Sitelet https://github.com/lightspeedwp/.github/issues/3688
Skip to content

ci: gate - two PRs merged without CodeRabbit approval, and the README bot cannot push workflow-adjacent files #3688

Description

@eleshar

CI Summary

Records that two pull requests were merged to develop without satisfying the merge gate, and closes the loop retroactively. The rule is that nothing merges unless all of the following hold on the current head: every check run is success, skipped or neutral; the AI Feedback Validation report carries no red X; and coderabbitai[bot] has an APPROVED review. Neither pull request had a CodeRabbit approval. The decision taken was to keep them merged and satisfy the gates retroactively rather than revert.

Pull request Merge commit Subject
#3682 d7e98f3068e6046dc549e8b034109c546f6c72e7 feat(footers): add a non-blocking footer shape signal
#3604 5675299b1f084e76b6218cb212e46bb77309d632 fix: merged advisory and spec - rate limiter atomicity, branch-age gate and renumber residue

(a) Neither pull request had a CodeRabbit approval

Verified from the reviews API on the merged pull requests. Every coderabbitai[bot] review is DISMISSED or COMMENTED; there is no APPROVED review on either.

Both pull requests documented the gap themselves. #3682's description states the CHANGES_REQUESTED reviews are dismissed on evidence, "not on a CodeRabbit re-approval; the CLI is rate limited (3 included reviews per day) and was skipped rather than retried, and the GitHub app does not re-review incrementally here". A review thread on #3682 ends "Not merged." #3604's description records that the pre-merge CodeRabbit reviews never completed - one failed with "Pull request base or head changed", another with "Review rate limited" - and that both merged carrying a stale CHANGES_REQUESTED.

(b) #3682 merged with a red AI Feedback report and cancelled runs

The <!-- ai-feedback-validation --> report comment on #3682 carries a red X: "No issue link found: the PR must include Resolves #123 or Closes #123." Its body carried only a Refs #3451, which the check does not accept. That report is still present and unresolved. Runs on the final head were also cancelled.

#3604's body does carry Refs #1396 and its AI Feedback check passes, so (b) is specific to #3682.

(c) Retroactive CodeRabbit review results

Run with the local CLI from a dedicated worktree on a fresh fetch of develop, one commit at a time, quota confirmed first (coderabbit usage: 3 of 3 included reviews remaining).

Pull request Base Findings
#3682 d7e98f3~1 1 - .github/workflows/documentation.yml, minor
#3604 5675299~1 2 - FEEDBACK_RESPONSE.md, minor; .github/specs/018-claude-cloud-environment/spec.md, minor

All three were verified against current develop and all three were valid.

(d) Follow-up fix pull request

A single pull request off develop carries all three corrections. It does not revert either merge.

  • .github/workflows/documentation.yml - the advisory comment and emitted ::notice quoted 930 flagged, 280 no-known-footer, 30.1%, and called that figure a false-positive rate. npm run measure:footers:shape on the current tree returns 899 flagged, 255 with no known footer, a 28.4% share, 644 with two known and 96.7% recall, which is what docs/FOOTER_REMEDIATION_GUIDE.md and scripts/measure-footer-shape.js already state. The 28.4% is a share of flagged files, not a rate: a file carrying an unrecognised but genuine duplicate footer is counted in it, and a file with known phrases is not independently confirmed, so no rate follows. Both now carry 899 / 255 / 28.4% and the share wording, and the step keeps continue-on-error and still states it does not fail the build.
  • .github/specs/018-claude-cloud-environment/spec.md - SC-002 claimed empty claude/* branches are removed through spec 009 so that none stays longer than 48 hours, but FR-020 defers auto-approved deletion and states that while the deferral holds no claude/* branch qualifies for automatic deletion and a branch routed to DISCUSS has no route to approval. SC-002 now applies the bound only once the deferral is lifted, and the Assumptions bullet that said branches "are removed" now says the same. The measurable claim is untouched and the bound is retained, not deleted.
  • FEEDBACK_RESPONSE.md - the sentence above the feedback table said the items are "listed above"; the Feedback heading is at line 29, below the sentence at line 18, so the reference pointed at nothing. Changed to "below". The file's two other directional references were checked and are already correct.

