ci: reserve ci/ statuses; trusted reuse; required contexts !482

merged merged by cmc on 2026-09-28 22:33 UTC · krz/gitbay:ci-status-trust into main

Discussion

cmc

Statuses that gate merges belong to the build subsystem, and results are reused only within one trust domain.

  • status set refuses ci/ contexts (case-insensitive, exit 4); the runner writes them directly.
  • Tree reuse and same-commit dedupe count only trusted builds, and tree reuse keys on the job's declared image. A fork's green build no longer stands for the same commit on a branch. A job naming no image matches only builds that named none; the CI page gives the remedies.
  • repo settings require-contexts <owner/name> [<ctx>...]: a non-empty list turns require-checks on; an empty list clears it and leaves require-checks as it was. A required context that has not reported counts as pending (<ctx>=missing, checks_missing in --json). Shown on repo settings show, the settings page and the MR page.
  • API, CI, Users, Parity and Architecture pages; #258 leaves Known-Gaps. CHANGELOG * Unreleased carries #255 and #258.

Stacked on !479 (ci-untrusted-home); merge that first.

Closes #258