Skip to content

ops: define fail-closed core repository protection - #136

Draft
abrichr wants to merge 2 commits into
mainfrom
codex/core-protection-policy
Draft

ops: define fail-closed core repository protection#136
abrichr wants to merge 2 commits into
mainfrom
codex/core-protection-policy

Conversation

@abrichr

@abrichr abrichr commented Aug 20, 2026

Copy link
Copy Markdown
Member

Summary

  • define no-bypass main and immutable release-tag protection for the eight owned public core repositories
  • add read-only plan and verify modes plus a guarded apply transaction
  • keep private openadapt-cloud audit-only because the current GitHub plan cannot issue private repository attestations
  • document exact release environments, checks, and Desktop FFmpeg tag protection

Safety

This pull request does not apply any GitHub setting. Apply requires a recent reviewed plan, unchanged main commits and workflow inputs, no active pull-request checks, exact confirmation text, and the approved release App identity. The tool refuses incomplete or unsupported repository state.

Validation

  • Ruff passed
  • 210 tests passed
  • policy and documentation validation passed
  • strict MkDocs build passed with existing warnings
  • fail-closed plan test exited 2 and wrote no plan

@abrichr
abrichr marked this pull request as draft August 20, 2026 15:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant