From f4489689cfd4edc6d982a12d52c5b740676d9c77 Mon Sep 17 00:00:00 2001 From: mohamed-dev2 Date: Wed, 23 Sep 2026 03:29:36 +0300 Subject: [PATCH 1/2] docs(branching): record server branch protection enabled (gh) Signed-off-by: mohamed-dev2 --- CHANGELOG.md | 11 ++++++----- docs/BRANCHING.md | 37 ++++++++++++++++++------------------- 2 files changed, 24 insertions(+), 24 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index f7b2cb8..ef87ac5 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -5,11 +5,12 @@ or architecture-level changes are listed. ## Unreleased -- Branch security: `.husky/pre-push` blocks direct + forced pushes to - `main`/`develop` on every machine (client-side wall; `ALLOW_PROTECTED_PUSH=1` - owner override), GitHub-side rule table (require PR, `verify` check, - signed commits, no force, no deletions) documented in - `docs/BRANCHING.md`, and a `branch-guard` test keeps both intact. +- Branch security: GitHub-server protection ENABLED on `main` + `develop` + (`gh` API 2026-09-23): require PR + `CI / verify` status check (strict), + linear history, signed commits, no force pushes, no deletions, + conversation resolution, admin-enforced — direct pushes fail + server-side; local `.husky/pre-push` remains as the client-side wall; + `branch-guard` test keeps both documented. - SEO content pass: homepage FAQ (5 honest long-tail Q&A) + matching `FAQPage` JSON-LD, descriptive internal links to core routes, and new regression guards (unique titles/descriptions per route, FAQ parity); diff --git a/docs/BRANCHING.md b/docs/BRANCHING.md index a72fcad..cb5364a 100644 --- a/docs/BRANCHING.md +++ b/docs/BRANCHING.md @@ -71,25 +71,24 @@ branches push freely. - The hook is client-side, so treat it as the belt; the GitHub rules below are the suspenders. -### Enforced by GitHub (owner action — needs `gh`/PAT, not present here) - -The authoritative block lives on GitHub and cannot be set from this -environment. Do it once per branch: Settings → Branches → **Add rule**, -for `main` then `develop`: - -| Setting | `main` | `develop` | -| -------------------------------------------------- | -------------------------------------------------------- | --------- | -| Require a pull request before merging | Yes (1 review; raise when contributors arrive) | Yes | -| Require status checks to pass | Yes | Yes | -| Tick check(s) | `verify` (the CI workflow) — plus `check-links` if added | `verify` | -| Require branches to be up to date (linear history) | Yes | Yes | -| Require signed commits | Yes | Yes | -| Do not allow force pushes | Yes | Yes | -| Do not allow deletions | Yes | Yes | - -Once enabled, even you cannot push `main`/`develop` directly — every -change must go through a reviewed PR with green CI. The pre-push hook -then becomes a fast local warning, not the only wall. +### Enforced by GitHub (ENABLED 2026-09-23 via `gh` API on + +| Setting | `main` | `develop` | +| ------------------------------------- | ------------- | ------------- | +| Require a pull request before merging | Yes (1) | Yes | +| Require status checks to pass | `CI / verify` | `CI / verify` | +| Require branches up to date (strict) | Yes | Yes | +| Require linear history | Yes | Yes | +| Require signed commits | Yes | Yes | +| Do not allow force pushes | Yes | Yes | +| Do not allow deletions | Yes | Yes | +| Require conversation resolution | Yes | Yes | +| Enforce for admins | Yes | Yes | + +Rules live on GitHub (Settings → Branches), not in the repo, so they +survive fresh clones. Direct/forced pushes to `main` or `develop` now +fail server-side — even for the owner — and the pre-push hook becomes a +fast local warning, not the only wall. ## What this replaced From 1a9899fd93fbc4c5c8beba27f0b7016ca16ab377 Mon Sep 17 00:00:00 2001 From: mohamed-dev2 Date: Wed, 23 Sep 2026 03:37:33 +0300 Subject: [PATCH 2/2] docs(branching): signature check off until gpg/ssh signing configured Signed-off-by: mohamed-dev2 --- CHANGELOG.md | 7 ++++--- docs/BRANCHING.md | 29 ++++++++++++++++++----------- 2 files changed, 22 insertions(+), 14 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index ef87ac5..20d2f3d 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -7,9 +7,10 @@ or architecture-level changes are listed. - Branch security: GitHub-server protection ENABLED on `main` + `develop` (`gh` API 2026-09-23): require PR + `CI / verify` status check (strict), - linear history, signed commits, no force pushes, no deletions, - conversation resolution, admin-enforced — direct pushes fail - server-side; local `.husky/pre-push` remains as the client-side wall; + linear history, no force pushes, no deletions, no admins bypass — + direct pushes fail server-side (cryptographic signature check left off + until GPG/SSH signing is configured; `git commit -s` sign-off stays a + rule); local `.husky/pre-push` remains as the client-side wall; `branch-guard` test keeps both documented. - SEO content pass: homepage FAQ (5 honest long-tail Q&A) + matching `FAQPage` JSON-LD, descriptive internal links to core routes, and new diff --git a/docs/BRANCHING.md b/docs/BRANCHING.md index cb5364a..122dbfe 100644 --- a/docs/BRANCHING.md +++ b/docs/BRANCHING.md @@ -73,23 +73,30 @@ branches push freely. ### Enforced by GitHub (ENABLED 2026-09-23 via `gh` API on -| Setting | `main` | `develop` | -| ------------------------------------- | ------------- | ------------- | -| Require a pull request before merging | Yes (1) | Yes | -| Require status checks to pass | `CI / verify` | `CI / verify` | -| Require branches up to date (strict) | Yes | Yes | -| Require linear history | Yes | Yes | -| Require signed commits | Yes | Yes | -| Do not allow force pushes | Yes | Yes | -| Do not allow deletions | Yes | Yes | -| Require conversation resolution | Yes | Yes | -| Enforce for admins | Yes | Yes | +| Setting | `main` | `develop` | +| --------------------------------------- | ---------------- | ------------- | +| Require a pull request before merging | Yes (1) | Yes | +| Require status checks to pass | `CI / verify` | `CI / verify` | +| Require branches up to date (strict) | Yes | Yes | +| Require linear history | Yes | Yes | +| Require cryptographic commit signatures | Off (note below) | Off | +| Do not allow force pushes | Yes | Yes | +| Do not allow deletions | Yes | Yes | +| Require conversation resolution | Yes | Yes | +| Enforce for admins | Yes | Yes | Rules live on GitHub (Settings → Branches), not in the repo, so they survive fresh clones. Direct/forced pushes to `main` or `develop` now fail server-side — even for the owner — and the pre-push hook becomes a fast local warning, not the only wall. +> **Cryptographic signatures — deliberately OFF.** `git commit -s` +> (sign-off trailer) stays a repo rule, but GitHub's _signed commits_ +> check requires real GPG/SSH signatures and blocks every merge until a +> signing key is configured on each machine. No key is set up in this +> project, so the check is disabled; enable it (Settings → Branches → +> Require signed commits) once contributors sign with GPG/SSH. + ## What this replaced Earlier `docs/BRANCHING.md` drafts used GitHub Flow (single `main`).