Repository navigation
docs(reviewers): Elsa 3 Code Review is the only merge gate; bots are advisory - #280
Conversation
sfmskywalker
left a comment
There was a problem hiding this comment.
Elsa 3 Code Review: REQUEST_CHANGES + HIGH @ 01a582d
Code Review, Round 1/4
Scope: .github/reviewers.md (Greptile row and Rules) and one line of AGENTS.md, docs only. This is a companion to the matching PRs in the other two Elsa 3 repositories.
Verified
- Stale wording is gone from the claimed files. The Greptile "required for merge" row, the Greptile 5/5 gate and the waive exception are removed from
.github/reviewers.md. The stale Greptile line inAGENTS.md(line 3) is fixed. - The new Rules match the policy:
- the Elsa 3 Code Review is the only gate, together with green CI on the head;
- the merge is pinned to the approved SHA (
gh pr merge --match-head-commit, or the merge APIsha); - any push voids the approval until it is re-confirmed on the new head;
- authors never approve their own PRs (unchanged rule);
- Greptile, CodeRabbit, Copilot and Bugbot are advisory only, with no score gate and no waive process.
- Consistency across the three repositories. The merge gate, merge pin and advisory bullets are word for word identical in elsa-core, elsa-studio and elsa-extensions. The remaining differences are intended: Bugbot is live only on elsa-core, Greptile is not live on elsa-extensions, and elsa-extensions picks exactly one advisory reviewer.
- No other governance file states a Greptile gate or waive process:
CONTRIBUTING.mdand.github/agentswere checked. The only other Greptile hits are historical lines in the 3.7.0 changelog. There are no links in the changed text. - No U+2013 or U+2014 dashes in either file, before or after.
- CI at head: ubuntu-latest, submit-nuget, CodeQL, Analyze (csharp, actions), GitGuardian and license/cla pass.
Blocker
B1. The gate bullet does not give the exact review header that people and tooling match on (.github/reviewers.md line 21).
- The gate is defined by recognising one review. The bullet says the body "reads
APPROVE + HIGH @ <head sha>", but a Code Review body starts with the lineElsa 3 Code Review: <APPROVE|REQUEST_CHANGES> + <confidence> @ <full head sha>. A check written from this text, such as "starts withAPPROVE + HIGH", would never match a real approval. - The bullet also presents COMMENTED as a side effect of the posting account. The rule is that the review is always posted with event COMMENT.
- A reader seeing "posted as
sfmskywalker" next to "the PR author never reviews or approves its own PR" may read it as self approval when the author uses the same account. One clause removes that doubt.
Replace:
- Merge gate: the only merge gate is an Elsa 3 Code Review GitHub review on the PR whose body reads
APPROVE + HIGH @ <head sha>(the full 40-character SHA of the PR's current head commit; posted assfmskywalker, so its review state is COMMENTED, not APPROVED), plus green CI on that head.
with:
- Merge gate: the only merge gate is an Elsa 3 Code Review on the PR whose body starts with the line
Elsa 3 Code Review: APPROVE + HIGH @ <head sha>(the full 40-character SHA of the PR's current head commit), plus green CI on that head. The Code Review is posted assfmskywalkerwith review event COMMENT, so its GitHub review state is COMMENTED, not APPROVED. AREQUEST_CHANGESverdict, a confidence belowHIGH, or a SHA other than the current head does not pass. The Code Review is a separate reviewer from the PR author, even when both post from the same account.
Notes (non-blocking)
N1. The AGENTS.md summary line paraphrases the gate as APPROVE + HIGH @ <head sha>. That is fine as a pointer to .github/reviewers.md, and it needs no change once B1 lands there.
N2. Last verified still reads 2026-10-03, but the Rules changed in this PR. elsa-core bumped it to 2026-10-04. Consider bumping it here too.
Gate: with B1 applied verbatim (the same text in all three repositories), this is ready.
…ules in the merge gate; bump Last verified
sfmskywalker
left a comment
There was a problem hiding this comment.
Elsa 3 Code Review: APPROVE + HIGH @ 2307c3f
Code Review, Round 2/4
Delta reviewed: 01a582d...2307c3f.
B1 (Merge gate bullet): resolved. The bullet in .github/reviewers.md now matches the requested text word for word: the body must start with Elsa 3 Code Review: APPROVE + HIGH @ <head sha>, the review is posted with event COMMENT so its state is COMMENTED, a REQUEST_CHANGES verdict, a confidence below HIGH, or a stale SHA does not pass, and the Code Review is a separate reviewer from the author even on a shared account. The pinned merge bullet now uses the same full first line for re-confirmation, so the two bullets agree. The wording is identical across elsa-core, elsa-studio and elsa-extensions.
Last verified (note from Round 1): resolved. It now reads 2026-10-04, matching elsa-core.
CI was still running on this head when this review was posted. Per the rule this PR documents, merge only once CI is green on this exact head, pinned with --match-head-commit 2307c3f62c38b1fc14ed48f2ed4518d824f8f19d. Any further push voids this approval.
Verdict: APPROVE + HIGH at 2307c3f.
Aligns the reviewer docs with the merge rule set on 2026-10-03.
Merge gate (the only one): an Elsa 3 Code Review GitHub review on the PR whose body reads
APPROVE + HIGH @ <head sha>(posted assfmskywalker, state COMMENTED), plus green CI on that head. The merge is pinned to that SHA (gh pr merge --match-head-commit <sha>or the merge API withsha=). Any push after the approval needs Code Review to re-confirm.Advisory only: Greptile, CodeRabbit, Copilot and Bugbot. There is no Greptile 5/5 gate and no waive process.
Changes:
.github/reviewers.md: Greptile row drops the "waived" status/wording (it is simply not live here and advisory), and the merge rule spells out the review body, author/state, and SHA-pinned merge, matching elsa-core.AGENTS.md: replaces "Greptile is waived" with the advisory/gate wording.Docs only; no code or workflow changes.
Companion PRs: elsa-workflows/elsa-core#8605, elsa-workflows/elsa-studio#1124, #280.