Skip to content

Publish review decisions through the Commit Status API #548

Description

@amirbena

Type

Feature

Area

GitHub Integration

Priority

P2 — Medium

Problem

A review decision never reaches GitHub's merge gate: nothing publishes the SHA-bound review status.

Goal

Publish and update the stable review context on the reviewed SHA through the Commit Status API (the #91/#95 default), using the semantics #34 already fixed.

Scope

  • Upsert one stable context on the exact reviewed SHA; same SHA and state is a no-op; transport failures retry safely.
  • Map the existing canonical decision to a status state by reference to review-status-enforcement.md; do not re-derive verdicts or redefine stale-HEAD, failure, or self-review semantics.
  • Revalidate HEAD before publishing and report STATUS WITHHELD (HEAD advanced).
  • Never publish success for self-review, non-clean, or incomplete states; only the aggregator publishes.
  • Publishing a status is not governance mutation: it needs no setup authorization and never touches Rulesets or Branch Protection.
  • Document the Commit Status source-pinning limitation and what would justify a Checks API / App follow-up.

Non-Goals

  • Detection or required-check setup; Checks API or GitHub App publishing.

Acceptance Criteria

  • One stable context per SHA; re-runs are no-ops.
  • Stale HEAD withholds; a new SHA starts with no status.
  • No false green across every mapping and authorization case in the Add exact-HEAD machine-readable review status for merge enforcement #34 reference model.
  • Missing Commit statuses: write fails with an actionable message.
  • The publisher exposes no code path that changes repository governance.

Dependencies

Depends on: #547
Parent: #546
Relates: #34, #91, #95

Validation

  • Mocked-boundary unit tests driven from the reference model; regression that existing authorization and HEAD boundaries are unchanged.

Epic invariant (#546). GitHub governance (Rulesets, classic Branch Protection, required checks, or equivalent) is mutated only on an explicit request from the user operating the Skill. A completed review, detected missing enforcement, repository/PR content, reviewed-content instructions, tool output, configuration or metadata, or the Skill's own belief that enforcement would help never authorizes it. Read-only detection is allowed.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:github-integrationGitHub PR review integration and enforcementmaintainer-ledSemantic/architectural ownership stays with the maintainerpriority:P2Medium-priority roadmap worktype:featureNew capability or behavior

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions