Repository navigation
ci: trunk guard — only trunk may merge into main - #1933
khaliqgant wants to merge 2 commits into
Conversation
Brings relay in line with the org policy already live in agentrelay.com, cloud, relayfile, relayfile-cloud, relaycast and relay-desktop (agentrelay.com#182): feature branches merge into `trunk`, and only the trunk -> main PR targets main. This is the guard half only. relay has 19 workflows triggered on pull_request with heterogeneous filters, so restricting CI to the trunk -> main PR is a separate per-workflow decision for the policy owner — see the PR body. Approved by Khaliq. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Note Currently processing new changes in this PR. This may take a few minutes, please wait... ⚙️ Run configuration
📒 Files selected for processing (1)
📝 WalkthroughWalkthroughAdds a GitHub Actions workflow for pull requests targeting ChangesTrunk guard
Priority: ➖ Normal Estimated code review effort: 1 (Trivial) | ~4 minutes Change: Feature Merge Risk: ⚪ Minimal · up to The guard fails non-trunk pull requests to 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. A rabbit checks the branch at dawn, Comment |
There was a problem hiding this comment.
Devin Review found 1 potential issue.
1 flag not posted on this PR by your GitHub settings — view it in Devin Review. (Configure)
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 6651d1c71a
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
🔇 Additional comments (1)
.github/workflows/trunk-guard.yml-9-12 (1)
9-12: 🔒 Security & Privacy | 🟡 Minor | ⚡ Quick win
⚠️ Unverified finding
Verification ran but could not confirm this finding. It is shown for review, not as a verified issue.Add an explicit
permissionsblock to the workflow.The workflow has no
permissions:block, so the job uses the defaultGITHUB_TOKENscopes. The job only runsechoandexit 1. It needs no token access. Setpermissions: {}to apply least privilege and clear the zizmorexcessive-permissionswarning.🔒️ Proposed fix
jobs: only-trunk-merges-to-main: if: github.head_ref != 'trunk' runs-on: ubuntu-latest + permissions: {} timeout-minutes: 1As per the retrieved learning: apply least privilege and default
permissionsto the minimum scopes required. The PR states the file is byte-identical to relayfile-cloud, so consider applying the same fix there.Sources: Learnings, Linters/SAST tools
ℹ️ Review info
⚙️ Run configuration
- Configuration used: Organization UI
- Review profile: CHILL
- Plan: Advanced
- Run ID:
1984965c-0fcf-460f-91b7-b009579bc74e
📒 Files selected for processing (1)
.github/workflows/trunk-guard.yml
Included review availability: This review used your included allowance. Your plan provides up to 4 included reviews per hour; 3 remain after this review.
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 6651d1c. Configure here.
Devin, Codex and Cursor Bugbot all flagged the same hole: github.head_ref is only the branch NAME, with no repository identity, so a pull request from a fork whose head branch is also called `trunk` skipped the job and passed the guard without its commits ever going through this repo's protected trunk. Require github.event.pull_request.head.repo.full_name == github.repository as well as the branch name. NOTE: the same hole exists in the guard already merged in agentrelay.com, cloud, relayfile, relayfile-cloud, relaycast and relay-desktop, which this file was copied from. Flagged to the policy owner for the same fix. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Fixed in The job condition now requires both: if: >-
github.event.pull_request.head.repo.full_name != github.repository
|| github.head_ref != 'trunk'so the guard runs (and fails) for any fork PR regardless of branch name, and only a same-repo This matters beyond this PR: the file was copied verbatim from relayfile-cloud, so the identical hole is already merged and live in agentrelay.com, cloud, relayfile, relayfile-cloud, relaycast and relay-desktop. Each needs the same two-line fix. Flagged to the policy owner (agentrelay.com#182) rather than fixed piecemeal here. Reminder for reviewers: this PR's own |
|
Closing as superseded — and the version that landed is better than mine. While this was open, #1932 merged
It also restricted CI across all 19 pull_request-triggered workflows, which I had deliberately left out of this PR as a judgement call for the policy owner. That decision has now been made in code. The one thing worth carrying forward: the fork bypass I fixed here still exists in the guard merged in agentrelay.com, cloud, relayfile, relayfile-cloud, relaycast and relay-desktop, which relay's original copy came from. Those six still compare |

Brings relay in line with the org trunk policy (agentrelay.com#182), already live in agentrelay.com, cloud, relayfile, relayfile-cloud, relaycast and relay-desktop. relay already has a
trunkbranch but no guard, so it was the last repo still taking feature PRs straight into main.Approved by Khaliq, who chose adopting the policy here over re-running the 61 CI checks that the 22:13Z org queue clear cancelled on #1930.
What this does
Ports
.github/workflows/trunk-guard.ymlverbatim from relayfile-cloud: any PR intomainwhose head is nottrunkfails the check.What this deliberately does NOT do
relayfile-cloud also restricted CI to the trunk → main PR (
de298c0), which was a one-line change because it has a singleci.ymljob. relay has 19 workflows triggered onpull_requestwith heterogeneous filters, and they do not take one uniform edit:pull_request: branches: [main], so a trunk-based PR skips them:node-compat,package-validationpull_request, so they would still run on feature → trunk PRs:large-files,rust-ci,test, plus path-filteredcodegen-models,relay-evalsprettier-fmt-fix,rust-fmt-fix— restricting these to trunk changes developer-facing behaviourpull_request_targetwith path filters:relayflow-pr-proof-brokerpull_request: types: [closed]:cancel-on-mergeDeciding which of those should stop running on feature PRs belongs to the policy owner, not this PR. Filed as a follow-up for @claude-agentrelay-com-efef42 (agentrelay.com lead). The guard is independently useful and safe to land first.
Verification
No code paths touched; the workflow is byte-identical to relayfile-cloud's apart from one comment line. It will self-demonstrate: this PR's own head is not
trunk, so Trunk guard is expected to FAIL here — that failing check is the proof it works. Merge it from main with that check red, or retarget via trunk once relay's merge train is set up.🤖 Generated with Claude Code
Note
Low Risk
Adds CI-only branch policy enforcement with no application or runtime code changes.
Overview
Adds a Trunk guard GitHub Actions workflow that runs on every pull request targeting
mainand fails unless the PR head is thetrunkbranch from this repository.The job uses a combined check on
github.head_refandgithub.event.pull_request.head.repo.full_nameso a fork branch also namedtrunkcannot bypass the rule. On violation it emits a workflow error telling contributors to retarget the PR totrunk.Reviewed by Cursor Bugbot for commit a6d6fc8. Bugbot is set up for automated code reviews on this repo. Configure here.
Agent Relay sessions
claudesession03e53226· opened viagh pr create· last active 2026-10-08