fix(ci): let platform-bot co-author trailers pass the attribution guard - #27
Merged
Merged
Conversation
COMMIT_MSG_REGEX blanket-matched any 'co-authored-by:' trailer, while the sibling CONTENT_REGEX correctly requires an AI vendor name after it. GitHub adds 'Co-authored-by: dependabot[bot]' to squash merges automatically, so every dependabot squash-merge tripped an AI-ATTRIBUTION policy and turned main red. Strip dependabot/github-actions/renovate bot trailers before applying the AI regex. Genuine AI co-author trailers (claude/openai/copilot/anthropic/...) are still caught, and the CONTENT_REGEX file scan is untouched. Verified against the failing range 2a3ee2b..b8c0f6f — now passes.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Attribution Guardwent red on main after dependabot PRs were squash-merged.Cause:
COMMIT_MSG_REGEXblanket-matched anyco-authored-by:trailer, whereas the siblingCONTENT_REGEXcorrectly requires an AI vendor name after it. GitHub automatically addsCo-authored-by: dependabot[bot]to squash merges — so a dependency bot tripped an AI-attribution policy, making dependabot PRs impossible to squash-merge.Fix: strip
dependabot/github-actions/renovatebot trailers before applying the AI regex. Genuine AI co-author trailers (claude / openai / copilot / anthropic / …) are still caught, and the file-content scan is unchanged.Verified locally against the exact failing range
2a3ee2bd..b8c0f6f8: now passes.