diff --git a/CHANGELOG.md b/CHANGELOG.md index f7b2cb8..20d2f3d 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -5,11 +5,13 @@ or architecture-level changes are listed. ## Unreleased -- Branch security: `.husky/pre-push` blocks direct + forced pushes to - `main`/`develop` on every machine (client-side wall; `ALLOW_PROTECTED_PUSH=1` - owner override), GitHub-side rule table (require PR, `verify` check, - signed commits, no force, no deletions) documented in - `docs/BRANCHING.md`, and a `branch-guard` test keeps both intact. +- Branch security: GitHub-server protection ENABLED on `main` + `develop` + (`gh` API 2026-09-23): require PR + `CI / verify` status check (strict), + linear history, no force pushes, no deletions, no admins bypass — + direct pushes fail server-side (cryptographic signature check left off + until GPG/SSH signing is configured; `git commit -s` sign-off stays a + rule); local `.husky/pre-push` remains as the client-side wall; + `branch-guard` test keeps both documented. - SEO content pass: homepage FAQ (5 honest long-tail Q&A) + matching `FAQPage` JSON-LD, descriptive internal links to core routes, and new regression guards (unique titles/descriptions per route, FAQ parity); diff --git a/docs/BRANCHING.md b/docs/BRANCHING.md index a72fcad..122dbfe 100644 --- a/docs/BRANCHING.md +++ b/docs/BRANCHING.md @@ -71,25 +71,31 @@ branches push freely. - The hook is client-side, so treat it as the belt; the GitHub rules below are the suspenders. -### Enforced by GitHub (owner action — needs `gh`/PAT, not present here) - -The authoritative block lives on GitHub and cannot be set from this -environment. Do it once per branch: Settings → Branches → **Add rule**, -for `main` then `develop`: - -| Setting | `main` | `develop` | -| -------------------------------------------------- | -------------------------------------------------------- | --------- | -| Require a pull request before merging | Yes (1 review; raise when contributors arrive) | Yes | -| Require status checks to pass | Yes | Yes | -| Tick check(s) | `verify` (the CI workflow) — plus `check-links` if added | `verify` | -| Require branches to be up to date (linear history) | Yes | Yes | -| Require signed commits | Yes | Yes | -| Do not allow force pushes | Yes | Yes | -| Do not allow deletions | Yes | Yes | - -Once enabled, even you cannot push `main`/`develop` directly — every -change must go through a reviewed PR with green CI. The pre-push hook -then becomes a fast local warning, not the only wall. +### Enforced by GitHub (ENABLED 2026-09-23 via `gh` API on + +| Setting | `main` | `develop` | +| --------------------------------------- | ---------------- | ------------- | +| Require a pull request before merging | Yes (1) | Yes | +| Require status checks to pass | `CI / verify` | `CI / verify` | +| Require branches up to date (strict) | Yes | Yes | +| Require linear history | Yes | Yes | +| Require cryptographic commit signatures | Off (note below) | Off | +| Do not allow force pushes | Yes | Yes | +| Do not allow deletions | Yes | Yes | +| Require conversation resolution | Yes | Yes | +| Enforce for admins | Yes | Yes | + +Rules live on GitHub (Settings → Branches), not in the repo, so they +survive fresh clones. Direct/forced pushes to `main` or `develop` now +fail server-side — even for the owner — and the pre-push hook becomes a +fast local warning, not the only wall. + +> **Cryptographic signatures — deliberately OFF.** `git commit -s` +> (sign-off trailer) stays a repo rule, but GitHub's _signed commits_ +> check requires real GPG/SSH signatures and blocks every merge until a +> signing key is configured on each machine. No key is set up in this +> project, so the check is disabled; enable it (Settings → Branches → +> Require signed commits) once contributors sign with GPG/SSH. ## What this replaced