feat(guardrails): block gh pr merge and gh pr ready while a PR has unresolved review threads or failing checks
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 52/100
- Loại issue
- Tính năng
- Độ rõ ràng
- Đặc tả rõ ràng
- Mức độ hoạt động
- Sôi nổi
- Công nghệ
- bash, github, graphql, powershell, shell
- Lĩnh vực
- cli, developer-experience, tooling
Hướng nghiên cứu
Start from flag-commit-pr-skill-bypass.sh (it already guards gh pr create around the lines named in the issue) and the existing PreToolUse Bash/PowerShell hook pattern in this plugins repo. Add a command-position match for gh pr merge (including --auto and --admin) and extend the advisory to gh pr ready and gh pr merge pointing at /source-control:pull-request. Resolve the PR from args or the current branch, query unresolved reviewThreads, CHANGES_REQUESTED reviews, and failed/pending checks in one GraphQL call, block with the listed message, and fail open with a visible warning if gh is missing or unauthenticated. Done when the acceptance cases pass and tests cover both shells.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Problem
An agent can mark a PR ready and merge it without reading its reviews. flag-commit-pr-skill-bypass.sh covers only gh pr create (lines 2 and 256), so a direct gh pr ready or gh pr merge gets no check at all.
What happened on melodic-software/claude-code-account-rotation#218 (2026-10-05):
- The agent ran
gh pr ready, which made Codex post a review with one P2 thread. - The agent then ran
gh pr mergewithout reading that thread. - When the merge came back BLOCKED, it blamed an org ruleset parameter and asked the operator to run
gh pr merge --admin.
The block was the unresolved review thread. Instructions and memory don't reliably prevent this, and the rule has to hold on every machine and in every repo. A hook in a plugin that ships everywhere does both.
Proposal
Add a PreToolUse guard for Bash and PowerShell that matches gh pr merge (including --auto and --admin) at a command position.
- Resolve the PR from the arguments, or from the current branch when none is given.
- Query in one GraphQL call:
- unresolved
reviewThreads reviewswith state CHANGES_REQUESTED- failed or pending check runs on the head commit
- unresolved
- Block if anything is unresolved. Print each item: thread path:line with the first line of its comment, each failed check's name, and each changes-requested reviewer. The message names the fix: read and address the threads, then resolve them, then merge.
- Treat
--adminthe same way. A bypass flag does not exempt a merge from unread feedback.
Also extend the advisory in flag-commit-pr-skill-bypass.sh to gh pr ready and gh pr merge, pointing to /source-control:pull-request. Marking a PR ready is when bot reviewers post their reviews.
Related: #5947 proposes an opt-in ask guard for high-stakes gh calls. This guard is a deterministic block on PR state and doesn't depend on that one.
Acceptance
gh pr mergeon a PR with an unresolved thread is blocked, and the block message lists the thread.- After the thread is resolved and checks are green, the merge runs with no prompt.
--adminand--autoare blocked under the same conditions.- The guard fails open, with a visible warning, when
ghis missing or unauthenticated, so CI and other machines are never wedged. The warning says so plainly. - Tests cover both shells.
- Ngôn ngữ chính
- Shell
- Star
- 22
- Fork
- 2
- Merge trung bình
- 5 giờ 15 phút
- Pull request đã merge (30 ngày)
- 833
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Không có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của melodic-software/claude-code-plugins
-
good first issue needs-triage priority: medium
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
melodic-software/claude-code-plugins#6631 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
needs-triage
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
melodic-software/claude-code-plugins#6547 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
needs-triage
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
melodic-software/claude-code-plugins#6535 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
test_comment_census.py: SccArgv flag-shaped-filename test errors on Windows (#!/bin/sh scc shim)Đang mởgood first issue needs-triage priority: low
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
melodic-software/claude-code-plugins#6532 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
good first issue needs-triage priority: low
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
melodic-software/claude-code-plugins#6390 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của melodic-software/claude-code-plugins
Issue tương tự
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
aws-samples/appmod-blueprints#972 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
status:needs-triage
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 62/100
Maintainer thường phản hồi trong vòng 1 ngày
-
go: new version 1.27.2Đang mởout-of-date
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 62/100
CachyOS/CachyOS-PKGBUILDS#1965 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
enhancement good first issue help wanted
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
Sorogate/example-consumer#14 ·