Guard flow integration lifecycle - #46
Merged
Merged
Conversation
xormania
marked this pull request as ready for review
August 3, 2026 04:26
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
flowprogram topology with exactgroup/<group>and matchingslice/group/<group>/<slice>routesflowtodevmerge human-ownedflowbootstrap event,Required gates, and CodeQLWhy
The existing rails covered ordinary and legacy workstream development but could not safely express a long-running program integration branch. R0 establishes that delivery path before
flowexists, without makingflowauthoritative overdevor granting agents direct integration authority.Security and behavior impact
Required evidence now fails closed when a worker is missing, skipped, cancelled, stale, misclassified, or infrastructure-uncertain. The verified helper binds operations to the expected repository, exact PR head and base, approval, ancestry, and successful
Required gatesplus CodeQL results. Program synchronization uses merge commits so earlier review and test evidence remains reachable.Serena remains advisory and no-network. Its project config selects the preseeded Bash Language Server 5.6.0 and gives agents bounded host-side workflow orientation; extensionless Bash remains on the ordinary-tool path.
Validation
./scripts/dev/check default quick— 33 passed, 0 failed, 0 skipped, 0 infrastructure errors./tools/validate.sh --strict— passed./scripts/dev/docker-gate— 8 passed, 0 failed, 0 skipped, 0 infrastructure errors./scripts/dev/serena-smoke— Codex, Claude, and Grok activation and semantic smoke passed./scripts/dev/lint-scriptsandgit diff --check— passedHuman follow-up after merge
Create literal
flowat the exact R0-updateddevcommit, then install hosted rulesets requiring current-headCI / Required gatesand CodeQL, current-base testing or a merge queue, latest-head approval, merge commits, and no force push, deletion, or automatic program-branch deletion.