पाठ 21 / 25
Review and Merge Policy
Decide what can ever merge without a human.
Tiers by risk
Define tiers: low-risk changes (formatting, lint auto-fixes, patch-level dependency bumps with passing tests) might merge after CI and a quick human approval or, in mature setups, automatically; medium-risk bug fixes need a code owner's review; high-risk areas (security, payments, data migrations, authentication) are out of scope for autonomous fixing or always need senior review. Reviewers should check the root-cause explanation, not just the green checks.
A risk-tier policy
Adjust to your organisation.
tier examples merge requirement
low lint fixes, typo fixes, patch dependency bumps CI green + 1 approval (or auto after trial period)
medium bug fixes with reproduction tests CI green + code owner approval
high auth, payments, crypto, migrations, infra not eligible for autonomous fixingStart every tier with human review
Allow any auto-merge only after months of measured, clean history for that tier.
त्वरित जाँच: Which change is least suitable for autonomous fixing?
- Fixing a lint warning
- A change to authentication logic
- A patch-level dependency bump with passing tests
- Correcting a typo in a log message
Answer
A change to authentication logic — High-risk areas need human ownership.