Skip to content

[Security] Strengthen branch protection settings #183

@pcdubs

Description

@pcdubs

Priority: High

OpenSSF Scorecard Finding: Branch-Protection (6/10)
Risk Level: High

Description

Branch protection is enabled but not maximal on development and all release branches.

Recommendation

Strengthen branch protection rules to include:

  • Require pull request reviews before merging (at least 1-2 approvals)
  • Require status checks to pass before merging
  • Require branches to be up to date before merging
  • Enforce for administrators
  • Restrict who can push to matching branches

References

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions