From 92b224961c4ff05a6ac0b16d233a69cffebea230 Mon Sep 17 00:00:00 2001 From: "mastra-platform[bot]" <284800079+mastra-platform[bot]@users.noreply.github.com> Date: Fri, 2 Oct 2026 05:04:02 +0000 Subject: [PATCH 1/3] ci: require exact-head live evidence before auto-queueing (#100) Use a serial in-place Mergify queue so Unfret reviews the PR head and live-gate must pass before automatic queueing. Co-Authored-By: mastra-platform[bot] <284800079+mastra-platform[bot]@users.noreply.github.com> --- .mergify.yml | 34 ++++++++++++++++++++++++++++++++++ 1 file changed, 34 insertions(+) create mode 100644 .mergify.yml diff --git a/.mergify.yml b/.mergify.yml new file mode 100644 index 00000000..6f4cf01c --- /dev/null +++ b/.mergify.yml @@ -0,0 +1,34 @@ +merge_queue: + max_parallel_checks: 1 + +queue_rules: + - name: default + batch_size: 1 + checks_timeout: null + merge_method: merge + queue_conditions: + - -draft + - check-success=verify + - check-success=Unfret + - check-success=live-gate + merge_conditions: [] + +merge_protections_settings: + auto_merge_conditions: + - base = main + +merge_protections: + - name: Queue ready pull requests + description: Automatically queue non-draft pull requests targeting main after verify, Unfret, and live-gate pass on the head. + if: + - base = main + success_conditions: + - -draft + - check-success=verify + - check-success=Unfret + - check-success=live-gate + +commands_restrictions: + requeue: + conditions: + - sender-permission >= write From f65069fe3d35ba550c991e3fccc18a685b646b60 Mon Sep 17 00:00:00 2001 From: "mastra-platform[bot]" <284800079+mastra-platform[bot]@users.noreply.github.com> Date: Fri, 2 Oct 2026 05:23:38 +0000 Subject: [PATCH 2/3] ci: exclude workflow changes from automatic queue gates (#100) Require operator queueing for .github/ changes to prevent workflow-generated checks from spoofing the automatic gates. Co-Authored-By: mastra-platform[bot] <284800079+mastra-platform[bot]@users.noreply.github.com> --- .mergify.yml | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/.mergify.yml b/.mergify.yml index 6f4cf01c..6f931144 100644 --- a/.mergify.yml +++ b/.mergify.yml @@ -6,7 +6,9 @@ queue_rules: batch_size: 1 checks_timeout: null merge_method: merge + # Block workflow check spoofing; .github/ changes require an operator queue. queue_conditions: + - -files~=^\.github/ - -draft - check-success=verify - check-success=Unfret @@ -22,7 +24,9 @@ merge_protections: description: Automatically queue non-draft pull requests targeting main after verify, Unfret, and live-gate pass on the head. if: - base = main + # Block workflow check spoofing; .github/ changes require an operator queue. success_conditions: + - -files~=^\.github/ - -draft - check-success=verify - check-success=Unfret From 91b0d5b47c46e1bcb57e38ded79f1f98f64987f1 Mon Sep 17 00:00:00 2001 From: "mastra-platform[bot]" <284800079+mastra-platform[bot]@users.noreply.github.com> Date: Fri, 2 Oct 2026 05:42:52 +0000 Subject: [PATCH 3/3] ci: preserve operator queueing for workflow changes (#100) Restrict the workflow exclusion to automatic queue admission so operators can still manually queue workflow changes after the required gates pass. Co-Authored-By: mastra-platform[bot] <284800079+mastra-platform[bot]@users.noreply.github.com> --- .mergify.yml | 6 ++---- 1 file changed, 2 insertions(+), 4 deletions(-) diff --git a/.mergify.yml b/.mergify.yml index 6f931144..0339fe2a 100644 --- a/.mergify.yml +++ b/.mergify.yml @@ -6,9 +6,7 @@ queue_rules: batch_size: 1 checks_timeout: null merge_method: merge - # Block workflow check spoofing; .github/ changes require an operator queue. queue_conditions: - - -files~=^\.github/ - -draft - check-success=verify - check-success=Unfret @@ -18,15 +16,15 @@ queue_rules: merge_protections_settings: auto_merge_conditions: - base = main + # Workflow changes never auto-queue; the operator queues them by hand. + - -files~=^\.github/ merge_protections: - name: Queue ready pull requests description: Automatically queue non-draft pull requests targeting main after verify, Unfret, and live-gate pass on the head. if: - base = main - # Block workflow check spoofing; .github/ changes require an operator queue. success_conditions: - - -files~=^\.github/ - -draft - check-success=verify - check-success=Unfret