Required Checks

Required Status Checks and Required Reviews

A status check is a named pass/fail result attached to a commit, reported by GitHub Actions 29 (Workflow Fundamentals) or by any CI server through the commit statuses API (Jenkins 8,793 , Jenkins). A required_status_checks rule blocks merging until the named checks pass on the pull request's head commit; its strict option also demands that the branch be up to date with main. Sam's second ruleset, require-tests.json, is built like the first, with one rule requiring the context booknest/tests. He creates it, opens the CODEOWNERS pull request, asks for auto-merge (Auto-Merge), and reports the local test result as a status, the way a CI server would:

A second ruleset, a pull request waiting for it, and a status reportShell
gh api repos/{owner}/{repo}/rulesets --input require-tests.json \
  --jq '"ruleset \(.id) \(.name): \(.enforcement)"'
gh pr create --title "Add a CODEOWNERS file" --body-file pr-codeowners.md
gh pr merge --auto --squash
gh pr view --json mergeStateStatus,autoMergeRequest \
  --jq '{state: .mergeStateStatus, auto: .autoMergeRequest.mergeMethod}'
SHA=$(git rev-parse HEAD)
npm test --silent > test.log && STATE=success || STATE=failure
gh api repos/{owner}/{repo}/statuses/$SHA -f state=$STATE -f context=booknest/tests \
  -f description="$(grep -c '^✔' test.log) tests passed" --jq '"\(.context): \(.state)"'
Output
ruleset 23992941 Require tests: active
https://github.com/binarybehemoth/booknest/pull/10
✓ Pull request binarybehemoth/booknest#10 will be automatically merged via squash when all
  requirements
are met
{"auto":"SQUASH","state":"BLOCKED"}
{"message":"Resource not accessible by personal access token",...,"status":"403"}
gh: Resource not accessible by personal access token (HTTP 403)

This time auto-merge waits, because the pull request is BLOCKED until booknest/tests succeeds. The status call failed only because this chapter's token lacks the Commit statuses write permission; Matrices and Caching reports a real check from GitHub Actions.

Required reviews live in the pull_request rule. Sam raised required_approving_review_count in protect-main.json to 1 and sent it with gh 29 api -X PUT repos/{owner}/{repo}/rulesets/23992928. The pull request's reviewDecision became REVIEW_REQUIRED, since its author cannot approve it (Approvals), and gh pr merge 10 --squash refused: "the base branch policy prohibits the merge". Two more options harden review: dismiss_stale_reviews_on_push withdraws approvals when new code arrives, and require_last_push_approval makes someone other than the last pusher approve.