Verification on that branch: actionlint clean; spec 018 suite 41/41; governance suite 18/18; the changelog gate reports the same 3 length, 5 missing-link and 1 tense violations as develop, so the entry adds none; Semgrep p/security-audit and p/secrets 0 findings over 4 files.

(e) Observed finding: the README bot cannot push workflow-adjacent files

This is an observation, not a task. It is not fixed here and no fix is proposed in this issue.

"Auto-regenerate Documentation" failed on two develop merge commits, both of which changed a workflow file:

Merges that did not touch workflows passed, and develop head 5675299 is green. The refusal line from run 36567389709:

! [remote rejected]       chore/readme-regeneration -> chore/readme-regeneration (refusing to allow a GitHub App to create or update workflow `.github/workflows/README.md` without `workflows` permission)

The bot pushes a branch named chore/readme-regeneration, and the file it wants to write is .github/workflows/README.md. GitHub classifies that path as workflow-adjacent, so the push is refused without the workflows permission. Any future merge touching a workflow file is likely to reproduce this.

Two residual inconsistencies found while tracing this, recorded rather than fixed because they sit outside the corrections above:

  • .github/specs/018-claude-cloud-environment/plan.md:89 still reads "Cleanup removes empty claude/* branches that would lower the compliance metric", in present tense, and plan.md contains no mention of the deferral.
  • scripts/measure-footer-shape.js still names the field falsePositiveRate while printing NO-KNOWN-FOOTER SHARE. Terminology only.

Linear code review on the merged pull requests

Readable for merged pull requests; both were queried fresh by URL.

#3682 #3604
Readable yes yes
Status merged merged
viewerReviewState.currentDecision commented commented
CodeRabbit lastSubmittedDecision null - no approval commented - no approval
Unresolved review threads (Linear) 11 19
Unresolved review threads (GitHub) 0 (5 outdated) 0 (9 outdated)

The unresolved Linear threads are mostly bot status messages. Two are substantive: #3682's red AI Feedback report, and CodeRabbit rate-limit notices on #3604 ("Review rate limited", "Your included review limit...", "Action not completed").

Linked Stories/Tasks/PRs/Epic

Related epic: none
Related issues: #3451 (referenced by #3682), #1396 (referenced by #3604)
Related pull requests: #3682, #3604, and the follow-up fix pull request for the three corrections

Milestones & Timeline

No deadline. (c) and (d) are complete. (e) is an observation awaiting a maintainer decision.

Steps / Checklist

Acceptance Criteria

  • Both merged pull requests are recorded as having merged without a CodeRabbit approval
  • feat(footers): add a non-blocking footer shape signal #3682 is recorded as having merged with a red AI Feedback report and cancelled runs
  • Retroactive review results are recorded per pull request
  • The follow-up fix pull request is recorded
  • The README bot refusal is recorded as an observation, with run 36567389709 quoted and no fix applied here
  • A maintainer decision is recorded on the README bot permission
  • Neither merged pull request is reverted and nothing is force-pushed

Additional Context

The retroactive reviews were run with coderabbit review --agent --committed --base-commit <merge-sha>~1 from a dedicated worktree, after git fetch origin "+refs/heads/develop:refs/remotes/origin/develop" --force. Quota was 3 of 3 before the two reviews. No review was simulated or reconstructed by hand.

One finding was initially applied in the wrong direction and corrected before commit. The reviewer's suggested wording quoted 899 / 255 / 28.4% and that was the correct target; an intermediate edit kept the stale 930 / 280 / 30.1% figures while only fixing the metric's name, which would have made a checkably false claim more precise. The figures were re-measured on the branch before the final edit. A second review pass caught that, and also caught an over-length changelog entry that would have failed a required check.


Definition of Ready (DoR)

  • Build/CI goal and scope defined
  • Checklist prepared
  • Estimate added

Definition of Done (DoD)

  • Retroactive review performed and recorded
  • All findings addressed in a follow-up pull request
  • Documentation/changelog updated
  • Approved by at least one maintainer
  • PR uses correct branch prefix (fix/)
  • Branch deleted/merged
  • Linked issue(s) updated with latest status
  • The related epic should not be closed, instead updated with a comment to reflect the closed issue

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Fields

    Priority

    None yet

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions