docs: correct the review-gate claims to what the API actually returns (GTM-33) - #38
Conversation
… (GTM-33) Both surfaces claimed governance controls this repository does not have. `docs/repository-settings.md` stated emphatically that code-owner review "is enabled and does bind" and that "nothing here should be read as saying that control is inert — it is not." The API returns `require_code_owner_reviews: false`. The document's own rule is that the API is the arbiter, so this is the rule being exercised against the document that carries it. README repeated the same claim. The remediation section described a two-phase plan with "Phase 1 (current): Greptile as independent review gate". Both phases have in fact executed, and the result is worse than either intended: - Phase 2 already happened — required code-owner approval is off. - Phase 1 was tried and withdrawn. `Greptile Review` was required from 2026-08-12 and removed 2026-08-13, because the Greptile trial account hit its 50-credit limit and now posts a credit-limit notice instead of a review while emitting no check run. Observed on PR #37: reviewed head 4f9e8f6, zero check runs, where #34/#35/#36 each produced exactly one. A required context nothing can emit blocks every merge. So the honest statement is stronger than the one being replaced. It was "no enforceable *independent* review path"; it is now "no review requirement at all" — no approving-review count, no code-owner requirement, and no required review status context. CI correctness and conversation resolution are the whole merge contract, and admin enforcement is off on top of that. A quota notice is not review evidence. Absence of a check is recorded as absence, never as a pass.
There was a problem hiding this comment.
qmarcelle has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.
Reviewer's GuideUpdates documentation to accurately reflect current GitHub branch protection and review settings, emphasizing that no reviewer of any kind is currently required and recording the failed Greptile review gate experiment and disabled code-owner review enforcement. Flow diagram for current branch-protection merge contract with no review requirementflowchart TD
Dev[Developer opens pull request] --> BP[Branch protection evaluation]
BP --> CI[CI checks on Node20/Node22]
BP --> CR[Conversation resolution]
CI -->|pass| Gate[Merge allowed]
CI -->|fail| Block[Merge blocked]
CR -->|all resolved| Gate
CR -->|unresolved| Block
BP -.-> Reviews[Human or Greptile review]
Reviews -.-> Gate
subgraph Non_enforced_review_controls
CODEOWNERS[CODEOWNERS ownership routing]
Greptile[Greptile Review status context]
end
CODEOWNERS --> Reviews
Greptile --> Reviews
Admin[Administrator] --> Gate
Admin --> Block
note_none["No reviewer requirement: required_approving_review_count = 0, require_code_owner_reviews = false, no required review status context"] --> BP
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
There was a problem hiding this comment.
Hey - I've found 1 issue
Prompt for AI Agents
Please address the comments from this code review:
## Individual Comments
### Comment 1
<location path="docs/repository-settings.md" line_range="141-143" />
<code_context>
+`Greptile Review` was added as a required status context and removed on
+2026-08-13. The Greptile trial account reached its 50-credit limit, after which
+the app posts a credit-limit notice in place of a review and emits **no check
+run at all**. A required context nothing can produce blocks every merge, so the
+requirement was withdrawn rather than left to deadlock `main`. The same failure
+and the same withdrawal are recorded for `workspacejson/integrations` in that
</code_context>
<issue_to_address>
**suggestion (typo):** The phrase "A required context nothing can produce" is grammatically awkward; consider inserting "that" for clarity.
You might rewrite this clause to something like "a required context that nothing can produce" to make the sentence flow more naturally; the current wording reads as if a word is missing.
```suggestion
the app posts a credit-limit notice in place of a review and emits **no check
run at all**. A required context that nothing can produce blocks every merge, so
the requirement was withdrawn rather than left to deadlock `main`. The same failure
```
</issue_to_address>Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.
"A required context nothing can produce" reads as if a word is dropped. "A required context that nothing can produce" is what was meant.
There was a problem hiding this comment.
qmarcelle has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.
Correcting the code-owner and Greptile claims left six places contradicting the corrections — a document arguing that settings drift is detectable only if the intent is written down should not itself say two things. - Heading and framing still said "no enforceable independent-review path"; the measured state is no review requirement at all. - Point 3 explained why a self-authored change "cannot satisfy the code-owner requirement" two paragraphs after point 2 established there is no such requirement. It now states what it is actually evidence for: re-enabling that control would block every change rather than get any reviewed. - The closing paragraph still described the Greptile/Sourcery transition as planned, immediately above the section recording that it was tried and withdrawn. - The interim-governance diagram still listed "Required Greptile review" as a merge authorization input. - "The remediation has two phases:" ran directly into "Both phases have been executed." - The table listing controls "not in place" gained two rows while its lead-in still said two. Also sharpened one thing the corrections understated: with no required reviewer, `enforce_admins: false` is no longer the first way an unreviewed change reaches `main` — it is the second.
There was a problem hiding this comment.
qmarcelle has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.
|



Found by the GTM-33 launch hygiene audit while verifying the branch-protection change on this repository.
Both public surfaces claimed governance controls this repository does not have — in the direction of appearing more governed than it is.
The measured contradiction
docs/repository-settings.md)require_code_owner_reviews: falseREADME.md)require_code_owner_reviews: falserequired_approving_review_count: 0docs/repository-settings.mdalready carries the rule that settles this: when the API disagrees with the file, the API is right and the file is a documentation defect. This is that rule exercised against the document that states it.Both remediation phases have executed
Greptile Reviewwas required from 2026-08-12 and removed 2026-08-13. The Greptile trial account reached its 50-credit limit; it now posts a credit-limit notice in place of a review and emits no check run, so the required context could not be satisfied by anything andmainwas unmergeable.Observed on PR #37 — Greptile reviewed the exact head
4f9e8f6fand produced zeroGreptile Reviewcheck runs, where #34, #35 and #36 each produced exactly one:Verbatim, in place of the review:
A quota notice is not review evidence. Absence of a check is recorded as absence, never as a pass.
The replacement claim is stronger, not weaker
It was "
mainhas no enforceable independent-review path." It is now "mainhas no review requirement at all" — no approving-review count, no code-owner requirement, no required review status context. Phase 2 removed the gate that could not be satisfied; Phase 1 removed the gate meant to replace it. CI correctness and conversation resolution are the entire merge contract, with admin enforcement off on top.This is a real reduction in enforcement and is stated plainly rather than softened. The re-admission condition is recorded: a review gate returns only when both a substantive review on the current head and a mechanically enforceable current-head signal are observed. Greptile met the second only while its trial lasted, which is why it was promoted and withdrawn inside two days.
Verification
pnpm run check:docspasses — 184 links resolved, 87 documented commands verified, 4 stable read paths confirmed, 11 prose enumerations complete.Note for GTM-33 §5: this modifies
README.md, so the comprehension gate re-pins to the merge commit of this PR.Summary by Sourcery
Update documentation to accurately reflect current branch protection and review requirements based on GitHub API state.
Documentation:
maincurrently has no review requirement.