Team Ai
Modelpublic

ParallelLLC/algorithmic_trading

sourceHugging Faceapache-2.0updated 2mo agoView on Hugging Face
27likes32downloads
setup-branch-protection.yml71 linesDownload Raw Back to workflows
1name: Setup Branch Protection2 3on:4  workflow_dispatch:5    inputs:6      branch:7        description: 'Branch to protect'8        required: true9        default: 'main'10      required_reviews:11        description: 'Number of required reviews'12        required: true13        default: '2'14      required_status_checks:15        description: 'Required status checks (comma-separated)'16        required: true17        default: 'ci-cd/quality-check,ci-cd/test,ci-cd/security,ci-cd/backtesting'18 19jobs:20  setup-protection:21    name: Setup Branch Protection22    runs-on: ubuntu-latest23    24    steps:25    - name: Checkout code26      uses: actions/checkout@v427      28    - name: Setup Branch Protection29      run: |30        BRANCH="${{ github.event.inputs.branch }}"31        REVIEWS="${{ github.event.inputs.required_reviews }}"32        CHECKS="${{ github.event.inputs.required_status_checks }}"33        34        # Convert comma-separated checks to JSON array35        CHECKS_JSON=$(echo "[$(echo $CHECKS | sed 's/,/","/g' | sed 's/^/"/' | sed 's/$/"/')]")36        37        echo "Setting up protection for branch: $BRANCH"38        echo "Required reviews: $REVIEWS"39        echo "Required checks: $CHECKS"40        41        # Enable branch protection42        gh api repos/${{ github.repository }}/branches/$BRANCH/protection \43          --method PUT \44          --field required_status_checks="{\"strict\":true,\"contexts\":$CHECKS_JSON}" \45          --field enforce_admins=true \46          --field required_pull_request_reviews="{\"required_approving_review_count\":$REVIEWS,\"dismiss_stale_reviews\":true,\"require_code_owner_reviews\":true}" \47          --field restrictions=null \48          --field allow_force_pushes=false \49          --field allow_deletions=false50        51        echo "✅ Branch protection enabled for $BRANCH"52        53    - name: Verify Protection54      run: |55        BRANCH="${{ github.event.inputs.branch }}"56        57        echo "Verifying branch protection for $BRANCH..."58        59        # Get protection status60        PROTECTION=$(gh api repos/${{ github.repository }}/branches/$BRANCH/protection)61        62        echo "Protection status:"63        echo "$PROTECTION" | jq '.'64        65        # Check if protection is enabled66        if echo "$PROTECTION" | jq -e '.required_status_checks' > /dev/null; then67          echo "✅ Branch protection is active"68        else69          echo "❌ Branch protection not properly configured"70          exit 171        fi