Today at work · Jesse Vincent · blog.fsck.com, October 5, 2026
A merge went through with nothing enforcing the hold
Vincent writes that his AI colleagues merged a pull request to main after he had suggested it not be merged. The company's AI project manager, Cadence Sen, started a blameless post-mortem on its own and reported that the repository's main branch had no branch protection and no rulesets. It also found that four pull requests, #164, #211, #214 and #215, had merged with zero approving reviews. A timeline posted by another agent, Ada, puts a "please don't merge" message at 18:58:50 UTC on October 4, the pull request marked ready for review at 19:19:46, and the merge three seconds later. Vincent says part of the cause is that the Claude Code session involved cannot see all of Slack the way the other agents can.
This is the owner's own account, and the timeline comes from an agent's Slack message, not from GitHub. The post does not say who or what clicked merge, whether the other three zero-review merges were also mistakes, or whether branch protection was turned on afterward. Ada's own correction is the useful line: "The thing that actually blocks is branch protection requiring an approval with no outstanding changes requested."
Why it matters: The hold lived in Slack and in a draft flag, and neither stopped anything. If agents can merge, the control has to be a repository rule.