Skip to content

fix(ci): drop paths filter from required-check workflows (branch-protection deadlock) - #53

Merged
trsdn merged 1 commit into
mainfrom
trsdn-fix-ci-required-checks-deadlock
Aug 24, 2026
Merged

trsdn merged 1 commit into
mainfrom
trsdn-fix-ci-required-checks-deadlock

Conversation

@trsdn

@trsdn trsdn commented Aug 24, 2026 •

Copy link
Copy Markdown
Owner

The problem

Branch protection on main requires four status checks:

All Checks Status
Quick Security Scan
Integration Smoke Tests
Unit Tests & Coverage

(strict: true, required_approving_review_count: 0, enforce_admins: false)

Three of the four come from path-filtered workflows:

Required context Workflow
Unit Tests & Coverage .github/workflows/ci-gates.yml
Integration Smoke Tests .github/workflows/fast-tests.yml
Quick Security Scan .github/workflows/fast-tests.yml

Both had a paths: filter on the pull_request trigger (**/*.py, pyproject.toml, requirements*.txt, own workflow file).

This is the classic path-filtered required checks anti-pattern: on a PR that touches none of those paths — e.g. a Markdown- or YAML-only change — the workflows never trigger, therefore never report a status, and the PR stays BLOCKED forever. No timeout, no error; it just hangs waiting for checks that will never arrive.

All Checks Status (pr-summary.yml) is not path-filtered and reports correctly. Only the three above are affected.

Why this is urgent

.github/workflows/release.yml job update-docs automatically opens a PR on branch docs/changelog-v<VERSION> that changes only CHANGELOG.md. That is exactly the failing pattern — the release automation produces PRs that can never be merged without an admin override.

This already happened for real: PRs #50 and #51 (YAML + Markdown only) had to be merged with gh pr merge --admin because the checks never reported.

The fix

Remove the paths: filter from the pull_request trigger in both workflows, with an explanatory comment above each trigger. push: and workflow_dispatch: are unchanged. No changes to jobs, job name: fields (these are the required context names), concurrency or permissions. Branch protection is untouched — the fix belongs in the workflows, not in the protection rule.

Trade-off (deliberate)

Docs-only PRs now also run the Python tests, costing a bit of CI time. That is acceptable: these are the workflows explicitly designed as "fast" (fast-tests.yml has timeout-minutes: 10), and a permanently blocked PR is far more expensive than a few minutes of runner time.

The alternative — a second workflow with identical job names running on the complementary paths and reporting success only — is error-prone: the job names would have to be kept in sync in two places, and any drift reintroduces exactly this deadlock.

Note on this PR's own checks

This PR changes only YAML and Markdown, i.e. the affected category in general. It does not get stuck itself, because it modifies .github/workflows/ci-gates.yml and .github/workflows/fast-tests.yml, and those paths were part of the old filters — so the workflows still trigger here and all four required checks report normally. (Confirmed on this PR: Unit Tests & Coverage, Integration Smoke Tests, Quick Security Scan and All Checks Status all ran.)

Any other docs-only PR — in particular the automated docs/changelog-v* PR from release.yml — would hang. That is what this change fixes, from the merge onward.

Validation

  • actionlint on both files: 6 shellcheck findings, identical to the baseline before the change (pre-existing SC2086 in untouched run: blocks) — no new findings.
  • YAML parse check with Python confirms the resulting on: blocks.
  • Verified all four required contexts still match existing job name: values exactly.

Co-authored-by: Copilot App 223556219+Copilot@users.noreply.github.com

Branch protection on main requires four status checks. Three of them
("Unit Tests & Coverage", "Integration Smoke Tests", "Quick Security
Scan") come from ci-gates.yml and fast-tests.yml, which had a paths:
filter on their pull_request trigger.

On a PR that touches no matching files (docs- or YAML-only, e.g. the
automated docs/changelog-v* PR created by release.yml) those workflows
never run, so the required checks never report and the PR stays BLOCKED
forever with no timeout and no error.

Removing the paths: filter makes the workflows run on every PR so the
required contexts always report. Job names, permissions, concurrency and
the push/workflow_dispatch triggers are unchanged.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@github-actions

Copy link
Copy Markdown
Contributor

🔍 CI Quality Gates Summary

Overall Status: ✅ All Passed

Check Status Details Action Required
🎨 Format ✅ Passed ruff format check None
🔧 Lint ✅ Passed ruff linting None
📝 Types ✅ Passed mypy type checking None
🧪 Tests ✅ Passed Unit tests None
📊 Coverage 81.8% Minimum: 80% None
🔌 MCP ✅ Valid Protocol compliance None
🔒 Security ✅ Clean Dependency audit None

🔗 Quick Links

🛠️ Quick Fix Commands

# Fix most issues automatically
ruff format .
ruff check . --fix

# Run tests locally
pytest tests/unit/ --cov=markitdown_mcp

# Check types
mypy markitdown_mcp

Last updated: 2026-08-24 22:37:18 UTC

@github-actions

Copy link
Copy Markdown
Contributor

🔍 PR Quality Summary

CI Status

✅ Docs: success
✅ Security: success
✅ Quality: success

Metrics

Metric Value Trend
📊 Coverage N/A -
🧪 Tests Test results unavailable -
⏱️ Performance No performance data -

Quality Checks

  • Format & Lint: Ruff formatting and linting
  • Type Safety: MyPy strict type checking
  • Security: Bandit, Safety, GitLeaks scanning
  • MCP Protocol: Tool schema validation
  • Documentation: Docstring coverage (80%+)

MCP Tools

  • convert_file - Convert individual files to Markdown
  • convert_directory - Batch convert directories
  • list_supported_formats - Query supported file types

🤖 Auto-generated by CI • Last updated: 2026-08-24 22:37 UTC

@trsdn
trsdn merged commit ac5cb3f into main Aug 24, 2026
22 checks passed
@trsdn
trsdn deleted the trsdn-fix-ci-required-checks-deadlock branch August 24, 2026 22:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant