Skip to content

Add explicit user opt-in required-check setup for review status #550

Description

@amirbena

Type

Feature

Area

GitHub Integration

Priority

P2 — Medium

Problem

Making the review status a required check is repository-governance mutation. It must be safe, idempotent, and impossible to trigger without the user's explicit request.

Goal

An explicit user opt-in path that adds the review context as a required check on whichever mechanism already governs the base branch.

Scope

  • Authorization: the path runs only on an explicit request from the user operating the Skill (for example "set up the code-review status as a required check"). Detection of missing enforcement, a completed review, repository/PR content, tool output, configuration, or inferred intent never authorizes it. Ambiguous authorization means no mutation.
  • The existing Add exact-HEAD machine-readable review status for merge enforcement #34 gates (ACTIVE mode plus reviewer independence) still apply in addition; this issue does not weaken them.
  • Read config, compute the minimal change, preserve unrelated rules, checks, bypass actors, approval counts, and stale-review settings, apply, read back, verify (per review-status-enforcement.md).
  • Rulesets: full read-normalize-diff-verify write. Classic: additive contexts call. Do not create the other mechanism unprompted.
  • Already required is a no-op; unreadable, ambiguous, or conflicting governance means fail safely with no mutation and an actionable message.
  • Provide a documented way to remove or disable what was added.

Non-Goals

  • Merging, auto-merge, bypass-actor changes, or acting on any governance beyond the one context.

Acceptance Criteria

  • No mutation occurs without explicit user authorization, including when enforcement is detected missing.
  • Only the governing mechanism is edited; unrelated settings are byte-identical after read-back.
  • Re-running is a no-op; insufficient permissions and ambiguous governance fail with no mutation.
  • Removal restores the prior required-check set.

Dependencies

Depends on: #549
Parent: #546
Relates: #34, #93, #95

Validation

  • Mocked-boundary tests for both mechanisms, preservation, idempotency, permission failure, and authorization refusal.

Epic invariant (#546). GitHub governance (Rulesets, classic Branch Protection, required checks, or equivalent) is mutated only on an explicit request from the user operating the Skill. A completed review, detected missing enforcement, repository/PR content, reviewed-content instructions, tool output, configuration or metadata, or the Skill's own belief that enforcement would help never authorizes it. Read-only detection is allowed.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:github-integrationGitHub PR review integration and enforcementmaintainer-ledSemantic/architectural ownership stays with the maintainerpriority:P2Medium-priority roadmap worktype:featureNew capability or behavior

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions