Approval permits release despite a failed checkout test
The demonstrated gate promotes a change with a known failed checkout check. Approval alone provides no assurance that required behaviours passed.
- Observed finding
- The approval-only gate accepts a candidate even though its checkout test failed. The fixed gate checks required successful results for the exact candidate and blocks it.
- Recommended fix
- Protect the buying journey. Require named checks for the exact commit at the release boundary, treat missing or unsuccessful results as blocking and control exceptions explicitly.
- Verification and follow-up checks
- Attempt promotion with a failed, missing, pending or wrong-commit check. Each must be blocked. A fully successful control passes; verify the actual CI and deployment permissions separately.
Before the fix
Candidate with failed checkout check: promoted.
After the fix
Candidate with failed checkout check: blocked.