Skip to content

docs: define default branch check policy - #10

Merged
altaywtf merged 2 commits into
mainfrom
chore/github-policy
Sep 8, 2026
Merged

docs: define default branch check policy#10
altaywtf merged 2 commits into
mainfrom
chore/github-policy

Conversation

@altaywtf

@altaywtf altaywtf commented Sep 8, 2026

Copy link
Copy Markdown
Member

Problem

Required checks used for native dependency automerge also constrain direct default-branch writers, but the shared guidance did not explain that contract.

Solution

Document explicit native-automerge opt-ins, repository-scoped writer exceptions, separate baseline protections, and reviewed fleet readback. Keep private policy inventories with their private owner.

Copilot AI lite review requested due to automatic review settings September 8, 2026 20:07
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 8, 2026

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review Completed 2026-09-08T20:10:37.995493Z df20406 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

There is a grammatical/clarity issue in the new README text that should be corrected before merging.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Pull request overview

Documents the policy contract around default-branch required checks so that GitHub-native Renovate automerge opt-ins (and their constraints on direct default-branch writers) are explicit and easier to apply consistently across repositories.

Changes:

  • Adds a “Default-branch checks” section describing native Renovate automerge opt-in requirements (platformAutomerge: true + default-branch-checks ruleset).
  • Clarifies that required checks apply to direct default-branch pushes and that writer exceptions must be repository-scoped.
  • Adds guidance for safely changing rulesets (before/after capture, canary, post-rollout verification) and keeping private inventories private.
File summaries
File Description
README.md Adds documentation defining the default-branch checks policy contract and change-management guidance.
Review details
  • Files reviewed: 1/1 changed files
  • Comments generated: 1
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread README.md Outdated

@slopzapper slopzapper Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✨ CLEAN

The new default-branch check policy matches the shared preset's platformAutomerge opt-in and the org baseline split for signing, deletion, and force-push. No correctness defect in the eligible README change.

@altaywtf
altaywtf merged commit 01d0c3a into main Sep 8, 2026
4 checks passed
@altaywtf
altaywtf deleted the chore/github-policy branch September 8, 2026 20:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants