The claim anchor for the 37 rolled PRs of .github-private#923 (step 3 of .github-private#913). Each rolled PR carries Claim-issue: bounded-systems/.github#<this> and pr-claim / pr-claim is required org-wide, so this issue must be open and claimed until the last of the 37 merges.
Why here and not on the private issue. pr-claim reads the named issue with the PR repo's own token, so a PR in a public repo can never satisfy it by naming a private repo's issue (.github#358; docs/claim-trailers.md). All 37 targets are public; .github-private#923 is not readable to them, and it is closed anyway. This repo is public, exactly as .github#280 was for the pr-claim roll.
What the rolled file is. A thin caller of _auto-merge.yml (#386/#387): on every non-draft PR, arms auto-merge under the broker-minted pr-arm identity; the repo's required checks remain the only gate.
The 37 — the include list of .github-private org/rulesets/ci-green-standard.json: anchored-chain, anchored-chain-sqlite, audit-context, auth, bd, bounded.tools, cas, cf-oidc-token-broker, deploy, descriptor-kit, desk, disposition, door-net, door-peercred, env, fs, gh, git, git-ast, github-budget, hooksmith, host, installer, lone, machine-schema, mint, policy, proc, repo-root, schema-gen, scout, seam-check, site-mcp, slack, surface-sync, verbspec, verbspec-mcp.
Close when all 37 rolled PRs have merged (or been deliberately declined, named here).
The claim anchor for the 37 rolled PRs of
.github-private#923 (step 3 of.github-private#913). Each rolled PR carriesClaim-issue: bounded-systems/.github#<this>andpr-claim / pr-claimis required org-wide, so this issue must be open and claimed until the last of the 37 merges.Why here and not on the private issue.
pr-claimreads the named issue with the PR repo's own token, so a PR in a public repo can never satisfy it by naming a private repo's issue (.github#358;docs/claim-trailers.md). All 37 targets are public;.github-private#923 is not readable to them, and it is closed anyway. This repo is public, exactly as.github#280 was for the pr-claim roll.What the rolled file is. A thin caller of
_auto-merge.yml(#386/#387): on every non-draft PR, arms auto-merge under the broker-mintedpr-armidentity; the repo's required checks remain the only gate.The 37 — the include list of
.github-privateorg/rulesets/ci-green-standard.json: anchored-chain, anchored-chain-sqlite, audit-context, auth, bd, bounded.tools, cas, cf-oidc-token-broker, deploy, descriptor-kit, desk, disposition, door-net, door-peercred, env, fs, gh, git, git-ast, github-budget, hooksmith, host, installer, lone, machine-schema, mint, policy, proc, repo-root, schema-gen, scout, seam-check, site-mcp, slack, surface-sync, verbspec, verbspec-mcp.Close when all 37 rolled PRs have merged (or been deliberately declined, named here).