ci: require two approvals on docs-agent pull requests - #12274
Open
Conversation
`mergify-ci-bot` satisfies the "👀 Review Requirements" merge protection with **zero** approvals and is auto-queued through the `automated updates` lane. That is right for the deterministic syncers in `Mergifyio/ci-bot` — a changelog copy or a JSON-schema sync needs no reviewers — and wrong for the scheduled docs agent, which opens pull requests full of prose a model wrote. Nothing but the draft flag holds that line today. The agent opens drafts only (`draft: always-true`, not overridable at runtime), so a human must act before anything lands; but the moment someone marks one ready, it can merge with no approval on it at all. ci-bot#282 merged today, which armed the Monday 06:00 Europe/Paris health audit, so this wants to land first. Both bots push from the same fork (`mergify-ci-bot/docs`), so `author` and `head-repo-full-name` cannot tell them apart. The branch prefix can: the runner's `scope.py` names every branch `docs-agent/health-audit-<section>` or `docs-agent/change-watch`, and it is the only place a branch name is minted. Four rules change, keyed on that prefix so the syncers keep their fast path: - **`👀 Review Requirements`** — the `mergify-ci-bot` free pass is now conditional on the head *not* being a `docs-agent/` branch. Agent pull requests fall through to `#approved-reviews-by >= 2`, the same bar as anyone else. The `&DefaultReviewCond` anchor is shared, so the hotfix rule tightens identically. - **`automated updates` queue rule** — agent branches are kept out of the fast-forward, batch-of-10 lane. - **`default` queue rule** — and therefore have to be let in here, or they would match no queue at all and could not be merged even once approved (`auto_merge_conditions: true` auto-queues, then the queue rules route). They inherit `squash` and the weekday merge window, like human pull requests. - **`request review`** — routes agent pull requests to `@devs`, since they now need approvals and nothing else would ask for them. Gated on `-draft`, so the ten drafts a Monday audit opens do not each ping the team before a human has decided one is worth merging. Not changed: the `automated updates` *priority* rule still matches the agent, so its pull requests sit at `low` behind human work in the `default` queue. That reads as correct; say so if it isn't. ## Note on the snippet in the ticket MRGFY-8340 and `docs-agent/README.md` both propose `-head-ref ~= ^docs-agent/`. There is no `head-ref` attribute — the 75 condition attributes in `public/mergify-configuration-schema.json` have `head` ("the name of the branch where the pull request changes are implemented"). Using `head` here. The snippet also stopped at two rules; the `default` queue and review routing above are the rest of the change. ## Validation - `mergify config validate` on a merge-key-expanded copy of this file: valid. (Run against the file as written it reports three pre-existing `'<<' was unexpected` errors — the CLI's loader does not resolve YAML merge keys. Same three before and after this change.) - `mergify config simulate https://github.com/Mergifyio/docs/pull/12272` (a real `mergify-ci-bot` schema-sync pull request, from the fork) with this config: `-head ~= ^docs-agent/` evaluates true, the free pass holds, and `request review` stays not-applicable. The syncers are unaffected. - Same simulation with the regex swapped to `^json-schema-` so that it matches #12272's actual head: the free pass collapses, `#approved-reviews-by >= 2` becomes the operative condition, and `request review` activates. That is the docs-agent path, demonstrated on a real pull request rather than read by eye. - `pnpm check`: green. No `docs-agent/` pull request exists yet to simulate against directly — the first one arrives with the first scheduled run. MRGFY-8340 Change-Id: I18fd35f5d4b02daa5f2afa22af99745463982e4d
Contributor
Merge Protections🔴 2 of 7 protections blocking · waiting on 👀 reviews
🔴 👀 Review RequirementsWaiting for
This rule is failing.
🔴 🔎 ReviewsWaiting for
This rule is failing.
Show 5 satisfied protections🟢 📃 Configuration Change RequirementsMergify configuration change
🟢 🤖 Continuous Integration
🟢 Enforce conventional commitMake sure that we follow https://www.conventionalcommits.org/en/v1.0.0/
🟢 📕 PR description
🟢 🚦 Auto-queueWhen all merge protections are satisfied, this pull request will be queued automatically. |
There was a problem hiding this comment.
Pull request overview
This PR updates the repository’s Mergify configuration to ensure docs-agent pull requests (identified by the docs-agent/ head branch prefix) no longer inherit the “zero-approval” fast path intended for deterministic mergify-ci-bot sync PRs, and instead require human review before merging.
Changes:
- Tightens the shared review-requirements condition so
mergify-ci-botonly bypasses approvals when the PR head branch does not match^docs-agent/. - Excludes
docs-agent/branches from theautomated updatesqueue lane and routes them to thedefaultqueue lane so they remain mergeable once approved. - Updates the “request review” rule to request
@devsreview fordocs-agent/PRs only after they are no longer drafts.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
jd
marked this pull request as ready for review
July 30, 2026 18:46
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
mergify-ci-botsatisfies the "👀 Review Requirements" merge protection withzero approvals and is auto-queued through the
automated updateslane.That is right for the deterministic syncers in
Mergifyio/ci-bot— a changelogcopy or a JSON-schema sync needs no reviewers — and wrong for the scheduled
docs agent, which opens pull requests full of prose a model wrote.
Nothing but the draft flag holds that line today. The agent opens drafts only
(
draft: always-true, not overridable at runtime), so a human must act beforeanything lands; but the moment someone marks one ready, it can merge with no
approval on it at all. ci-bot#282 merged today, which armed the Monday 06:00
Europe/Paris health audit, so this wants to land first.
Both bots push from the same fork (
mergify-ci-bot/docs), soauthorandhead-repo-full-namecannot tell them apart. The branch prefix can: therunner's
scope.pynames every branchdocs-agent/health-audit-<section>ordocs-agent/change-watch, and it is the only place a branch name is minted.Four rules change, keyed on that prefix so the syncers keep their fast path:
👀 Review Requirements— themergify-ci-botfree pass is nowconditional on the head not being a
docs-agent/branch. Agent pullrequests fall through to
#approved-reviews-by >= 2, the same bar as anyoneelse. The
&DefaultReviewCondanchor is shared, so the hotfix rule tightensidentically.
automated updatesqueue rule — agent branches are kept out of thefast-forward, batch-of-10 lane.
defaultqueue rule — and therefore have to be let in here, or theywould match no queue at all and could not be merged even once approved
(
auto_merge_conditions: trueauto-queues, then the queue rules route).They inherit
squashand the weekday merge window, like human pull requests.request review— routes agent pull requests to@devs, since they nowneed approvals and nothing else would ask for them. Gated on
-draft, so theten drafts a Monday audit opens do not each ping the team before a human has
decided one is worth merging.
Not changed: the
automated updatespriority rule still matches the agent,so its pull requests sit at
lowbehind human work in thedefaultqueue.That reads as correct; say so if it isn't.
Note on the snippet in the ticket
MRGFY-8340 and
docs-agent/README.mdboth propose-head-ref ~= ^docs-agent/.There is no
head-refattribute — the 75 condition attributes inpublic/mergify-configuration-schema.jsonhavehead("the name of the branchwhere the pull request changes are implemented"). Using
headhere. Thesnippet also stopped at two rules; the
defaultqueue and review routing aboveare the rest of the change.
Validation
mergify config validateon a merge-key-expanded copy of this file: valid.(Run against the file as written it reports three pre-existing
'<<' was unexpectederrors — the CLI's loader does not resolve YAML mergekeys. Same three before and after this change.)
mergify config simulate https://github.com/Mergifyio/docs/pull/12272(a realmergify-ci-botschema-sync pull request, from the fork) with this config:-head ~= ^docs-agent/evaluates true, the free pass holds, andrequest reviewstays not-applicable. The syncers are unaffected.^json-schema-so that it matcheschore: sync Mergify JSON Schema files #12272's actual head: the free pass collapses,
#approved-reviews-by >= 2becomes the operative condition, and
request reviewactivates. That is thedocs-agent path, demonstrated on a real pull request rather than read by eye.
pnpm check: green.No
docs-agent/pull request exists yet to simulate against directly — thefirst one arrives with the first scheduled run.
MRGFY-8340