Skip to content

queen-bot: merge only what a reviewer bee passed (bee-reviewed + APPROVED) - #803

Closed
gHashTag wants to merge 1 commit into
mainfrom
bee-reviewed-gate-queen-bot
Closed

gHashTag wants to merge 1 commit into
mainfrom
bee-reviewed-gate-queen-bot

Conversation

@gHashTag

@gHashTag gHashTag commented Oct 2, 2026

Copy link
Copy Markdown
Owner

Owner's rule, 2026-10-02:

«королева сама не должна мержить!! королева управляет только!» — "the Queen must not merge by herself!! the Queen only manages!"
«борд-мерджер тоже лишить права мержить» — "take the merge right away from the board merger too."

No automation may merge on its own verdict. A merge happens only after a reviewer bee's review: an APPROVED review plus the bee-reviewed label added after the last commit. Same gate as gHashTag/t27#5526 (.github/workflows/auto-merge-ready-prs.yml).

What changes in .github/workflows/queen-bot.yml

  • The job now runs only when the PR carries both charter:r2-pass and bee-reviewed. Before this change, charter:r2-pass plus green CI was enough to squash-merge.
  • A new step, "Reviewer-bee gate", checks the current labels, requires at least one APPROVED review, and requires the latest bee-reviewed labeling to be no older than the head commit's committer date. A push after the review counts as unreviewed code.
  • pulls.merge now passes sha: pr.head.sha. If a commit lands between the gate and the merge, GitHub refuses the merge.
  • Security fixes found in the same file: under pull_request_target, which has a write token, the PR body was pasted straight into a shell script (body="${{ github.event.pull_request.body }}"). That allowed script injection, and actionlint flags it. The body is now passed through env. I also dropped the checkout of the untrusted PR head because no step used it.
  • Removed the check_suite trigger. Its payload has no pull_request, so the job's if: was always false for it.
  • Label bee-reviewed created in this repo.

Reviewer order: approve first, then add bee-reviewed. The labeled event is what starts the merge.

Verified locally

  • actionlint .github/workflows/queen-bot.yml: clean. The old file had the injection finding plus SC2046, and both are fixed.
  • I extracted the gate script and ran it against a mocked github client with 6 cases, all as expected: label after head + approved passes; no label fails; no approval fails; label before head fails; relabel after a push passes; an unrelated label event fails.

Not verified

  • No live run on GitHub Actions.
  • GitHub cannot tell a reviewer bee from anyone else with triage rights, so it is not established that only reviewer bees apply the label.

Author bee: I am not merging this. It waits for a reviewer bee.

phi^2 + phi^-2 = 3

🤖 Generated with Claude Code

…OVED)

Owner's rule 2026-10-02: no automation merges on its own verdict. The
merge step now requires an APPROVED review and the bee-reviewed label
applied after the head commit (same gate as gHashTag/t27#5526), and pins
the merge to the checked head sha. Also: PR body passed via env instead
of shell interpolation under pull_request_target, untrusted checkout
dropped, dead check_suite trigger removed.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@gHashTag

gHashTag commented Oct 2, 2026

Copy link
Copy Markdown
Owner Author

Superseded by #805: same diff, but the commit subject now matches the conventional format CI Validation needs. Closed instead of force-pushing.

@gHashTag gHashTag closed this Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant