Found during #3194 (OmniRoute docs/ops/BRANCH_PROTECTION_MAIN.md comparison).
Observed
gh api repos/Xore/APIARY/branches/main/protection → 404 Branch not protected; gh api repos/Xore/APIARY/rulesets → empty. main has no required status checks at all.
.github/workflows/dependabot-auto-merge.yml approves patch/minor updates and runs gh pr merge --auto --squash. With zero required checks, GitHub reports the PR mergeable immediately and the call merges on the spot instead of arming a wait.
- Dependabot PRs merged by
github-actions[bot] 25–40 s after their CI started, with failures on their own head commits:
| PR |
Merged |
Failed checks on its head |
| #3285 backend-compatible group |
2026-09-25 06:15 |
backend-service, dicompot |
| #3288 base64 0.22→0.23 |
06:17 |
backend-service, dicompot |
| #3287 rand 0.9→0.10 |
06:20 |
Dashboard backend-service (Rust) |
| #3289 sha2 0.10→0.11 |
06:22 |
Dashboard backend-service (Rust) |
| #3291 actions-compatible group |
06:18 |
backend-service, dicompot, dns-honeypot, rdp-honeypot, endlessh-honeypot, agent-intrusion-worker |
Timeline for #3289: CI runs created 06:22:28, merged 06:22:56.
Proposal
- Add a ruleset on
main with required status checks. Required contexts must be checks that always report (aggregate jobs), not path-filtered ones that skip, or every non-matching PR blocks forever — needs a check inventory first.
- Until then: make the workflow refuse to merge when
gh pr view --json mergeStateStatus is CLEAN with no required checks, i.e. never call gh pr merge without protection; comment instead.
- Treat Cargo
0.x minor bumps as major for auto-merge (dependency-type/update-type + previous-version starts with 0.), or exclude Cargo from auto-merge.
- Correct the
docs/CI-CD.md Dependabot paragraph.
Refs #3194.
Found during #3194 (OmniRoute
docs/ops/BRANCH_PROTECTION_MAIN.mdcomparison).Observed
gh api repos/Xore/APIARY/branches/main/protection→ 404 Branch not protected;gh api repos/Xore/APIARY/rulesets→ empty.mainhas no required status checks at all..github/workflows/dependabot-auto-merge.ymlapproves patch/minor updates and runsgh pr merge --auto --squash. With zero required checks, GitHub reports the PR mergeable immediately and the call merges on the spot instead of arming a wait.github-actions[bot]25–40 s after their CI started, with failures on their own head commits:Timeline for #3289: CI runs created 06:22:28, merged 06:22:56.
mainwas left with a broken Rust backend until fix(backend): migrate rand call sites to 0.10 #3300 (fix(backend): migrate rand call sites to 0.10, 13:44).rand/sha2/base640.x minor bumps are semver-breaking in Cargo, yetfetch-metadataclassifies themsemver-minor— so they qualify for auto-merge.docs/CI-CD.md(Dependabot section) states these PRs "still wait for branch protection and all required checks" — untrue on this repo.Protected branch rules not configuredfallback does fire sometimes (chore(deps): bump sha2 from 0.10.9 to 0.11.0 in /arcane/home/honeypot-dashboard/backend-service #3289 carries that comment) but does not stop the merge path above.Proposal
mainwith required status checks. Required contexts must be checks that always report (aggregate jobs), not path-filtered ones that skip, or every non-matching PR blocks forever — needs a check inventory first.gh pr view --json mergeStateStatusisCLEANwith no required checks, i.e. never callgh pr mergewithout protection; comment instead.0.xminor bumps as major for auto-merge (dependency-type/update-type+previous-versionstarts with0.), or exclude Cargo from auto-merge.docs/CI-CD.mdDependabot paragraph.Refs #3194.