Skip to content

no-release: [PE-7420] allow for merge queues - #36

Merged
kivra-pauoli merged 1 commit into
masterfrom
feature/merge-group
Sep 17, 2026
Merged

kivra-pauoli merged 1 commit into
masterfrom
feature/merge-group

Conversation

@kivra-pauoli

Copy link
Copy Markdown
Contributor

Motivation

Increase confidence in our releases by preventing integration bugs.

Description

Currently, concurrent pull requests are often merged out of sequence. This can introduce undetected issues because the changes are tested in isolation against an older base branch rather than the combined latest state.

To prevent this, we are enabling merge queues. This ensures every PR is tested against the most up-to-date state before it is merged. This is particularly helpful for increasing confidence in PRs that modify state-dependent external services.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The workflow exposes write-capable execution to merge-group code and may invalidate required checks.

Get a fresh assessment by requesting another Copilot review.

Pull request overview

Enables GitHub merge queue validation so pull requests are tested against the latest queued state.

Changes:

  • Adds the merge_group.checks_requested trigger.
  • Renames the CI workflow.
File summaries
File Summary
.github/workflows/ci.yml Enables merge queue checks and updates workflow metadata; review findings identify workflow permission and required-check compatibility issues.
Review details

Suppressed comments (1)

.github/workflows/ci.yml:2

  • Changing the workflow name changes the check-suite/check display identity for this workflow. If the existing ci check is required by branch protection or the merge queue, that required check will no longer match and merges can remain blocked (or the queue can stop recognizing the required check). This trigger-only change should keep the existing workflow name, or update the repository's required-check configuration in the same change.
name: Continuous Integration
  • Files reviewed: 1/1 changed files
  • Comments generated: 1
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/ci.yml

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

Merge-group CI must avoid exposing write-capable repository credentials to queued code.

Review details

Suppressed comments (1)

.github/workflows/ci.yml:16

  • Adding merge_group causes the queued PR's checked-out code to run with this workflow's contents: write token. A merge-group run is not a fork pull_request run, so the token is not automatically downgraded; code executed by make ci (including dependency/build hooks) can use the persisted checkout credentials to push to the repository. Keep merge-group validation read-only by separating the Renovate/release write operations into trusted jobs/workflows and granting this CI job only contents: read before enabling this trigger.
  merge_group:
    types:
      - checks_requested
  • Files reviewed: 1/1 changed files
  • Comments generated: 0 new
  • Review effort level: Lite

@kivra-pauoli
kivra-pauoli merged commit 1956503 into master Sep 17, 2026
9 of 10 checks passed
@kivra-pauoli
kivra-pauoli deleted the feature/merge-group branch September 17, 2026 17:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants