Repository navigation
ci: add fail-closed validation aggregates - #551
Merged
Merged
Conversation
This was referenced Oct 6, 2026
Collaborator
Author
|
Review at 8da3ea6. The aggregates are correct:
Also noting that the PR description says the full local |
3 tasks
Collaborator
Author
|
Review follow-up applied in b6d158c and 443ab43:
Validation:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Add stable, fail-closed merge-policy contexts for the framework validation contract.
Issue
Refs #540
Validation
tests/ci-policy-contract.shtests/quality-contract.shshellcheck --severity=warning tests/ci-policy-contract.sh tests/validate.sh tests/lint-warnings.sh./tests/validate.shreached all 708 BATS tests and the Python contract suite successfully; the later artifact-contract fixture failed because the sandboxedapi.github.testendpoint reset its connection.Demo Impact
None.
Docs Impact
Updated
docs/ci-policy.mdwith the aggregate contexts, coverage, fail-closed behavior, accepted same-workflow trust boundary, and post-merge ruleset readback procedure.API Impact
None.
CI Impact
Product validationaggregates platform, minimum-runtime, compatibility, release, and Beacon lanes.Quality contractaggregates the quality lane. Both run withalways()and require every dependency to report exactlysuccess. Both are intended to become required after the post-merge ruleset readback.Security Notes
No additional permissions; aggregate jobs remain
contents: read.Notes
This PR intentionally does not mutate live branch protection. After merge, add
Product validationandQuality contractwith Actions integration ID15368to the effective ruleset and read back the existing controls, per the documented procedure.