Skip to content

ci: audit overlapping branch protection - #4

Merged
showxu merged 1 commit into
masterfrom
ci/legacy-protection-audit
Oct 6, 2026
Merged

showxu merged 1 commit into
masterfrom
ci/legacy-protection-audit

Conversation

@showxu

@showxu showxu commented Oct 6, 2026

Copy link
Copy Markdown
Member

The settings audit previously checked rulesets alone, so it missed older branch protection that still locks swift-gyb master and requires an additional approval. swift-codex also retains overlapping legacy checks. Audit the legacy branch-protection endpoint and declare the active rulesets as the single source of enforcement.

Migration verifies each effective default-branch ruleset, its signatures, pull-request rules and required checks before retiring the overlapping legacy rule. Existing rulesets are retained; no administrator merge bypass is used. The Codex legacy checks are already covered by its active ruleset.

Also clarify that the source-policy allowlist retains semantic identifiers such as pagination cursors and CSS keywords.

Validation: 19 behavior tests, workflow derivation, actionlint and whitespace checks pass. The new regression covers a locked legacy branch despite matching rulesets, and distinguishes an explicitly unprotected branch from missing-resource or permission errors. No Swift compilation was run.

@showxu
showxu merged commit ff0c5d5 into master Oct 6, 2026
2 checks passed
@showxu
showxu deleted the ci/legacy-protection-audit branch October 6, 2026 06:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant