Skip to content

ci: always-reporting Quality/Containers gates for the main ruleset; hold 0.x minor bumps - #3336

Merged
Xore merged 2 commits into
mainfrom
fix/3311-main-ruleset-gates
Sep 26, 2026
Merged

Xore merged 2 commits into
mainfrom
fix/3311-main-ruleset-gates

Conversation

@Xore

@Xore Xore commented Sep 26, 2026

Copy link
Copy Markdown
Owner

Summary

Prerequisite for the main ruleset in #3311. main has no protection today, so Dependabot's gh pr merge --auto merges immediately; five PRs landed 2026-09-25 with red checks (#3285, #3287, #3288, #3289, #3291) and the backend stayed broken until #3300.

  • Quality gate (quality.yml): one always-reporting context. Passes only when the router succeeded and each job pair produced a homeserver success or skip + GitHub-hosted success, plus the existing Go formatting and tests / Scripts and Compose aggregates.
  • Containers gate (containers.yml): router and every image row succeeded.
  • dependabot-auto-merge: holds any 0.x minor bump (fetch-metadata calls rand 0.9 → 0.10 semver-minor) and comments instead of approving.
  • docs/CI-CD.md: ruleset contract and the rule for adding new job pairs; corrects the paragraph claiming protection existed.

The ruleset itself is created after this merges. Requiring Quality gate before the job exists on main would leave every open PR pending.

Security impact

  • No real credentials, private addresses, payloads, PCAPs, keys, or .env files were added.
  • Sandbox/network-isolation implications were reviewed. (None: CI only.)
  • Publicly exposed ports and routes are unchanged.

Validation

  • actionlint 1.7.7 on all three workflows: no new findings (only the existing info-level SC2086 at quality.yml:201/219).
  • Gate logic run locally against simulated needs results: all-green homeserver → pass; all-green fallback → pass; homeserver twin failed → fail; fallback twin failed → fail; router failed and everything skipped → fail; Go aggregate failed → fail; cancelled → fail.
  • 0.x hold: rand 0.9.5 → 0.10.2 held; serde 1.0 → 1.1 and tokio 0.2.1 → 0.2.3 (patch) not held; empty metadata not held.
  • This PR's own run is the first real run of both gates.

Refs #3311

…old 0.x minor bumps

main had no branch protection, so dependabot's `gh pr merge --auto` merged
on the spot: five PRs landed on 2026-09-25 with red Rust and container
checks, and main's backend stayed broken until #3300.

A ruleset needs contexts that report on every PR. Quality's jobs come in
homeserver/GitHub-hosted pairs and Containers' rows carry a "(GitHub-hosted)"
suffix on fallback days, so no individual job name is stable. Add:

- quality-gate ("Quality gate"): success iff the router succeeded and every
  pair produced a homeserver success or a skip + fallback success, plus the
  existing Go and Scripts aggregates. always(), so a failed router reports
  red rather than pending.
- containers-gate ("Containers gate"): router and every image row succeeded.

dependabot-auto-merge: hold any update that moves a 0.x dependency's minor
version (grouped PRs: any member). fetch-metadata labels 0.9 -> 0.10
semver-minor although semver and Cargo treat it as breaking; that is how
rand (#3287) and sha2 (#3289) qualified.

docs/CI-CD.md: document the ruleset and its required contexts, correct the
Dependabot paragraph that claimed protection already existed.

Refs #3311
@Xore Xore added ops Deployment, runners, observability, host access security Security hardening or a security defect labels Sep 26, 2026
@github-actions

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

Scanned Files

None

@Xore
Xore merged commit 478bca9 into main Sep 26, 2026
111 of 112 checks passed
@Xore
Xore deleted the fix/3311-main-ruleset-gates branch September 26, 2026 12:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ops Deployment, runners, observability, host access security Security hardening or a security defect

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant