Skip to content

CI: add requireable aggregate/no-op checks for branch protection - #984

Merged
bigdaz merged 2 commits into
mainfrom
ci-required-check-gates
Jun 10, 2026
Merged

CI: add requireable aggregate/no-op checks for branch protection#984
bigdaz merged 2 commits into
mainfrom
ci-required-check-gates

Conversation

@bigdaz

@bigdaz bigdaz commented Jun 10, 2026

Copy link
Copy Markdown
Member

Prepares CI so a small, stable set of required status checks can be enabled (which in turn unlocks auto-merge), instead of having to list every fanned-out matrix job. GitHub required checks match by exact name — no wildcards — so this reduces the surface to a handful of high-level checks.

Changes

  • ci-integ-test.yml: add an aggregate gate job integ-test-success that needs: all four top-level jobs (the three suite jobs each wrap a reusable workflow that fans out into many nested checks) and fails if any did not succeed. if: always() ensures it reports even when a dependency fails. This collapses dozens of nested integ-test checks into a single requireable check.

  • ci-init-script-check.yml: remove the workflow-level pull_request.paths filter so the workflow runs on every PR and always reports a status check (previously it was absent on most PRs, which would deadlock a required check). Relevant-change detection moves into the job via tj-actions/changed-files (same pinned action already used by ci-check-no-dist-update.yml). On a PR the Java/Gradle/test steps run only when init-script files changed; otherwise the job is a fast no-op that still succeeds. Push and workflow_dispatch runs execute fully as before.

Suggested required-check set (all run on every PR, none can deadlock)

  • CI-check-and-unit-test / check-format-and-unit-test
  • ci-validate-typings.yml / validate-typings
  • CI-validate-wrappers / validation
  • CI-codeql / Analyze (javascript-typescript)
  • CI-integ-test / integ-test-success
  • CI-init-script-check / test-init-scripts

ci-check-no-dist-update is intentionally omitted — it only runs on dist/** edits and is designed to fail, so it shouldn't be a required gate.

Confirm the exact check names from the list GitHub shows after this branch runs once.

🤖 Generated with Claude Code

bigdaz and others added 2 commits June 10, 2026 09:27
Collapses the many fanned-out integ-test checks into a single
'integ-test-success' check that can be used as a required status check,
since GitHub required checks match by exact name (no wildcards).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Removes the workflow-level pull_request paths filter so the workflow always
runs and reports a status check (safe to mark as a required check). Relevant-
change detection moves into the job via tj-actions/changed-files: on PRs the
Java/Gradle/test steps run only when init-script files changed, otherwise the
job is a fast no-op that still succeeds. Push and workflow_dispatch runs
execute fully as before.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@bigdaz
bigdaz merged commit 8b6cdb5 into main Jun 10, 2026
191 of 193 checks passed
@bigdaz
bigdaz deleted the ci-required-check-gates branch June 10, 2026 17:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant