The finding
The ruleset on main requires five status checks. One of them, CodeRabbit
(integration_id: 347564), has never been posted on this repository — zero
appearances across PRs #106–#113 inclusive.
A required context that no actor ever posts can never be satisfied. It is not a
failing check; it is an absent one, and absence never turns into a pass.
Why it is being raised now
PR #113 fixes a different deadlock: a duplicate with: key in
.github/workflows/ci.yml meant every run was created with zero jobs, so
Code Coverage could never report. That is fixed and measured — PR #113's ci.yml
run creates 11 jobs where main's creates 0.
The effect is that required contexts went from 0/5 to 4/5:
| required context |
integration_id |
status on PR #113 |
Code Coverage |
15368 |
✅ skipped (satisfies — a skip is a pass; an absence is not) |
CodeQL |
57789 |
✅ success |
governance / Code quality + docs |
15368 |
✅ success |
SonarCloud Code Analysis |
12526 |
✅ success |
CodeRabbit |
347564 |
❌ never posted, on any PR |
So main is still closed to non-admin merges, now for this reason alone. Every
merge on this repository continues to be a silent admin bypass until it is resolved.
This needs an owner decision, not a code change
Two routes, and they are not equivalent:
- Install / enable CodeRabbit on this repository so the context actually posts.
Keeps the intended review gate.
- Remove
CodeRabbit from the ruleset's required_status_checks. Honest about
what is enforced, but drops the gate.
I have deliberately not changed the ruleset. Editing branch protection is the
owner's call and is outside the scope of the CI fix in #113.
Acceptance criteria
- A pull request on this repository shows all five required contexts in a terminal
state — or the ruleset lists only contexts that actually post.
- The proof is a real PR's posted check-runs
(gh api repos/.../commits/<head_sha>/check-runs), not the ruleset JSON. A
committed or configured ruleset is not evidence of what reports; only a real PR is.
- A merge lands without an admin bypass.
Note for whoever picks this up
Check integration_id as well as the context name. The ruleset pins each context to
a specific app, so a check of the right name posted by the wrong app does not
satisfy the rule.
🤖 Generated with Claude Code
https://claude.ai/code/session_01X3hgXxWm6umMgZkjYyHnnm
The finding
The ruleset on
mainrequires five status checks. One of them,CodeRabbit(
integration_id: 347564), has never been posted on this repository — zeroappearances across PRs #106–#113 inclusive.
A required context that no actor ever posts can never be satisfied. It is not a
failing check; it is an absent one, and absence never turns into a pass.
Why it is being raised now
PR #113 fixes a different deadlock: a duplicate
with:key in.github/workflows/ci.ymlmeant every run was created with zero jobs, soCode Coveragecould never report. That is fixed and measured — PR #113's ci.ymlrun creates 11 jobs where
main's creates 0.The effect is that required contexts went from 0/5 to 4/5:
Code Coverageskipped(satisfies — a skip is a pass; an absence is not)CodeQLgovernance / Code quality + docsSonarCloud Code AnalysisCodeRabbitSo
mainis still closed to non-admin merges, now for this reason alone. Everymerge on this repository continues to be a silent admin bypass until it is resolved.
This needs an owner decision, not a code change
Two routes, and they are not equivalent:
Keeps the intended review gate.
CodeRabbitfrom the ruleset'srequired_status_checks. Honest aboutwhat is enforced, but drops the gate.
I have deliberately not changed the ruleset. Editing branch protection is the
owner's call and is outside the scope of the CI fix in #113.
Acceptance criteria
state — or the ruleset lists only contexts that actually post.
(
gh api repos/.../commits/<head_sha>/check-runs), not the ruleset JSON. Acommitted or configured ruleset is not evidence of what reports; only a real PR is.
Note for whoever picks this up
Check
integration_idas well as the context name. The ruleset pins each context toa specific app, so a check of the right name posted by the wrong app does not
satisfy the rule.
🤖 Generated with Claude Code
https://claude.ai/code/session_01X3hgXxWm6umMgZkjYyHnnm