no-release: [PE-7420] allow for merge queues - #81
Conversation
There was a problem hiding this comment.
🟡 Changes recommended
The updated actions/checkout ref expression can break CI for fork-based pull requests by trying to fetch github.head_ref from the base repository.
Get a fresh assessment by requesting another Copilot review.
Pull request overview
Updates the CI workflow to support GitHub merge queues so that required checks can run on merge_group events and PRs are validated against the latest queued state before merging.
Changes:
- Rename the workflow and refine triggers to run on
pull_request,push(master only), andmerge_group(checks requested). - Run
build_and_testonly for non-masterrefs and ensure Renovate-specific push logic runs only onpull_request. - Adjust checkout ref handling and Renovate branch matching/push ref formatting.
File summaries
| File | Description |
|---|---|
| .github/workflows/ci.yml | Adds merge_group support and updates CI triggers/checkout behavior to work with merge queues. |
Review details
- Files reviewed: 1/1 changed files
- Comments generated: 1
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
8be5da1 to
903db61
Compare
There was a problem hiding this comment.
🔵 Needs a closer look
The workflow introduces merge-queue execution paths that should pin checkout to github.sha for merge-group correctness and should avoid persisting write-capable git credentials by default for security.
Review details
Suppressed comments (2)
Previously missed (2) — in code that hasn't changed since the last review.
.github/workflows/ci.yml:37
- With
merge_groupenabled, this job will run PR code in the base-repo context; leaving checkout credentials persisted (default) makes it easier for scripts to perform unintended pushes using the configured git remote. Consider disabling persisted credentials except for Renovate PRs that intentionally push updates.
.github/workflows/ci.yml:38 - For
merge_groupruns, checking out bygithub.refcan be less reliable than pinning the exact commit SHA for the merge-group head. Usinggithub.shaensures the workflow tests the precise queued merge commit while keeping PRs checked out at the PR head SHA.
- Files reviewed: 1/1 changed files
- Comments generated: 0 new
- Review effort level: Lite
Motivation
Increase confidence in our releases by preventing integration bugs.
Description
Currently, concurrent pull requests are often merged out of sequence. This can introduce undetected issues because the changes are tested in isolation against an older base branch rather than the combined latest state.
To prevent this, we are enabling merge queues. This ensures every PR is tested against the most up-to-date state before it is merged. This is particularly helpful for increasing confidence in PRs that modify state-dependent external services.