Add support for branch rulesets in compliance checks #1987
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Overview
This PR adds support for GitHub branch rulesets to the repo-policy-compliance application, resolving issue #314. The application can now validate branch protection configured through both classic branch protection and the newer rulesets API.
Problem
Previously, the application only supported checking classic branch protection. When users configured branch protection using rulesets (the newer GitHub feature), the application would fail with a 404 error and display a message suggesting that rulesets might be defined instead, but it couldn't actually verify them.
Solution
This PR adds comprehensive support for checking branch rulesets with the same validation criteria as classic branch protection:
Implementation Details
New GitHub Client Function
Added
get_rulesets_for_branch()ingithub_client.py:New Validation Function
Added
_check_rulesets_for_pull_request_reviews()incheck.py:Updated Target Branch Protection Check
Modified
target_branch_protection()to:Testing
Backward Compatibility
This implementation maintains full backward compatibility:
Example
Closes #314
Original prompt
Fixes #1831
✨ Let Copilot coding agent set things up for you — coding agent works faster and does higher quality work when set up for your repo.