Skip to content

Continuous Integration enforcement checklist

Use this checklist to keep CI truthful, minimal, and reviewer-friendly.

  1. Canonical PR gate
  2. Keep ✅ PR CI as the only required PR workflow.
  3. Required checks on main:

    • Lint (ruff)
    • Smoke tests
  4. Branch protection settings

  5. Enable Require status checks to pass before merging.
  6. Enable Require branches to be up to date before merging.
  7. If merge queue is enabled, ensure it uses the same required checks.
  8. Verify/enforce configuration: bash python scripts/verify_branch_protection.py --apply --branch main

  9. Heavy CI stays off PR gating

  10. Keep 🚀 Integration CI — Insight Demo for post-merge/release confidence:
    • push to main (full non-release validation surface)
    • release tags (v*, release-*)
    • manual dispatch
  11. Keep release-only publish/deploy/signing scoped to tag/manual contexts while all validation jobs run on merge-to-main.
  12. Do not add this full matrix back to required PR checks unless the PR gate is redesigned and docs/scripts are updated together.

  13. CI health monitoring

  14. Keep 🩺 CI Health / CI watchdog active to enforce required PR-gate health and context-aware remediation.
  15. Default behavior skips self-monitoring; only opt in with --include-self when explicitly auditing the watchdog workflow itself.
  16. For automatic branch-protection remediation, set ADMIN_GITHUB_TOKEN with branch admin scope.
  17. Without admin token, health checks run in read-only mode.

  18. Consistency checks after CI edits

  19. Update docs (README.md, docs/CI_WORKFLOW.md, this file).
  20. Update required check sources (scripts/required_checks.json, defaults in scripts/verify_branch_protection.py).
  21. Run: bash python tools/update_actions.py pre-commit run --files .github/workflows/ci.yml .github/workflows/pr-ci.yml .github/workflows/ci-health.yml

  22. Operational status checks

  23. Poll workflow state when debugging: bash python scripts/check_ci_status.py --wait-minutes 5 --pending-grace-minutes 45 --stale-minutes 90 # optional: add --dispatch-failed for explicit failed-run redispatches
  24. Use --once for immediate pass/fail status.

Following this checklist keeps PR gating small and high-signal while preserving deep validation on integration and release paths.