The workflow now triggers on pull_request instead of pull_request_target, which the auto-approve one-pager and the 2026-06-18 CI exposure post-mortem both forbid, and the job skips fork PRs since the read-only token cannot label them. The floor now follows the rubric's author row (Devin-opened low, human-opened medium, fork high) through a new authors.low list, and adds a paths.medium list for agent instruction files, conftest, helm, and docker. Two guards compare both sides of a file through git show: model map rows that change or disappear stop being low, and a budget file that raises a limit stops being low. A skip or importorskip call added to an existing test file with no net new test scores high. The last 400 staging merges score 218 high, 179 medium, 3 low; the author row alone moves 37 human-opened docs and test PRs from low to medium
The workflow now runs on pull_request_target so the base branch's copy of
the script and config scores every PR, forks included, and a PR can no
longer edit the gate that scores it. The PR head is only ever read as a
diff. Forks are passed --from-fork so the author factor is live
The diff parser reads git renames, so a pure move counts zero lines and
both paths take part in the paths and modules factors. The size factor
counts only files outside the docs, tests, and model map tiers, and
.only( joins the silenced-test markers
Config: every pyproject.toml is always-human, the MCP auth, credential,
OAuth, and discovery files are always-human, and the lint budget files
are low. The last 400 staging merges now score 217 high, 139 medium,
44 low
The author factor now only raises a PR to high when it comes from a fork,
so an internal human-opened docs or test-only PR can reach the low tier
the one-pager's tier 0 needs. Over the last 400 staging merges that moves
the low count from 2 to 29 with no reverted merge among them
Skip markers only count when they silence a test unconditionally:
pytest.mark.skipif, unittest.skipIf/skipUnless, a guarded pytest.skip(),
and Playwright's conditional test.skip(cond, reason) no longer rank a PR
high. Test directories anywhere in the tree count as test files, and the
enterprise auth and management endpoint packages join the always-human
paths