From c30ed18dbd60f97206ce1421a3427d518961e582 Mon Sep 17 00:00:00 2001 From: John McCall Date: Thu, 27 Aug 2026 11:32:02 -0400 Subject: [PATCH 1/2] [CHORE](ci) Always run vnext-compat check with a noop + rollup path Trigger fired only on PRs targeting main, so a PR based on any other branch (e.g. #434, based on vnext) never got a run. Marking this check required would hang those PRs forever. Drop the branches:[main] restriction so the workflow always fires. Guard compat-check to only do real work for PRs targeting main (excluding the vnext release PR itself); add a noop job for everything else. Both feed a vnext-status rollup via lowlydba/are-we-good, so there's one consistently-named check to eventually require. Fixes OvertureMaps/schema#704 Signed-off-by: John McCall --- .github/workflows/vnext-compat.yaml | 33 +++++++++++++++++++++++------ 1 file changed, 27 insertions(+), 6 deletions(-) diff --git a/.github/workflows/vnext-compat.yaml b/.github/workflows/vnext-compat.yaml index 3a3e9f8b2..f563b3013 100644 --- a/.github/workflows/vnext-compat.yaml +++ b/.github/workflows/vnext-compat.yaml @@ -1,14 +1,18 @@ name: vnext compatibility check -# Runs on every PR targeting main. Simulates squashing the PR onto main, then -# attempts a dry-run rebase of vnext onto the result. If vnext would conflict, -# the check fails and posts a comment with exact commands to resolve it. +# Runs on every PR regardless of base branch, so this can safely be made a +# required status check without hanging PRs whose base isn't main. Simulates +# squashing the PR onto main, then attempts a dry-run rebase of vnext onto the +# result. If vnext would conflict, the check fails and posts a comment with +# exact commands to resolve it. # -# Skipped for vnext→main release PRs (head_ref == 'vnext') — self-referential. +# Only PRs targeting main do that real work — compat-check is a no-op for +# anything else (including vnext→main release PRs, head_ref == 'vnext'). The +# noop job covers that inverse case, and both paths feed vnext-status so +# there's always a single, consistently-named check to require. on: pull_request: - branches: [main] types: [opened, reopened, synchronize, edited] permissions: @@ -21,7 +25,7 @@ concurrency: jobs: compat-check: name: Check vnext compatibility - if: github.head_ref != 'vnext' + if: github.event.pull_request.base.ref == 'main' && github.head_ref != 'vnext' runs-on: ubuntu-slim permissions: contents: read @@ -153,3 +157,20 @@ jobs: run: | echo "::error::This PR conflicts with 'vnext' when rebased onto main. See the PR comment for resolution instructions." exit 1 + + noop: + name: Skip vnext compatibility check + if: github.event.pull_request.base.ref != 'main' || github.head_ref == 'vnext' + runs-on: ubuntu-slim + steps: + - run: echo "Base isn't main, or this is the vnext release PR — nothing to check here." + + vnext-status: + name: vnext compatibility status + needs: [compat-check, noop] + if: always() + runs-on: ubuntu-slim + steps: + - uses: lowlydba/are-we-good@375b418aa07a163e0614537a3fa5c51e53a757e9 # v1.0.0 + with: + jobs: ${{ toJSON(needs) }} From cabb68f5ecd3dbf0e7582cac647610e1c0314442 Mon Sep 17 00:00:00 2001 From: John McCall Date: Thu, 27 Aug 2026 11:40:46 -0400 Subject: [PATCH 2/2] Address review: pin are-we-good to v1.0.5, scope vnext-status permissions Match the pin already used by check-python-code.yaml and require-changelog-fragment.yaml, and give the rollup job an explicit empty permissions block since it only reads the needs context. Signed-off-by: John McCall --- .github/workflows/vnext-compat.yaml | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/.github/workflows/vnext-compat.yaml b/.github/workflows/vnext-compat.yaml index f563b3013..2d5425496 100644 --- a/.github/workflows/vnext-compat.yaml +++ b/.github/workflows/vnext-compat.yaml @@ -170,7 +170,8 @@ jobs: needs: [compat-check, noop] if: always() runs-on: ubuntu-slim + permissions: {} steps: - - uses: lowlydba/are-we-good@375b418aa07a163e0614537a3fa5c51e53a757e9 # v1.0.0 + - uses: lowlydba/are-we-good@f506ed6324f55ec5e4ff5d92204a72c7f1c2b4f8 # v1.0.5 with: jobs: ${{ toJSON(needs) }}