Skip to content

fix(ci): merge validated ingest pull requests automatically - #366

Merged
duncanleo merged 1 commit into
mainfrom
codex/automate-ingest-merge
Oct 1, 2026
Merged

duncanleo merged 1 commit into
mainfrom
codex/automate-ingest-merge

Conversation

@duncanleo

@duncanleo duncanleo commented Oct 1, 2026 •

Copy link
Copy Markdown
Member

Summary

  • Run deterministic repository checks, package builds and tests, fixture validation, and a Pages build before committing generated ingest data.
  • Merge each validated automated PR directly, guarded by the exact pushed head SHA. This covers both newly created and updated automated PRs.
  • Dispatch the Pages deployment after the merge because a merge made with GITHUB_TOKEN does not trigger a push workflow.

Why

gh pr merge --auto failed on a clean PR because main has no required merge conditions. PR workflows created with GITHUB_TOKEN require manual approval, so making those checks required would not provide unattended merges.

Verification

  • npm run lint
  • npm run check
  • npm run build:packages
  • npm run fixtures:validate
  • TZ=UTC npm test (372 tests)
  • TZ=UTC npm run test:packages
  • npm run pages:build
  • npm run data:validate
  • YAML syntax parse and git diff --check

Summary by CodeRabbit

  • Chores
    • Automated content updates now pass validation, build, and test checks before being merged.
    • Site deployment is triggered after eligible updates are merged to the main branch.

Co-Authored-By: Codex <noreply@openai.com>
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-01T06:06:45.966616Z 5801f47 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 8e5eb166-c863-4d04-b588-d028e71a9834

📥 Commits

Reviewing files that changed from the base of the PR and between fd500f4 and 5801f47.

📒 Files selected for processing (1)
  • .github/workflows/ingest.yml

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The ingestion workflow now runs checks when it detects changes. It records the pushed commit SHA, conditionally squash-merges the target branch, and explicitly dispatches Pages deployment.

Changes

Ingestion workflow

Layer / File(s) Summary
Pre-push validation
.github/workflows/ingest.yml
When changes are detected, the workflow runs six checks before it selects a target branch or pushes changes.
Conditional merge and deployment
.github/workflows/ingest.yml
The workflow records the pushed commit SHA and updates the pull request title and body. It squash-merges only if the target branch head matches that SHA, then dispatches Pages deployment when changes exist.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~12 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to 5801f

The workflow validates ingestion updates before merging and explicitly starts Pages deployment afterward. No actionable merge-blocking risk was identified.

Architecture Summary

Architecture risk: 🔵 Low · up to 5801f

The changed surface does not map to a changed system, dependency edge, entrypoint, or external dependency.

Changed systems: None identified.

Architecture concerns
No architecture-level concerns identified.

Review details

Before / after behavior

  • observed — Modified behavior in .github/workflows/ingest.yml: The workflow adds the actions: write permission.
  • observed — Modified behavior in .github/workflows/ingest.yml: A new step runs six checks when changes were detected, before the workflow chooses a target branch or pushes changes.
  • observed — Modified behavior in .github/workflows/ingest.yml: The push step gains an ID so later steps can access its outputs.
  • observed — Modified behavior in .github/workflows/ingest.yml: After pushing, the workflow records the commit SHA. The pull-request creation condition remains limited to changed runs whose latest branch is main.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: automatically merging validated ingest pull requests.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@duncanleo
duncanleo merged commit a9c1586 into main Oct 1, 2026
2 checks passed
@duncanleo
duncanleo deleted the codex/automate-ingest-merge branch October 1, 2026 06:06

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 5801f47f42

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

GH_TOKEN: ${{ github.token }}
BRANCH_NAME: ${{ steps.target-branch.outputs.branch-name }}
HEAD_SHA: ${{ steps.push-changes.outputs.head-sha }}
run: gh pr merge "$BRANCH_NAME" --repo "$GITHUB_REPOSITORY" --squash --match-head-commit "$HEAD_SHA"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Gate automatic merges on semantic ingestion checks

When ingestion produces schema-valid but semantically incorrect data, this unconditional merge publishes it without review. docs/plans/active/direct-main-ingestion.md lines 18-56 documents material errors still caught by review—including seven automated PRs rejected entirely—and says the current detectors miss incorrect scopes, effects, periods, issue matching, and relevance; none of the newly added deterministic commands supplies the planned semantic guards, quarantine, or source-eligibility gate. Retain review or implement those gates before merging every ingest result automatically.

AGENTS.md reference: AGENTS.md:L106-L107

Useful? React with 👍 / 👎.

GH_TOKEN: ${{ github.token }}
BRANCH_NAME: ${{ steps.target-branch.outputs.branch-name }}
HEAD_SHA: ${{ steps.push-changes.outputs.head-sha }}
run: gh pr merge "$BRANCH_NAME" --repo "$GITHUB_REPOSITORY" --squash --match-head-commit "$HEAD_SHA"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Revalidate after confirming main is unchanged

When main advances after checkout while model calls and tests are running, this command merges a head validated against the old base into the new main. As confirmed by gh pr merge --help, --match-head-commit only requires that the pull-request head match the supplied SHA; it does not pin the base, and the ingestion concurrency group does not block unrelated merges. Thus non-conflicting schema and data changes can produce a combined tree that was never validated, contrary to the discard-and-rerun requirement in docs/plans/active/direct-main-ingestion.md lines 301-303; capture the starting main SHA and rerun if it changes before merging.

AGENTS.md reference: AGENTS.md:L106-L107

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants