Source: MIZOKI audit 2026-09-06 (pinned fc8b03f9) → work-order backlog 2026-09-08 (docs/audits/AUDIT_WORK_ORDERS_2026-09-08.md). Findings are hypotheses until reproduced on current main (WO-00).

Finding: main unprotected (rulesets API 403, plan-related); auto-merge reruns gates on merge result but the push-retry path can rebase after the check [R0][R26]. Several MCP/spec/origin suites absent from CI wiring. Files: .github/workflows/auto-merge-ai-branches.yml, auto-merge-grothendieck.yml, auto-merge-mcclintock.yml, auto-sync-main.yml, ci.yaml. Fix: retry path re-runs gates on the rebased SHA or fails; required checks at repo level (branch protection if rulesets unavailable on plan); map every required suite to a CI job. Acceptance: simulated rebase-after-check → merge blocked; required-checks list committed and enforced. Depends on: WO-00.

← All docsView source on GitHub →