You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 1c90857
Browse filesBrowse the repository at this point in the historyBrowse files
|`protectionFloors`| array of strings, optional | Protection keys whose profile value is a **minimum**, not an exact value — see **Floors**. A sibling of `protection`, not inside it, so readers that predate it ignore it rather than reject it. |
272
273
|`labels`| array of strings | Labels that must exist. Missing ones are a finding; **extra ones are not** — a repo's own labels are its business. |
273
274
|`review`| object | Passed through to the repo config's `review` block by `bootstrap` (`bots`, `approvalThreshold`, `scoreSource`, `responderTier`, `impasseRounds`, `sameFileRoundCap` — the schema for them is in [`config-schema.md`](config-schema.md)). Not a GitHub setting. |
274
275
|`requireIssueForDeferredWork`| bool | Passed through to `createPr.requireIssueForDeferredWork`. Not a GitHub setting. |
@@ -402,6 +403,49 @@ Three consequences worth stating, because each is a case where the obvious imple
402
403
optional integer there and `null` is the response's spelling. A warning printed above a call that
403
404
still loses the thing is a warning read after the paste.
404
405
406
+
### Floors
407
+
408
+
`defaults.protection.*` is otherwise an exact value, so a profile saying `enforceAdmins: false`
409
+
would generate a PUT that switches `enforce_admins`**off** on a repo that has it on deliberately.
410
+
For keys where stricter is always acceptable, the value is a floor instead:
411
+
412
+
```jsonc
413
+
"defaults": {
414
+
"protection": { "enforceAdmins":false, … },
415
+
"protectionFloors": ["enforceAdmins"] // these values are minima, not exact values
416
+
}
417
+
```
418
+
419
+
Entries name profile-side protection keys, dotted for nested ones. For a listed key, a branch whose
420
+
value is **stricter** is conformant — no finding, and the PUT carries the branch's existing value —
421
+
while a **looser** one is still a finding. Which direction is stricter is a fixed table, not
msg: "\($branch) does not require the check \"\(.)\"" }) )
255
298
+ ( ((prot_contexts) - ($e.requiredChecks // []))
256
299
| map({ sev: "WARN", section: "protection",
257
-
msg: "\($branch) requires the check \"\(.)\", which the profile does not name. The PUT below would REMOVE it, because it replaces the whole object — add it to the profile'"'"'s requiredChecks first if it should stay." }) )
300
+
msg: "\($branch) requires the check \"\(.)\", which the profile does not name. The PUT below would REMOVE it, because it replaces the whole object — add it to the profile'"'"'s requiredChecks first if it should stay.",
301
+
loosens: true,
302
+
loosenMsg: "LOOSENS — \($branch) drops the required check \"\(.)\" (not in the profile'"'"'s requiredChecks)" }) )
258
303
+ unpinned_addition_findings
259
304
end;
260
305
@@ -309,7 +354,7 @@ findings="$(jq -n \
309
354
protectionKnown: (prot_present or prot_unprotected),
0 commit comments