTABLE, Validate repository: FAILURE
gh run view 35479359358 --repo cncf/endusers --log-failed
# not ok 11 - accepts a valid catalog / not ok 15 - accepts records without an assets array
This also retroactively answers the older gap 'npm run test:unit is not executed by any CI workflow' — it now executes on PRs, but nothing enforces it, so a test-breaking PR can still merge green.
Recommendation
Require the Validate repository check in main's branch protection (repo admin action — Settings → Branches → main → require status checks). Separately, the failing tests in PRs #334 and #354 need fixing (or the PRs rebased) before they merge; they are red on their own branches today.
Filed by scanner agent (ACMM L4 — issues-only mode)
🐝 Hive Agent: scanner | Instance: hosted-available-lke648397-260827-5n31 | SHA: 00b44df
— hive: agent=scanner backend=copilot model=kimi-k3
Finding
.github/workflows/ci.yml(workflow name:Validate repository) runsnpm run test:unitandnpm run build:productionon every pull_request, but the check is not a required status check onmain. A PR whose own unit tests fail is still reported as mergeable.Evidence (2026-09-20, live API):
fix: validate architecture catalog sourceUrl scheme and asset containment):mergeable: MERGEABLE,mergeStateStatus: UNSTABLE, CheckRunValidate repository= FAILURE (run 35479359358, tests 'accepts a valid catalog' and 'accepts records without an assets array' fail on its own branch).test: resolve the test harness repo root with fileURLToPath):mergeable: MERGEABLE,mergeStateStatus: UNSTABLE, CheckRunValidate repository= FAILURE (run 35519074857, test 'the sandbox directory is removed once the run returns' fails).mergeStateStatus: UNSTABLE(rather thanBLOCKED) means the failing check is non-required — if it were required, GitHub would reportBLOCKED. Meanwhile main's ownValidate repositoryruns are green (e.g. run 35513128830), so these failures are introduced by the PRs themselves, not pre-existing breakage.Steps to Reproduce / Evidence
This also retroactively answers the older gap 'npm run test:unit is not executed by any CI workflow' — it now executes on PRs, but nothing enforces it, so a test-breaking PR can still merge green.
Recommendation
Require the
Validate repositorycheck in main's branch protection (repo admin action — Settings → Branches → main → require status checks). Separately, the failing tests in PRs #334 and #354 need fixing (or the PRs rebased) before they merge; they are red on their own branches today.Filed by scanner agent (ACMM L4 — issues-only mode)
🐝 Hive Agent:
scanner| Instance:hosted-available-lke648397-260827-5n31| SHA:00b44df— hive: agent=scanner backend=copilot model=kimi-k3