feat(guardrails): block gh pr merge and gh pr ready while a PR has unresolved review threads or failing checks
メンテナーはふだん 1 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 初心者へのやさしさ
- 52/100
- issue の種類
- 機能追加
- 明瞭さ
- 明確に書かれている
- 活発さ
- 活発
- 技術スタック
- bash, github, graphql, powershell, shell
調査の方向性
Start from flag-commit-pr-skill-bypass.sh (it already guards gh pr create around the lines named in the issue) and the existing PreToolUse Bash/PowerShell hook pattern in this plugins repo. Add a command-position match for gh pr merge (including --auto and --admin) and extend the advisory to gh pr ready and gh pr merge pointing at /source-control:pull-request. Resolve the PR from args or the current branch, query unresolved reviewThreads, CHANGES_REQUESTED reviews, and failed/pending checks in one GraphQL call, block with the listed message, and fail open with a visible warning if gh is missing or unauthenticated. Done when the acceptance cases pass and tests cover both shells.
索引モデルが issue の本文から書いたものです。
説明
Problem
An agent can mark a PR ready and merge it without reading its reviews. flag-commit-pr-skill-bypass.sh covers only gh pr create (lines 2 and 256), so a direct gh pr ready or gh pr merge gets no check at all.
What happened on melodic-software/claude-code-account-rotation#218 (2026-10-05):
- The agent ran
gh pr ready, which made Codex post a review with one P2 thread. - The agent then ran
gh pr mergewithout reading that thread. - When the merge came back BLOCKED, it blamed an org ruleset parameter and asked the operator to run
gh pr merge --admin.
The block was the unresolved review thread. Instructions and memory don't reliably prevent this, and the rule has to hold on every machine and in every repo. A hook in a plugin that ships everywhere does both.
Proposal
Add a PreToolUse guard for Bash and PowerShell that matches gh pr merge (including --auto and --admin) at a command position.
- Resolve the PR from the arguments, or from the current branch when none is given.
- Query in one GraphQL call:
- unresolved
reviewThreads reviewswith state CHANGES_REQUESTED- failed or pending check runs on the head commit
- unresolved
- Block if anything is unresolved. Print each item: thread path:line with the first line of its comment, each failed check's name, and each changes-requested reviewer. The message names the fix: read and address the threads, then resolve them, then merge.
- Treat
--adminthe same way. A bypass flag does not exempt a merge from unread feedback.
Also extend the advisory in flag-commit-pr-skill-bypass.sh to gh pr ready and gh pr merge, pointing to /source-control:pull-request. Marking a PR ready is when bot reviewers post their reviews.
Related: #5947 proposes an opt-in ask guard for high-stakes gh calls. This guard is a deterministic block on PR state and doesn't depend on that one.
Acceptance
gh pr mergeon a PR with an unresolved thread is blocked, and the block message lists the thread.- After the thread is resolved and checks are green, the merge runs with no prompt.
--adminand--autoare blocked under the same conditions.- The guard fails open, with a visible warning, when
ghis missing or unauthenticated, so CI and other machines are never wedged. The warning says so plainly. - Tests cover both shells.
- 主要言語
- Shell
- スター
- 22
- フォーク
- 2
- 平均マージ
- 5時間 11分
- マージ済み PR(30日)
- 838
環境構築
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートなし
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
melodic-software/claude-code-plugins のほかの issue
-
good first issue needs-triage priority: medium
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
melodic-software/claude-code-plugins#6631 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
needs-triage
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
melodic-software/claude-code-plugins#6547 ·
メンテナーはふだん 1 日以内に返信
-
needs-triage
難易度 2/5 1〜3時間 初心者へのやさしさ 76/100
melodic-software/claude-code-plugins#6535 ·
メンテナーはふだん 1 日以内に返信
-
test_comment_census.py: SccArgv flag-shaped-filename test errors on Windows (#!/bin/sh scc shim)オープンgood first issue needs-triage priority: low
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
melodic-software/claude-code-plugins#6532 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
good first issue needs-triage priority: low
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
melodic-software/claude-code-plugins#6390 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
melodic-software/claude-code-plugins の issue をすべて見る
似ている issue
-
status:needs-triage
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
メンテナーはふだん 1 日以内に返信
-
documentation
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
alunduil/alunduil-chezmoi#874 ·
メンテナーはふだん 1 日以内に返信
-
enhancement
難易度 1/5 1時間未満 初心者へのやさしさ 85/100
alunduil/zellij-claude-pair#53 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 77/100
FluidNumerics/fluid-walk-blocker#201 ·
メンテナーはふだん 1 日以内に返信
-
cao-evolution cao-evolution:compiler-security
難易度 1/5 1〜3時間 初心者へのやさしさ 72/100
githubnext/gh-aw-cao#16895 ·
メンテナーはふだん 1 日以内に返信