Skip to content

Rulesets docs don't disclose that bypass_actors is not honored by auto-merge completion #45265

Description

@jgsuess

Page(s) affected

What's wrong

The Rulesets documentation describes bypass_actors (a Team, Role, GitHub App/Integration, etc. added to a ruleset's bypass list) as being able to bypass a rule such as "Require a pull request before merging" / "Require review from Code Owners". It does not document an important limitation we've confirmed by testing: the bypass grant is only honored by a synchronous, direct merge call — it is not consulted by GitHub's async auto-merge completion process (gh pr merge --auto, enablePullRequestAutoMerge, or the "Merge when ready" UI button).

Repro / evidence

  • Ruleset: pull_request rule, require_code_owner_review: true, required_approving_review_count: 1, with a GitHub App added to bypass_actors (Integration type; tested both bypass_mode: "always" and "pull_request").
  • A PR approved by the bypass-listed actor with auto-merge enabled (gh pr merge --auto --squash) stayed mergeStateStatus: BLOCKED / reviewDecision: REVIEW_REQUIRED indefinitely — confirmed via a clean 10-minute poll (every 20s, 30/30 polls) with a fresh trigger event and zero manual intervention.
  • The same PR, same bypass-eligible actor, merged instantly when calling the merge endpoint directly instead:
    gh api repos/OWNER/REPO/pulls/N/merge -X PUT -f merge_method=squash
    

So the bypass mechanism works, but only for one of the two documented ways to merge a PR, and the docs don't call this out anywhere.

What we'd like to see

A note on the bypass_actors / rules pages clarifying that bypass grants are not currently honored by auto-merge completion, and that automation relying on bypass should call the merge endpoint directly rather than enabling auto-merge, until/unless this is fixed at the platform level.

Related reports (same underlying platform behavior, not a docs-only issue)

Metadata

Metadata

Assignees

No one assigned

    Labels

    contentThis issue or pull request belongs to the Docs Content teamneeds SMEThis proposal needs review from a subject matter expertrepositoriesContent related to repositories

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions