Skip to content

Ruleset 21022482 required_status_checks missing Security Scan and Release config #56

Description

@bketelsen

Summary

Ruleset 21022482's required_status_checks currently lists only:

Docs integrity
Lint
Race Detection
Unit Tests
Verify

Two CI jobs that exist and run on pull requests are not in that list, so a
red result from either currently informs but does not block merge:

  • Release config (goreleaser check job, added in ci(release): validate .goreleaser.yaml on every pull request #31) — that PR's own
    description explicitly flagged this as "not yet blocking," noting that
    adding it to ruleset 21022482 is an operator repository-settings act
    outside the PR itself (core's scripts/apply-repo-settings.sh).
  • Security Scan (govulncheck) — this gap was never previously flagged in
    any PR; it has the identical effect of a red vulnerability scan not
    blocking merge.

Verification

gh api repos/frostyard/std/rulesets/21022482 --jq '.rules[] | select(.type=="required_status_checks") | .parameters.required_status_checks[].context'

Currently prints only Docs integrity, Lint, Race Detection,
Unit Tests, Verify — confirmed live as of 2026-08-22.

Ask

Operator: please add both Security Scan and Release config as required
contexts on ruleset 21022482 (via core's scripts/apply-repo-settings.sh or
equivalent), so a red govulncheck or goreleaser check result blocks merge
instead of only informing.

References

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions