fix(ci): scope application and dependency PR concurrency - #1609
fix(ci): scope application and dependency PR concurrency#1609seonghobae wants to merge 4 commits into
Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Exact-head audit: head |
Current authority — 2026-09-08
develop@042b0c70531b229af3acbd0421a2f23098d848b352914bf07abff73cf887faf90793afbdba15c513develop: 0 files, +0/-0, behind 0Finding and owner repair
The generated lineage proposed useful but overlapping changes to Application CI and Dependency Review concurrency: repository-qualified groups and cancellation only for pull-request events, preserving push/workflow-dispatch runs. The proposal is not discarded, but these exact workflow surfaces are already active canonical CI/evidence owner territory: #1587 owns stacked-PR admission and #1600 owns source-head-bound Application/Bandit/Dependency/Docker validation plus retained visual evidence. Dependency Review also has an older deletion/centralization proposal in #1539, so introducing an independent third policy lane here would make the live workflow contract ambiguous before those owners reconcile.
The original changes remain in ancestry for explicit succession. Ordinary child
544449af0938677655e662fcef27fe44e469605frestores the protected workflow/test tree without force-push. Because the generated branch ancestry was stale relative to protecteddevelop, two-parent ordinary merge52914bf07abff73cf887faf90793afbdba15c513then adopts exact protecteddevelopas the second parent. Fresh comparison is ahead-only, behind 0, with no effective files.Succession boundary
Do not treat the zero effective delta as proof that the concurrency intent has already landed. Keep this PR open/Draft until the canonical #1587/#1600 lineage, or a verified successor, explicitly evaluates and carries the valid Application CI / Dependency Review concurrency semantics together with its exact-source-head and admission contracts, then normally integrates into protected
develop. A post-merge audit must prove repository scoping, PR-only cancellation where intended, source-head checkout identity, Dependency Review admission, and non-regression of push/manual execution before this provenance lane can be closed as fully succeeded.Do not merge this zero-delta PR as a parallel workflow owner. No force-push, destructive rebase, self-approval, dummy/no-op requeue, synthetic status, workflow copy, review fabrication/dismissal, authorization widening, or gate weakening.