Repository navigation
fix(ci): drop paths filter from required-check workflows (branch-protection deadlock) - #53
Merged
Merged
Conversation
Branch protection on main requires four status checks. Three of them
("Unit Tests & Coverage", "Integration Smoke Tests", "Quick Security
Scan") come from ci-gates.yml and fast-tests.yml, which had a paths:
filter on their pull_request trigger.
On a PR that touches no matching files (docs- or YAML-only, e.g. the
automated docs/changelog-v* PR created by release.yml) those workflows
never run, so the required checks never report and the PR stays BLOCKED
forever with no timeout and no error.
Removing the paths: filter makes the workflows run on every PR so the
required contexts always report. Job names, permissions, concurrency and
the push/workflow_dispatch triggers are unchanged.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Contributor
🔍 CI Quality Gates SummaryOverall Status: ✅ All Passed
🔗 Quick Links🛠️ Quick Fix Commands# Fix most issues automatically
ruff format .
ruff check . --fix
# Run tests locally
pytest tests/unit/ --cov=markitdown_mcp
# Check types
mypy markitdown_mcpLast updated: 2026-08-24 22:37:18 UTC |
Contributor
🔍 PR Quality SummaryCI Status✅ Docs: success Metrics
Quality Checks
MCP Tools
🤖 Auto-generated by CI • Last updated: 2026-08-24 22:37 UTC |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The problem
Branch protection on
mainrequires four status checks:(
strict: true,required_approving_review_count: 0,enforce_admins: false)Three of the four come from path-filtered workflows:
Unit Tests & Coverage.github/workflows/ci-gates.ymlIntegration Smoke Tests.github/workflows/fast-tests.ymlQuick Security Scan.github/workflows/fast-tests.ymlBoth had a
paths:filter on thepull_requesttrigger (**/*.py,pyproject.toml,requirements*.txt, own workflow file).This is the classic path-filtered required checks anti-pattern: on a PR that touches none of those paths — e.g. a Markdown- or YAML-only change — the workflows never trigger, therefore never report a status, and the PR stays
BLOCKEDforever. No timeout, no error; it just hangs waiting for checks that will never arrive.All Checks Status(pr-summary.yml) is not path-filtered and reports correctly. Only the three above are affected.Why this is urgent
.github/workflows/release.ymljobupdate-docsautomatically opens a PR on branchdocs/changelog-v<VERSION>that changes onlyCHANGELOG.md. That is exactly the failing pattern — the release automation produces PRs that can never be merged without an admin override.This already happened for real: PRs #50 and #51 (YAML + Markdown only) had to be merged with
gh pr merge --adminbecause the checks never reported.The fix
Remove the
paths:filter from thepull_requesttrigger in both workflows, with an explanatory comment above each trigger.push:andworkflow_dispatch:are unchanged. No changes to jobs, jobname:fields (these are the required context names),concurrencyorpermissions. Branch protection is untouched — the fix belongs in the workflows, not in the protection rule.Trade-off (deliberate)
Docs-only PRs now also run the Python tests, costing a bit of CI time. That is acceptable: these are the workflows explicitly designed as "fast" (
fast-tests.ymlhastimeout-minutes: 10), and a permanently blocked PR is far more expensive than a few minutes of runner time.The alternative — a second workflow with identical job names running on the complementary paths and reporting success only — is error-prone: the job names would have to be kept in sync in two places, and any drift reintroduces exactly this deadlock.
Note on this PR's own checks
This PR changes only YAML and Markdown, i.e. the affected category in general. It does not get stuck itself, because it modifies
.github/workflows/ci-gates.ymland.github/workflows/fast-tests.yml, and those paths were part of the old filters — so the workflows still trigger here and all four required checks report normally. (Confirmed on this PR:Unit Tests & Coverage,Integration Smoke Tests,Quick Security ScanandAll Checks Statusall ran.)Any other docs-only PR — in particular the automated
docs/changelog-v*PR fromrelease.yml— would hang. That is what this change fixes, from the merge onward.Validation
actionlinton both files: 6 shellcheck findings, identical to the baseline before the change (pre-existing SC2086 in untouchedrun:blocks) — no new findings.on:blocks.name:values exactly.Co-authored-by: Copilot App 223556219+Copilot@users.noreply.github.com