Skip to content

docs: correct the review-gate claims to what the API actually returns (GTM-33) - #38

Merged
qmarcelle merged 3 commits into
mainfrom
gtm-33-correct-review-gate-claims
Aug 13, 2026
Merged

qmarcelle merged 3 commits into
mainfrom
gtm-33-correct-review-gate-claims

Conversation

@qmarcelle

@qmarcelle qmarcelle commented Aug 13, 2026 •

Copy link
Copy Markdown
Contributor

Found by the GTM-33 launch hygiene audit while verifying the branch-protection change on this repository.

Both public surfaces claimed governance controls this repository does not have — in the direction of appearing more governed than it is.

The measured contradiction

Claim on the surface GitHub API
"Code-owner review is enabled and does bind… nothing here should be read as saying that control is inert — it is not." (docs/repository-settings.md) require_code_owner_reviews: false
"code-owner review is enabled and does block affected pull requests" (README.md) require_code_owner_reviews: false
"Branch protection … PR + 1 review + CI + conversation resolution + codeowner" required_approving_review_count: 0
"Phase 1 (current): Greptile as independent review gate" removed 2026-08-13

docs/repository-settings.md already carries the rule that settles this: when the API disagrees with the file, the API is right and the file is a documentation defect. This is that rule exercised against the document that states it.

Both remediation phases have executed

  • Phase 2 already happened — required code-owner approval is off.
  • Phase 1 was tried and withdrawn. Greptile Review was required from 2026-08-12 and removed 2026-08-13. The Greptile trial account reached its 50-credit limit; it now posts a credit-limit notice in place of a review and emits no check run, so the required context could not be satisfied by anything and main was unmergeable.

Observed on PR #37 — Greptile reviewed the exact head 4f9e8f6f and produced zero Greptile Review check runs, where #34, #35 and #36 each produced exactly one:

PR #34 head 1692e7b4 : Greptile Review check runs = 1
PR #35 head 207e2c8e : Greptile Review check runs = 1
PR #36 head b8289a07 : Greptile Review check runs = 1
PR #37 head 4f9e8f6f : Greptile Review check runs = 0

Verbatim, in place of the review:

qmarcelle has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.

A quota notice is not review evidence. Absence of a check is recorded as absence, never as a pass.

The replacement claim is stronger, not weaker

It was "main has no enforceable independent-review path." It is now "main has no review requirement at all" — no approving-review count, no code-owner requirement, no required review status context. Phase 2 removed the gate that could not be satisfied; Phase 1 removed the gate meant to replace it. CI correctness and conversation resolution are the entire merge contract, with admin enforcement off on top.

This is a real reduction in enforcement and is stated plainly rather than softened. The re-admission condition is recorded: a review gate returns only when both a substantive review on the current head and a mechanically enforceable current-head signal are observed. Greptile met the second only while its trial lasted, which is why it was promoted and withdrawn inside two days.

Verification

pnpm run check:docs passes — 184 links resolved, 87 documented commands verified, 4 stable read paths confirmed, 11 prose enumerations complete.

Note for GTM-33 §5: this modifies README.md, so the comprehension gate re-pins to the merge commit of this PR.

Summary by Sourcery

Update documentation to accurately reflect current branch protection and review requirements based on GitHub API state.

Documentation:

  • Clarify that branch protection requires CI and conversation resolution but no reviewers, code owners, or review status contexts.
  • Record execution and withdrawal of the Greptile-based independent review gate and the disabling of code-owner review, noting that main currently has no review requirement.
  • Explain that CODEOWNERS now only routes ownership and review requests without acting as a merge gate, and document the conditions for reintroducing enforceable review gates.

… (GTM-33)

Both surfaces claimed governance controls this repository does not have.

`docs/repository-settings.md` stated emphatically that code-owner review "is
enabled and does bind" and that "nothing here should be read as saying that
control is inert — it is not." The API returns
`require_code_owner_reviews: false`. The document's own rule is that the API is
the arbiter, so this is the rule being exercised against the document that
carries it. README repeated the same claim.

The remediation section described a two-phase plan with "Phase 1 (current):
Greptile as independent review gate". Both phases have in fact executed, and the
result is worse than either intended:

- Phase 2 already happened — required code-owner approval is off.
- Phase 1 was tried and withdrawn. `Greptile Review` was required from
  2026-08-12 and removed 2026-08-13, because the Greptile trial account hit its
  50-credit limit and now posts a credit-limit notice instead of a review while
  emitting no check run. Observed on PR #37: reviewed head 4f9e8f6, zero check
  runs, where #34/#35/#36 each produced exactly one. A required context nothing
  can emit blocks every merge.

So the honest statement is stronger than the one being replaced. It was "no
enforceable *independent* review path"; it is now "no review requirement at
all" — no approving-review count, no code-owner requirement, and no required
review status context. CI correctness and conversation resolution are the whole
merge contract, and admin enforcement is off on top of that.

A quota notice is not review evidence. Absence of a check is recorded as
absence, never as a pass.
Copilot AI lite review requested due to automatic review settings August 13, 2026 05:15

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

qmarcelle has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@sourcery-ai

sourcery-ai Bot commented Aug 13, 2026 •

Copy link
Copy Markdown

Reviewer's Guide

Updates documentation to accurately reflect current GitHub branch protection and review settings, emphasizing that no reviewer of any kind is currently required and recording the failed Greptile review gate experiment and disabled code-owner review enforcement.

