From 2cdc1ae87a243b4814dd0e517c04174dec9a786e Mon Sep 17 00:00:00 2001 From: Cameron Brooks Date: Sun, 6 Sep 2026 21:40:50 -0400 Subject: [PATCH] ci: add an ok aggregator as the single required status check Branch protection should require one stable context, not a list of job names that changes whenever CI does. Every new job goes in `needs:` here instead of in repository settings. It requires SUCCESS rather than testing for failure. `contains(needs.*.result, 'failure')` does not match 'skipped', so an `if: false` on a real job yields a fully green pull request with nothing checked -- measured in a sibling repo, where it produced exactly that. This workflow has no path filtering, so nothing here skips legitimately; a repo that does filter needs the tolerant form instead. --- .github/workflows/ci.yml | 26 ++++++++++++++++++++++++++ 1 file changed, 26 insertions(+) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 0d1b9d1..972c481 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -69,3 +69,29 @@ jobs: name: coverage-report path: coverage.xml retention-days: 7 + + # The ONLY job branch protection requires. Add every new job to `needs:` here + # rather than to the protection settings, so CI can evolve without touching + # repository configuration. + # + # It requires SUCCESS rather than testing for failure. `contains(needs.*.result, + # 'failure')` does not match 'skipped', so an `if: false` on a real job produces a + # fully green pull request with nothing checked -- measured in a sibling repo. + # This workflow has no path filtering, so no job here skips legitimately; a repo + # that does filter needs the tolerant form instead. + ok: + name: ok + if: always() + needs: [lint, typecheck, test] + runs-on: ubuntu-latest + timeout-minutes: 5 + steps: + - name: Fail unless every upstream job succeeded + if: >- + needs.lint.result != 'success' || + needs.typecheck.result != 'success' || + needs.test.result != 'success' + run: exit 1 + - name: Pass + run: echo 'All checks passed' +