Skip to content

ci: add the CI passed aggregate the org rule can require - #30

Merged
msalvatti merged 2 commits into
mainfrom
chore/ci-passed-aggregate-gate
Aug 7, 2026
Merged

msalvatti merged 2 commits into
mainfrom
chore/ci-passed-aggregate-gate

Conversation

@msalvatti

Copy link
Copy Markdown
Member

Adds one job that reports a single check named CI passed, summarising the jobs this repository already runs. Nothing about the pipeline itself changes.

Gates on: install,lint,typecheck,build,unit,e2e — read from this repo's own ci.yml, not templated.

Why

A required status check is matched by literal name, and the repos in this org name their jobs nothing alike — verify here, quality/container/e2e there, sixteen separate jobs in rust-auth. There is no list of contexts that can be written once at the organisation level, and that is why required checks were never centralised: today only 12 of 38 repos require CI at all.

With every repo exposing CI passed, one organisation ruleset requires one context — and every repository created from now on inherits the gate with no configuration.

The two guards in the condition

always() — without it the job is skipped the instant a dependency fails, and a skipped check reports neutral. The pull request would read as unblocked exactly when it is broken.

cancelled — a cancelled job is not a passing one. Not hypothetical: the Actions incident of 2026-08-06 produced hours of cancelled jobs, and a gate ignoring them would have waved the whole day through.

A skipped dependency is accepted on purpose, since jobs here are conditional on the event.

Validated first

Piloted in nest-cache-example#24: the check appears at top level as exactly CI passed (not ci / CI passed), and a skipped Mutation testing did not fail it.

A required status check is matched by literal name, and no two repos here
name their jobs alike — from one job in bymax-bio-web to sixteen in
rust-auth. There is no list of contexts that works org-wide, which is why
required checks never moved above the repository level: only 12 of 38
repos require CI at all, each with its own vocabulary.

One aggregate per repo, always spelled `CI passed`, is what a single
organisation ruleset can require. It also means a repository created from
now on inherits the gate without anyone configuring it.

always() is what makes it a gate: without it the job is skipped as soon as
a dependency fails, and a skipped check reports neutral — the pull request
would look unblocked exactly when it is broken. cancelled is named for the
same reason, and is not hypothetical: the Actions incident of 2026-08-06
produced nothing but cancelled jobs for hours.
Copilot AI lite review requested due to automatic review settings August 7, 2026 17:03

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds an aggregate GitHub Actions job that reports a single required-check-friendly status (CI passed) summarizing the outcomes of the existing CI jobs, enabling an org ruleset to require one consistent check name across repositories without changing the underlying pipeline behavior.

Changes:

  • Adds a new terminal job (ci-pass) named CI passed that always runs and depends on install, lint, typecheck, build, unit, e2e.
  • Fails the aggregate job if any dependency concluded with failure or cancelled (while allowing skipped dependencies).
Suppressed comments (1)

.github/workflows/ci.yml:129

  • This line uses a Unicode em dash (—). Consider replacing it with ASCII punctuation (e.g., a semicolon) to keep workflow comments plain-ASCII.
  # neutral — the pull request would look unblocked precisely when it is broken.

Comment thread .github/workflows/ci.yml
# Single check the org ruleset can require, in every repo, under one name.
#
# A required status check is matched by literal name, and this repo's jobs are
# named nothing like the next repo's — so there is no list of contexts that
- timeout-minutes: once this is the required check, a hung runner holds
  every merge behind it for GitHub's default of six hours.
- Report every dependency's result, on success as well as failure. The
  gate reported a bare red X and left the reader opening each job to find
  which one broke.
- Rename the step to what the condition does. skipped is deliberately not
  a failure here, so "did not succeed" described a stricter gate.
Copilot AI review requested due to automatic review settings August 7, 2026 17:22
@msalvatti

Copy link
Copy Markdown
Member Author

On the em dash: I checked before changing it, and the convention here goes the other way — bymaxone/.github has 37 em dashes across its workflows, nest-core has 8, bymax-bio-mobile has 7. This repo happens to have none, so the file looked like an outlier when it is the suggestion that would make it one.

Applying it would create a single repo whose workflow comments are punctuated differently from every other, which is worse for searching than the character itself. Left as is.

The other three findings from this review round were real and are applied across all 25 pull requests in this rollout: timeout-minutes, a dependency-result table printed on success as well as failure, and a step name that matches what the condition does.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 1 out of 1 changed files in this pull request and generated no new comments.

@msalvatti
msalvatti merged commit 554ff28 into main Aug 7, 2026
13 of 14 checks passed
@msalvatti
msalvatti deleted the chore/ci-passed-aggregate-gate branch August 7, 2026 17:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants