ci: run required checks on merge_group for the merge queue (#159)
Some checks are pending
Architecture and changed-file quality / architecture (push) Waiting to run
Backend CI / Build and test (push) Waiting to run

Build and test, architecture, and dependency-review are the required checks
on main. A merge queue only counts checks that ran on the merge_group event,
so each workflow now triggers on it. The architecture gate reads the merge
group's own base and head because github.event.before is empty there. The
dependency-review action cannot diff a merge group, so that event reports the
same check name from a pass-through job; the real review already gated the
pull request before it could be queued.
This commit is contained in:
Adam Moussa 2026-09-18 18:16:10 -04:00 • committed by GitHub
parent 4fb4159df2
commit 1888b66940
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
3 changed files with 22 additions and 2 deletions

View file

@ -2,6 +2,8 @@ name: Architecture and changed-file quality
on:
pull_request:
# Required by the merge queue; see ci.yml.
merge_group:
push:
branches: [main]
@ -26,6 +28,8 @@ jobs:
- name: Repository quality gate
shell: bash
env:
BASE_REF: ${{ github.event.pull_request.base.sha || github.event.before }}
HEAD_REF: ${{ github.event.pull_request.head.sha || github.sha }}
# A merge group carries its own base and head; github.event.before is
# empty on that event.
BASE_REF: ${{ github.event.pull_request.base.sha || github.event.merge_group.base_sha || github.event.before }}
HEAD_REF: ${{ github.event.pull_request.head.sha || github.event.merge_group.head_sha || github.sha }}
run: bash scripts/governance-check.sh

View file

@ -3,6 +3,9 @@ name: Backend CI
on:
pull_request:
branches: [main, dev, staging]
# The merge queue builds main plus the queued pull requests on a temporary
# branch and only counts checks that ran on the merge_group event.
merge_group:
push:
branches: [main]

View file

@ -1,8 +1,21 @@
name: Dependency Review
on:
pull_request:
merge_group:
permissions:
contents: read
jobs:
review:
if: github.event_name == 'pull_request'
uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@4a6cbfd362140a68810f0f46d338026863b8e827 # v1.0.10
# The dependency-review action only diffs a pull request, and the org callable
# does not take explicit base and head refs. Every pull request in a merge
# group already passed the real review above before it could be queued, so the
# merge group reports the same required check name and passes.
review-merge-group:
if: github.event_name == 'merge_group'
name: review / dependency-review
runs-on: ubuntu-latest
steps:
- run: echo "Dependency review ran on the pull request before it entered the merge queue."