Levelrail
Skip to content

glinr-bot ​

A GitHub App that reads a policy file, checks each pull request against it, and says why. In shadow mode it only comments. In enforce mode it can also approve and arm auto-merge, and GitHub still waits for the required checks.

How it works ​

  • Trigger: pull_request_target, so the app secrets are available to Dependabot and same-repo PRs.
  • Safety: the job checks out the base branch only. The policy and the evaluator come from the base, so a PR cannot edit its own rules, and nothing from the PR is built or executed. It reads the PR through the API.
  • Output: one comment per PR, updated in place, with a table of gates.

The policy file ​

.github/glinr-bot.yml:

KeyMeaning
modeshadow comments only, enforce may approve and merge
deny_pathsglobs that always send the PR to a person
block_labelslabels that always send the PR to a person
rules[].authorsexact logins allowed
rules[].paths_onlyevery changed file must match one glob
rules[].max_files, max_changed_linessize limits
rules[].update_typespatch, minor or major, read from "from X to Y" in the title
rules[].title_prefixrequired title start
rules[].actionscomment, approve, automerge

Global gates apply before any rule: not a draft, not from a fork, touches no denied path, no blocking label. The first rule whose gates all pass wins.

Rollout pattern for other repos ​

  1. Install the app on the repo and set the RELEASE_APP_CLIENT_ID variable and RELEASE_APP_PRIVATE_KEY secret.
  2. Copy .github/workflows/glinr-bot.yml, .github/glinr-bot.yml and scripts/glinr-bot/.
  3. Start with mode: shadow and read the comments for a week.
  4. Move the lowest-risk rule to enforce first, for example docs only.

What it does not do ​

It does not review code quality, does not merge past failing required checks, and never acts on a fork or on a path in deny_paths.

Released under the Apache 2.0 License.