You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
[Devops] Wire schema's CI checks up as required status checks (safe-settings in omf-github-terraform) #646
schema's repo-level ruleset (default + vnext, covers main and vnext) has no required_status_checks rule. The only required check anywhere is the org-wide DCO ruleset, on main only. None of this repo's own CI, check-python-code, vnext-compat compatibility check, require-changelog-fragment, enforce-change-type-label, check-python-package-versions, test-schema, or the Phase 3 publish workflows, is required to pass before merge.
Now that Phase 3 (#509) lands the last piece of the branching/versioning/publish pipeline, this is the point to lock the existing CI safety nets in as required checks instead of advisory-only.
Per the precedent on #584 (tag immutability), ruleset changes on OvertureMaps/schema are managed declaratively as a safe-settings change in omf-github-terraform, not clicked in the UI or set via the API directly on this repo.
Scope
Open a PR in omf-github-terraform adding a required_status_checks rule to schema's branch ruleset (main and vnext), covering at minimum:
Confirm each check's name is stable before pinning it: matrix jobs (check-python-code.yaml's per-Python-version cells) produce one status per cell with no aggregator, so adding a Python version to the matrix silently drops it from the required set until the ruleset is updated to match. Consider adding an all-checks-pass gate job (needs: [...], if: always()) to check-python-code.yaml first, so the required-check list only ever needs one stable name.
pr-advisory.yaml is explicitly advisory (surfaces a likely change-type/target-branch mismatch for the reviewer to judge), not a candidate for required.
Context
schema's repo-level ruleset (default + vnext, coversmainandvnext) has norequired_status_checksrule. The only required check anywhere is the org-wideDCOruleset, onmainonly. None of this repo's own CI,check-python-code,vnext-compatcompatibility check,require-changelog-fragment,enforce-change-type-label,check-python-package-versions,test-schema, or the Phase 3 publish workflows, is required to pass before merge.Now that Phase 3 (#509) lands the last piece of the branching/versioning/publish pipeline, this is the point to lock the existing CI safety nets in as required checks instead of advisory-only.
Per the precedent on #584 (tag immutability), ruleset changes on
OvertureMaps/schemaare managed declaratively as a safe-settings change inomf-github-terraform, not clicked in the UI or set via the API directly on this repo.Scope
omf-github-terraformadding arequired_status_checksrule toschema's branch ruleset (mainandvnext), covering at minimum:Check (default, py3.10)…Check (default, py3.14),Check (lowest-direct, py3.10)(check-python-code.yaml)Build(test-schema.yaml, now PR-triggered, see companion fix on PR [FEATURE] Branching strategy Phase 3 - PyPI and CodeArtifact publish workflows #638)Check vnext compatibility(vnext-compat.yaml)Require changelog on package change(require-changelog-fragment.yaml)Check label(enforce-change-type-label.yaml)Check Python package versions(check-python-package-versions.yaml)check-python-code.yaml's per-Python-version cells) produce one status per cell with no aggregator, so adding a Python version to the matrix silently drops it from the required set until the ruleset is updated to match. Consider adding anall-checks-passgate job (needs: [...],if: always()) tocheck-python-code.yamlfirst, so the required-check list only ever needs one stable name.push-only workflows don't fire for fork PRs and would deadlock a required check that depends on them (see thetest-schema.yamlfix on PR [FEATURE] Branching strategy Phase 3 - PyPI and CodeArtifact publish workflows #638).Out of scope
pr-advisory.yamlis explicitly advisory (surfaces a likely change-type/target-branch mismatch for the reviewer to judge), not a candidate for required.release-trigger.yaml/release-publish.yaml/main-publish.yaml's push-triggered publish job aren't PR checks.Acceptance
required_status_checksis live onschema'smain/vnextruleset via a mergedomf-github-terraformPR (not applied ad hoc via the UI).Parent: #509