Skip to content

Fix CI checks to run in merge queue - #1654

Merged
DonOmalVindula merged 1 commit into
thunder-id:mainfrom
DonOmalVindula:fix-merge-queue
Mar 4, 2026
Merged

DonOmalVindula merged 1 commit into
thunder-id:mainfrom
DonOmalVindula:fix-merge-queue

Conversation

@DonOmalVindula

@DonOmalVindula DonOmalVindula commented Mar 4, 2026 •

Copy link
Copy Markdown
Contributor

Purpose

This pull request updates several GitHub Actions workflow files to support the new merge_group event, which is triggered by GitHub's merge queue feature. This ensures that our CI/CD pipelines and checks will run correctly when changes are merged via the queue, not just on traditional pull requests. The main changes involve updating workflow triggers and job conditions to include merge_group alongside pull_request.

Workflow trigger updates:

  • Added merge_group as a trigger in .github/workflows/pr-builder.yml, .github/workflows/pr-label-check.yml, and .github/workflows/docs-style-check.yml to ensure workflows run for merge queue events. [1] [2] [3]

Job condition updates:

  • Updated the if conditions for jobs like security-audit, dependency-review, lint, build, test-frontend, build_samples, and detect-powershell-changes in .github/workflows/pr-builder.yml to run for both pull_request and merge_group events. This guarantees that all relevant CI checks are performed for merge queue entries. [1] [2] [3] [4] [5] [6] [7]

PR label check workflow:

  • Ensured that the check-labels job in .github/workflows/pr-label-check.yml only runs for pull_request events, even though the workflow is triggered for merge_group as well, to avoid unnecessary label checks for merge queue events.

These changes improve compatibility with GitHub's merge queue and ensure our workflows remain robust and reliable.

Related Issues

  • N/A

Related PRs

  • N/A

Checklist

  • Followed the contribution guidelines.
  • Manual test round performed and verified.
  • Documentation provided. (Add links if there are any)
    • Ran Vale and fixed all errors and warnings
  • Tests provided. (Add links if there are any)
    • Unit Tests
    • Integration Tests
  • Breaking changes. (Fill if applicable)
    • Breaking changes section filled.
    • breaking change label added.

Security checks

  • Followed secure coding standards in WSO2 Secure Coding Guidelines
  • Confirmed that this PR doesn't commit any keys, passwords, tokens, usernames, or other secrets.

Summary by CodeRabbit

  • Chores
    • CI workflows now recognize GitHub merge-group events and run grouped PR checks like individual pull requests.
    • Workflow conditions updated so audits, linting, builds, and tests run for merge groups as well as pull requests, with some uploads gated for merge-group runs.
    • Improved base-branch/commit detection and SHA handling for affected-change calculations and tooling.
    • Label validation skips merge-group events while remaining enforced for standard pull requests.
    • Default and patch coverage reports now include informational reporting for greater visibility.

@DonOmalVindula
DonOmalVindula enabled auto-merge March 4, 2026 04:40
@coderabbitai

coderabbitai Bot commented Mar 4, 2026 •

Copy link
Copy Markdown
Contributor

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

Adds merge_group event handling across CI workflows, adjusts base-ref/SHA resolution for changed-file detection and Nx affected calculations, skips PR label checks for merge_group, and marks default and patch Codecov reports as informational.

Changes

Cohort / File(s) Summary
Docs style workflow
.github/workflows/docs-style-check.yml
Add merge_group trigger; compute BASE_REF from github.event.merge_group.base_ref when present; use origin/${BASE_REF} for git diff targeting *.md/*.mdx; keep existing filter and empty-result behavior.
PR builder workflow
.github/workflows/pr-builder.yml
Add merge_group trigger to many jobs; add fetch-main and set-shas steps; wire Nx base/head and affected calculations to steps.set-shas.outputs; gate uploads and some steps when event_name == 'merge_group'.
PR label check
.github/workflows/pr-label-check.yml
Add merge_group trigger and a no-op skip step; constrain label validation step to run only on pull_request events.
Codecov config
codecov.yml
Set informational: true for project default and patch default coverage statuses; other blocks unchanged.

Sequence Diagram(s)

sequenceDiagram
    participant MergeQueue as Merge Queue (merge_group)
    participant GHRunner as GitHub Actions Runner
    participant Fetch as fetch-main / set-shas
    participant Diff as changed-files / git-diff
    participant Nx as Nx affected/base/head
    participant Jobs as CI Jobs (build/test/lint)
    participant Codecov as Codecov

    MergeQueue->>GHRunner: Trigger workflows (event: merge_group)
    GHRunner->>Fetch: run fetch-main & set-shas (determine base/head)
    Fetch->>GHRunner: outputs.base_sha, outputs.head_sha
    GHRunner->>Diff: compute BASE_REF and git diff (markdown filters)
    GHRunner->>Nx: run affected commands using set-shas outputs
    GHRunner->>Jobs: execute jobs with merge_group-specific gating
    Jobs->>Codecov: conditionally upload (skip when merge_group)
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Poem

🐰 I hopped through YAML in the night,
added merge groups, set SHAs just right.
Fetched the main, diffed docs with care,
labels nap until PRs are there.
CI hums softly — carrots everywhere.

🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely summarizes the main objective of the pull request: enabling CI checks to run in the merge queue.
Description check ✅ Passed The description includes Purpose and Approach sections with detailed explanations of the changes. However, several checklist items remain unchecked.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@DonOmalVindula DonOmalVindula added the skip-changelog Skip generating changelog for a particular PR label Mar 4, 2026
ThaminduDilshan
ThaminduDilshan previously approved these changes Mar 4, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
.github/workflows/docs-style-check.yml (1)

45-52: ⚠️ Potential issue | 🟡 Minor

github-pr-check reporter may have limited functionality in merge_group context.

The reporter: github-pr-check option creates inline annotations on pull requests. During merge_group events, this reporter may not function as expected since the PR context differs. Consider whether this is acceptable or if you need conditional reporter selection.

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In @.github/workflows/docs-style-check.yml around lines 45 - 52, The Vale action
step ("🔍 Run Vale" using errata-ai/[email protected]) currently hard-codes
reporter: github-pr-check which can fail for merge_group/other event contexts;
update the workflow to choose the reporter conditionally (e.g., use
github-pr-check only when github.event_name == 'pull_request' or when running in
a PR context, and fall back to a different reporter like 'github' or 'console'
otherwise) so the step behaves correctly across merge_group runs; locate the
step by its name/uses and change how the reporter input is set (conditional
input or separate steps) to ensure annotations are produced only when PR context
supports them.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Inline comments:
In @.github/workflows/docs-style-check.yml:
- Line 11: The workflow currently uses github.base_ref when building the git
diff for the merge_group run, but github.base_ref is undefined for merge_group
events; update the git diff logic (the step that constructs origin/${{
github.base_ref }}...HEAD) to conditionally use
github.event.merge_group.base_ref when the event is merge_group (i.e., detect
github.event_name == 'merge_group' or check existence of
github.event.merge_group.base_ref) and fall back to github.base_ref otherwise,
ensuring the git diff command uses either github.event.merge_group.base_ref or
github.base_ref appropriately.

---

Outside diff comments:
In @.github/workflows/docs-style-check.yml:
- Around line 45-52: The Vale action step ("🔍 Run Vale" using
errata-ai/[email protected]) currently hard-codes reporter: github-pr-check
which can fail for merge_group/other event contexts; update the workflow to
choose the reporter conditionally (e.g., use github-pr-check only when
github.event_name == 'pull_request' or when running in a PR context, and fall
back to a different reporter like 'github' or 'console' otherwise) so the step
behaves correctly across merge_group runs; locate the step by its name/uses and
change how the reporter input is set (conditional input or separate steps) to
ensure annotations are produced only when PR context supports them.

ℹ️ Review info
Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: ca7950bc-21d4-48dd-92aa-7307e94be8ee

📥 Commits

Reviewing files that changed from the base of the PR and between a834289 and 686bd6c.

📒 Files selected for processing (3)
  • .github/workflows/docs-style-check.yml
  • .github/workflows/pr-builder.yml
  • .github/workflows/pr-label-check.yml

Comment thread .github/workflows/docs-style-check.yml
@codecov

codecov Bot commented Mar 4, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 91.20%. Comparing base (ee7e8c5) to head (c35d1e0).
⚠️ Report is 1 commits behind head on main.

Additional details and impacted files
@@            Coverage Diff             @@
##             main    #1654      +/-   ##
==========================================
+ Coverage   91.18%   91.20%   +0.01%     
==========================================
  Files         715      715              
  Lines       48419    48419              
==========================================
+ Hits        44152    44159       +7     
+ Misses       2841     2835       -6     
+ Partials     1426     1425       -1     
Flag Coverage Δ
backend-integration-postgres 50.18% <ø> (ø)
backend-integration-sqlite 50.16% <ø> (ø)
backend-unit 83.76% <ø> (+0.01%) ⬆️
frontend-apps-develop-unit 97.50% <ø> (+<0.01%) ⬆️
frontend-apps-gate-unit 99.76% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

ThaminduDilshan
ThaminduDilshan previously approved these changes Mar 4, 2026
@DonOmalVindula
DonOmalVindula added this pull request to the merge queue Mar 4, 2026
@DonOmalVindula
DonOmalVindula removed this pull request from the merge queue due to a manual request Mar 4, 2026
ThaminduDilshan
ThaminduDilshan previously approved these changes Mar 4, 2026
@DonOmalVindula
DonOmalVindula enabled auto-merge March 4, 2026 05:02
@DonOmalVindula
DonOmalVindula added this pull request to the merge queue Mar 4, 2026
@senthalan
senthalan removed this pull request from the merge queue due to a manual request Mar 4, 2026
@senthalan
senthalan added this pull request to the merge queue Mar 4, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Mar 4, 2026
@DonOmalVindula
DonOmalVindula enabled auto-merge March 4, 2026 05:20
ThaminduDilshan
ThaminduDilshan previously approved these changes Mar 4, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
.github/workflows/pr-builder.yml (1)

100-116: ⚠️ Potential issue | 🔴 Critical

The dependency-review-action is missing required parameters for merge_group events and will fail.

The dependency-review-action only auto-detects base and head refs on pull_request / pull_request_target events. For merge_group events, you must explicitly pass base-ref and head-ref, or the action will fail with "Both a base ref and head ref must be provided". Additionally, comment-summary-in-pr: always won't work correctly on merge_group since those events don't include full PR context.

🔧 Proposed fix
      - name: 🔎 Dependency Review
        uses: actions/dependency-review-action@v4
        with:
          fail-on-severity: high
          deny-licenses: GPL-3.0-only,GPL-3.0-or-later,AGPL-3.0-only,AGPL-3.0-or-later
+         base-ref: ${{ github.event.merge_group.base_sha || github.event.pull_request.base.sha }}
+         head-ref: ${{ github.event.merge_group.head_sha || github.event.pull_request.head.sha }}
-         comment-summary-in-pr: always
+         comment-summary-in-pr: ${{ github.event_name == 'pull_request' && 'always' || 'never' }}
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In @.github/workflows/pr-builder.yml around lines 100 - 116, The Dependency
Review step using actions/dependency-review-action@v4 fails for merge_group
events because base/head refs and PR context are not auto-detected; update the
"🔎 Dependency Review" step to explicitly supply base-ref and head-ref when
github.event_name == 'merge_group' (e.g., base-ref: ${{
github.event.pull_request.base.ref }} and head-ref: ${{
github.event.pull_request.head.ref }} or equivalent fields from the merge_group
payload) and make comment-summary-in-pr conditional (disable or set to 'never'
for merge_group) so the action has required refs and does not attempt to post a
PR summary when PR context is missing.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Outside diff comments:
In @.github/workflows/pr-builder.yml:
- Around line 100-116: The Dependency Review step using
actions/dependency-review-action@v4 fails for merge_group events because
base/head refs and PR context are not auto-detected; update the "🔎 Dependency
Review" step to explicitly supply base-ref and head-ref when github.event_name
== 'merge_group' (e.g., base-ref: ${{ github.event.pull_request.base.ref }} and
head-ref: ${{ github.event.pull_request.head.ref }} or equivalent fields from
the merge_group payload) and make comment-summary-in-pr conditional (disable or
set to 'never' for merge_group) so the action has required refs and does not
attempt to post a PR summary when PR context is missing.

ℹ️ Review info
Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: b7813212-417a-46bc-9ce3-cde7eca82462

📥 Commits

Reviewing files that changed from the base of the PR and between 686bd6c and 94f5002.

📒 Files selected for processing (3)
  • .github/workflows/docs-style-check.yml
  • .github/workflows/pr-builder.yml
  • .github/workflows/pr-label-check.yml
🚧 Files skipped from review as they are similar to previous changes (1)
  • .github/workflows/pr-label-check.yml

@DonOmalVindula
DonOmalVindula added this pull request to the merge queue Mar 4, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Mar 4, 2026
@DonOmalVindula
DonOmalVindula enabled auto-merge March 4, 2026 05:36

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🧹 Nitpick comments (2)
codecov.yml (1)

61-61: Ensure required coverage checks still match your enforcement intent.

At Line 61 and Line 98, default project/patch statuses are now informational, so they won’t block merges. If coverage must remain enforced, make sure branch protection requires the non-informational flag-specific statuses.

Also applies to: 98-98

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@codecov.yml` at line 61, The codecov.yml currently sets coverage statuses to
non-blocking by using "informational: true" for the project and patch statuses;
either change those flags to "informational: false" in the codecov.yml entries
that define the project and patch status checks (search for the "informational:
true" lines and the surrounding "project" and "patch" status blocks) to make
coverage checks blocking again, or keep them informational and update your
branch protection rules in your repository settings to require the corresponding
Codecov status checks instead.
.github/workflows/pr-builder.yml (1)

134-135: Avoid fail-open behavior when fetching main for Nx base calculation.

Line 135 uses || true, which can mask fetch failures and lead to incorrect affected-range computation.

Proposed adjustment
-      - name: 🔄 Fetch main branch for Nx affected base
-        run: git fetch origin main:main --update-head-ok || true
+      - name: 🔄 Fetch main branch for Nx affected base
+        run: |
+          for i in 1 2 3; do
+            git fetch origin main:main --update-head-ok && exit 0
+            sleep 2
+          done
+          echo "Failed to fetch main after retries."
+          exit 1
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In @.github/workflows/pr-builder.yml around lines 134 - 135, The git fetch
invocation currently uses a fail-open pattern ("git fetch origin main:main
--update-head-ok || true") which can hide failures and produce incorrect Nx
affected-range calculations; update the fetch step used in the workflow by
removing the "|| true" fallback so that the step fails on fetch errors (or
replace it with an explicit retry/exit-on-failure strategy), ensuring the
command referenced ("git fetch origin main:main --update-head-ok") returns a
nonzero exit code on failure and the workflow/job halts so Nx's base calculation
runs against a valid main branch state.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Inline comments:
In @.github/workflows/pr-builder.yml:
- Line 102: The dependency-review-action@v4 step needs explicit base-ref and
head-ref inputs when run by non-pull_request events (like merge_group); update
the "🔎 Dependency Review" step that uses actions/dependency-review-action@v4 to
add with inputs base-ref and head-ref using the merge_group fallback expressions
(use github.event.merge_group.base_sha || github.event.pull_request.base.sha for
base-ref and github.event.merge_group.head_sha ||
github.event.pull_request.head.sha for head-ref) alongside the existing
fail-on-severity, deny-licenses, and comment-summary-in-pr settings so the
action works for both pull_request and merge_group triggers.
- Line 717: The paths-filter@v3 step is missing explicit base/ref inputs needed
for correct detection on merge_group events; update the step's with block for
the paths-filter action (the paths-filter@v3 step) to include base and ref using
the provided conditional expressions so merge_group uses
github.event.merge_group.base_sha and github.sha while pull_request uses
pull_request.base.sha and pull_request.head.sha (i.e., add base: ${{
github.event_name == 'merge_group' && github.event.merge_group.base_sha ||
github.event.pull_request.base.sha }} and ref: ${{ github.event_name ==
'merge_group' && github.sha || github.event.pull_request.head.sha }}).

---

Nitpick comments:
In @.github/workflows/pr-builder.yml:
- Around line 134-135: The git fetch invocation currently uses a fail-open
pattern ("git fetch origin main:main --update-head-ok || true") which can hide
failures and produce incorrect Nx affected-range calculations; update the fetch
step used in the workflow by removing the "|| true" fallback so that the step
fails on fetch errors (or replace it with an explicit retry/exit-on-failure
strategy), ensuring the command referenced ("git fetch origin main:main
--update-head-ok") returns a nonzero exit code on failure and the workflow/job
halts so Nx's base calculation runs against a valid main branch state.

In `@codecov.yml`:
- Line 61: The codecov.yml currently sets coverage statuses to non-blocking by
using "informational: true" for the project and patch statuses; either change
those flags to "informational: false" in the codecov.yml entries that define the
project and patch status checks (search for the "informational: true" lines and
the surrounding "project" and "patch" status blocks) to make coverage checks
blocking again, or keep them informational and update your branch protection
rules in your repository settings to require the corresponding Codecov status
checks instead.

ℹ️ Review info
Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 07ebccc6-9fa9-4edc-a8fe-01b10aa61d23

📥 Commits

Reviewing files that changed from the base of the PR and between 2042d86 and 4365d1d.

📒 Files selected for processing (4)
  • .github/workflows/docs-style-check.yml
  • .github/workflows/pr-builder.yml
  • .github/workflows/pr-label-check.yml
  • codecov.yml
🚧 Files skipped from review as they are similar to previous changes (1)
  • .github/workflows/pr-label-check.yml

Comment thread .github/workflows/pr-builder.yml
Comment thread .github/workflows/pr-builder.yml
ThaminduDilshan
ThaminduDilshan previously approved these changes Mar 4, 2026
@DonOmalVindula
DonOmalVindula added this pull request to the merge queue Mar 4, 2026
brionmario
brionmario previously approved these changes Mar 4, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Mar 4, 2026
@ThaminduDilshan
ThaminduDilshan added this pull request to the merge queue Mar 4, 2026
@DonOmalVindula
DonOmalVindula removed this pull request from the merge queue due to a manual request Mar 4, 2026
@DonOmalVindula
DonOmalVindula enabled auto-merge March 4, 2026 07:20
ThaminduDilshan
ThaminduDilshan previously approved these changes Mar 4, 2026
run: |
cd frontend
pnpm nx affected --target=lint --parallel=3 --base=${{ env.NX_BASE }} --head=${{ env.NX_HEAD }}
pnpm nx affected --target=lint --parallel=3 --base=${{ steps.set-shas.outputs.base }} --head=${{ steps.set-shas.outputs.head }}

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Seems to be an unrelated change but seems like its valid. Lets see if cache is working properly

@DonOmalVindula
DonOmalVindula added this pull request to the merge queue Mar 4, 2026
@DonOmalVindula
DonOmalVindula removed this pull request from the merge queue due to a manual request Mar 4, 2026
@DonOmalVindula
DonOmalVindula enabled auto-merge March 4, 2026 08:03
@DonOmalVindula
DonOmalVindula added this pull request to the merge queue Mar 4, 2026
Merged via the queue into thunder-id:main with commit 21cee21 Mar 4, 2026
23 checks passed
@coderabbitai coderabbitai Bot mentioned this pull request Mar 4, 2026
3 of 12 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

skip-changelog Skip generating changelog for a particular PR

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants