Skip to content

ci: require trustworthy SDK checks on pull requests - #225

Merged
Divkix merged 1 commit into
mainfrom
mira/logwell-sdk-ci-gate
Sep 23, 2026
Merged

Divkix merged 1 commit into
mainfrom
mira/logwell-sdk-ci-gate

Conversation

@Divkix

@Divkix Divkix commented Sep 23, 2026 •

Copy link
Copy Markdown
Owner

Agent-authored: This PR was created using an agent (Mira).

What changes

  • Make each SDK workflow run on every PR, while its validation jobs run only when that SDK or its workflow changed. Each workflow always emits a distinct required-check candidate: SDK TypeScript CI Success, SDK Python CI Success, and SDK Go CI Success.
  • Remove the prior API-token/polling approach. Each gate directly depends on that PR's validation jobs; there is no cross-PR run lookup.
  • Scope npm/PyPI OIDC permission to main-only publish jobs.
  • Add a small configuration regression test to root CI and a .github/CODEOWNERS policy for future CI changes.

Verification

  • Local Python config tests: 3 passed.
  • actionlint on all four edited workflows: clean.
  • Simulated GitHub Actions shell blocks with PR SDK changes, unrelated changes, push, and success/failure/skipped job states: passed for all three SDKs.
  • git diff --check: clean.
  • GitHub Actions on this draft PR: root CI Success and all three SDK success checks passed; main-only publish jobs were skipped.

Rollout / safety

main now requires root CI Success, all three SDK success checks, and GitGuardian, with admin enforcement and an up-to-date branch. GitHub accepted these settings; check enforcement against a failing/missing check before enabling unattended merges. This PR is still a draft and needs your manual review before merging. The CODEOWNERS file cannot protect its own first landing because GitHub reads it from the base branch; once merged, enabling Require review from Code Owners with at least one required approval would protect future CI-policy edits. That setting would make routine Dependabot updates manual, so Logwell Dependabot auto-merge remains off until we have an independently trusted gate or an approved review/automation approach. No release or deployment is included.

@Divkix
Divkix marked this pull request as ready for review September 23, 2026 02:14
@Divkix
Divkix merged commit 404216e into main Sep 23, 2026
44 checks passed
@Divkix
Divkix deleted the mira/logwell-sdk-ci-gate branch September 23, 2026 02:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant