Verification gates: tests before any merge

A verification gate is a check a change must pass before it moves on; DevFlow's gates run only the configured test commands, in containers capped at 4 CPUs and 4 GB.

General meaning

A gate is a point in a pipeline where work stops until a condition holds. In CI that condition is usually a green build and passing tests. In an agentic pipeline it matters more, because no person watched the code being written.

The gates in DevFlow

DevFlow has four executable ones: the final build check, the per-subtask verify, the manual preflight and the end-to-end run. All of them run only what the repository's test_commands rows contain. There is no implicit default runner: if a command is not configured, it does not run.

A repository with no commands is never built or tested. The task can still proceed on the AI review alone, but the timeline records a skipped verification, so a change that merged unchecked is visible.

Where commands run

Rows hold the bare command, such as corepack pnpm test. At check time DevFlow wraps it in a Docker command for the repository's image.

Containers run as a non-root user. The default caps are 4 CPUs, 4 GB of memory, 6 GB with swap, and 512 processes.

When one fails

A code failure in the final build check starts a rework subtask, at most 2 times. An environment failure, such as a missing toolchain or an out-of-memory kill with exit code 137, does not. The task fails with a message that names the active caps and the setting to raise.

The record

Passed and failed build checks are logged as events and feed the merge evidence report. A repository without a build command is reported as skipped, never as passed.

FAQ

Does a security scan block a DevFlow verification gate?

No. DevFlow dependency scans run when a task finishes, stop after 300 seconds by default and never block a verification gate. The scan summary goes into the evidence report.

Can I add my own checks to DevFlow verification gates?

Yes. Any lint, unit, integration or end-to-end command stored for the repository runs at the DevFlow verification gates.