Skip to content

Commit 096aa77

Browse files
authored
Merge pull request #46195 from github/repo-sync
Repo sync
2 parents 86c19ef + 2e3a124 commit 096aa77

42 files changed

Lines changed: 2088 additions & 360 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎.github/rulesets/README.md‎

Lines changed: 35 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,35 @@
1+
# Rulesets
2+
3+
Copies of the repository rulesets on github/docs-internal and github/docs, exported from the live settings. One file per ruleset, named after the ruleset.
4+
5+
| Folder | Applies to |
6+
| --- | --- |
7+
| `docs-internal/` | github/docs-internal |
8+
| `docs/` | github/docs |
9+
10+
This folder is mirrored to github/docs along with the rest of the repo, so both folders appear in both repos. The folder name says which repo a file belongs to, not the repo you are reading it in. A ruleset payload has no field naming its repo, and both repos have a ruleset called `main branch protection`.
11+
12+
GitHub does not apply these files. Editing a file changes nothing live, and editing a ruleset in the UI changes nothing here. Keep the two matching by hand.
13+
14+
The weekday [ruleset drift check](https://github.com/github/technical-content/tree/main/.github/scripts/ruleset-drift) in github/technical-content reads these files and alerts when the live rules on `main` are weaker than what they say. [Branch protection with rulesets](https://github.com/github/technical-content/blob/main/engineering/branch-protection-rulesets.md) explains why each rule exists.
15+
16+
## Change a ruleset
17+
18+
Edit the file in a pull request here in docs-internal, including files under `docs/`. After it merges, apply it as a repo admin of the repo named by the folder:
19+
20+
```sh
21+
repo=docs-internal
22+
name="main branch protection"
23+
id=$(gh api "repos/github/$repo/rulesets" --jq ".[] | select(.name == \"$name\") | .id")
24+
gh api -X PUT "repos/github/$repo/rulesets/$id" --input ".github/rulesets/$repo/main-branch-protection.json"
25+
```
26+
27+
`PUT` replaces the whole ruleset. For a new ruleset, `POST` instead: `gh api -X POST repos/github/REPO/rulesets --input .github/rulesets/REPO/FILE.json`.
28+
29+
When you add or remove a test suite in `.github/workflows/test.yml`, update `required_status_checks` in both `docs-internal/main-branch-protection.json` and `docs/main-branch-protection.json`, except for suites the matrix excludes on github/docs.
30+
31+
## Export a ruleset
32+
33+
```sh
34+
gh api repos/github/REPO/rulesets/ID --jq '{name, target, enforcement, bypass_actors, conditions, rules}' > .github/rulesets/REPO/FILE.json
35+
```
Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,29 @@
1+
{
2+
"name": "Copilot code review",
3+
"target": "branch",
4+
"enforcement": "active",
5+
"bypass_actors": [
6+
{
7+
"actor_id": 5,
8+
"actor_type": "RepositoryRole",
9+
"bypass_mode": "always"
10+
}
11+
],
12+
"conditions": {
13+
"ref_name": {
14+
"exclude": [],
15+
"include": [
16+
"~DEFAULT_BRANCH"
17+
]
18+
}
19+
},
20+
"rules": [
21+
{
22+
"type": "copilot_code_review",
23+
"parameters": {
24+
"review_on_push": false,
25+
"review_draft_pull_requests": false
26+
}
27+
}
28+
]
29+
}
Lines changed: 36 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,36 @@
1+
{
2+
"name": "frozen archive branches",
3+
"target": "branch",
4+
"enforcement": "active",
5+
"bypass_actors": [
6+
{
7+
"actor_id": 5,
8+
"actor_type": "RepositoryRole",
9+
"bypass_mode": "always"
10+
}
11+
],
12+
"conditions": {
13+
"ref_name": {
14+
"exclude": [],
15+
"include": [
16+
"refs/heads/old-nanoc-site-archive",
17+
"refs/heads/gh-pages-archive",
18+
"refs/heads/old-main"
19+
]
20+
}
21+
},
22+
"rules": [
23+
{
24+
"type": "deletion"
25+
},
26+
{
27+
"type": "non_fast_forward"
28+
},
29+
{
30+
"type": "update"
31+
},
32+
{
33+
"type": "creation"
34+
}
35+
]
36+
}
Lines changed: 271 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,271 @@
1+
{
2+
"name": "main branch protection",
3+
"target": "branch",
4+
"enforcement": "active",
5+
"bypass_actors": [
6+
{
7+
"actor_id": 5,
8+
"actor_type": "RepositoryRole",
9+
"bypass_mode": "always"
10+
},
11+
{
12+
"actor_id": 87537,
13+
"actor_type": "Integration",
14+
"bypass_mode": "always"
15+
},
16+
{
17+
"actor_id": 87541,
18+
"actor_type": "Integration",
19+
"bypass_mode": "always"
20+
},
21+
{
22+
"actor_id": 325922,
23+
"actor_type": "Team",
24+
"bypass_mode": "always"
25+
}
26+
],
27+
"conditions": {
28+
"ref_name": {
29+
"exclude": [],
30+
"include": [
31+
"refs/heads/main"
32+
]
33+
}
34+
},
35+
"rules": [
36+
{
37+
"type": "creation"
38+
},
39+
{
40+
"type": "deletion"
41+
},
42+
{
43+
"type": "non_fast_forward"
44+
},
45+
{
46+
"type": "pull_request",
47+
"parameters": {
48+
"required_approving_review_count": 1,
49+
"dismiss_stale_reviews_on_push": false,
50+
"required_reviewers": [],
51+
"require_code_owner_review": true,
52+
"dismissal_restriction": {
53+
"enabled": false,
54+
"allowed_actors": []
55+
},
56+
"require_last_push_approval": false,
57+
"required_review_thread_resolution": false,
58+
"ignore_approvals_from_contributors": false,
59+
"require_extra_approval_for_unattributed_changes": true,
60+
"allowed_merge_methods": [
61+
"merge",
62+
"squash",
63+
"rebase"
64+
]
65+
}
66+
},
67+
{
68+
"type": "merge_queue",
69+
"parameters": {
70+
"merge_method": "SQUASH",
71+
"max_entries_to_build": 20,
72+
"min_entries_to_merge": 1,
73+
"max_entries_to_merge": 10,
74+
"min_entries_to_merge_wait_minutes": 5,
75+
"grouping_strategy": "ALLGREEN",
76+
"check_response_timeout_minutes": 60,
77+
"check_run_retries_limit": 0,
78+
"actor_controlled_merging": true
79+
}
80+
},
81+
{
82+
"type": "required_status_checks",
83+
"parameters": {
84+
"strict_required_status_checks_policy": true,
85+
"do_not_enforce_on_create": false,
86+
"required_status_checks": [
87+
{
88+
"context": "archives",
89+
"integration_id": 15368
90+
},
91+
{
92+
"context": "article-api",
93+
"integration_id": 15368
94+
},
95+
{
96+
"context": "assets",
97+
"integration_id": 15368
98+
},
99+
{
100+
"context": "audit-logs",
101+
"integration_id": 15368
102+
},
103+
{
104+
"context": "automated-pipelines",
105+
"integration_id": 15368
106+
},
107+
{
108+
"context": "color-schemes",
109+
"integration_id": 15368
110+
},
111+
{
112+
"context": "content-linter",
113+
"integration_id": 15368
114+
},
115+
{
116+
"context": "content-render",
117+
"integration_id": 15368
118+
},
119+
{
120+
"context": "data-directory",
121+
"integration_id": 15368
122+
},
123+
{
124+
"context": "early-access",
125+
"integration_id": 15368
126+
},
127+
{
128+
"context": "events",
129+
"integration_id": 15368
130+
},
131+
{
132+
"context": "fixtures",
133+
"integration_id": 15368
134+
},
135+
{
136+
"context": "frame",
137+
"integration_id": 15368
138+
},
139+
{
140+
"context": "ghes-releases",
141+
"integration_id": 15368
142+
},
143+
{
144+
"context": "github-apps",
145+
"integration_id": 15368
146+
},
147+
{
148+
"context": "graphql",
149+
"integration_id": 15368
150+
},
151+
{
152+
"context": "journeys",
153+
"integration_id": 15368
154+
},
155+
{
156+
"context": "landings",
157+
"integration_id": 15368
158+
},
159+
{
160+
"context": "languages",
161+
"integration_id": 15368
162+
},
163+
{
164+
"context": "links",
165+
"integration_id": 15368
166+
},
167+
{
168+
"context": "observability",
169+
"integration_id": 15368
170+
},
171+
{
172+
"context": "products",
173+
"integration_id": 15368
174+
},
175+
{
176+
"context": "redirects",
177+
"integration_id": 15368
178+
},
179+
{
180+
"context": "release-notes",
181+
"integration_id": 15368
182+
},
183+
{
184+
"context": "rest",
185+
"integration_id": 15368
186+
},
187+
{
188+
"context": "search",
189+
"integration_id": 15368
190+
},
191+
{
192+
"context": "secret-scanning",
193+
"integration_id": 15368
194+
},
195+
{
196+
"context": "shielding",
197+
"integration_id": 15368
198+
},
199+
{
200+
"context": "versions",
201+
"integration_id": 15368
202+
},
203+
{
204+
"context": "webhooks",
205+
"integration_id": 15368
206+
},
207+
{
208+
"context": "workflows",
209+
"integration_id": 15368
210+
},
211+
{
212+
"context": "lint-content",
213+
"integration_id": 15368
214+
},
215+
{
216+
"context": "line-endings",
217+
"integration_id": 15368
218+
},
219+
{
220+
"context": "lint-code",
221+
"integration_id": 15368
222+
},
223+
{
224+
"context": "local-dev",
225+
"integration_id": 15368
226+
},
227+
{
228+
"context": "playwright-tests (playwright-a11y)",
229+
"integration_id": 15368
230+
},
231+
{
232+
"context": "playwright-tests (playwright-rendering)",
233+
"integration_id": 15368
234+
},
235+
{
236+
"context": "playwright-tests (playwright-secret-scanning)",
237+
"integration_id": 15368
238+
},
239+
{
240+
"context": "set-vault-keys",
241+
"integration_id": 15368
242+
},
243+
{
244+
"context": "docs-internal-moda-config-bundle / docs-internal-moda-config-bundle",
245+
"integration_id": 15368
246+
},
247+
{
248+
"context": "docs-internal-docker-image / docs-internal-docker-image",
249+
"integration_id": 15368
250+
},
251+
{
252+
"context": "docs-internal-docker-security / docs-internal-docker-security",
253+
"integration_id": 15368
254+
},
255+
{
256+
"context": "merge-queue-restriction",
257+
"integration_id": 15368
258+
}
259+
]
260+
}
261+
},
262+
{
263+
"type": "required_deployments",
264+
"parameters": {
265+
"required_deployment_environments": [
266+
"production"
267+
]
268+
}
269+
}
270+
]
271+
}

0 commit comments

Comments
 (0)