Repository navigation
Conversation
…OVED) Owner's rule 2026-10-02: no automation merges on its own verdict. The merge step now requires an APPROVED review and the bee-reviewed label applied after the head commit (same gate as gHashTag/t27#5526), and pins the merge to the checked head sha. Also: PR body passed via env instead of shell interpolation under pull_request_target, untrusted checkout dropped, dead check_suite trigger removed. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Owner
Author
|
Superseded by #805: same diff, but the commit subject now matches the conventional format CI Validation needs. Closed instead of force-pushing. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Owner's rule, 2026-10-02:
No automation may merge on its own verdict. A merge happens only after a reviewer bee's review: an APPROVED review plus the
bee-reviewedlabel added after the last commit. Same gate as gHashTag/t27#5526 (.github/workflows/auto-merge-ready-prs.yml).What changes in
.github/workflows/queen-bot.ymlcharter:r2-passandbee-reviewed. Before this change,charter:r2-passplus green CI was enough to squash-merge.APPROVEDreview, and requires the latestbee-reviewedlabeling to be no older than the head commit's committer date. A push after the review counts as unreviewed code.pulls.mergenow passessha: pr.head.sha. If a commit lands between the gate and the merge, GitHub refuses the merge.pull_request_target, which has a write token, the PR body was pasted straight into a shell script (body="${{ github.event.pull_request.body }}"). That allowed script injection, and actionlint flags it. The body is now passed throughenv. I also dropped the checkout of the untrusted PR head because no step used it.check_suitetrigger. Its payload has nopull_request, so the job'sif:was always false for it.bee-reviewedcreated in this repo.Reviewer order: approve first, then add
bee-reviewed. Thelabeledevent is what starts the merge.Verified locally
actionlint .github/workflows/queen-bot.yml: clean. The old file had the injection finding plus SC2046, and both are fixed.githubclient with 6 cases, all as expected: label after head + approved passes; no label fails; no approval fails; label before head fails; relabel after a push passes; an unrelated label event fails.Not verified
Author bee: I am not merging this. It waits for a reviewer bee.
phi^2 + phi^-2 = 3
🤖 Generated with Claude Code