ci: require two approvals on docs-agent pull requests - #12274
Conversation
`mergify-ci-bot` satisfies the "👀 Review Requirements" merge protection with **zero** approvals and is auto-queued through the `automated updates` lane. That is right for the deterministic syncers in `Mergifyio/ci-bot` — a changelog copy or a JSON-schema sync needs no reviewers — and wrong for the scheduled docs agent, which opens pull requests full of prose a model wrote. Nothing but the draft flag holds that line today. The agent opens drafts only (`draft: always-true`, not overridable at runtime), so a human must act before anything lands; but the moment someone marks one ready, it can merge with no approval on it at all. ci-bot#282 merged today, which armed the Monday 06:00 Europe/Paris health audit, so this wants to land first. Both bots push from the same fork (`mergify-ci-bot/docs`), so `author` and `head-repo-full-name` cannot tell them apart. The branch prefix can: the runner's `scope.py` names every branch `docs-agent/health-audit-<section>` or `docs-agent/change-watch`, and it is the only place a branch name is minted. Four rules change, keyed on that prefix so the syncers keep their fast path: - **`👀 Review Requirements`** — the `mergify-ci-bot` free pass is now conditional on the head *not* being a `docs-agent/` branch. Agent pull requests fall through to `#approved-reviews-by >= 2`, the same bar as anyone else. The `&DefaultReviewCond` anchor is shared, so the hotfix rule tightens identically. - **`automated updates` queue rule** — agent branches are kept out of the fast-forward, batch-of-10 lane. - **`default` queue rule** — and therefore have to be let in here, or they would match no queue at all and could not be merged even once approved (`auto_merge_conditions: true` auto-queues, then the queue rules route). They inherit `squash` and the weekday merge window, like human pull requests. - **`request review`** — routes agent pull requests to `@devs`, since they now need approvals and nothing else would ask for them. Gated on `-draft`, so the ten drafts a Monday audit opens do not each ping the team before a human has decided one is worth merging. Not changed: the `automated updates` *priority* rule still matches the agent, so its pull requests sit at `low` behind human work in the `default` queue. That reads as correct; say so if it isn't. ## Note on the snippet in the ticket MRGFY-8340 and `docs-agent/README.md` both propose `-head-ref ~= ^docs-agent/`. There is no `head-ref` attribute — the 75 condition attributes in `public/mergify-configuration-schema.json` have `head` ("the name of the branch where the pull request changes are implemented"). Using `head` here. The snippet also stopped at two rules; the `default` queue and review routing above are the rest of the change. ## Validation - `mergify config validate` on a merge-key-expanded copy of this file: valid. (Run against the file as written it reports three pre-existing `'<<' was unexpected` errors — the CLI's loader does not resolve YAML merge keys. Same three before and after this change.) - `mergify config simulate https://github.com/Mergifyio/docs/pull/12272` (a real `mergify-ci-bot` schema-sync pull request, from the fork) with this config: `-head ~= ^docs-agent/` evaluates true, the free pass holds, and `request review` stays not-applicable. The syncers are unaffected. - Same simulation with the regex swapped to `^json-schema-` so that it matches #12272's actual head: the free pass collapses, `#approved-reviews-by >= 2` becomes the operative condition, and `request review` activates. That is the docs-agent path, demonstrated on a real pull request rather than read by eye. - `pnpm check`: green. No `docs-agent/` pull request exists yet to simulate against directly — the first one arrives with the first scheduled run. MRGFY-8340 Change-Id: I18fd35f5d4b02daa5f2afa22af99745463982e4d
Merge Protections🟢 All 7 merge protections satisfied — ready to merge. Show 7 satisfied protections🟢 📃 Configuration Change RequirementsMergify configuration change
🟢 🤖 Continuous Integration
🟢 👀 Review Requirements
🟢 Enforce conventional commitMake sure that we follow https://www.conventionalcommits.org/en/v1.0.0/
🟢 🔎 Reviews
🟢 📕 PR description
🟢 🚦 Auto-queueWhen all merge protections are satisfied, this pull request will be queued automatically. |
There was a problem hiding this comment.
Pull request overview
This PR updates the repository’s Mergify configuration to ensure docs-agent pull requests (identified by the docs-agent/ head branch prefix) no longer inherit the “zero-approval” fast path intended for deterministic mergify-ci-bot sync PRs, and instead require human review before merging.
Changes:
- Tightens the shared review-requirements condition so
mergify-ci-botonly bypasses approvals when the PR head branch does not match^docs-agent/. - Excludes
docs-agent/branches from theautomated updatesqueue lane and routes them to thedefaultqueue lane so they remain mergeable once approved. - Updates the “request review” rule to request
@devsreview fordocs-agent/PRs only after they are no longer drafts.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Merge Queue Status
This pull request spent 2 minutes 53 seconds in the queue, including 1 minute 58 seconds running CI. Required conditions to merge
|
mergify-ci-botsatisfies the "👀 Review Requirements" merge protection withzero approvals and is auto-queued through the
automated updateslane.That is right for the deterministic syncers in
Mergifyio/ci-bot— a changelogcopy or a JSON-schema sync needs no reviewers — and wrong for the scheduled
docs agent, which opens pull requests full of prose a model wrote.
Nothing but the draft flag holds that line today. The agent opens drafts only
(
draft: always-true, not overridable at runtime), so a human must act beforeanything lands; but the moment someone marks one ready, it can merge with no
approval on it at all. ci-bot#282 merged today, which armed the Monday 06:00
Europe/Paris health audit, so this wants to land first.
Both bots push from the same fork (
mergify-ci-bot/docs), soauthorandhead-repo-full-namecannot tell them apart. The branch prefix can: therunner's
scope.pynames every branchdocs-agent/health-audit-<section>ordocs-agent/change-watch, and it is the only place a branch name is minted.Four rules change, keyed on that prefix so the syncers keep their fast path:
👀 Review Requirements— themergify-ci-botfree pass is nowconditional on the head not being a
docs-agent/branch. Agent pullrequests fall through to
#approved-reviews-by >= 2, the same bar as anyoneelse. The
&DefaultReviewCondanchor is shared, so the hotfix rule tightensidentically.
automated updatesqueue rule — agent branches are kept out of thefast-forward, batch-of-10 lane.
defaultqueue rule — and therefore have to be let in here, or theywould match no queue at all and could not be merged even once approved
(
auto_merge_conditions: trueauto-queues, then the queue rules route).They inherit
squashand the weekday merge window, like human pull requests.request review— routes agent pull requests to@devs, since they nowneed approvals and nothing else would ask for them. Gated on
-draft, so theten drafts a Monday audit opens do not each ping the team before a human has
decided one is worth merging.
Not changed: the
automated updatespriority rule still matches the agent,so its pull requests sit at
lowbehind human work in thedefaultqueue.That reads as correct; say so if it isn't.
Note on the snippet in the ticket
MRGFY-8340 and
docs-agent/README.mdboth propose-head-ref ~= ^docs-agent/.There is no
head-refattribute — the 75 condition attributes inpublic/mergify-configuration-schema.jsonhavehead("the name of the branchwhere the pull request changes are implemented"). Using
headhere. Thesnippet also stopped at two rules; the
defaultqueue and review routing aboveare the rest of the change.
Validation
mergify config validateon a merge-key-expanded copy of this file: valid.(Run against the file as written it reports three pre-existing
'<<' was unexpectederrors — the CLI's loader does not resolve YAML mergekeys. Same three before and after this change.)
mergify config simulate https://github.com/Mergifyio/docs/pull/12272(a realmergify-ci-botschema-sync pull request, from the fork) with this config:-head ~= ^docs-agent/evaluates true, the free pass holds, andrequest reviewstays not-applicable. The syncers are unaffected.^json-schema-so that it matcheschore: sync Mergify JSON Schema files #12272's actual head: the free pass collapses,
#approved-reviews-by >= 2becomes the operative condition, and
request reviewactivates. That is thedocs-agent path, demonstrated on a real pull request rather than read by eye.
pnpm check: green.No
docs-agent/pull request exists yet to simulate against directly — thefirst one arrives with the first scheduled run.
MRGFY-8340