You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Let the automation app merge its own ordinary pull requests without the owner's approval, as the ruleset pair intends, instead of hitting the "extra approval for unattributed changes" setting.
Evidence
cbusillo/shiny-infra-ops#305 was opened by shiny-code-app[bot] and passes validation-gate, but stays BLOCKED. Merging it as the app fails.
Both rulesets on that repository have require_extra_approval_for_unattributed_changes: true. One of them, "Code-owner review for DIRECTION.md", has no bypass actors by design, so the app cannot bypass it.
git-commit-as-bot authored the commit as shiny-code-bot (the older machine user, from CODEX_AUTOMATION_LOGIN in local.env), not the app. After the commit was re-credited to shiny-code-app[bot], the timeline recorded the force push as cbusillo. So git-push-as-bot pushed with a credential that resolves to the owner, and the PR stayed blocked.
cbusillo/direction#1 merged because the owner approved it.
Inferred, not verified: the push and commit identity not matching the app that authored the pull request counts as an "unattributed change".
Finish Line
A bot-authored pull request whose commits and pushes come from the app merges as the app with no owner approval on a repository with the standard ruleset pair, and DIRECTION.md pull requests still require the owner. Or, if that is not possible, the rulesets change so that only DIRECTION.md and CODEOWNERS require the owner, as the owner decided on 2026-09-21.
Current Status
State: Active.
Next action: confirm which credential git-push-as-bot resolves in owner sessions, and what GitHub counts as unattributed; then fix the helper identity or the ruleset setting.
Objective
Let the automation app merge its own ordinary pull requests without the owner's approval, as the ruleset pair intends, instead of hitting the "extra approval for unattributed changes" setting.
Evidence
shiny-code-app[bot]and passesvalidation-gate, but staysBLOCKED. Merging it as the app fails.require_extra_approval_for_unattributed_changes: true. One of them, "Code-owner review for DIRECTION.md", has no bypass actors by design, so the app cannot bypass it.git-commit-as-botauthored the commit asshiny-code-bot(the older machine user, fromCODEX_AUTOMATION_LOGINinlocal.env), not the app. After the commit was re-credited toshiny-code-app[bot], the timeline recorded the force push ascbusillo. Sogit-push-as-botpushed with a credential that resolves to the owner, and the PR stayed blocked.merged_by: cbusillo, with commits byshiny-code-bot. Merges there appear to land under the owner's account, not the app.Inferred, not verified: the push and commit identity not matching the app that authored the pull request counts as an "unattributed change".
Finish Line
A bot-authored pull request whose commits and pushes come from the app merges as the app with no owner approval on a repository with the standard ruleset pair, and
DIRECTION.mdpull requests still require the owner. Or, if that is not possible, the rulesets change so that onlyDIRECTION.mdandCODEOWNERSrequire the owner, as the owner decided on 2026-09-21.Current Status
State: Active.
Next action: confirm which credential
git-push-as-botresolves in owner sessions, and what GitHub counts as unattributed; then fix the helper identity or the ruleset setting.