feat(guardrails): block gh pr merge and gh pr ready while a PR has unresolved review threads or failing checks
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Aptitud para principiantes
- 52/100
- Tipo de issue
- Nueva funcionalidad
- Claridad
- Bien especificado
- Estado de actividad
- Activo
- Stack tecnológico
- bash, github, graphql, powershell, shell
- Área
- cli, developer-experience, tooling
Línea de trabajo
Start from flag-commit-pr-skill-bypass.sh (it already guards gh pr create around the lines named in the issue) and the existing PreToolUse Bash/PowerShell hook pattern in this plugins repo. Add a command-position match for gh pr merge (including --auto and --admin) and extend the advisory to gh pr ready and gh pr merge pointing at /source-control:pull-request. Resolve the PR from args or the current branch, query unresolved reviewThreads, CHANGES_REQUESTED reviews, and failed/pending checks in one GraphQL call, block with the listed message, and fail open with a visible warning if gh is missing or unauthenticated. Done when the acceptance cases pass and tests cover both shells.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Problem
An agent can mark a PR ready and merge it without reading its reviews. flag-commit-pr-skill-bypass.sh covers only gh pr create (lines 2 and 256), so a direct gh pr ready or gh pr merge gets no check at all.
What happened on melodic-software/claude-code-account-rotation#218 (2026-10-05):
- The agent ran
gh pr ready, which made Codex post a review with one P2 thread. - The agent then ran
gh pr mergewithout reading that thread. - When the merge came back BLOCKED, it blamed an org ruleset parameter and asked the operator to run
gh pr merge --admin.
The block was the unresolved review thread. Instructions and memory don't reliably prevent this, and the rule has to hold on every machine and in every repo. A hook in a plugin that ships everywhere does both.
Proposal
Add a PreToolUse guard for Bash and PowerShell that matches gh pr merge (including --auto and --admin) at a command position.
- Resolve the PR from the arguments, or from the current branch when none is given.
- Query in one GraphQL call:
- unresolved
reviewThreads reviewswith state CHANGES_REQUESTED- failed or pending check runs on the head commit
- unresolved
- Block if anything is unresolved. Print each item: thread path:line with the first line of its comment, each failed check's name, and each changes-requested reviewer. The message names the fix: read and address the threads, then resolve them, then merge.
- Treat
--adminthe same way. A bypass flag does not exempt a merge from unread feedback.
Also extend the advisory in flag-commit-pr-skill-bypass.sh to gh pr ready and gh pr merge, pointing to /source-control:pull-request. Marking a PR ready is when bot reviewers post their reviews.
Related: #5947 proposes an opt-in ask guard for high-stakes gh calls. This guard is a deterministic block on PR state and doesn't depend on that one.
Acceptance
gh pr mergeon a PR with an unresolved thread is blocked, and the block message lists the thread.- After the thread is resolved and checks are green, the merge runs with no prompt.
--adminand--autoare blocked under the same conditions.- The guard fails open, with a visible warning, when
ghis missing or unauthenticated, so CI and other machines are never wedged. The warning says so plainly. - Tests cover both shells.
- Lenguaje dominante
- Shell
- Estrellas
- 22
- Forks
- 2
- Merge medio
- 5 h 11 min
- PR fusionados (30 d)
- 838
Preparar el entorno
- Sin Dockerfile ni archivo de Docker Compose
- Sin plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de melodic-software/claude-code-plugins
-
good first issue needs-triage priority: medium
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
melodic-software/claude-code-plugins#6631 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
needs-triage
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
melodic-software/claude-code-plugins#6547 ·
Los mantenedores suelen responder en 1 día
-
needs-triage
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
melodic-software/claude-code-plugins#6535 ·
Los mantenedores suelen responder en 1 día
-
test_comment_census.py: SccArgv flag-shaped-filename test errors on Windows (#!/bin/sh scc shim)Abiertogood first issue needs-triage priority: low
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
melodic-software/claude-code-plugins#6532 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
good first issue needs-triage priority: low
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
melodic-software/claude-code-plugins#6390 · 1 comentario ·
Los mantenedores suelen responder en 1 día
Todos los issues de melodic-software/claude-code-plugins
Issues similares
-
`helios / deploy`: switch zone wait in `deploy.sh` has almost no headroom over healthy startup timesPosiblemente ocupada Un pull request vinculado a esta issue está abierto o ya se fusionó. AbiertoTest Flake
Dificultad 2/5 1-3 horas Aptitud para principiantes 74/100
oxidecomputer/omicron#11453 ·
Los mantenedores suelen responder en 1 día
-
feat: Fall OpenAPI newsletterAbierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 64/100
-
bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 85/100
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
gnosis/gnosis_vpn#540 ·
Los mantenedores suelen responder en 1 día