kendex.ai

Marketplaces / vanillagreencom/kendex / review-gate

review-gate

Load to watch pull requests, report the organization standard, or adopt consumer refresh.

skill · review · @ 8ee7099

Supported tools: all tools

Install in kendex: kendex add --skill review-gate after subscribing to vanillagreencom/kendex.

Review operations

GitHub rulesets enforce approvals, stale-approval dismissal and review-thread resolution. This package watches pull requests, reports repository configuration and refreshes consumer installs. It posts no review status.

Watching pull requests

Run scripts/pr-watch.sh through the harness's wake-up mechanism. Read its attention lines rather than watching review-state transitions. Output and exit codes: pr-watch.sh --help.

Organization standard

Run scripts/validate-standard.sh for a read-only report. Run scripts/provision-environment.sh --org ORG from the organization owner's machine to provision app-secret environments, adding --repo ORG/NAME to provision one repository. Settings and repository wiring: references/adoption.md.

Consumer refresh

An existing consumer first follows references/adoption.md § Trusted removal for an existing consumer. Automatic refresh runs only after that normally reviewed removal merges. Fresh installs run refresh/adopt-refresh.sh from a kendex checkout at a release tag. Each consumer calls the shared workflow, which runs its scripts from that release checkout. Environment and token requirements: references/adoption.md § Automatic consumer refresh.

4. Operations

A pull request with no automatic review needs a Copilot request. When orch is present, request through its mode owner, approval-wait <PR#> --request-review --base-checkout PATH, per orch's references/gates.md § Copilot requests, which routes its off and fallback answers. Without orch, request directly: gh pr edit <PR#> --add-reviewer @copilot. Ruleset targeting and request failures: references/automatic-review.md.

The overseer's fallback approval and emergency merge follow the managing repository's merge workflow. This package grants no bypass and changes no ruleset.

Scripts

ScriptPurpose
scripts/pr-watch.shReduce open pull requests to attention lines from GitHub's review state.
scripts/validate-standard.shReport rulesets, required checks, app installation and secret placement.
scripts/provision-environment.shProvision the organization's declared app-secret environment.
refresh/adopt-refresh.sh in the release checkoutAdopt the refresh workflow. --retire-writer opts into trusted retirement.
scripts/install-latest.shInstall the latest stable release for kendex CI and the retained writer template.
refresh/refresh-consumer.sh in the release checkoutRebuild the rolling refresh branch from the default branch and open or update its pull request at any measured class. Run the classifier from the same release checkout. Refuse held render edits before workflow adoption or publication. Preserve workflow edits under the adoption contract. Wait for GitHub to show the published head before arming app-token auto-merge. A head that stays unseen produces an unarmed warning. Confirm that the arm enabled auto-merge, queued or merged the pull request. The merge queue merges it once the required approval, thread resolution and checks pass. The body names the class, classifier cause and path. An unmeasured class stops publication.
refresh/refresh-reviews.sh in the release checkoutHandle automatic review findings under the thread-resolution rules.
refresh/dispatch-refresh.sh in the catalog checkoutSignal consumers visible to the catalog app installation.

Reviewer routing for installed packages: references/vendored-paths.md.