You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Decision packet from the 2026-09-29 audit of the Cursor agent run. Nothing is implemented; the question is the owner's.
What happened
PR #5154's body said "Superseded by #5059 ... Do not merge this draft." app/cursor merged it on 2026-09-28 at 10:42 UTC and it shipped playbooks 0.13.17 (units of #4027). The PR carried no do-not-merge label, and the label is the only thing ci-status reads.
Two audit groups asked for a guard. Playbooks asked ci to make a PR body containing "Do not merge" fail ci-status or auto-apply the label. Claude-config asked source-control to make such a body block the unattended merge lane. The lane side is independent of this question: app/cursor merged #5154, not the babysit lane.
Why this is the owner's decision
docs/conventions/loop-lane/README.md:169-175 says the do-not-merge label is the only cross-lane hold and that prose on a PR is advisory. Each option below either adds a second signal or changes who applies the first.
The pr-contract step that reads the label lives in the ci-status composite of melodic-software/ci-workflows (pinned at 4610c31e, v0.27.1, in .github/workflows/ci.yml), not in this repo. Changing what it reads is a change there plus a repin here.
The phrase is common in legitimate PR bodies. gh pr list --state all --search '"do not merge" in:body' on 2026-09-29, filtered to a literal case-insensitive match:
Anywhere in the body: 63 PRs (22 merged, 39 closed, 2 open).
A body gate would have stopped those seven merges until someone edited the body to release the hold.
Options
(A) Keep the convention. The label stays the only hold and a lane or person that decides not to merge applies it. No change.
(B) ci-status fails while a body line starts with "Do not merge" (case-insensitive) and passes once the line is edited out. Change in ci-workflows pr-contract, a repin here, and line 169 of the loop-lane README updated to name the body line. Releasing a hold then means editing the body.
(D) Instruct the agents that open PRs (root AGENTS.md, and the Cursor agent's own instructions): a PR that is superseded or must not merge gets the label, not prose. No infrastructure; it depends on the agent following it.
Recommendation (a recommendation, not a decision)
D now; revisit B if a second PR merges after saying it must not.
Basis: the counts in item 4 (a body gate changes how seven past holds would have been released) and docs/conventions/loop-lane/README.md:169-175 (the label is already the hold). D is reversible and touches no shared infrastructure; B and C need a change in another repo or a credential.
What would change it: a second such merge, or the owner wanting prose enforced server-side (then B, with the pattern narrowed to a marker the owner picks).
Question for the owner
Which option stands: A, B, C or D? If B, which pattern: any line starting with "Do not merge", or a marker such as an HTML comment that the agents are told to write?
Unblocks
The playbooks and claude-config merge-guard requests recorded on PR #5316, and whether the babysit skill body needs a body-text rule of its own.
Related
Refs #4027 (the change #5154 carried), #4144 (token that re-triggers CI), #4670 (the contract-only ci-status stale-read defect: a change to what pr-contract reads should land with that upstream fix, in the same repo and repin).
Decision packet from the 2026-09-29 audit of the Cursor agent run. Nothing is implemented; the question is the owner's.
What happened
PR #5154's body said "Superseded by #5059 ... Do not merge this draft." app/cursor merged it on 2026-09-28 at 10:42 UTC and it shipped playbooks 0.13.17 (units of #4027). The PR carried no
do-not-mergelabel, and the label is the only thingci-statusreads.Two audit groups asked for a guard. Playbooks asked ci to make a PR body containing "Do not merge" fail
ci-statusor auto-apply the label. Claude-config asked source-control to make such a body block the unattended merge lane. The lane side is independent of this question: app/cursor merged #5154, not the babysit lane.Why this is the owner's decision
docs/conventions/loop-lane/README.md:169-175says thedo-not-mergelabel is the only cross-lane hold and that prose on a PR is advisory. Each option below either adds a second signal or changes who applies the first.The
pr-contractstep that reads the label lives in theci-statuscomposite of melodic-software/ci-workflows (pinned at4610c31e, v0.27.1, in.github/workflows/ci.yml), not in this repo. Changing what it reads is a change there plus a repin here.A workflow in this repo that applies the label with
GITHUB_TOKENdoes not re-runci-status: events triggered by that token create no new workflow runs, exceptworkflow_dispatchandrepository_dispatch(GitHub docs, "Triggering a workflow"; cited in the.github/workflows/dependabot-plugin-release.ymlcomment on PR ci: re-pin gitleaks composite, extend the Windows lane, wire unwired suites #5316, and the same question as ci: every Dependabot PR touching plugins/** fails the changelog-parity bump gate, because Dependabot cannot bump a manifest or write a changelog entry #4144). A token that does re-trigger is a credential only the owner can create.The phrase is common in legitimate PR bodies.
gh pr list --state all --search '"do not merge" in:body'on 2026-09-29, filtered to a literal case-insensitive match:A body gate would have stopped those seven merges until someone edited the body to release the hold.
Options
ci-statusfails while a body line starts with "Do not merge" (case-insensitive) and passes once the line is edited out. Change in ci-workflowspr-contract, a repin here, and line 169 of the loop-lane README updated to name the body line. Releasing a hold then means editing the body.ci-status(operator credential, as in ci: every Dependabot PR touching plugins/** fails the changelog-parity bump gate, because Dependabot cannot bump a manifest or write a changelog entry #4144 option B). WithGITHUB_TOKENthe label lands andci-statusstays green.AGENTS.md, and the Cursor agent's own instructions): a PR that is superseded or must not merge gets the label, not prose. No infrastructure; it depends on the agent following it.Recommendation (a recommendation, not a decision)
D now; revisit B if a second PR merges after saying it must not.
Basis: the counts in item 4 (a body gate changes how seven past holds would have been released) and
docs/conventions/loop-lane/README.md:169-175(the label is already the hold). D is reversible and touches no shared infrastructure; B and C need a change in another repo or a credential.What would change it: a second such merge, or the owner wanting prose enforced server-side (then B, with the pattern narrowed to a marker the owner picks).
Question for the owner
Which option stands: A, B, C or D? If B, which pattern: any line starting with "Do not merge", or a marker such as an HTML comment that the agents are told to write?
Unblocks
The playbooks and claude-config merge-guard requests recorded on PR #5316, and whether the babysit skill body needs a body-text rule of its own.
Related
Refs #4027 (the change #5154 carried), #4144 (token that re-triggers CI), #4670 (the contract-only
ci-statusstale-read defect: a change to whatpr-contractreads should land with that upstream fix, in the same repo and repin).