github / github/docs

Rulesets docs don't disclose that bypass_actors is not honored by auto-merge completion

未關閉 適合新手
#45,265 2 則留言 1 個 reaction 已指派 0 人 在 GitHub 檢視
content needs SME repositories
主要語言
TypeScript
星號
20.8k
分支
68.7k
平均合併
13 小時 10 分鐘
30 天內合併 PR
111

描述

### Page(s) affected

- https://docs.github.com/en/repositories/configuring-branches-and-merges-in-your-repository/managing-rulesets/creating-rulesets-for-a-repository
- https://docs.github.com/en/repositories/configuring-branches-and-merges-in-your-repository/managing-rulesets/available-rules-for-rulesets (bypass list / pull request rule sections)

### What's wrong

The Rulesets documentation describes `bypass_actors` (a Team, Role, GitHub App/Integration, etc. added to a ruleset's bypass list) as being able to bypass a rule such as "Require a pull request before merging" / "Require review from Code Owners". It does not document an important limitation we've confirmed by testing: **the bypass grant is only honored by a synchronous, direct merge call — it is not consulted by GitHub's async auto-merge completion process (`gh pr merge --auto`, `enablePullRequestAutoMerge`, or the "Merge when ready" UI button).**

### Repro / evidence

- Ruleset: `pull_request` rule, `require_code_owner_review: true`, `required_approving_review_count: 1`, with a GitHub App added to `bypass_actors` (`Integration` type; tested both `bypass_mode: "always"` and `"pull_request"`).
- A PR approved by the bypass-listed actor with auto-merge enabled (`gh pr merge --auto --squash`) stayed `mergeStateStatus: BLOCKED` / `reviewDecision: REVIEW_REQUIRED` indefinitely — confirmed via a clean 10-minute poll (every 20s, 30/30 polls) with a fresh trigger event and zero manual intervention.
- The same PR, same bypass-eligible actor, merged **instantly** when calling the merge endpoint directly instead:
```
gh api repos/OWNER/REPO/pulls/N/merge -X PUT -f merge_method=squash
```

So the bypass mechanism works, but only for one of the two documented ways to merge a PR, and the docs don't call this out anywhere.

### What we'd like to see

A note on the bypass_actors / rules pages clarifying that bypass grants are not currently honored by auto-merge completion, and that automation relying on bypass should call the merge endpoint directly rather than enabling auto-merge, until/unless this is fixed at the platform level.

### Related reports (same underlying platform behavior, not a docs-only issue)

- https://github.com/orgs/community/discussions/162623
- https://github.com/orgs/community/discussions/190610
- https://github.com/orgs/community/discussions/113172
- https://github.com/orgs/community/discussions/167357
- https://github.com/orgs/community/discussions/136531
- https://github.com/cli/cli/issues/13388
- https://github.com/cli/cli/issues/13458

貢獻指南

開啟貢獻指南

研究方向

從受影響的兩個 Rulesets 頁面開始:「Creating rulesets for a repository」和「Available rules for rulesets」,尤其是 bypass 清單和提取要求規則區段。檢視回報的 auto-merge 行為,並新增一則清楚的限制說明,涵蓋 bypass_actors 和 auto-merge 完成;當兩個相關頁面都準確說明此行為時,該 issue 即完成。

由索引模型根據 Issue 內容生成。

評估

技術堆疊
github
領域
documentation
Issue 類型
文件
難度
2/5
預估耗時
1-3 小時
活躍度
冷清
描述清晰度
描述清楚
新手友好度
76/100

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。