Key merge-bot concurrency on PR number, not github.ref - #206

Merged
ptr727 merged 1 commit into
developfrom
mergebot-per-pr-concurrency
Jun 25, 2026
Merged

Key merge-bot concurrency on PR number, not github.ref#206
ptr727 merged 1 commit into
developfrom
mergebot-per-pr-concurrency

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Surfaced by Copilot during the NxWitness re-sync (#448) — a real regression from the pull_request_target switch (#201).

Under pull_request_target, github.ref resolves to the base branch, so the merge-bot concurrency group …-${{ github.ref }} serialized every bot PR against a base into one queue — delaying auto-merge/disable when multiple Dependabot/codegen PRs are open. Keying on github.event.pull_request.number restores per-PR scoping (a PR's events still process in arrival order; different PRs run concurrently).

🤖 Generated with Claude Code

The pull_request_target switch (#201) changed github.ref from the PR
merge ref to the base branch, so the concurrency group serialized every
bot PR against a base into one queue - delaying auto-merge/disable when
multiple Dependabot/codegen PRs are open. Key on github.event.pull_request.number
so each PR's events still process in arrival order while different PRs run
concurrently. Surfaced by Copilot on the NxWitness re-sync (#448).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 24, 2026 05:34
ptr727 added a commit to ptr727/NxWitness that referenced this pull request Jun 24, 2026
Re-pull the upstream fix (ptr727/ProjectTemplate#206): pull_request_target
makes github.ref the base branch, so the group serialized all bot PRs
against a base. Key on github.event.pull_request.number for per-PR scoping.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR fixes an Actions concurrency regression in the merge-bot workflow introduced by using pull_request_target, where github.ref points at the base branch and unintentionally serialized all bot PR events targeting the same base branch.

Changes:

  • Change the workflow concurrency group key from ${{ github.ref }} to ${{ github.event.pull_request.number }} to scope concurrency per PR (while preserving cancel-in-progress: false).
  • Update the workflow comment to document why PR-number scoping is required under pull_request_target.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 1 out of 1 changed files in this pull request and generated no new comments.

@ptr727
ptr727 merged commit 5981466 into developJun 25, 2026
11 checks passed
@ptr727
ptr727 deleted the mergebot-per-pr-concurrency branch June 25, 2026 14:04
ptr727 added a commit that referenced this pull request Jun 25, 2026
…eadme, carry-whole-file (#207)
Phase-0 of the template-to-downstream convergence sweep: the template
absorbs everything downstream repos had reinvented, so derived repos can
take the carried artifacts verbatim with zero hand-rolling. Builds on
#205 (orchestration personas) and #206 (per-PR merge-bot concurrency),
which this branch incorporates. Held for end-gate review; not to be
merged midway.
## What this PR does
- **Absorbs downstream-led action pins** (template now leads per #204):
`dependabot/fetch-metadata` v2.5.0 -> v3.1.0 and
`softprops/action-gh-release` v2.6.2 -> v3.0.1, the SHAs the downstreams
already run.
- **Generalizes the release model + adds a loud guard.** Every release
is a tag on the built commit plus an auto source zip, README, and
LICENSE; targets amend it by uploading `release-asset-<branch>-*`
artifacts (binaries/packages) or pushing elsewhere (image/registry).
`github-release` collects assets by the `release-asset-<branch>-*`
pattern so the job is target-agnostic and carries verbatim.
- **Makes the Docker README + date badge main-only, caller-gated.**
Neither has per-branch context, so both move out of the publisher branch
matrix into single jobs gated on `main` being published.
`publish-docker-readme-task.yml` is rebuilt generic: a matrix over a
`repositories` input (or a manifest-derived list), a caller-passed
`ref`, and an optional transform step (e.g. m4) to render the README
before pushing.
- **Adopts the carry-whole-file rule.** Replaces "drop the sections you
don't ship": derived repos carry each shared file in full (an inert
`[*.cs]` block or unused-language `CODESTYLE.md` section costs nothing),
so every re-sync is a clean overwrite, not a partial merge.
`CODESTYLE.md` is genericized into a self-contained drop-in (no
demo-project names, no template-onboarding pointers) and carries both
the .NET and Python sections whole. Only per-language
`.vscode/tasks.json` task definitions still track the repo's language.
All carried files stay self-contained (no template/demo/cross-project
references except the sanctioned upstream-drift pointer). Workflow YAML
and Markdown remain CRLF per the line-ending governance. Validated with
actionlint and markdownlint-cli2 (clean).
## Documented adaptations (for review)
These are the genuine, intentional deviations the maintainer should
review at the end gate. Each is a sanctioned exception with its
rationale recorded inline in the artifact; nothing here is accidental
drift.
- **`fail_on_unmatched_files: true` on `github-release`** - a promised
`release-asset-*` that goes missing or is misnamed fails the release
loudly; a Docker-only / no-file-target repo is the one case that relaxes
it (no release asset to attach).
- **`merge-bot-pull-request.yml` concurrency: per-PR group,
`cancel-in-progress: false`** - under `pull_request_target` `github.ref`
is the base branch, which would serialize every bot PR against that
base, so the group keys on the PR number; cancellation would leave
auto-merge in an inconsistent state, so events queue and each runs to
completion.
- **`publish-release.yml` concurrency: global ref-independent group,
`cancel-in-progress: false`** - it publishes shared ref-independent
artifacts (both branches' Docker tags/caches and GitHub releases)
regardless of the triggering ref, so a ref-scoped group would let a
scheduled run and a manual dispatch double-push; cancelling mid-flight
can leave a partial tag set or half-created release.
- **`dotnet/nbgv` consumed via `@master` (no SHA pin)** - the upstream
tag stream lags `master` substantially and Dependabot's tag-tracking
would propose a downgrade; this is the one documented no-SHA-pin
exception.
- **Ruleset-bound job name kept verbatim (no "job" suffix)** - `Check
pull request workflow status` in `test-pull-request.yml` is referenced
as a required-status-check `context:` in the branch ruleset; renaming it
to fit the "every job name ends in job" convention would silently break
required-status-check enforcement.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@ptr727ptr727 mentioned this pull request Jul 4, 2026
ptr727 added a commit that referenced this pull request Jul 4, 2026
Promote the accumulated `develop` work to `main`. Twelve changes since
the last promotion:
- Add `WORKFLOW.md`: workflow style, architecture, behavioral contract,
test methodology (#223)
- Use NBGV `IGNORE_GITHUB_REF` instead of the ineffective `GITHUB_REF`
override (#222)
- Skip validate-release on smoke builds (#220)
- Gate asset delete on the release create/refresh condition (#218)
- Ship branch rulesets as versioned JSON in the re-sync / drift loop
(#212)
- Clean up transfer artifacts surgically at consumption, not
blanket-delete (#216)
- Version each publish leg against its own branch; validate at entry
(#215)
- Consolidate workspace configurations into a unified ProjectTemplate
workspace (#210)
- Template convergence barrier: absorb pins, generic release +
docker-readme, carry-whole-file (#207)
- Key merge-bot concurrency on PR number, not `github.ref` (#206)
- Codify orchestrated re-sync personas and full-replacement rule (#205)
- Lead action pins; affirm pattern-based artifact handoff (#204)
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Key merge-bot concurrency on PR number, not github.ref - #206

Merged
ptr727 merged 1 commit into
developfrom
mergebot-per-pr-concurrency
Jun 25, 2026
Merged

Key merge-bot concurrency on PR number, not github.ref#206
ptr727 merged 1 commit into
developfrom
mergebot-per-pr-concurrency

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Surfaced by Copilot during the NxWitness re-sync (#448) — a real regression from the pull_request_target switch (#201).

Under pull_request_target, github.ref resolves to the base branch, so the merge-bot concurrency group …-${{ github.ref }} serialized every bot PR against a base into one queue — delaying auto-merge/disable when multiple Dependabot/codegen PRs are open. Keying on github.event.pull_request.number restores per-PR scoping (a PR's events still process in arrival order; different PRs run concurrently).

🤖 Generated with Claude Code

The pull_request_target switch (#201) changed github.ref from the PR
merge ref to the base branch, so the concurrency group serialized every
bot PR against a base into one queue - delaying auto-merge/disable when
multiple Dependabot/codegen PRs are open. Key on github.event.pull_request.number
so each PR's events still process in arrival order while different PRs run
concurrently. Surfaced by Copilot on the NxWitness re-sync (#448).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 24, 2026 05:34
ptr727 added a commit to ptr727/NxWitness that referenced this pull request Jun 24, 2026
Re-pull the upstream fix (ptr727/ProjectTemplate#206): pull_request_target
makes github.ref the base branch, so the group serialized all bot PRs
against a base. Key on github.event.pull_request.number for per-PR scoping.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR fixes an Actions concurrency regression in the merge-bot workflow introduced by using pull_request_target, where github.ref points at the base branch and unintentionally serialized all bot PR events targeting the same base branch.

Changes:

  • Change the workflow concurrency group key from ${{ github.ref }} to ${{ github.event.pull_request.number }} to scope concurrency per PR (while preserving cancel-in-progress: false).
  • Update the workflow comment to document why PR-number scoping is required under pull_request_target.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 1 out of 1 changed files in this pull request and generated no new comments.

@ptr727
ptr727 merged commit 5981466 into developJun 25, 2026
11 checks passed
@ptr727
ptr727 deleted the mergebot-per-pr-concurrency branch June 25, 2026 14:04
ptr727 added a commit that referenced this pull request Jun 25, 2026
…eadme, carry-whole-file (#207)
Phase-0 of the template-to-downstream convergence sweep: the template
absorbs everything downstream repos had reinvented, so derived repos can
take the carried artifacts verbatim with zero hand-rolling. Builds on
#205 (orchestration personas) and #206 (per-PR merge-bot concurrency),
which this branch incorporates. Held for end-gate review; not to be
merged midway.
## What this PR does
- **Absorbs downstream-led action pins** (template now leads per #204):
`dependabot/fetch-metadata` v2.5.0 -> v3.1.0 and
`softprops/action-gh-release` v2.6.2 -> v3.0.1, the SHAs the downstreams
already run.
- **Generalizes the release model + adds a loud guard.** Every release
is a tag on the built commit plus an auto source zip, README, and
LICENSE; targets amend it by uploading `release-asset-<branch>-*`
artifacts (binaries/packages) or pushing elsewhere (image/registry).
`github-release` collects assets by the `release-asset-<branch>-*`
pattern so the job is target-agnostic and carries verbatim.
- **Makes the Docker README + date badge main-only, caller-gated.**
Neither has per-branch context, so both move out of the publisher branch
matrix into single jobs gated on `main` being published.
`publish-docker-readme-task.yml` is rebuilt generic: a matrix over a
`repositories` input (or a manifest-derived list), a caller-passed
`ref`, and an optional transform step (e.g. m4) to render the README
before pushing.
- **Adopts the carry-whole-file rule.** Replaces "drop the sections you
don't ship": derived repos carry each shared file in full (an inert
`[*.cs]` block or unused-language `CODESTYLE.md` section costs nothing),
so every re-sync is a clean overwrite, not a partial merge.
`CODESTYLE.md` is genericized into a self-contained drop-in (no
demo-project names, no template-onboarding pointers) and carries both
the .NET and Python sections whole. Only per-language
`.vscode/tasks.json` task definitions still track the repo's language.
All carried files stay self-contained (no template/demo/cross-project
references except the sanctioned upstream-drift pointer). Workflow YAML
and Markdown remain CRLF per the line-ending governance. Validated with
actionlint and markdownlint-cli2 (clean).
## Documented adaptations (for review)
These are the genuine, intentional deviations the maintainer should
review at the end gate. Each is a sanctioned exception with its
rationale recorded inline in the artifact; nothing here is accidental
drift.
- **`fail_on_unmatched_files: true` on `github-release`** - a promised
`release-asset-*` that goes missing or is misnamed fails the release
loudly; a Docker-only / no-file-target repo is the one case that relaxes
it (no release asset to attach).
- **`merge-bot-pull-request.yml` concurrency: per-PR group,
`cancel-in-progress: false`** - under `pull_request_target` `github.ref`
is the base branch, which would serialize every bot PR against that
base, so the group keys on the PR number; cancellation would leave
auto-merge in an inconsistent state, so events queue and each runs to
completion.
- **`publish-release.yml` concurrency: global ref-independent group,
`cancel-in-progress: false`** - it publishes shared ref-independent
artifacts (both branches' Docker tags/caches and GitHub releases)
regardless of the triggering ref, so a ref-scoped group would let a
scheduled run and a manual dispatch double-push; cancelling mid-flight
can leave a partial tag set or half-created release.
- **`dotnet/nbgv` consumed via `@master` (no SHA pin)** - the upstream
tag stream lags `master` substantially and Dependabot's tag-tracking
would propose a downgrade; this is the one documented no-SHA-pin
exception.
- **Ruleset-bound job name kept verbatim (no "job" suffix)** - `Check
pull request workflow status` in `test-pull-request.yml` is referenced
as a required-status-check `context:` in the branch ruleset; renaming it
to fit the "every job name ends in job" convention would silently break
required-status-check enforcement.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@ptr727ptr727 mentioned this pull request Jul 4, 2026
ptr727 added a commit that referenced this pull request Jul 4, 2026
Promote the accumulated `develop` work to `main`. Twelve changes since
the last promotion:
- Add `WORKFLOW.md`: workflow style, architecture, behavioral contract,
test methodology (#223)
- Use NBGV `IGNORE_GITHUB_REF` instead of the ineffective `GITHUB_REF`
override (#222)
- Skip validate-release on smoke builds (#220)
- Gate asset delete on the release create/refresh condition (#218)
- Ship branch rulesets as versioned JSON in the re-sync / drift loop
(#212)
- Clean up transfer artifacts surgically at consumption, not
blanket-delete (#216)
- Version each publish leg against its own branch; validate at entry
(#215)
- Consolidate workspace configurations into a unified ProjectTemplate
workspace (#210)
- Template convergence barrier: absorb pins, generic release +
docker-readme, carry-whole-file (#207)
- Key merge-bot concurrency on PR number, not `github.ref` (#206)
- Codify orchestrated re-sync personas and full-replacement rule (#205)
- Lead action pins; affirm pattern-based artifact handoff (#204)
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Key merge-bot concurrency on PR number, not github.ref - #206

Merged
ptr727 merged 1 commit into
developfrom
mergebot-per-pr-concurrency
Jun 25, 2026
Merged

Key merge-bot concurrency on PR number, not github.ref#206
ptr727 merged 1 commit into
developfrom
mergebot-per-pr-concurrency

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Surfaced by Copilot during the NxWitness re-sync (#448) — a real regression from the pull_request_target switch (#201).

Under pull_request_target, github.ref resolves to the base branch, so the merge-bot concurrency group …-${{ github.ref }} serialized every bot PR against a base into one queue — delaying auto-merge/disable when multiple Dependabot/codegen PRs are open. Keying on github.event.pull_request.number restores per-PR scoping (a PR's events still process in arrival order; different PRs run concurrently).

🤖 Generated with Claude Code

The pull_request_target switch (#201) changed github.ref from the PR
merge ref to the base branch, so the concurrency group serialized every
bot PR against a base into one queue - delaying auto-merge/disable when
multiple Dependabot/codegen PRs are open. Key on github.event.pull_request.number
so each PR's events still process in arrival order while different PRs run
concurrently. Surfaced by Copilot on the NxWitness re-sync (#448).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 24, 2026 05:34
ptr727 added a commit to ptr727/NxWitness that referenced this pull request Jun 24, 2026
Re-pull the upstream fix (ptr727/ProjectTemplate#206): pull_request_target
makes github.ref the base branch, so the group serialized all bot PRs
against a base. Key on github.event.pull_request.number for per-PR scoping.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR fixes an Actions concurrency regression in the merge-bot workflow introduced by using pull_request_target, where github.ref points at the base branch and unintentionally serialized all bot PR events targeting the same base branch.

Changes:

  • Change the workflow concurrency group key from ${{ github.ref }} to ${{ github.event.pull_request.number }} to scope concurrency per PR (while preserving cancel-in-progress: false).
  • Update the workflow comment to document why PR-number scoping is required under pull_request_target.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 1 out of 1 changed files in this pull request and generated no new comments.

@ptr727
ptr727 merged commit 5981466 into developJun 25, 2026
11 checks passed
@ptr727
ptr727 deleted the mergebot-per-pr-concurrency branch June 25, 2026 14:04
ptr727 added a commit that referenced this pull request Jun 25, 2026
…eadme, carry-whole-file (#207)
Phase-0 of the template-to-downstream convergence sweep: the template
absorbs everything downstream repos had reinvented, so derived repos can
take the carried artifacts verbatim with zero hand-rolling. Builds on
#205 (orchestration personas) and #206 (per-PR merge-bot concurrency),
which this branch incorporates. Held for end-gate review; not to be
merged midway.
## What this PR does
- **Absorbs downstream-led action pins** (template now leads per #204):
`dependabot/fetch-metadata` v2.5.0 -> v3.1.0 and
`softprops/action-gh-release` v2.6.2 -> v3.0.1, the SHAs the downstreams
already run.
- **Generalizes the release model + adds a loud guard.** Every release
is a tag on the built commit plus an auto source zip, README, and
LICENSE; targets amend it by uploading `release-asset-<branch>-*`
artifacts (binaries/packages) or pushing elsewhere (image/registry).
`github-release` collects assets by the `release-asset-<branch>-*`
pattern so the job is target-agnostic and carries verbatim.
- **Makes the Docker README + date badge main-only, caller-gated.**
Neither has per-branch context, so both move out of the publisher branch
matrix into single jobs gated on `main` being published.
`publish-docker-readme-task.yml` is rebuilt generic: a matrix over a
`repositories` input (or a manifest-derived list), a caller-passed
`ref`, and an optional transform step (e.g. m4) to render the README
before pushing.
- **Adopts the carry-whole-file rule.** Replaces "drop the sections you
don't ship": derived repos carry each shared file in full (an inert
`[*.cs]` block or unused-language `CODESTYLE.md` section costs nothing),
so every re-sync is a clean overwrite, not a partial merge.
`CODESTYLE.md` is genericized into a self-contained drop-in (no
demo-project names, no template-onboarding pointers) and carries both
the .NET and Python sections whole. Only per-language
`.vscode/tasks.json` task definitions still track the repo's language.
All carried files stay self-contained (no template/demo/cross-project
references except the sanctioned upstream-drift pointer). Workflow YAML
and Markdown remain CRLF per the line-ending governance. Validated with
actionlint and markdownlint-cli2 (clean).
## Documented adaptations (for review)
These are the genuine, intentional deviations the maintainer should
review at the end gate. Each is a sanctioned exception with its
rationale recorded inline in the artifact; nothing here is accidental
drift.
- **`fail_on_unmatched_files: true` on `github-release`** - a promised
`release-asset-*` that goes missing or is misnamed fails the release
loudly; a Docker-only / no-file-target repo is the one case that relaxes
it (no release asset to attach).
- **`merge-bot-pull-request.yml` concurrency: per-PR group,
`cancel-in-progress: false`** - under `pull_request_target` `github.ref`
is the base branch, which would serialize every bot PR against that
base, so the group keys on the PR number; cancellation would leave
auto-merge in an inconsistent state, so events queue and each runs to
completion.
- **`publish-release.yml` concurrency: global ref-independent group,
`cancel-in-progress: false`** - it publishes shared ref-independent
artifacts (both branches' Docker tags/caches and GitHub releases)
regardless of the triggering ref, so a ref-scoped group would let a
scheduled run and a manual dispatch double-push; cancelling mid-flight
can leave a partial tag set or half-created release.
- **`dotnet/nbgv` consumed via `@master` (no SHA pin)** - the upstream
tag stream lags `master` substantially and Dependabot's tag-tracking
would propose a downgrade; this is the one documented no-SHA-pin
exception.
- **Ruleset-bound job name kept verbatim (no "job" suffix)** - `Check
pull request workflow status` in `test-pull-request.yml` is referenced
as a required-status-check `context:` in the branch ruleset; renaming it
to fit the "every job name ends in job" convention would silently break
required-status-check enforcement.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@ptr727ptr727 mentioned this pull request Jul 4, 2026
ptr727 added a commit that referenced this pull request Jul 4, 2026
Promote the accumulated `develop` work to `main`. Twelve changes since
the last promotion:
- Add `WORKFLOW.md`: workflow style, architecture, behavioral contract,
test methodology (#223)
- Use NBGV `IGNORE_GITHUB_REF` instead of the ineffective `GITHUB_REF`
override (#222)
- Skip validate-release on smoke builds (#220)
- Gate asset delete on the release create/refresh condition (#218)
- Ship branch rulesets as versioned JSON in the re-sync / drift loop
(#212)
- Clean up transfer artifacts surgically at consumption, not
blanket-delete (#216)
- Version each publish leg against its own branch; validate at entry
(#215)
- Consolidate workspace configurations into a unified ProjectTemplate
workspace (#210)
- Template convergence barrier: absorb pins, generic release +
docker-readme, carry-whole-file (#207)
- Key merge-bot concurrency on PR number, not `github.ref` (#206)
- Codify orchestrated re-sync personas and full-replacement rule (#205)
- Lead action pins; affirm pattern-based artifact handoff (#204)
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Key merge-bot concurrency on PR number, not github.ref - #206

Merged
ptr727 merged 1 commit into
developfrom
mergebot-per-pr-concurrency
Jun 25, 2026
Merged

Key merge-bot concurrency on PR number, not github.ref#206
ptr727 merged 1 commit into
developfrom
mergebot-per-pr-concurrency

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Surfaced by Copilot during the NxWitness re-sync (#448) — a real regression from the pull_request_target switch (#201).

Under pull_request_target, github.ref resolves to the base branch, so the merge-bot concurrency group …-${{ github.ref }} serialized every bot PR against a base into one queue — delaying auto-merge/disable when multiple Dependabot/codegen PRs are open. Keying on github.event.pull_request.number restores per-PR scoping (a PR's events still process in arrival order; different PRs run concurrently).

🤖 Generated with Claude Code

The pull_request_target switch (#201) changed github.ref from the PR
merge ref to the base branch, so the concurrency group serialized every
bot PR against a base into one queue - delaying auto-merge/disable when
multiple Dependabot/codegen PRs are open. Key on github.event.pull_request.number
so each PR's events still process in arrival order while different PRs run
concurrently. Surfaced by Copilot on the NxWitness re-sync (#448).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 24, 2026 05:34
ptr727 added a commit to ptr727/NxWitness that referenced this pull request Jun 24, 2026
Re-pull the upstream fix (ptr727/ProjectTemplate#206): pull_request_target
makes github.ref the base branch, so the group serialized all bot PRs
against a base. Key on github.event.pull_request.number for per-PR scoping.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR fixes an Actions concurrency regression in the merge-bot workflow introduced by using pull_request_target, where github.ref points at the base branch and unintentionally serialized all bot PR events targeting the same base branch.

Changes:

  • Change the workflow concurrency group key from ${{ github.ref }} to ${{ github.event.pull_request.number }} to scope concurrency per PR (while preserving cancel-in-progress: false).
  • Update the workflow comment to document why PR-number scoping is required under pull_request_target.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 1 out of 1 changed files in this pull request and generated no new comments.

@ptr727
ptr727 merged commit 5981466 into developJun 25, 2026
11 checks passed
@ptr727
ptr727 deleted the mergebot-per-pr-concurrency branch June 25, 2026 14:04
ptr727 added a commit that referenced this pull request Jun 25, 2026
…eadme, carry-whole-file (#207)
Phase-0 of the template-to-downstream convergence sweep: the template
absorbs everything downstream repos had reinvented, so derived repos can
take the carried artifacts verbatim with zero hand-rolling. Builds on
#205 (orchestration personas) and #206 (per-PR merge-bot concurrency),
which this branch incorporates. Held for end-gate review; not to be
merged midway.
## What this PR does
- **Absorbs downstream-led action pins** (template now leads per #204):
`dependabot/fetch-metadata` v2.5.0 -> v3.1.0 and
`softprops/action-gh-release` v2.6.2 -> v3.0.1, the SHAs the downstreams
already run.
- **Generalizes the release model + adds a loud guard.** Every release
is a tag on the built commit plus an auto source zip, README, and
LICENSE; targets amend it by uploading `release-asset-<branch>-*`
artifacts (binaries/packages) or pushing elsewhere (image/registry).
`github-release` collects assets by the `release-asset-<branch>-*`
pattern so the job is target-agnostic and carries verbatim.
- **Makes the Docker README + date badge main-only, caller-gated.**
Neither has per-branch context, so both move out of the publisher branch
matrix into single jobs gated on `main` being published.
`publish-docker-readme-task.yml` is rebuilt generic: a matrix over a
`repositories` input (or a manifest-derived list), a caller-passed
`ref`, and an optional transform step (e.g. m4) to render the README
before pushing.
- **Adopts the carry-whole-file rule.** Replaces "drop the sections you
don't ship": derived repos carry each shared file in full (an inert
`[*.cs]` block or unused-language `CODESTYLE.md` section costs nothing),
so every re-sync is a clean overwrite, not a partial merge.
`CODESTYLE.md` is genericized into a self-contained drop-in (no
demo-project names, no template-onboarding pointers) and carries both
the .NET and Python sections whole. Only per-language
`.vscode/tasks.json` task definitions still track the repo's language.
All carried files stay self-contained (no template/demo/cross-project
references except the sanctioned upstream-drift pointer). Workflow YAML
and Markdown remain CRLF per the line-ending governance. Validated with
actionlint and markdownlint-cli2 (clean).
## Documented adaptations (for review)
These are the genuine, intentional deviations the maintainer should
review at the end gate. Each is a sanctioned exception with its
rationale recorded inline in the artifact; nothing here is accidental
drift.
- **`fail_on_unmatched_files: true` on `github-release`** - a promised
`release-asset-*` that goes missing or is misnamed fails the release
loudly; a Docker-only / no-file-target repo is the one case that relaxes
it (no release asset to attach).
- **`merge-bot-pull-request.yml` concurrency: per-PR group,
`cancel-in-progress: false`** - under `pull_request_target` `github.ref`
is the base branch, which would serialize every bot PR against that
base, so the group keys on the PR number; cancellation would leave
auto-merge in an inconsistent state, so events queue and each runs to
completion.
- **`publish-release.yml` concurrency: global ref-independent group,
`cancel-in-progress: false`** - it publishes shared ref-independent
artifacts (both branches' Docker tags/caches and GitHub releases)
regardless of the triggering ref, so a ref-scoped group would let a
scheduled run and a manual dispatch double-push; cancelling mid-flight
can leave a partial tag set or half-created release.
- **`dotnet/nbgv` consumed via `@master` (no SHA pin)** - the upstream
tag stream lags `master` substantially and Dependabot's tag-tracking
would propose a downgrade; this is the one documented no-SHA-pin
exception.
- **Ruleset-bound job name kept verbatim (no "job" suffix)** - `Check
pull request workflow status` in `test-pull-request.yml` is referenced
as a required-status-check `context:` in the branch ruleset; renaming it
to fit the "every job name ends in job" convention would silently break
required-status-check enforcement.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@ptr727ptr727 mentioned this pull request Jul 4, 2026
ptr727 added a commit that referenced this pull request Jul 4, 2026
Promote the accumulated `develop` work to `main`. Twelve changes since
the last promotion:
- Add `WORKFLOW.md`: workflow style, architecture, behavioral contract,
test methodology (#223)
- Use NBGV `IGNORE_GITHUB_REF` instead of the ineffective `GITHUB_REF`
override (#222)
- Skip validate-release on smoke builds (#220)
- Gate asset delete on the release create/refresh condition (#218)
- Ship branch rulesets as versioned JSON in the re-sync / drift loop
(#212)
- Clean up transfer artifacts surgically at consumption, not
blanket-delete (#216)
- Version each publish leg against its own branch; validate at entry
(#215)
- Consolidate workspace configurations into a unified ProjectTemplate
workspace (#210)
- Template convergence barrier: absorb pins, generic release +
docker-readme, carry-whole-file (#207)
- Key merge-bot concurrency on PR number, not `github.ref` (#206)
- Codify orchestrated re-sync personas and full-replacement rule (#205)
- Lead action pins; affirm pattern-based artifact handoff (#204)
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Key merge-bot concurrency on PR number, not github.ref - #206

Merged
ptr727 merged 1 commit into
developfrom
mergebot-per-pr-concurrency
Jun 25, 2026
Merged

Key merge-bot concurrency on PR number, not github.ref#206
ptr727 merged 1 commit into
developfrom
mergebot-per-pr-concurrency

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Surfaced by Copilot during the NxWitness re-sync (#448) — a real regression from the pull_request_target switch (#201).

Under pull_request_target, github.ref resolves to the base branch, so the merge-bot concurrency group …-${{ github.ref }} serialized every bot PR against a base into one queue — delaying auto-merge/disable when multiple Dependabot/codegen PRs are open. Keying on github.event.pull_request.number restores per-PR scoping (a PR's events still process in arrival order; different PRs run concurrently).

🤖 Generated with Claude Code

The pull_request_target switch (#201) changed github.ref from the PR
merge ref to the base branch, so the concurrency group serialized every
bot PR against a base into one queue - delaying auto-merge/disable when
multiple Dependabot/codegen PRs are open. Key on github.event.pull_request.number
so each PR's events still process in arrival order while different PRs run
concurrently. Surfaced by Copilot on the NxWitness re-sync (#448).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 24, 2026 05:34
ptr727 added a commit to ptr727/NxWitness that referenced this pull request Jun 24, 2026
Re-pull the upstream fix (ptr727/ProjectTemplate#206): pull_request_target
makes github.ref the base branch, so the group serialized all bot PRs
against a base. Key on github.event.pull_request.number for per-PR scoping.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR fixes an Actions concurrency regression in the merge-bot workflow introduced by using pull_request_target, where github.ref points at the base branch and unintentionally serialized all bot PR events targeting the same base branch.

Changes:

  • Change the workflow concurrency group key from ${{ github.ref }} to ${{ github.event.pull_request.number }} to scope concurrency per PR (while preserving cancel-in-progress: false).
  • Update the workflow comment to document why PR-number scoping is required under pull_request_target.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 1 out of 1 changed files in this pull request and generated no new comments.

@ptr727
ptr727 merged commit 5981466 into developJun 25, 2026
11 checks passed
@ptr727
ptr727 deleted the mergebot-per-pr-concurrency branch June 25, 2026 14:04
ptr727 added a commit that referenced this pull request Jun 25, 2026
…eadme, carry-whole-file (#207)
Phase-0 of the template-to-downstream convergence sweep: the template
absorbs everything downstream repos had reinvented, so derived repos can
take the carried artifacts verbatim with zero hand-rolling. Builds on
#205 (orchestration personas) and #206 (per-PR merge-bot concurrency),
which this branch incorporates. Held for end-gate review; not to be
merged midway.
## What this PR does
- **Absorbs downstream-led action pins** (template now leads per #204):
`dependabot/fetch-metadata` v2.5.0 -> v3.1.0 and
`softprops/action-gh-release` v2.6.2 -> v3.0.1, the SHAs the downstreams
already run.
- **Generalizes the release model + adds a loud guard.** Every release
is a tag on the built commit plus an auto source zip, README, and
LICENSE; targets amend it by uploading `release-asset-<branch>-*`
artifacts (binaries/packages) or pushing elsewhere (image/registry).
`github-release` collects assets by the `release-asset-<branch>-*`
pattern so the job is target-agnostic and carries verbatim.
- **Makes the Docker README + date badge main-only, caller-gated.**
Neither has per-branch context, so both move out of the publisher branch
matrix into single jobs gated on `main` being published.
`publish-docker-readme-task.yml` is rebuilt generic: a matrix over a
`repositories` input (or a manifest-derived list), a caller-passed
`ref`, and an optional transform step (e.g. m4) to render the README
before pushing.
- **Adopts the carry-whole-file rule.** Replaces "drop the sections you
don't ship": derived repos carry each shared file in full (an inert
`[*.cs]` block or unused-language `CODESTYLE.md` section costs nothing),
so every re-sync is a clean overwrite, not a partial merge.
`CODESTYLE.md` is genericized into a self-contained drop-in (no
demo-project names, no template-onboarding pointers) and carries both
the .NET and Python sections whole. Only per-language
`.vscode/tasks.json` task definitions still track the repo's language.
All carried files stay self-contained (no template/demo/cross-project
references except the sanctioned upstream-drift pointer). Workflow YAML
and Markdown remain CRLF per the line-ending governance. Validated with
actionlint and markdownlint-cli2 (clean).
## Documented adaptations (for review)
These are the genuine, intentional deviations the maintainer should
review at the end gate. Each is a sanctioned exception with its
rationale recorded inline in the artifact; nothing here is accidental
drift.
- **`fail_on_unmatched_files: true` on `github-release`** - a promised
`release-asset-*` that goes missing or is misnamed fails the release
loudly; a Docker-only / no-file-target repo is the one case that relaxes
it (no release asset to attach).
- **`merge-bot-pull-request.yml` concurrency: per-PR group,
`cancel-in-progress: false`** - under `pull_request_target` `github.ref`
is the base branch, which would serialize every bot PR against that
base, so the group keys on the PR number; cancellation would leave
auto-merge in an inconsistent state, so events queue and each runs to
completion.
- **`publish-release.yml` concurrency: global ref-independent group,
`cancel-in-progress: false`** - it publishes shared ref-independent
artifacts (both branches' Docker tags/caches and GitHub releases)
regardless of the triggering ref, so a ref-scoped group would let a
scheduled run and a manual dispatch double-push; cancelling mid-flight
can leave a partial tag set or half-created release.
- **`dotnet/nbgv` consumed via `@master` (no SHA pin)** - the upstream
tag stream lags `master` substantially and Dependabot's tag-tracking
would propose a downgrade; this is the one documented no-SHA-pin
exception.
- **Ruleset-bound job name kept verbatim (no "job" suffix)** - `Check
pull request workflow status` in `test-pull-request.yml` is referenced
as a required-status-check `context:` in the branch ruleset; renaming it
to fit the "every job name ends in job" convention would silently break
required-status-check enforcement.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@ptr727ptr727 mentioned this pull request Jul 4, 2026
ptr727 added a commit that referenced this pull request Jul 4, 2026
Promote the accumulated `develop` work to `main`. Twelve changes since
the last promotion:
- Add `WORKFLOW.md`: workflow style, architecture, behavioral contract,
test methodology (#223)
- Use NBGV `IGNORE_GITHUB_REF` instead of the ineffective `GITHUB_REF`
override (#222)
- Skip validate-release on smoke builds (#220)
- Gate asset delete on the release create/refresh condition (#218)
- Ship branch rulesets as versioned JSON in the re-sync / drift loop
(#212)
- Clean up transfer artifacts surgically at consumption, not
blanket-delete (#216)
- Version each publish leg against its own branch; validate at entry
(#215)
- Consolidate workspace configurations into a unified ProjectTemplate
workspace (#210)
- Template convergence barrier: absorb pins, generic release +
docker-readme, carry-whole-file (#207)
- Key merge-bot concurrency on PR number, not `github.ref` (#206)
- Codify orchestrated re-sync personas and full-replacement rule (#205)
- Lead action pins; affirm pattern-based artifact handoff (#204)
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Key merge-bot concurrency on PR number, not github.ref - #206

Merged
ptr727 merged 1 commit into
developfrom
mergebot-per-pr-concurrency
Jun 25, 2026
Merged

Key merge-bot concurrency on PR number, not github.ref#206
ptr727 merged 1 commit into
developfrom
mergebot-per-pr-concurrency

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Surfaced by Copilot during the NxWitness re-sync (#448) — a real regression from the pull_request_target switch (#201).

Under pull_request_target, github.ref resolves to the base branch, so the merge-bot concurrency group …-${{ github.ref }} serialized every bot PR against a base into one queue — delaying auto-merge/disable when multiple Dependabot/codegen PRs are open. Keying on github.event.pull_request.number restores per-PR scoping (a PR's events still process in arrival order; different PRs run concurrently).

🤖 Generated with Claude Code

The pull_request_target switch (#201) changed github.ref from the PR
merge ref to the base branch, so the concurrency group serialized every
bot PR against a base into one queue - delaying auto-merge/disable when
multiple Dependabot/codegen PRs are open. Key on github.event.pull_request.number
so each PR's events still process in arrival order while different PRs run
concurrently. Surfaced by Copilot on the NxWitness re-sync (#448).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 24, 2026 05:34
ptr727 added a commit to ptr727/NxWitness that referenced this pull request Jun 24, 2026
Re-pull the upstream fix (ptr727/ProjectTemplate#206): pull_request_target
makes github.ref the base branch, so the group serialized all bot PRs
against a base. Key on github.event.pull_request.number for per-PR scoping.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR fixes an Actions concurrency regression in the merge-bot workflow introduced by using pull_request_target, where github.ref points at the base branch and unintentionally serialized all bot PR events targeting the same base branch.

Changes:

  • Change the workflow concurrency group key from ${{ github.ref }} to ${{ github.event.pull_request.number }} to scope concurrency per PR (while preserving cancel-in-progress: false).
  • Update the workflow comment to document why PR-number scoping is required under pull_request_target.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 1 out of 1 changed files in this pull request and generated no new comments.

@ptr727
ptr727 merged commit 5981466 into developJun 25, 2026
11 checks passed
@ptr727
ptr727 deleted the mergebot-per-pr-concurrency branch June 25, 2026 14:04
ptr727 added a commit that referenced this pull request Jun 25, 2026
…eadme, carry-whole-file (#207)
Phase-0 of the template-to-downstream convergence sweep: the template
absorbs everything downstream repos had reinvented, so derived repos can
take the carried artifacts verbatim with zero hand-rolling. Builds on
#205 (orchestration personas) and #206 (per-PR merge-bot concurrency),
which this branch incorporates. Held for end-gate review; not to be
merged midway.
## What this PR does
- **Absorbs downstream-led action pins** (template now leads per #204):
`dependabot/fetch-metadata` v2.5.0 -> v3.1.0 and
`softprops/action-gh-release` v2.6.2 -> v3.0.1, the SHAs the downstreams
already run.
- **Generalizes the release model + adds a loud guard.** Every release
is a tag on the built commit plus an auto source zip, README, and
LICENSE; targets amend it by uploading `release-asset-<branch>-*`
artifacts (binaries/packages) or pushing elsewhere (image/registry).
`github-release` collects assets by the `release-asset-<branch>-*`
pattern so the job is target-agnostic and carries verbatim.
- **Makes the Docker README + date badge main-only, caller-gated.**
Neither has per-branch context, so both move out of the publisher branch
matrix into single jobs gated on `main` being published.
`publish-docker-readme-task.yml` is rebuilt generic: a matrix over a
`repositories` input (or a manifest-derived list), a caller-passed
`ref`, and an optional transform step (e.g. m4) to render the README
before pushing.
- **Adopts the carry-whole-file rule.** Replaces "drop the sections you
don't ship": derived repos carry each shared file in full (an inert
`[*.cs]` block or unused-language `CODESTYLE.md` section costs nothing),
so every re-sync is a clean overwrite, not a partial merge.
`CODESTYLE.md` is genericized into a self-contained drop-in (no
demo-project names, no template-onboarding pointers) and carries both
the .NET and Python sections whole. Only per-language
`.vscode/tasks.json` task definitions still track the repo's language.
All carried files stay self-contained (no template/demo/cross-project
references except the sanctioned upstream-drift pointer). Workflow YAML
and Markdown remain CRLF per the line-ending governance. Validated with
actionlint and markdownlint-cli2 (clean).
## Documented adaptations (for review)
These are the genuine, intentional deviations the maintainer should
review at the end gate. Each is a sanctioned exception with its
rationale recorded inline in the artifact; nothing here is accidental
drift.
- **`fail_on_unmatched_files: true` on `github-release`** - a promised
`release-asset-*` that goes missing or is misnamed fails the release
loudly; a Docker-only / no-file-target repo is the one case that relaxes
it (no release asset to attach).
- **`merge-bot-pull-request.yml` concurrency: per-PR group,
`cancel-in-progress: false`** - under `pull_request_target` `github.ref`
is the base branch, which would serialize every bot PR against that
base, so the group keys on the PR number; cancellation would leave
auto-merge in an inconsistent state, so events queue and each runs to
completion.
- **`publish-release.yml` concurrency: global ref-independent group,
`cancel-in-progress: false`** - it publishes shared ref-independent
artifacts (both branches' Docker tags/caches and GitHub releases)
regardless of the triggering ref, so a ref-scoped group would let a
scheduled run and a manual dispatch double-push; cancelling mid-flight
can leave a partial tag set or half-created release.
- **`dotnet/nbgv` consumed via `@master` (no SHA pin)** - the upstream
tag stream lags `master` substantially and Dependabot's tag-tracking
would propose a downgrade; this is the one documented no-SHA-pin
exception.
- **Ruleset-bound job name kept verbatim (no "job" suffix)** - `Check
pull request workflow status` in `test-pull-request.yml` is referenced
as a required-status-check `context:` in the branch ruleset; renaming it
to fit the "every job name ends in job" convention would silently break
required-status-check enforcement.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@ptr727ptr727 mentioned this pull request Jul 4, 2026
ptr727 added a commit that referenced this pull request Jul 4, 2026
Promote the accumulated `develop` work to `main`. Twelve changes since
the last promotion:
- Add `WORKFLOW.md`: workflow style, architecture, behavioral contract,
test methodology (#223)
- Use NBGV `IGNORE_GITHUB_REF` instead of the ineffective `GITHUB_REF`
override (#222)
- Skip validate-release on smoke builds (#220)
- Gate asset delete on the release create/refresh condition (#218)
- Ship branch rulesets as versioned JSON in the re-sync / drift loop
(#212)
- Clean up transfer artifacts surgically at consumption, not
blanket-delete (#216)
- Version each publish leg against its own branch; validate at entry
(#215)
- Consolidate workspace configurations into a unified ProjectTemplate
workspace (#210)
- Template convergence barrier: absorb pins, generic release +
docker-readme, carry-whole-file (#207)
- Key merge-bot concurrency on PR number, not `github.ref` (#206)
- Codify orchestrated re-sync personas and full-replacement rule (#205)
- Lead action pins; affirm pattern-based artifact handoff (#204)
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Key merge-bot concurrency on PR number, not github.ref - #206

Merged
ptr727 merged 1 commit into
developfrom
mergebot-per-pr-concurrency
Jun 25, 2026
Merged

Key merge-bot concurrency on PR number, not github.ref#206
ptr727 merged 1 commit into
developfrom
mergebot-per-pr-concurrency

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Surfaced by Copilot during the NxWitness re-sync (#448) — a real regression from the pull_request_target switch (#201).

Under pull_request_target, github.ref resolves to the base branch, so the merge-bot concurrency group …-${{ github.ref }} serialized every bot PR against a base into one queue — delaying auto-merge/disable when multiple Dependabot/codegen PRs are open. Keying on github.event.pull_request.number restores per-PR scoping (a PR's events still process in arrival order; different PRs run concurrently).

🤖 Generated with Claude Code

The pull_request_target switch (#201) changed github.ref from the PR
merge ref to the base branch, so the concurrency group serialized every
bot PR against a base into one queue - delaying auto-merge/disable when
multiple Dependabot/codegen PRs are open. Key on github.event.pull_request.number
so each PR's events still process in arrival order while different PRs run
concurrently. Surfaced by Copilot on the NxWitness re-sync (#448).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 24, 2026 05:34
ptr727 added a commit to ptr727/NxWitness that referenced this pull request Jun 24, 2026
Re-pull the upstream fix (ptr727/ProjectTemplate#206): pull_request_target
makes github.ref the base branch, so the group serialized all bot PRs
against a base. Key on github.event.pull_request.number for per-PR scoping.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR fixes an Actions concurrency regression in the merge-bot workflow introduced by using pull_request_target, where github.ref points at the base branch and unintentionally serialized all bot PR events targeting the same base branch.

Changes:

  • Change the workflow concurrency group key from ${{ github.ref }} to ${{ github.event.pull_request.number }} to scope concurrency per PR (while preserving cancel-in-progress: false).
  • Update the workflow comment to document why PR-number scoping is required under pull_request_target.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 1 out of 1 changed files in this pull request and generated no new comments.

@ptr727
ptr727 merged commit 5981466 into developJun 25, 2026
11 checks passed
@ptr727
ptr727 deleted the mergebot-per-pr-concurrency branch June 25, 2026 14:04
ptr727 added a commit that referenced this pull request Jun 25, 2026
…eadme, carry-whole-file (#207)
Phase-0 of the template-to-downstream convergence sweep: the template
absorbs everything downstream repos had reinvented, so derived repos can
take the carried artifacts verbatim with zero hand-rolling. Builds on
#205 (orchestration personas) and #206 (per-PR merge-bot concurrency),
which this branch incorporates. Held for end-gate review; not to be
merged midway.
## What this PR does
- **Absorbs downstream-led action pins** (template now leads per #204):
`dependabot/fetch-metadata` v2.5.0 -> v3.1.0 and
`softprops/action-gh-release` v2.6.2 -> v3.0.1, the SHAs the downstreams
already run.
- **Generalizes the release model + adds a loud guard.** Every release
is a tag on the built commit plus an auto source zip, README, and
LICENSE; targets amend it by uploading `release-asset-<branch>-*`
artifacts (binaries/packages) or pushing elsewhere (image/registry).
`github-release` collects assets by the `release-asset-<branch>-*`
pattern so the job is target-agnostic and carries verbatim.
- **Makes the Docker README + date badge main-only, caller-gated.**
Neither has per-branch context, so both move out of the publisher branch
matrix into single jobs gated on `main` being published.
`publish-docker-readme-task.yml` is rebuilt generic: a matrix over a
`repositories` input (or a manifest-derived list), a caller-passed
`ref`, and an optional transform step (e.g. m4) to render the README
before pushing.
- **Adopts the carry-whole-file rule.** Replaces "drop the sections you
don't ship": derived repos carry each shared file in full (an inert
`[*.cs]` block or unused-language `CODESTYLE.md` section costs nothing),
so every re-sync is a clean overwrite, not a partial merge.
`CODESTYLE.md` is genericized into a self-contained drop-in (no
demo-project names, no template-onboarding pointers) and carries both
the .NET and Python sections whole. Only per-language
`.vscode/tasks.json` task definitions still track the repo's language.
All carried files stay self-contained (no template/demo/cross-project
references except the sanctioned upstream-drift pointer). Workflow YAML
and Markdown remain CRLF per the line-ending governance. Validated with
actionlint and markdownlint-cli2 (clean).
## Documented adaptations (for review)
These are the genuine, intentional deviations the maintainer should
review at the end gate. Each is a sanctioned exception with its
rationale recorded inline in the artifact; nothing here is accidental
drift.
- **`fail_on_unmatched_files: true` on `github-release`** - a promised
`release-asset-*` that goes missing or is misnamed fails the release
loudly; a Docker-only / no-file-target repo is the one case that relaxes
it (no release asset to attach).
- **`merge-bot-pull-request.yml` concurrency: per-PR group,
`cancel-in-progress: false`** - under `pull_request_target` `github.ref`
is the base branch, which would serialize every bot PR against that
base, so the group keys on the PR number; cancellation would leave
auto-merge in an inconsistent state, so events queue and each runs to
completion.
- **`publish-release.yml` concurrency: global ref-independent group,
`cancel-in-progress: false`** - it publishes shared ref-independent
artifacts (both branches' Docker tags/caches and GitHub releases)
regardless of the triggering ref, so a ref-scoped group would let a
scheduled run and a manual dispatch double-push; cancelling mid-flight
can leave a partial tag set or half-created release.
- **`dotnet/nbgv` consumed via `@master` (no SHA pin)** - the upstream
tag stream lags `master` substantially and Dependabot's tag-tracking
would propose a downgrade; this is the one documented no-SHA-pin
exception.
- **Ruleset-bound job name kept verbatim (no "job" suffix)** - `Check
pull request workflow status` in `test-pull-request.yml` is referenced
as a required-status-check `context:` in the branch ruleset; renaming it
to fit the "every job name ends in job" convention would silently break
required-status-check enforcement.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@ptr727ptr727 mentioned this pull request Jul 4, 2026
ptr727 added a commit that referenced this pull request Jul 4, 2026
Promote the accumulated `develop` work to `main`. Twelve changes since
the last promotion:
- Add `WORKFLOW.md`: workflow style, architecture, behavioral contract,
test methodology (#223)
- Use NBGV `IGNORE_GITHUB_REF` instead of the ineffective `GITHUB_REF`
override (#222)
- Skip validate-release on smoke builds (#220)
- Gate asset delete on the release create/refresh condition (#218)
- Ship branch rulesets as versioned JSON in the re-sync / drift loop
(#212)
- Clean up transfer artifacts surgically at consumption, not
blanket-delete (#216)
- Version each publish leg against its own branch; validate at entry
(#215)
- Consolidate workspace configurations into a unified ProjectTemplate
workspace (#210)
- Template convergence barrier: absorb pins, generic release +
docker-readme, carry-whole-file (#207)
- Key merge-bot concurrency on PR number, not `github.ref` (#206)
- Codify orchestrated re-sync personas and full-replacement rule (#205)
- Lead action pins; affirm pattern-based artifact handoff (#204)
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Key merge-bot concurrency on PR number, not github.ref - #206

Merged
ptr727 merged 1 commit into
developfrom
mergebot-per-pr-concurrency
Jun 25, 2026
Merged

Key merge-bot concurrency on PR number, not github.ref#206
ptr727 merged 1 commit into
developfrom
mergebot-per-pr-concurrency

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Surfaced by Copilot during the NxWitness re-sync (#448) — a real regression from the pull_request_target switch (#201).

Under pull_request_target, github.ref resolves to the base branch, so the merge-bot concurrency group …-${{ github.ref }} serialized every bot PR against a base into one queue — delaying auto-merge/disable when multiple Dependabot/codegen PRs are open. Keying on github.event.pull_request.number restores per-PR scoping (a PR's events still process in arrival order; different PRs run concurrently).

🤖 Generated with Claude Code

The pull_request_target switch (#201) changed github.ref from the PR
merge ref to the base branch, so the concurrency group serialized every
bot PR against a base into one queue - delaying auto-merge/disable when
multiple Dependabot/codegen PRs are open. Key on github.event.pull_request.number
so each PR's events still process in arrival order while different PRs run
concurrently. Surfaced by Copilot on the NxWitness re-sync (#448).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 24, 2026 05:34
ptr727 added a commit to ptr727/NxWitness that referenced this pull request Jun 24, 2026
Re-pull the upstream fix (ptr727/ProjectTemplate#206): pull_request_target
makes github.ref the base branch, so the group serialized all bot PRs
against a base. Key on github.event.pull_request.number for per-PR scoping.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR fixes an Actions concurrency regression in the merge-bot workflow introduced by using pull_request_target, where github.ref points at the base branch and unintentionally serialized all bot PR events targeting the same base branch.

Changes:

  • Change the workflow concurrency group key from ${{ github.ref }} to ${{ github.event.pull_request.number }} to scope concurrency per PR (while preserving cancel-in-progress: false).
  • Update the workflow comment to document why PR-number scoping is required under pull_request_target.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 1 out of 1 changed files in this pull request and generated no new comments.

@ptr727
ptr727 merged commit 5981466 into developJun 25, 2026
11 checks passed
@ptr727
ptr727 deleted the mergebot-per-pr-concurrency branch June 25, 2026 14:04
ptr727 added a commit that referenced this pull request Jun 25, 2026
…eadme, carry-whole-file (#207)
Phase-0 of the template-to-downstream convergence sweep: the template
absorbs everything downstream repos had reinvented, so derived repos can
take the carried artifacts verbatim with zero hand-rolling. Builds on
#205 (orchestration personas) and #206 (per-PR merge-bot concurrency),
which this branch incorporates. Held for end-gate review; not to be
merged midway.
## What this PR does
- **Absorbs downstream-led action pins** (template now leads per #204):
`dependabot/fetch-metadata` v2.5.0 -> v3.1.0 and
`softprops/action-gh-release` v2.6.2 -> v3.0.1, the SHAs the downstreams
already run.
- **Generalizes the release model + adds a loud guard.** Every release
is a tag on the built commit plus an auto source zip, README, and
LICENSE; targets amend it by uploading `release-asset-<branch>-*`
artifacts (binaries/packages) or pushing elsewhere (image/registry).
`github-release` collects assets by the `release-asset-<branch>-*`
pattern so the job is target-agnostic and carries verbatim.
- **Makes the Docker README + date badge main-only, caller-gated.**
Neither has per-branch context, so both move out of the publisher branch
matrix into single jobs gated on `main` being published.
`publish-docker-readme-task.yml` is rebuilt generic: a matrix over a
`repositories` input (or a manifest-derived list), a caller-passed
`ref`, and an optional transform step (e.g. m4) to render the README
before pushing.
- **Adopts the carry-whole-file rule.** Replaces "drop the sections you
don't ship": derived repos carry each shared file in full (an inert
`[*.cs]` block or unused-language `CODESTYLE.md` section costs nothing),
so every re-sync is a clean overwrite, not a partial merge.
`CODESTYLE.md` is genericized into a self-contained drop-in (no
demo-project names, no template-onboarding pointers) and carries both
the .NET and Python sections whole. Only per-language
`.vscode/tasks.json` task definitions still track the repo's language.
All carried files stay self-contained (no template/demo/cross-project
references except the sanctioned upstream-drift pointer). Workflow YAML
and Markdown remain CRLF per the line-ending governance. Validated with
actionlint and markdownlint-cli2 (clean).
## Documented adaptations (for review)
These are the genuine, intentional deviations the maintainer should
review at the end gate. Each is a sanctioned exception with its
rationale recorded inline in the artifact; nothing here is accidental
drift.
- **`fail_on_unmatched_files: true` on `github-release`** - a promised
`release-asset-*` that goes missing or is misnamed fails the release
loudly; a Docker-only / no-file-target repo is the one case that relaxes
it (no release asset to attach).
- **`merge-bot-pull-request.yml` concurrency: per-PR group,
`cancel-in-progress: false`** - under `pull_request_target` `github.ref`
is the base branch, which would serialize every bot PR against that
base, so the group keys on the PR number; cancellation would leave
auto-merge in an inconsistent state, so events queue and each runs to
completion.
- **`publish-release.yml` concurrency: global ref-independent group,
`cancel-in-progress: false`** - it publishes shared ref-independent
artifacts (both branches' Docker tags/caches and GitHub releases)
regardless of the triggering ref, so a ref-scoped group would let a
scheduled run and a manual dispatch double-push; cancelling mid-flight
can leave a partial tag set or half-created release.
- **`dotnet/nbgv` consumed via `@master` (no SHA pin)** - the upstream
tag stream lags `master` substantially and Dependabot's tag-tracking
would propose a downgrade; this is the one documented no-SHA-pin
exception.
- **Ruleset-bound job name kept verbatim (no "job" suffix)** - `Check
pull request workflow status` in `test-pull-request.yml` is referenced
as a required-status-check `context:` in the branch ruleset; renaming it
to fit the "every job name ends in job" convention would silently break
required-status-check enforcement.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@ptr727ptr727 mentioned this pull request Jul 4, 2026
ptr727 added a commit that referenced this pull request Jul 4, 2026
Promote the accumulated `develop` work to `main`. Twelve changes since
the last promotion:
- Add `WORKFLOW.md`: workflow style, architecture, behavioral contract,
test methodology (#223)
- Use NBGV `IGNORE_GITHUB_REF` instead of the ineffective `GITHUB_REF`
override (#222)
- Skip validate-release on smoke builds (#220)
- Gate asset delete on the release create/refresh condition (#218)
- Ship branch rulesets as versioned JSON in the re-sync / drift loop
(#212)
- Clean up transfer artifacts surgically at consumption, not
blanket-delete (#216)
- Version each publish leg against its own branch; validate at entry
(#215)
- Consolidate workspace configurations into a unified ProjectTemplate
workspace (#210)
- Template convergence barrier: absorb pins, generic release +
docker-readme, carry-whole-file (#207)
- Key merge-bot concurrency on PR number, not `github.ref` (#206)
- Codify orchestrated re-sync personas and full-replacement rule (#205)
- Lead action pins; affirm pattern-based artifact handoff (#204)
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ptr727