Flow diagram for current branch-protection merge contract with no review requirement

flowchart TD
    Dev[Developer opens pull request] --> BP[Branch protection evaluation]

    BP --> CI[CI checks on Node20/Node22]
    BP --> CR[Conversation resolution]

    CI -->|pass| Gate[Merge allowed]
    CI -->|fail| Block[Merge blocked]

    CR -->|all resolved| Gate
    CR -->|unresolved| Block

    BP -.-> Reviews[Human or Greptile review]
    Reviews -.-> Gate

    subgraph Non_enforced_review_controls
      CODEOWNERS[CODEOWNERS ownership routing]
      Greptile[Greptile Review status context]
    end

    CODEOWNERS --> Reviews
    Greptile --> Reviews

    Admin[Administrator] --> Gate
    Admin --> Block

    note_none["No reviewer requirement: required_approving_review_count = 0, require_code_owner_reviews = false, no required review status context"] --> BP
Loading

File-Level Changes

Change Details Files
Clarify branch protection description to remove implied reviewer requirements and align with actual GitHub API settings.
  • Change branch protection summary from including PR + 1 review + CI + conversation resolution + codeowner to PR + CI + conversation resolution with no reviewer required
  • Update governance summary from no independent-review path to no review requirement of any kind, explicitly listing required_approving_review_count, require_code_owner_reviews, and absence of required review status contexts
docs/repository-settings.md
README.md
Document that code-owner review is not enabled and that CODEOWNERS only routes review requests, not enforceable gates.
  • Replace prior assertion that code-owner review is enabled and binding with explicit statement that require_code_owner_reviews is false and the previous claim was incorrect per API
  • Clarify that a sole-steward CODEOWNERS configuration cannot satisfy a code-owner review requirement and therefore does not gate merges
docs/repository-settings.md
README.md
Record the execution and rollback of the Greptile-based independent review gate and the resulting lack of any review requirement.
  • Replace forward-looking two-phase remediation plan with a retrospective account that both phases executed and produced a worse outcome than intended
  • Describe Greptile trial credit exhaustion, absence of Greptile Review check runs on PR docs(settings): record the social preview as applied and verified (GTM-43) #37, and removal of the required status context to avoid deadlocking main
  • State the current condition: main requires no reviewer at all and define criteria for re-admitting a review gate (substantive review plus enforceable status check)
docs/repository-settings.md
Enumerate missing controls explicitly as not present in branch protection, including admin enforcement, code-owner review, and Greptile as a required context.
  • Extend the table of controls not in place to include code-owner review disabled and Greptile Review removed as a required context
  • Align descriptive prose with the table values, emphasizing that enforcement on admins and review-related gates are absent
docs/repository-settings.md

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've found 1 issue

Prompt for AI Agents
Please address the comments from this code review:

## Individual Comments

### Comment 1
<location path="docs/repository-settings.md" line_range="141-143" />
<code_context>
+`Greptile Review` was added as a required status context and removed on
+2026-08-13. The Greptile trial account reached its 50-credit limit, after which
+the app posts a credit-limit notice in place of a review and emits **no check
+run at all**. A required context nothing can produce blocks every merge, so the
+requirement was withdrawn rather than left to deadlock `main`. The same failure
+and the same withdrawal are recorded for `workspacejson/integrations` in that
</code_context>
<issue_to_address>
**suggestion (typo):** The phrase "A required context nothing can produce" is grammatically awkward; consider inserting "that" for clarity.

You might rewrite this clause to something like "a required context that nothing can produce" to make the sentence flow more naturally; the current wording reads as if a word is missing.

```suggestion
the app posts a credit-limit notice in place of a review and emits **no check
run at all**. A required context that nothing can produce blocks every merge, so
the requirement was withdrawn rather than left to deadlock `main`. The same failure
```
</issue_to_address>

Sourcery is free for open source - if you like our reviews please consider sharing them ✨
Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.

Comment thread docs/repository-settings.md
"A required context nothing can produce" reads as if a word is dropped.
"A required context that nothing can produce" is what was meant.

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

qmarcelle has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.

Correcting the code-owner and Greptile claims left six places contradicting the
corrections — a document arguing that settings drift is detectable only if the
intent is written down should not itself say two things.

- Heading and framing still said "no enforceable independent-review path"; the
  measured state is no review requirement at all.
- Point 3 explained why a self-authored change "cannot satisfy the code-owner
  requirement" two paragraphs after point 2 established there is no such
  requirement. It now states what it is actually evidence for: re-enabling that
  control would block every change rather than get any reviewed.
- The closing paragraph still described the Greptile/Sourcery transition as
  planned, immediately above the section recording that it was tried and
  withdrawn.
- The interim-governance diagram still listed "Required Greptile review" as a
  merge authorization input.
- "The remediation has two phases:" ran directly into "Both phases have been
  executed."
- The table listing controls "not in place" gained two rows while its lead-in
  still said two.

Also sharpened one thing the corrections understated: with no required reviewer,
`enforce_admins: false` is no longer the first way an unreviewed change reaches
`main` — it is the second.

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

qmarcelle has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.

@sonarqubecloud

Copy link
Copy Markdown

@qmarcelle
qmarcelle merged commit a8c53c6 into main Aug 13, 2026
7 checks passed
@qmarcelle
qmarcelle deleted the gtm-33-correct-review-gate-claims branch August 13, 2026 05:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants