Skip to content

[Devops] Wire schema's CI checks up as required status checks (safe-settings in omf-github-terraform) #646

Description

@lowlydba

Context

schema's repo-level ruleset (default + vnext, covers main and vnext) has no required_status_checks rule. The only required check anywhere is the org-wide DCO ruleset, on main only. None of this repo's own CI, check-python-code, vnext-compat compatibility check, require-changelog-fragment, enforce-change-type-label, check-python-package-versions, test-schema, or the Phase 3 publish workflows, is required to pass before merge.

Now that Phase 3 (#509) lands the last piece of the branching/versioning/publish pipeline, this is the point to lock the existing CI safety nets in as required checks instead of advisory-only.

Per the precedent on #584 (tag immutability), ruleset changes on OvertureMaps/schema are managed declaratively as a safe-settings change in omf-github-terraform, not clicked in the UI or set via the API directly on this repo.

Scope

  • Open a PR in omf-github-terraform adding a required_status_checks rule to schema's branch ruleset (main and vnext), covering at minimum:
    • Check (default, py3.10) … Check (default, py3.14), Check (lowest-direct, py3.10) (check-python-code.yaml)
    • Build (test-schema.yaml, now PR-triggered, see companion fix on PR [FEATURE] Branching strategy Phase 3 - PyPI and CodeArtifact publish workflows #638)
    • Check vnext compatibility (vnext-compat.yaml)
    • Require changelog on package change (require-changelog-fragment.yaml)
    • Check label (enforce-change-type-label.yaml)
    • Check Python package versions (check-python-package-versions.yaml)
  • Confirm each check's name is stable before pinning it: matrix jobs (check-python-code.yaml's per-Python-version cells) produce one status per cell with no aggregator, so adding a Python version to the matrix silently drops it from the required set until the ruleset is updated to match. Consider adding an all-checks-pass gate job (needs: [...], if: always()) to check-python-code.yaml first, so the required-check list only ever needs one stable name.
  • Verify against a real fork PR (not just a same-repo branch) that every required check actually triggers, push-only workflows don't fire for fork PRs and would deadlock a required check that depends on them (see the test-schema.yaml fix on PR [FEATURE] Branching strategy Phase 3 - PyPI and CodeArtifact publish workflows #638).

Out of scope

Acceptance

  • required_status_checks is live on schema's main/vnext ruleset via a merged omf-github-terraform PR (not applied ad hoc via the UI).
  • A PR from a fork (not just an org member's branch) is confirmed to trigger and satisfy every newly-required check.

Parent: #509

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

No labels
No labels

Type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions