Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 7 additions & 5 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,11 +5,13 @@ or architecture-level changes are listed.

## Unreleased

- Branch security: `.husky/pre-push` blocks direct + forced pushes to
`main`/`develop` on every machine (client-side wall; `ALLOW_PROTECTED_PUSH=1`
owner override), GitHub-side rule table (require PR, `verify` check,
signed commits, no force, no deletions) documented in
`docs/BRANCHING.md`, and a `branch-guard` test keeps both intact.
- Branch security: GitHub-server protection ENABLED on `main` + `develop`
(`gh` API 2026-09-23): require PR + `CI / verify` status check (strict),
linear history, no force pushes, no deletions, no admins bypass —
direct pushes fail server-side (cryptographic signature check left off
until GPG/SSH signing is configured; `git commit -s` sign-off stays a
rule); local `.husky/pre-push` remains as the client-side wall;
`branch-guard` test keeps both documented.
- SEO content pass: homepage FAQ (5 honest long-tail Q&A) + matching
`FAQPage` JSON-LD, descriptive internal links to core routes, and new
regression guards (unique titles/descriptions per route, FAQ parity);
Expand Down
44 changes: 25 additions & 19 deletions docs/BRANCHING.md
Original file line number Diff line number Diff line change
Expand Up @@ -71,25 +71,31 @@ branches push freely.
- The hook is client-side, so treat it as the belt; the GitHub rules
below are the suspenders.

### Enforced by GitHub (owner action — needs `gh`/PAT, not present here)

The authoritative block lives on GitHub and cannot be set from this
environment. Do it once per branch: Settings → Branches → **Add rule**,
for `main` then `develop`:

| Setting | `main` | `develop` |
| -------------------------------------------------- | -------------------------------------------------------- | --------- |
| Require a pull request before merging | Yes (1 review; raise when contributors arrive) | Yes |
| Require status checks to pass | Yes | Yes |
| Tick check(s) | `verify` (the CI workflow) — plus `check-links` if added | `verify` |
| Require branches to be up to date (linear history) | Yes | Yes |
| Require signed commits | Yes | Yes |
| Do not allow force pushes | Yes | Yes |
| Do not allow deletions | Yes | Yes |

Once enabled, even you cannot push `main`/`develop` directly — every
change must go through a reviewed PR with green CI. The pre-push hook
then becomes a fast local warning, not the only wall.
### Enforced by GitHub (ENABLED 2026-09-23 via `gh` API on

| Setting | `main` | `develop` |
| --------------------------------------- | ---------------- | ------------- |
| Require a pull request before merging | Yes (1) | Yes |
| Require status checks to pass | `CI / verify` | `CI / verify` |
| Require branches up to date (strict) | Yes | Yes |
| Require linear history | Yes | Yes |
| Require cryptographic commit signatures | Off (note below) | Off |
| Do not allow force pushes | Yes | Yes |
| Do not allow deletions | Yes | Yes |
| Require conversation resolution | Yes | Yes |
| Enforce for admins | Yes | Yes |

Rules live on GitHub (Settings → Branches), not in the repo, so they
survive fresh clones. Direct/forced pushes to `main` or `develop` now
fail server-side — even for the owner — and the pre-push hook becomes a
fast local warning, not the only wall.

> **Cryptographic signatures — deliberately OFF.** `git commit -s`
> (sign-off trailer) stays a repo rule, but GitHub's _signed commits_
> check requires real GPG/SSH signatures and blocks every merge until a
> signing key is configured on each machine. No key is set up in this
> project, so the check is disabled; enable it (Settings → Branches →
> Require signed commits) once contributors sign with GPG/SSH.

## What this replaced

Expand Down
Loading