Mergify Ci

作者 mergifyioe7c1ebbc2813无许可证收录于 2026年10月8日更新于 2026年10月8日

Use Mergify CI commands to upload JUnit test results, detect git references, manage CI scopes, and retrieve merge queue metadata. ALWAYS use this skill when working with CI pipelines, test result uploads, quarantine, scopes detection, or merge queue CI context. Triggers on CI, JUnit, test results, quarantine, scopes, git refs, CI insights.

仅含说明DevOps & Cloud
AI 生成的概览

运行 Mergify CI 命令,上传 JUnit 结果、检测 git 引用与范围,并管理测试隔离。

功能
该技能说明用于 CI 流水线的 mergify ci 与 mergify tests 命令组。内容涵盖将 JUnit XML 测试结果上传到 Mergify CI Insights 并进行隔离评估、检测 base 与 head git 引用、检测并上报用于选择性测试的 CI 范围,以及从 git note 读取合并队列批次元数据。它还涵盖查询测试健康状况,以及列出、添加、获取和移除被隔离的测试,并说明认证密钥类别与退出码。
适用场景
适用于配置或运行与 Mergify 集成的 CI 流水线,例如上传测试结果、评估隔离或检测受影响的范围。也适用于查看测试健康状况或管理 CI Insights 隔离列表。
运行要求
需要安装并可调用 mergify CLI。命令需要 Mergify 的 ci 或 admin 应用密钥,某些情况下需要 GitHub PAT,可通过 --token 或 MERGIFY_TOKEN 环境变量提供;git-refs、scopes 和 queue-info 不需要令牌。上传与隔离相关命令需要访问 Mergify API 的网络连接,queue-info 需要可访问的 origin 远程仓库。该技能不附带脚本,仅为说明文档。

Mergify CI Commands

Overview

The mergify ci command group provides tools for CI pipelines: uploading JUnit test results to Mergify CI Insights, detecting git references for diff-based operations, managing CI scopes for selective testing, and retrieving merge queue batch metadata.

Commands

bash
mergify ci junit-process FILES...         # Upload JUnit XML + evaluate quarantine (primary command)mergify ci junit-upload FILES...          # (Deprecated) Use junit-process insteadmergify ci git-refs                       # Detect base/head git references for the current PRmergify ci scopes --config PATH           # Detect scopes impacted by changed filesmergify ci scopes-send -s SCOPE           # Report scopes against the pull request's head commitmergify ci queue-info                     # Output the current build's merge queue batch metadata (from the git note)mergify tests show NAME...                # Look up tests by name and print health, ratios, last failuremergify tests quarantines add NAME        # Add a test to the CI Insights quarantinemergify tests quarantines remove NAME     # Remove a test from the CI Insights quarantinemergify tests quarantines get NAME        # Print a single quarantine by test name or idmergify tests quarantines list            # List the tests currently in the CI Insights quarantine

Authentication

Two classes of Mergify application key, both minted in the dashboard:

KeyReaches
ciWhat a CI job does: trace upload, scopes-send, quarantine evaluation (junit-process) and the quarantine list.
adminEverything a ci key reaches, plus reading test health and mutating the quarantine.

Every endpoint below that refuses a ci key accepts a GitHub PAT instead. GITHUB_TOKEN inside GitHub Actions is not a PAT — it is the ephemeral installation token — so do not reach for it to clear one of these 403s.

The split follows the endpoint each command calls: reads of test health and writes to the quarantine are a person inspecting or overriding a repository, not something a pipeline does, so they are outside what a ci key carries. Per command:

Commandci key
ci junit-process, ci junit-upload, ci scopes-sendyes
tests quarantines list, tests quarantines getyes — both read the quarantine list
tests showno — 403
tests quarantines add, tests quarantines removeno — 403

ci git-refs, ci scopes and ci queue-info are evaluated locally and need no token at all.

JUnit Processing (junit-process)

The primary CI command. Parses JUnit XML reports, checks quarantine status for failing tests, uploads results to Mergify CI Insights, and determines the final CI exit code.

bash
mergify ci junit-process \  --token "$MERGIFY_TOKEN" \  --repository owner/repo \  --tests-target-branch main \  path/to/junit-results.xml

FILES can be individual paths or quoted glob patterns (e.g. 'reports/**/*.xml'). Always quote the pattern so Mergify expands it rather than the shell — this is the recommended approach for large, sharded test suites.

Key options:

  • --token / -t (env: MERGIFY_TOKEN) -- CI Insights application key
  • --repository / -r -- Repository full name (auto-detected in GitHub Actions)
  • --tests-target-branch / -ttb -- Branch used for quarantine evaluation. Auto-detected per CI provider: GitHub Actions (GITHUB_BASE_REF → GITHUB_HEAD_REF → GITHUB_REF_NAME → GITHUB_REF), Buildkite (BUILDKITE_PULL_REQUEST_BASE_BRANCH → BUILDKITE_BRANCH), CircleCI (CIRCLE_BRANCH), Jenkins (CHANGE_TARGET → GIT_BRANCH).
  • --api-url / -u (env: MERGIFY_API_URL) -- Mergify API URL (default: https://api.mergify.com)
  • --test-framework -- Test framework name (optional metadata)
  • --test-language -- Test language (optional metadata)
  • --test-exit-code / -e (env: MERGIFY_TEST_EXIT_CODE) -- Exit code of the test runner, used to detect silent failures where the runner crashed but the JUnit report appears clean

Behavior:

  1. Parses JUnit XML files into test spans
  2. Checks quarantine status for failing tests against the Mergify API
  3. Uploads all test spans to Mergify CI Insights
  4. Prints a summary: tests run, failures, quarantined vs blocking
  5. Exits with code 0 if all failures are quarantined, code 1 if any are blocking
  6. If --test-exit-code is non-zero but no test failures are found, exits with code 1 (silent failure detection)
  7. Upload failures never affect the exit code (Mergify-side trouble must not break CI), but they are surfaced: on GitHub Actions the command emits an ::error:: annotation when the upload is rejected (HTTP 4xx except 408/429, e.g. a token without CI Insights access) or a ::warning:: annotation for transient errors (5xx, 408, 429, network), and appends test_results_upload=success|rejected|failed to $GITHUB_OUTPUT so workflows can detect dead ingest programmatically

GitHub Actions example:

yaml
- name: Run tests  id: tests  run: pytest --junitxml=results.xml || echo "exit_code=$?" >> "$GITHUB_OUTPUT"
- name: Process test results  if: always()  run: |    mergify ci junit-process \      --test-exit-code ${{ steps.tests.outputs.exit_code || 0 }} \      results.xml  env:    MERGIFY_TOKEN: ${{ secrets.MERGIFY_TOKEN }}

Git References (git-refs)

Detects the base and head git references for the current pull request context. Writes results to GITHUB_OUTPUT when running in GitHub Actions, and to Buildkite meta-data (mergify-ci.base, mergify-ci.head, mergify-ci.source) when running in Buildkite.

bash
mergify ci git-refs# Output:# Base: abc1234# Head: def5678

Output formats (--format):

  • text (default) — human-readable Base: / Head: lines
  • shell — MERGIFY_GIT_REFS_{BASE,HEAD,SOURCE}=... lines suitable for eval, with POSIX-safe shell quoting. When base can't be detected, MERGIFY_GIT_REFS_BASE=''.
  • json — single-line JSON object with base, head, source keys. base may be null when it can't be detected (e.g., workflow_dispatch events); use jq -r '.base // ""' to coalesce to empty string.
bash
# Consume values in a shell script without parsing:eval "$(mergify ci git-refs --format=shell)"nx show projects --affected \  --base="$MERGIFY_GIT_REFS_BASE" \  --head="$MERGIFY_GIT_REFS_HEAD"
# Or with jq:BASE=$(mergify ci git-refs --format=json | jq -r '.base // ""')

Sources detected (in priority order): merge queue context, GitHub pull request event, GitHub push event, fallback to last commit.

Scopes (scopes)

Detects which CI scopes are impacted by changed files, based on a Mergify configuration file. Used for selective/targeted CI -- only run tests for scopes that have changed files.

bash
# Detect scopes from changed filesmergify ci scopes --config .mergify.yml
# Detect scopes with explicit base/headmergify ci scopes --config .mergify.yml --base origin/main --head HEAD
# Write detected scopes to a filemergify ci scopes --config .mergify.yml --write scopes.json

Key options:

  • --config (env: MERGIFY_CONFIG_PATH) -- Path to the Mergify YAML config file (auto-detected)
  • --base -- Base git reference (auto-detected)
  • --head -- Head git reference (default: HEAD)
  • --write / -w -- Write detected scopes to a JSON file

The config file defines scopes with file patterns. When files change between base and head, matching scopes are identified and written to GITHUB_OUTPUT (on GitHub Actions) or to Buildkite meta-data under mergify-ci.scopes (on Buildkite), as a JSON map of scope names to "true"/"false".

A renamed file counts against both of its paths, same as the engine: git mv critical/guard.txt ignored/guard.txt touches critical and ignored.

Scopes Send (scopes-send)

Sends scopes tied to a pull request to the Mergify API. Used when scopes are determined manually or from a file rather than auto-detected.

The report is addressed by the pull request's head SHA, so it says which revision it was computed for and a result computed for an older head cannot be taken for the current one. The head is detected from the CI environment (GitHub Actions event payload, or BUILDKITE_COMMIT); pass --head-sha to name it explicitly. When no head SHA can be resolved -- or the Mergify deployment predates the commit endpoint -- the command falls back to reporting against the pull request number alone, which is what it always did.

bash
# Send specific scopesmergify ci scopes-send -s frontend -s backend -p 123
# Send scopes from a JSON file (produced by `mergify ci scopes --write`)mergify ci scopes-send --scopes-json scopes.json -p 123
# Send scopes from a plain-text file (one scope per line)mergify ci scopes-send --scopes-file scopes.txt -p 123
# Declare the PR impacts every scope (merge-queue barrier),# e.g. a build-system or CI-workflow changemergify ci scopes-send -s build-system --all -p 123
# Name the revision explicitly (the pull request head, not the# revision a `pull_request` job checked out)mergify ci scopes-send -s frontend -p 123 --head-sha "$PR_HEAD_SHA"

Key options:

  • --token / -t (env: MERGIFY_TOKEN) -- Mergify key
  • --repository / -r -- Repository full name (auto-detected)
  • --pull-request / -p -- Pull request number (auto-detected in GitHub Actions)
  • --scope / -s -- Scope name (repeatable)
  • --scopes-json -- JSON file containing scopes (output of mergify ci scopes --write)
  • --scopes-file -- Plain-text file with one scope per line
  • --head-sha -- Head SHA the scopes were computed for, 40 hexadecimal characters (auto-detected from the CI environment)
  • --all -- Declare the pull request impacts every scope. The merge queue treats it as a barrier: never batched or run in parallel with other pull requests. The concrete scopes are still sent alongside the flag.

Tests Show (tests show)

Looks up tests by name on the repository's default branch and prints their health, success/failure ratios, and last failure context. The search is a batch API: pass one or more names (globs supported) and one block per match is rendered. It is read-only: it exits 0 once it has rendered the matches, whatever their health. Gate on health by consuming --json, not the exit code.

Needs an admin key or a GitHub PAT — a ci key gets a 403. See Authentication.

bash
# Single test.mergify tests show -r owner/repo \  'ApplicationKeys.spec.ts.Permissions › Should not see keys table if not admin'
# Batch with glob, narrowed to one pipeline, JSON for jq.mergify tests show -r owner/repo \  --pipeline-name e2e --json \  '*test_login*' '*test_logout*' \  | jq '.tests[] | {test_name, health_status}'

Key options:

  • --repository / -r -- Repository full name (owner/repo); auto-detected from the CI environment or the local git remote when omitted.
  • --token / -t (env: MERGIFY_TOKEN) -- Mergify credential. Falls back to the credential mergify auth login stored, then to GITHUB_TOKEN / gh auth token, both deprecated for the Mergify API.
  • --api-url / -u (env: MERGIFY_API_URL) -- API base URL.
  • --pipeline-name, --pipeline-name-exclude -- Restrict / exclude by pipeline.
  • --job-name, --job-name-exclude -- Restrict / exclude by job.
  • --per-page -- Cap the search result count (1–100, server default 10).
  • --json -- Emit a single JSON document {"tests": [...]} to stdout.

Exit codes:

  • 0 -- Tests rendered, or no match at all. Health does not affect it.
  • 6 -- Mergify API error, including the 403 a ci key gets here.

Tests Quarantines Add (tests quarantines add)

Adds a test to the repository's CI Insights quarantine, so its failures stop blocking the CI verdict. Takes a single fully qualified test name; a --reason is required.

Needs an admin key or a GitHub PAT — a ci key gets a 403. See Authentication.

bash
# Quarantine on all branches.mergify tests quarantines add -r owner/repo \  --reason 'flaky — tracked in MRGFY-1234' \  'test_login'
# Scope the quarantine to one branch (or branch pattern), JSON output.mergify tests quarantines add -r owner/repo \  --reason 'broken on release branch' --branch 'release/*' --json \  'test_logout'

Key options:

  • --repository / -r -- Repository full name (owner/repo); auto-detected from the CI environment or the local git remote when omitted.
  • --reason -- Reason recorded for the quarantine; required.
  • --branch / -b -- Branch name or pattern to scope to. Omit for all branches.
  • --token / -t (env: MERGIFY_TOKEN) -- Mergify credential. Falls back to the credential mergify auth login stored, then to GITHUB_TOKEN / gh auth token, both deprecated for the Mergify API.
  • --api-url / -u (env: MERGIFY_API_URL) -- API base URL.
  • --json -- Emit {"id", "test_name", "reason", "branch"} to stdout.

Exit codes:

  • 0 -- Test quarantined.
  • 6 -- Mergify API error (e.g. the test is already quarantined).

Tests Quarantines Remove (tests quarantines remove)

Removes a test from the quarantine. Accepts either the fully qualified test name (resolved to its quarantine id via the list endpoint) or the quarantine id directly (as printed by tests quarantines add). A UUID-shaped argument is treated as the id and deleted without a lookup.

Needs an admin key or a GitHub PAT — a ci key gets a 403. See Authentication.

bash
# By test name.mergify tests quarantines remove -r owner/repo 'test_login'
# By quarantine id (the value `tests quarantines add` printed).mergify tests quarantines remove -r owner/repo 12345678-1234-5678-1234-567812345678

Key options:

  • --repository / -r -- Repository full name (owner/repo); auto-detected from the CI environment or the local git remote when omitted.
  • --token / -t (env: MERGIFY_TOKEN) -- Mergify credential. Falls back to the credential mergify auth login stored, then to GITHUB_TOKEN / gh auth token, both deprecated for the Mergify API.
  • --api-url / -u (env: MERGIFY_API_URL) -- API base URL.
  • --json -- Emit {"id", "test_name"} to stdout (test_name is null when addressed by id).

Exit codes:

  • 0 -- Test unquarantined.
  • 6 -- Mergify API error (e.g. the test is not quarantined).

Tests Quarantines Get (tests quarantines get)

Prints a single quarantine, addressed by the fully qualified test name or the quarantine id (a UUID-shaped argument is matched against the id). The output mirrors one record of tests quarantines list.

bash
# By test name.mergify tests quarantines get -r owner/repo 'test_login'
# By quarantine id, JSON output.mergify tests quarantines get -r owner/repo --json \  12345678-1234-5678-1234-567812345678

Key options:

  • --repository / -r -- Repository full name (owner/repo); auto-detected from the CI environment or the local git remote when omitted.
  • --token / -t (env: MERGIFY_TOKEN) -- Mergify credential. Falls back to the credential mergify auth login stored, then to GITHUB_TOKEN / gh auth token, both deprecated for the Mergify API.
  • --api-url / -u (env: MERGIFY_API_URL) -- API base URL.
  • --json -- Emit the record (id, test_name, reason, branch, created_at, source, is_recovered) to stdout.

Exit codes:

  • 0 -- Quarantine found and printed.
  • 6 -- Mergify API error (e.g. no matching quarantine).

Tests Quarantines List (tests quarantines list)

Lists every test currently in the repository's CI Insights quarantine. Takes no test argument -- it prints the whole quarantine. Human output is one indented block per record -- the test name on its own line (never wrapped mid-name), then its id (the value delete accepts), branch, source, recovered, and reason. --json emits the full records.

bash
# Human output (one block per record).mergify tests quarantines list -r owner/repo
# JSON for jq -- e.g. names of quarantines an auto-recover run flagged.mergify tests quarantines list -r owner/repo --json \  | jq -r '.quarantined_tests[] | select(.is_recovered) | .test_name'

A null branch renders as * (the quarantine applies to all branches). source is manual (added by a user) or auto (added by flaky detection). is_recovered flags quarantines whose recent runs suggest they can be removed.

Key options:

  • --repository / -r -- Repository full name (owner/repo); auto-detected from the CI environment or the local git remote when omitted.
  • --token / -t (env: MERGIFY_TOKEN) -- Mergify credential. Falls back to the credential mergify auth login stored, then to GITHUB_TOKEN / gh auth token, both deprecated for the Mergify API.
  • --api-url / -u (env: MERGIFY_API_URL) -- API base URL.
  • --json -- Emit {"quarantined_tests": [...]} to stdout, each record carrying id, test_name, reason, branch, created_at, source, is_recovered.

Exit codes:

  • 0 -- Always, including an empty quarantine ("No quarantined tests found.").

Queue Info (queue-info)

Outputs the current build's merge queue batch metadata as JSON. Reads the refs/notes/mergify/<branch> git note Mergify writes on the merge queue branch head for the current HEAD; exits INVALID_STATE (7) when no note is found (i.e. not a merge queue batch build). Takes no arguments and needs no GitHub token.

The note's full payload is emitted verbatim (every field Mergify wrote, e.g. checking_base_sha, pull_requests with per-PR scopes, previous_failed_batches, top-level scopes). New fields appear automatically without a CLI update, so don't assume a fixed schema.

bash
# In CI, on a merge queue batch build. Works in any CI (GitHub Actions,# GitLab, CircleCI, Jenkins, ...) with plain git. When GITHUB_OUTPUT is# set (GitHub Actions runner) it also writes the metadata there.mergify ci queue-info

Mergify attaches the batch metadata as a git note to the MQ branch head commit, so reading it needs only git, no PR body and no GitHub token. The command runs git fetch origin "refs/notes/mergify/*" itself (notes aren't fetched by default), then returns the note attached to HEAD. Requirements: the origin remote is reachable and the checkout is at the MQ branch head commit, which is the normal state inside a merge-queue CI run. A detached HEAD is fine.

This command is useful in CI workflows that need to know whether the current run is part of a merge queue batch and what other PRs are in the batch.

Common Patterns

Full CI pipeline with quarantine

yaml
jobs:  test:    steps:      - uses: actions/checkout@v4      - name: Run tests        run: pytest --junitxml=results.xml      - name: Upload and evaluate        if: always()        run: mergify ci junit-process results.xml        env:          MERGIFY_TOKEN: ${{ secrets.MERGIFY_TOKEN }}

Selective testing with scopes

yaml
jobs:  detect:    outputs:      scopes: ${{ steps.scopes.outputs.scopes }}    steps:      - uses: actions/checkout@v4        with:          fetch-depth: 0      - id: scopes        run: mergify ci scopes --config .mergify.yml
  backend:    needs: detect    if: fromJSON(needs.detect.outputs.scopes).backend == 'true'    steps:      - run: pytest backend/

来源与署名

来源:mergifyio/mergify-cli位于skills/mergify-ci提交e7c1ebb

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架