Skip to content

Rulesets docs don't disclose that bypass_actors is not honored by auto-merge completion #45265

Description

@jgsuess

Page(s) affected

What's wrong

The Rulesets documentation describes bypass_actors (a Team, Role, GitHub App/Integration, etc. added to a ruleset's bypass list) as being able to bypass a rule such as "Require a pull request before merging" / "Require review from Code Owners". It does not document an important limitation we've confirmed by testing: the bypass grant is only honored by a synchronous, direct merge call — it is not consulted by GitHub's async auto-merge completion process (gh pr merge --auto, enablePullRequestAutoMerge, or the "Merge when ready" UI button).

Repro / evidence

  • Ruleset: pull_request rule, require_code_owner_review: true, required_approving_review_count: 1, with a GitHub App added to bypass_actors (Integration type; tested both bypass_mode: "always" and "pull_request").
  • A PR approved by the bypass-listed actor with auto-merge enabled (gh pr merge --auto --squash) stayed mergeStateStatus: BLOCKED / reviewDecision: REVIEW_REQUIRED indefinitely — confirmed via a clean 10-minute poll (every 20s, 30/30 polls) with a fresh trigger event and zero manual intervention.
  • The same PR, same bypass-eligible actor, merged instantly when calling the merge endpoint directly instead:
    gh api repos/OWNER/REPO/pulls/N/merge -X PUT -f merge_method=squash
    

So the bypass mechanism works, but only for one of the two documented ways to merge a PR, and the docs don't call this out anywhere.

What we'd like to see

A note on the bypass_actors / rules pages clarifying that bypass grants are not currently honored by auto-merge completion, and that automation relying on bypass should call the merge endpoint directly rather than enabling auto-merge, until/unless this is fixed at the platform level.

Related reports (same underlying platform behavior, not a docs-only issue)

Metadata

Metadata

Assignees

No one assigned

    Labels

    triageDo not begin working on this issue until triaged by the team

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions