Skip to content

Bot pull requests stay blocked by the unattributed-changes approval #791

Description

@shiny-code-app

Objective

Let the automation app merge its own ordinary pull requests without the owner's approval, as the ruleset pair intends, instead of hitting the "extra approval for unattributed changes" setting.

Evidence

  • cbusillo/shiny-infra-ops#305 was opened by shiny-code-app[bot] and passes validation-gate, but stays BLOCKED. Merging it as the app fails.
  • Both rulesets on that repository have require_extra_approval_for_unattributed_changes: true. One of them, "Code-owner review for DIRECTION.md", has no bypass actors by design, so the app cannot bypass it.
  • git-commit-as-bot authored the commit as shiny-code-bot (the older machine user, from CODEX_AUTOMATION_LOGIN in local.env), not the app. After the commit was re-credited to shiny-code-app[bot], the timeline recorded the force push as cbusillo. So git-push-as-bot pushed with a credential that resolves to the owner, and the PR stayed blocked.
  • In codex-skills, bot-authored PRs such as Preserve structural evidence in blocked train responses #788 show merged_by: cbusillo, with commits by shiny-code-bot. Merges there appear to land under the owner's account, not the app.
  • cbusillo/direction#1 merged because the owner approved it.

Inferred, not verified: the push and commit identity not matching the app that authored the pull request counts as an "unattributed change".

Finish Line

A bot-authored pull request whose commits and pushes come from the app merges as the app with no owner approval on a repository with the standard ruleset pair, and DIRECTION.md pull requests still require the owner. Or, if that is not possible, the rulesets change so that only DIRECTION.md and CODEOWNERS require the owner, as the owner decided on 2026-09-21.

Current Status

State: Active.
Next action: confirm which credential git-push-as-bot resolves in owner sessions, and what GitHub counts as unattributed; then fix the helper identity or the ruleset setting.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    planDurable planning issueplan:donePlan completed or superseded

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions