Skip to content

Verify environment reviewers during release setup - #31

Merged
samuel-williams-shopify merged 1 commit into
mainfrom
verify-environment-reviewers
Sep 22, 2026
Merged

samuel-williams-shopify merged 1 commit into
mainfrom
verify-environment-reviewers

Conversation

@samuel-williams-shopify

Copy link
Copy Markdown
Contributor

GitHub can accept an environment update while silently dropping Secret reviewer teams. Release setup previously reported success even though the requested publishing approval was not configured.

Plan and apply now reject Secret teams before changing settings, with instructions to make the team Visible. After an environment update, apply reads the settings back and verifies reviewer types/IDs and the preserved protections. Reviewer order and duplicate configured identities do not cause unnecessary updates. A mismatch stops setup and directs the administrator to inspect the environment and rerun plan.

Includes regression tests for dropped or unexpected reviewers, a removed reviewer rule, changed protections, and failed verification reads, plus updated setup guidance and an Unreleased note.

Validation:

  • 159 tests / 567 assertions passed using standard Covered/Sus integration; 530/530 library lines covered.
  • RuboCop passed; documentation coverage is 32/32 definitions.
  • Read-only setup plan against this repository confirms the existing Managers configuration matches.
  • Regenerated distributed guidance with bundle exec ruby -rfileutils -S bake utopia:project:agent:context:update.

@samuel-williams-shopify
samuel-williams-shopify merged commit a3c86ff into main Sep 22, 2026
25 checks passed
@samuel-williams-shopify
samuel-williams-shopify deleted the verify-environment-reviewers branch September 22, 2026 03:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant