docs: capture the dependabot gate friction, rule the route, and plan the bounded re-authoring - #660
Merged
Merged
Conversation
…bution gate The product thinker asked for the gate to change after PR 655 sat blocked with auto-merge armed. The record names the mechanism precisely, because the request names the trailer and the trailer is not what fails: the gate refuses a bot on identity, and the script deliberately says nothing about a missing trailer so the remedy is not misread. It reverses a stated rule, so the record asks for an ADR and a brief invariant before any code moves, and lists three candidate shapes for that decision to weigh. Refs: iss-2609221820487644 Assisted-by: Claude:claude-opus-5
…record the ruling that chose it Route 2 of the three the capture named: a workflow re-authors a bot-opened bump as the repository owner before the gate runs, bounded by the diff's shape (an ecosystem's manifest and its lock file on a branch the forge marks as that bot's) across every ecosystem dependabot opens, with the message naming the bot and the workflow and carrying Assisted-by: None. The attribution gate is not edited. Scaffolded into a managed repository by the verb that writes its release workflows, opt-in. The authorship point is named on the record rather than assumed. Refs: iss-2609221820487644 Assisted-by: Claude:claude-opus-5
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Assisted-byso the remedy is not misread. It lists three candidate shapes and says the change needs a decision, since it touches a stated rule.Assisted-by: None. The attribution script is not edited, and a test asserts it still refuses the bot's original while passing the re-authored commit. Scaffolded into a managed repository by the same verb that writes its release workflows, opt-in.Why
The gate's consequence is deliberate and written down. Its cost was not: every bump sits with auto-merge armed and every other check green, in a blocked state that reads as a missing review, and the only way through is a person re-authoring a two-line diff. One did that tonight, at the price of a hand-authored branch and two full gate runs.
A point named rather than assumed
A workflow that re-authors asserts the repository owner's authorship with no person in the loop. That is a different claim from a commit a person asked for, even though the gate would pass either. The record says so, and the owner's acceptance is made once in the configuration, under the diff-shaped bound.
Records
Refs: iss-2609221820487644
Assisted-by: Claude:claude-opus-5