Skip to content

no-release: [PE-7420] allow for merge queues - #81

Merged
kivra-pauoli merged 2 commits into
masterfrom
feature/merge-group
Sep 17, 2026
Merged

kivra-pauoli merged 2 commits into
masterfrom
feature/merge-group

Conversation

@kivra-pauoli

Copy link
Copy Markdown
Contributor

Motivation

Increase confidence in our releases by preventing integration bugs.

Description

Currently, concurrent pull requests are often merged out of sequence. This can introduce undetected issues because the changes are tested in isolation against an older base branch rather than the combined latest state.

To prevent this, we are enabling merge queues. This ensures every PR is tested against the most up-to-date state before it is merged. This is particularly helpful for increasing confidence in PRs that modify state-dependent external services.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The updated actions/checkout ref expression can break CI for fork-based pull requests by trying to fetch github.head_ref from the base repository.

Get a fresh assessment by requesting another Copilot review.

Pull request overview

Updates the CI workflow to support GitHub merge queues so that required checks can run on merge_group events and PRs are validated against the latest queued state before merging.

Changes:

  • Rename the workflow and refine triggers to run on pull_request, push (master only), and merge_group (checks requested).
  • Run build_and_test only for non-master refs and ensure Renovate-specific push logic runs only on pull_request.
  • Adjust checkout ref handling and Renovate branch matching/push ref formatting.
File summaries
File Description
.github/workflows/ci.yml Adds merge_group support and updates CI triggers/checkout behavior to work with merge queues.
Review details
  • Files reviewed: 1/1 changed files
  • Comments generated: 1
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/ci.yml

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

The workflow introduces merge-queue execution paths that should pin checkout to github.sha for merge-group correctness and should avoid persisting write-capable git credentials by default for security.

Review details

Suppressed comments (2)

Previously missed (2) — in code that hasn't changed since the last review.

.github/workflows/ci.yml:37

  • With merge_group enabled, this job will run PR code in the base-repo context; leaving checkout credentials persisted (default) makes it easier for scripts to perform unintended pushes using the configured git remote. Consider disabling persisted credentials except for Renovate PRs that intentionally push updates.
    .github/workflows/ci.yml:38
  • For merge_group runs, checking out by github.ref can be less reliable than pinning the exact commit SHA for the merge-group head. Using github.sha ensures the workflow tests the precise queued merge commit while keeping PRs checked out at the PR head SHA.
  • Files reviewed: 1/1 changed files
  • Comments generated: 0 new
  • Review effort level: Lite

@kivra-pauoli
kivra-pauoli merged commit f8b5c82 into master Sep 17, 2026
9 checks passed
@kivra-pauoli
kivra-pauoli deleted the feature/merge-group branch September 17, 2026 17:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants