Require two human reviewers on bot-authored pull requests - #361
Open
mattdurak wants to merge 1 commit into
Open
Conversation
The agent opens pull requests here, and a bot-authored PR merged on one approval has had only one human look at it. Calls the shared gate in c-build-tools.
|
Azure Pipelines: There may be pipelines that require an authorized user to comment /azp run to run. |
Contributor
Author
|
/azp run Azure-ctest-Gate |
|
Azure Pipelines: Successfully started running 1 pipeline(s). |
mattdurak
enabled auto-merge (squash)
August 3, 2026 21:52
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bot-authored pull requests should not merge on a single approval. On a human-authored PR two people have
looked at the change -- the author who wrote and vetted it, and the approver. When the agent opens the PR
that first human is missing, so one approval is the only human judgement applied to it. This restores the
second.
The logic is a reusable workflow in
Azure/c-build-tools,
so every repository shares one definition and this file stays a thin caller. Nothing about it requires this
repository to consume c-build-tools any other way -- Actions fetches a reusable workflow from the pinned
ref, which is neither a checkout nor a submodule.
What it does:
unaffected.
current head commit. An approval of an earlier commit does not carry over, because the bot pushes to
its own PR.
It reports as a status check but is not required yet. Making it required before this file is on the
default branch would leave every open PR waiting on a check that cannot run, so that is a separate step
after this merges.