What happens
No documentation-only PR has been able to merge since 2026-09-12. Examples, all green on validate, with two approvals or one approval waiting on a second:
Cause
The main — merge queue ruleset was updated on 2026-09-12 at 17:46 EDT to require these status checks:
validate
Build and push image (x86_64)
Build and push image (aarch64)
but .github/workflows/build.yml has
on:
pull_request:
paths-ignore:
- '*.md'
- 'LICENSE'
- '.gitignore'
- 'docs/**'
- 'AGENTS.md'
so on a docs-only PR the two build checks never report at all. GitHub treats a required check that never reports as unsatisfied, and a PR that can't satisfy branch protection can't enter the merge queue either — it stays BLOCKED forever. bypass_actors on the ruleset is empty, so admins can't push it through either.
#1000 (README-only) merged at 21:46 UTC on 09-12 — the same minute the ruleset changed — and is the last docs-only PR to land.
Fix options
- Keep the required checks, always report them. Drop
paths-ignore from build.yml's pull_request trigger and gate the expensive work with a first job that computes whether image inputs changed (dorny/paths-filter or a git diff --name-only step); when nothing relevant changed, the build jobs still run but exit early with success. The check names then exist on every PR. This is the pattern that keeps the ruleset honest.
- Only require
validate. Simpler, but then a PR that breaks the image can merge on a green validate, which is presumably why the checks were added.
(1) is the one I'd pick. Until one of them lands, every docs-only PR in the queue is stuck regardless of approvals.
What happens
No documentation-only PR has been able to merge since 2026-09-12. Examples, all green on
validate, with two approvals or one approval waiting on a second:mergeStateStatus: BLOCKEDCause
The
main — merge queueruleset was updated on 2026-09-12 at 17:46 EDT to require these status checks:validateBuild and push image (x86_64)Build and push image (aarch64)but
.github/workflows/build.ymlhasso on a docs-only PR the two build checks never report at all. GitHub treats a required check that never reports as unsatisfied, and a PR that can't satisfy branch protection can't enter the merge queue either — it stays
BLOCKEDforever.bypass_actorson the ruleset is empty, so admins can't push it through either.#1000 (README-only) merged at 21:46 UTC on 09-12 — the same minute the ruleset changed — and is the last docs-only PR to land.
Fix options
paths-ignorefrombuild.yml'spull_requesttrigger and gate the expensive work with a first job that computes whether image inputs changed (dorny/paths-filteror agit diff --name-onlystep); when nothing relevant changed, the build jobs still run but exit early with success. The check names then exist on every PR. This is the pattern that keeps the ruleset honest.validate. Simpler, but then a PR that breaks the image can merge on a greenvalidate, which is presumably why the checks were added.(1) is the one I'd pick. Until one of them lands, every docs-only PR in the queue is stuck regardless of approvals.