Objective
Create a .github/settings.yml file to codify branch protection rules for the main branch, making required status checks version controlled.
Context
Currently, branch protection rules are configured manually in the GitHub UI. This creates risks:
- Settings can drift over time
- Configuration is lost during repository transfers
- No audit trail for changes to protection rules
Approach
- Create
.github/settings.yml file
- Define protection rules for
main branch:
- Require status checks: Build and Lint (Node 18, 20, 22), Test Coverage, TypeScript Type Check, Test Examples, CodeQL, Trivy Container Scan
- Require 1 approving review
- Enforce up-to-date branches before merge
- Document the configuration in README or CONTRIBUTING.md
Files to Create/Modify
- Create:
.github/settings.yml
- Update:
README.md or CONTRIBUTING.md (document the settings file)
Acceptance Criteria
References
AI generated by Plan Command for discussion #345
Objective
Create a
.github/settings.ymlfile to codify branch protection rules for themainbranch, making required status checks version controlled.Context
Currently, branch protection rules are configured manually in the GitHub UI. This creates risks:
Approach
.github/settings.ymlfilemainbranch:Files to Create/Modify
.github/settings.ymlREADME.mdorCONTRIBUTING.md(document the settings file)Acceptance Criteria
.github/settings.ymlexists with comprehensive branch protection rulesReferences
.github/workflows/*.yml(for status check names)Related to [plan] improve ci/cd pipeline and quality gates #348