Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

feat(guardrails): block gh pr merge and gh pr ready while a PR has unresolved review threads or failing checks

Abierto
#6,463 2 comentarios 0 reacciones 0 asignados Ver en GitHub

Los mantenedores suelen responder en 1 día

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
4/5
Tiempo estimado
3-5 días
Aptitud para principiantes
52/100
Tipo de issue
Nueva funcionalidad
Claridad
Bien especificado
Estado de actividad
Activo
Stack tecnológico
bash, github, graphql, powershell, shell

Línea de trabajo

Start from flag-commit-pr-skill-bypass.sh (it already guards gh pr create around the lines named in the issue) and the existing PreToolUse Bash/PowerShell hook pattern in this plugins repo. Add a command-position match for gh pr merge (including --auto and --admin) and extend the advisory to gh pr ready and gh pr merge pointing at /source-control:pull-request. Resolve the PR from args or the current branch, query unresolved reviewThreads, CHANGES_REQUESTED reviews, and failed/pending checks in one GraphQL call, block with the listed message, and fail open with a visible warning if gh is missing or unauthenticated. Done when the acceptance cases pass and tests cover both shells.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

needs-human needs-triage

Problem

An agent can mark a PR ready and merge it without reading its reviews. flag-commit-pr-skill-bypass.sh covers only gh pr create (lines 2 and 256), so a direct gh pr ready or gh pr merge gets no check at all.

What happened on melodic-software/claude-code-account-rotation#218 (2026-10-05):

  1. The agent ran gh pr ready, which made Codex post a review with one P2 thread.
  2. The agent then ran gh pr merge without reading that thread.
  3. When the merge came back BLOCKED, it blamed an org ruleset parameter and asked the operator to run gh pr merge --admin.

The block was the unresolved review thread. Instructions and memory don't reliably prevent this, and the rule has to hold on every machine and in every repo. A hook in a plugin that ships everywhere does both.

Proposal

Add a PreToolUse guard for Bash and PowerShell that matches gh pr merge (including --auto and --admin) at a command position.

  1. Resolve the PR from the arguments, or from the current branch when none is given.
  2. Query in one GraphQL call:
    • unresolved reviewThreads
    • reviews with state CHANGES_REQUESTED
    • failed or pending check runs on the head commit
  3. Block if anything is unresolved. Print each item: thread path:line with the first line of its comment, each failed check's name, and each changes-requested reviewer. The message names the fix: read and address the threads, then resolve them, then merge.
  4. Treat --admin the same way. A bypass flag does not exempt a merge from unread feedback.

Also extend the advisory in flag-commit-pr-skill-bypass.sh to gh pr ready and gh pr merge, pointing to /source-control:pull-request. Marking a PR ready is when bot reviewers post their reviews.

Related: #5947 proposes an opt-in ask guard for high-stakes gh calls. This guard is a deterministic block on PR state and doesn't depend on that one.

Acceptance

  • gh pr merge on a PR with an unresolved thread is blocked, and the block message lists the thread.
  • After the thread is resolved and checks are green, the merge runs with no prompt.
  • --admin and --auto are blocked under the same conditions.
  • The guard fails open, with a visible warning, when gh is missing or unauthenticated, so CI and other machines are never wedged. The warning says so plainly.
  • Tests cover both shells.
Lenguaje dominante
Shell
Estrellas
22
Forks
2
Merge medio
5 h 11 min
PR fusionados (30 d)
838

Preparar el entorno

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de melodic-software/claude-code-plugins

Todos los issues de melodic-software/claude-code-plugins

Issues similares

Más issues de Shell/Bash

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.