Conversation
…-date branches An active repository ruleset with a MERGE_QUEUE rule now sets UpToDateBeforeMerge, so the requiresUpToDateBranches probe passes for branches that use a merge queue instead of strict status checks. GitHub documents the merge queue as providing the same benefits as "Require branches to be up to date before merging". The rule type is already returned by the existing rulesets GraphQL query, so no new API call or token scope is needed. Bypass actors continue to be reflected through EnforceAdmins, as for other rules. Fixes ossf#3678 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Signed-off-by: Erik Osterman <erik@cloudposse.com>
osterman
requested review from
justaugustus and
spencerschrock
and removed request for
a team
October 2, 2026 02:04
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What kind of change does this PR introduce?
Feature: Branch-Protection now counts a GitHub merge queue as meeting the "up-to-date branches" requirement.
What is the current behavior?
The
requiresUpToDateBranchesprobe passes only when "Require branches to be up to date before merging" (strict required status checks) is on. Some repositories require a merge queue through a repository ruleset instead. Those repositories getWarn: 'up-to-date branches' is disabled, even though GitHub documents the merge queue as providing "the same benefits as the Require branches to be up to date before merging branch protection".What is the new behavior (if this is a feature change)?
An active repository ruleset with a
MERGE_QUEUErule setsUpToDateBeforeMerge=truefor the branches it targets.rulesetsGraphQL query. No new API call, query field, or token scope is needed.ACTIVErulesets count (the existinggetActiveRuleSetsFromfilter).EnforceAdmins=false. This affects the "applies to administrators" probe, not this one.REQUIRED_STATUS_CHECKSrule in the same ruleset therefore can't override it.Example:
cloudposse/atmosenforces a merge queue onmainvia a ruleset with no bypass actors:Warn: 'up-to-date branches' is disabled on branch 'main'Info: 'up-to-date branches' is required to merge on branch 'main'New
Test_applyRepoRulescases:applyRepoRuleshas 100% statement coverage. All four new cases fail if the fix is removed.Which issue(s) this PR fixes
Fixes #3678
Special notes for your reviewer
BranchProtectionRuleobject has no merge-queue field. Supporting it would need an extrarepository.mergeQueue(branch:)query, which could be a follow-up.docs/checks/internal/checks.yamlandprobes/requiresUpToDateBranches/def.yml, anddocs/checks.md/docs/probes.mdwere regenerated withmake generate-docs.Does this PR introduce a user-facing change?
🤖 Generated with Claude Code