Mergify Merge Protections
Merge protections control when PRs are allowed to merge:
Depends-On and Merge-After are built-in — just add the header to the PR description (or commit message body when using mergify stack push) and Mergify enforces them automatically, no .mergify.yml configuration needed. Freezes are managed via CLI commands.
Depends-On
Block a PR from merging until one or more other PRs are merged first.
Syntax
Add one or more Depends-On: lines to the PR body:
All three formats are supported — use #NNN for same-repo, full URL or org/repo#NNN for cross-repo.
Rules
- All referenced PRs must be in repositories with Mergify enabled
- All referenced PRs must belong to the same GitHub organization
- Circular dependencies and self-references are silently ignored
- Multiple
Depends-On:lines are allowed (one per line)
With mergify stack push
The stack tool automatically adds Depends-On: #NNN between consecutive PRs in a stack. For dependencies outside the stack (cross-repo or unrelated PRs), add the header manually to the commit message body — it will be copied to the PR description on push.
When to suggest
- Feature spanning multiple repos (e.g., API change + client update)
- Schema migration must merge before application code
- Shared library update must land before consumers
Merge-After
Postpone merging until a specified date and time.
Syntax
Add a Merge-After: line to the PR body:
Supported timestamp formats (ISO 8601)
If no timezone is specified, UTC is assumed.
When to suggest
- Coordinated release: multiple PRs should merge together at a specific time
- Merge during a maintenance window or off-peak hours
- Embargo: PR is ready but should not ship before a date
Combining Depends-On and Merge-After
Both headers can be used together on the same PR:
The PR will not merge until PR #42 in billing-service is merged and the specified time has passed.
Scheduled Freezes
Scheduled freezes temporarily halt merging of pull requests matching specific conditions. Use them for deployment windows, incident response, maintenance periods, or any situation where merges should be paused.
Commands
Authentication
All commands require a Mergify credential. Run mergify auth login once, or:
--token/-t(env:MERGIFY_TOKEN) -- Mergify credential. Falls back to the credentialmergify auth loginstored, then toGITHUB_TOKEN/gh auth token, both deprecated for the Mergify API.--repository/-r-- Repository full name (auto-detected from git remote)--api-url/-u(env:MERGIFY_API_URL) -- Mergify API URL (default:https://api.mergify.com)
Creating a Freeze
Required options:
--reason-- Human-readable reason for the freeze--timezone-- IANA timezone name (e.g.,Europe/Paris,US/Eastern,UTC)
Optional options:
--start-- Start time in ISO 8601 format (default: now)--end-- End time in ISO 8601 format (default: no end, emergency freeze)--condition/-c-- Matching condition (repeatable, e.g.,-c 'base=main')--exclude/-e-- Exclude condition (repeatable, e.g.,-e 'label=hotfix')
Listing Freezes
The table shows: ID, reason, start/end times with timezone, matching conditions, and active/scheduled status.
Updating a Freeze
The FREEZE_ID is the UUID shown in mergify freeze list.
Deleting a Freeze
If the freeze is currently active, a --reason for deletion is required.
Common Patterns
Emergency freeze during an incident
Recurring deployment window
Create the freeze before each deployment window and delete it after:


