Root cause: e50ad812 introduced `const { minimatch } = require('minimatch')`
in scripts/pr-template-policy.cjs, but minimatch is not listed in
package.json (neither dependencies nor devDependencies). The
.github/workflows/pr-template-format.yml workflow checks out main via
actions/checkout and runs the script directly with no `npm ci`/`npm install`
step. Because the workflow uses `pull_request_target` + plain checkout
(no `ref:`), every PR — including PRs that don't touch this file — invokes
main's broken script and the `Pull request template format` check fails
with `Cannot find module 'minimatch'`. This blocks every open PR's check.
Fix choice: replace minimatch with Node's built-in `path.matchesGlob`
(stable since Node 22, required engine is `>=22.0.0`). The only minimatch
usage was `minimatch(file, pattern, { matchBase: false, dot: true })` in
allPathsAreTooling, against simple glob patterns (`**`, `*`, `*.md`,
`requirements*.txt`, etc.) with no extglobs, brace-expansion alternation,
or negation. path.matchesGlob handles all required cases including dot
files, so no new dependency is needed and no workflow change is required.
Verified: all 25 existing tests in tests/pr-template-policy.test.cjs pass,
including the tooling carve-out, exempt-marker, and template-detection
suites. Direct script invocation with CHANGED_FILES=.github/workflows/...
produces the expected `skipped: tooling-paths` carve-out.
This unblocks every open PR's `Pull request template format` check.
* fix(3696): pr-template enforcer recognises CI/tooling carve-out
The enforcer in scripts/pr-template-policy.cjs only validated against
three typed templates and three hard-coded DEFAULT_TEMPLATE_MARKERS.
It had zero awareness of the documented CI/tooling/dep/doc-only exception
in .github/pull_request_template.md, meaning external contributors who
followed the documented escape hatch still had their PRs auto-closed.
Fix:
1. Path-scope auto-skip: if every changed file matches a tooling glob
allowlist (.github/**, scripts/**, docs/**, *.md, .changeset/**,
dependency manifests), skip enforcement and exit success with no
comment posted.
2. Explicit exemption marker: if the PR body contains
<!-- pr-template-exempt: <non-empty reason> -->, skip enforcement.
3. Workflow updated to fetch changed file paths via gh and pass them
as CHANGED_FILES env to the policy script.
4. Pull request template updated to document both mechanisms and retire
the old "delete this file" prose carve-out.
5. 14 new tests (TDD red→green); all 25 tests pass.
Closes#3696
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* fix(3696): allow hyphenated pr-template exemption reasons
---------
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>