Finding
PR #177 was BLOCKED after every check went green, every review thread was resolved and the code-scanning alert set matched main. The only remaining blocker was required_signatures (rulesets 18110203 and 24256098): two commits on the branch were authored and committed by coderabbitai[bot] and carry no signature.
Measured 2026-10-01 via pulls/177/commits .commit.verification and GraphQL commit.signature:
| commit |
author |
signature |
6aa1b3e |
coderabbitai[bot] |
none |
a3ac208 |
coderabbitai[bot] |
none |
5a24ec2, 0f59a03, e71cd18 |
owner |
VALID |
Nothing in a check-run census shows this. The PR looked ready on every surface except the per-commit verification field.
Cause
CodeRabbit's "commit suggestion" / auto-commit feature pushes commits as the bot's own identity, unsigned. On a repository with required_signatures every such commit makes the PR unmergeable until a human rewrites history. The cure applied on #177 was a git rebase -S of the bot pair only (tree-identical, empty diff) and a --force-with-lease push.
Acceptance criteria
Related: #177, #176. Config change is the owner's to make; this issue records the finding and the criteria per the standing stopping rule.
🤖 Generated with Claude Code
https://claude.ai/code/session_01QYY8Gp4v4x2J7iSNn1vZ57
Finding
PR #177 was
BLOCKEDafter every check went green, every review thread was resolved and the code-scanning alert set matchedmain. The only remaining blocker wasrequired_signatures(rulesets 18110203 and 24256098): two commits on the branch were authored and committed bycoderabbitai[bot]and carry no signature.Measured 2026-10-01 via
pulls/177/commits.commit.verificationand GraphQLcommit.signature:6aa1b3ea3ac2085a24ec2,0f59a03,e71cd18Nothing in a check-run census shows this. The PR looked ready on every surface except the per-commit verification field.
Cause
CodeRabbit's "commit suggestion" / auto-commit feature pushes commits as the bot's own identity, unsigned. On a repository with
required_signaturesevery such commit makes the PR unmergeable until a human rewrites history. The cure applied on #177 was agit rebase -Sof the bot pair only (tree-identical, empty diff) and a--force-with-leasepush.Acceptance criteria
.coderabbit.yamlor the app config), or its commits arrive signed.pulls/{N}/commits.required_signaturesby a bot commit (positive control: fix(proofs): census reads logical roots from _CoqProject; restore FilesystemCNO.lean pending #167 #177 before the re-sign was so blocked).Related: #177, #176. Config change is the owner's to make; this issue records the finding and the criteria per the standing stopping rule.
🤖 Generated with Claude Code
https://claude.ai/code/session_01QYY8Gp4v4x2J7iSNn1vZ57