Skip to content

fix(ci): read trusted maintainer policy for older PR bases - #278

Merged
imran-siddique merged 1 commit into
mainfrom
fix/approval-policy-old-base
Oct 4, 2026
Merged

imran-siddique merged 1 commit into
mainfrom
fix/approval-policy-old-base

Conversation

@imran-siddique

Copy link
Copy Markdown
Member

PR #236 has an independent approval on its current head, but its approval gate fails because the older base commit predates .github/maintainers.json.

Re-render the gate from the reviewed organization template. A missing policy at the recorded base falls back to refs/heads/main; policy validation, current-head independent approvals and fail-closed behavior remain enforced.

Validation: all 12 organization gate tests passed, rendered-template drift was empty, and a probe reproduced the old 404, passed with the fix, and still rejected a missing approval. Hosted checks and independent review remain required.

@imran-siddique
imran-siddique requested review from a team and carloshvp as code owners October 4, 2026 04:15

Copy link
Copy Markdown
Member Author

I’m authorizing this merge to unblock PRs whose maintainer check fails because their old base revision predates the policy file. CI is green. This is a one-time exception to waiting for independent review of this fix. The gate still requires current-head maintainer approval and reads policy only from the base branch. After merging, we’ll rerun the affected checks and verify the result.

@imran-siddique
imran-siddique merged commit 32200d4 into main Oct 4, 2026
27 checks passed
@imran-siddique
imran-siddique deleted the fix/approval-policy-old-base branch October 4, 2026 18:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant