Pre-launch — Gluecron is in final validation. Public signups and git hosting for non-owner users open after launch review.
CodeIssuesPull RequestsActionsSecurityInsightsSettings
✨ AI
More
claude/adoring-hopper-5x74bqclaude/affectionate-feynman-ykrf1hclaude/architecture-audit-design-wxprenclaude/build-status-update-3MXsfclaude/charming-meitner-mllb5rclaude/compare-gate-gluecron-s4mFQclaude/confident-faraday-tikcwbclaude/continue-work-XMTlIclaude/crontech-gluecron-deploy-7MIECclaude/crontech-platform-setup-SeKfwclaude/design-2026claude/ecstatic-ptolemy-jMdigclaude/enhance-github-integration-QNHdGclaude/fix-aa-loop-issue-PonMQclaude/fix-actions-and-processclaude/fix-desktop-errors-XqoW8claude/fix-red-workflowsclaude/fix-website-access-6FKJNclaude/gatetest-integration-hardeningclaude/github-audit-improvements-bDFr9claude/gluecron-launch-status-FoMRlclaude/hopeful-lamport-olfCTclaude/issue-to-pr-and-protectionsclaude/jolly-heisenberg-2sg1Qclaude/launch-preparation-QmTb6claude/new-session-xk1l7claude/plan-platform-architecture-kkN4yclaude/platform-analysis-roadmap-1nUGLclaude/platform-launch-assessment-8dWV8claude/polish-platform-release-AeDrUclaude/resume-previous-work-KzyLwclaude/review-crontech-handoff-qYEVqclaude/review-project-completeness-lHhS2claude/review-readme-docs-ulqPKclaude/serene-edison-rj87weclaude/setup-multi-repo-dev-BCwNQclaude/ship-fixes-and-tests-Jvz1cclaude/site-audit-competitive-pctlwgclaude/site-migration-vercel-XstpKclaude/standalone-product-repos-XHFTDcopilot/feat-smart-empty-states-keyboard-first-enhancementcopilot/feat-smart-morning-digest-review-context-restorecopilot/fix-and-process-workflowscopilot/update-ai-powered-code-reviewfeat/debt-mapfeat/push-policy-codeowners-hardeningfeat/smart-digest-contextfeat/stage-impactfeat/t1-secret-migrationfeat/u-polishfeat/w-self-hostfeat/w2-claude-configfix/agent-journey-orphan-sweepgatetest/auto-fix-1776586424172gatetest/auto-fix-1776586534814gatetest/auto-fix-1776590685143gatetest/auto-fix-1776590808199mainops/redeploy-retriggerstyle/dxt-cta-themeworktree-agent-a3377aad30d55da26worktree-agent-a7ef607b7ee1d6c74
gate.ts5.1 KB · 184 lines
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
/**
 * Green gate enforcement.
 *
 * Checks that all quality gates pass before a merge is allowed:
 * 1. GateTest scan — runs automated tests/checks via the GateTest API
 * 2. AI code review — must be approved (no blocking issues)
 *
 * Nothing ships unless everything is green.
 */

import { config } from "./config";

export interface GateCheckResult {
  name: string;
  passed: boolean;
  details: string;
}

export interface GateResult {
  allPassed: boolean;
  checks: GateCheckResult[];
}

/**
 * Run GateTest scan on a repository at a specific ref.
 * Returns pass/fail with details.
 */
export async function runGateTestScan(
  owner: string,
  repo: string,
  ref: string,
  headSha: string
): Promise<GateCheckResult> {
  if (!config.gatetestUrl) {
    return { name: "GateTest", passed: true, details: "GateTest URL not configured — skipped" };
  }

  try {
    const headers: Record<string, string> = {
      "Content-Type": "application/json",
    };
    if (config.gatetestApiKey) {
      headers["Authorization"] = `Bearer ${config.gatetestApiKey}`;
    }

    const response = await fetch(config.gatetestUrl, {
      method: "POST",
      headers,
      body: JSON.stringify({
        repository: `${owner}/${repo}`,
        ref,
        sha: headSha,
        source: "gluecron",
        mode: "blocking", // Wait for results instead of fire-and-forget
      }),
    });

    if (!response.ok) {
      const body = await response.text().catch(() => "");
      return {
        name: "GateTest",
        passed: false,
        details: `GateTest returned ${response.status}: ${body.slice(0, 200)}`,
      };
    }

    const result = await response.json().catch(() => ({})) as Record<string, unknown>;

    // GateTest API returns { passed: boolean, summary: string, issues: [...] }
    const passed = result.passed === true || result.status === "passed" || result.status === "success";
    const summary = (result.summary as string) || (result.message as string) || (passed ? "All checks passed" : "Checks failed");

    return {
      name: "GateTest",
      passed,
      details: summary,
    };
  } catch (err) {
    console.error("[gate] GateTest scan error:", err);
    return {
      name: "GateTest",
      passed: false,
      details: `GateTest scan failed: ${err instanceof Error ? err.message : "Unknown error"}`,
    };
  }
}

/**
 * Check for merge conflicts between branches.
 */
export async function checkMergeability(
  owner: string,
  repo: string,
  baseBranch: string,
  headBranch: string
): Promise<GateCheckResult> {
  const { getRepoPath } = await import("../git/repository");
  const repoDir = getRepoPath(owner, repo);

  const proc = Bun.spawn(
    ["git", "merge-tree", `$(git merge-base ${baseBranch} ${headBranch})`, baseBranch, headBranch],
    { cwd: repoDir, stdout: "pipe", stderr: "pipe" }
  );
  // merge-tree isn't ideal — use merge --no-commit in a worktree style check
  await proc.exited;

  // Simpler: check if merge-base --is-ancestor works (fast-forward possible)
  const ffCheck = Bun.spawn(
    ["git", "merge-base", "--is-ancestor", baseBranch, headBranch],
    { cwd: repoDir, stdout: "pipe", stderr: "pipe" }
  );
  const ffExit = await ffCheck.exited;

  if (ffExit === 0) {
    return { name: "Merge check", passed: true, details: "Fast-forward merge possible" };
  }

  // Check if there would be conflicts
  const mergeBase = Bun.spawn(
    ["git", "merge-base", baseBranch, headBranch],
    { cwd: repoDir, stdout: "pipe", stderr: "pipe" }
  );
  const baseOut = await new Response(mergeBase.stdout).text();
  const baseExit = await mergeBase.exited;

  if (baseExit !== 0) {
    return { name: "Merge check", passed: false, details: "Branches have no common ancestor" };
  }

  // Use merge-tree (three-way) to detect conflicts without touching working tree
  const mergeTree = Bun.spawn(
    ["git", "merge-tree", baseOut.trim(), baseBranch, headBranch],
    { cwd: repoDir, stdout: "pipe", stderr: "pipe" }
  );
  const treeOut = await new Response(mergeTree.stdout).text();
  await mergeTree.exited;

  const hasConflicts = treeOut.includes("<<<<<<<");

  return {
    name: "Merge check",
    passed: !hasConflicts,
    details: hasConflicts
      ? "Merge conflicts detected — auto-resolution will be attempted"
      : "Clean merge possible",
  };
}

/**
 * Run all gate checks for a PR merge.
 */
export async function runAllGateChecks(
  owner: string,
  repo: string,
  baseBranch: string,
  headBranch: string,
  headSha: string,
  aiReviewApproved: boolean
): Promise<GateResult> {
  const checks: GateCheckResult[] = [];

  // Run GateTest and mergeability check in parallel
  const [gateTestResult, mergeResult] = await Promise.all([
    runGateTestScan(owner, repo, `refs/heads/${headBranch}`, headSha),
    checkMergeability(owner, repo, baseBranch, headBranch),
  ]);

  checks.push(gateTestResult);
  checks.push(mergeResult);

  // AI review check
  checks.push({
    name: "AI Review",
    passed: aiReviewApproved,
    details: aiReviewApproved
      ? "AI review approved"
      : "AI review found blocking issues — resolve before merging",
  });

  return {
    allPassed: checks.every((c) => c.passed),
    checks,
  };
}