What the gate does today
Pull requests run:
buf breaking --against ".git#branch=origin/$BASE_REF"
This correctly answers whether the PR is compatible with the branch it is being merged into.
On a push to main, the check skips because there is no meaningful base-branch comparison to perform.
The evidence files are regenerated by CI using the same script, so committed evidence cannot silently become stale.
That part is working as intended.
What it does not cover
The current check answers:
"Is this PR compatible with the branch it is merging into?"
It does not answer:
"Is main still compatible with the version consumers are actually running?"
Those two questions can diverge.
Examples include:
- a PR based on stale
main
- rewritten history
- a long sequence of individually compatible changes
- consumers still built against a release tag from months earlier
For a contracts repository, compatibility with the deployed or released baseline is the question consumers ultimately care about.
Acceptance criteria
Why both checks matter
The two checks answer different questions.
The base-branch comparison asks whether the current PR introduces a regression relative to its merge target.
The release-tag comparison asks whether the repository has drifted away from the contract that deployed consumers actually built against.
They are complementary, not redundant.
What the gate does today
Pull requests run:
buf breaking --against ".git#branch=origin/$BASE_REF"This correctly answers whether the PR is compatible with the branch it is being merged into.
On a push to
main, the check skips because there is no meaningful base-branch comparison to perform.The evidence files are regenerated by CI using the same script, so committed evidence cannot silently become stale.
That part is working as intended.
What it does not cover
The current check answers:
"Is this PR compatible with the branch it is merging into?"
It does not answer:
"Is main still compatible with the version consumers are actually running?"
Those two questions can diverge.
Examples include:
mainFor a contracts repository, compatibility with the deployed or released baseline is the question consumers ultimately care about.
Acceptance criteria
v1.0.0.buf breakinginvocation comparing against that release.mainas well.scripts/demonstrate-gate.shto demonstrate the release-tag comparison.Why both checks matter
The two checks answer different questions.
The base-branch comparison asks whether the current PR introduces a regression relative to its merge target.
The release-tag comparison asks whether the repository has drifted away from the contract that deployed consumers actually built against.
They are complementary, not redundant.