{"id":1195,"date":"2026-09-26T05:59:26","date_gmt":"2026-09-26T05:59:26","guid":{"rendered":"https:\/\/www.devopsschool.com\/tutorials\/?p=1195"},"modified":"2026-09-26T05:59:29","modified_gmt":"2026-09-26T05:59:29","slug":"github-repository-settings-complete-reference-guide-tutorial","status":"publish","type":"post","link":"https:\/\/www.devopsschool.com\/tutorials\/github-repository-settings-complete-reference-guide-tutorial\/","title":{"rendered":"GitHub Repository Settings \u2014 Complete Reference Guide &#038; Tutorial"},"content":{"rendered":"\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>Last Verified:<\/strong>&nbsp;September 2026<br><strong>Platform:<\/strong>&nbsp;GitHub.com \/ GitHub Enterprise Cloud unless stated otherwise<br><strong>Audience:<\/strong>&nbsp;Developers, DevOps engineers, repository administrators, security engineers, platform engineers, team leads, and trainers<\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">GitHub repository settings are the control plane for an individual repository. They define who can access the repository, how contributors are allowed to change code, which automation can run, how deployments are protected, which security controls are enabled, and how the repository behaves throughout its lifecycle.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This guide follows a practical progression:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Concept \u2192 Why \u2192 How \u2192 Example \u2192 Practice \u2192 Real-world use case \u2192 Best practices \u2192 Troubleshooting<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The exact settings visible in GitHub vary by repository ownership, visibility, plan, organization policy, enterprise policy, enabled products, and preview features. When a higher-level policy is enforced, a repository administrator may be able to see a setting but not change it.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">1. What Repository Settings Control<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Repository settings cover five broad concerns:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Area<\/th><th class=\"has-text-align-left\" data-align=\"left\">What it controls<\/th><th class=\"has-text-align-left\" data-align=\"left\">Typical owner<\/th><\/tr><\/thead><tbody><tr><td>General<\/td><td>Identity, default branch, merge behavior, features, lifecycle<\/td><td>Repository admin<\/td><\/tr><tr><td>Access<\/td><td>People, teams, roles, moderation<\/td><td>Repo admin \/ org owner<\/td><\/tr><tr><td>Code and automation<\/td><td>Rulesets, branches, Actions, webhooks, environments, Pages<\/td><td>Platform \/ DevOps \/ repo admin<\/td><\/tr><tr><td>Security and quality<\/td><td>Dependabot, code scanning, secret scanning, Code Quality, deploy keys<\/td><td>Security \/ platform \/ repo admin<\/td><\/tr><tr><td>Integrations<\/td><td>GitHub Apps, email notifications, external systems<\/td><td>Platform \/ repo admin<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">A useful mental model is:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>flowchart TD\n    E&#91;Enterprise Policy] --&gt; O&#91;Organization Policy]\n    O --&gt; R&#91;Repository Settings]\n    R --&gt; B&#91;Branch and Tag Rules]\n    R --&gt; A&#91;Actions and Automation]\n    R --&gt; S&#91;Security and Quality]\n    R --&gt; D&#91;Deployment Environments]\n    B --&gt; C&#91;Developer Contribution]\n    A --&gt; C\n    S --&gt; C\n    D --&gt; C\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>How to read the diagram:<\/strong>&nbsp;repository settings operate inside the boundaries created by enterprise and organization policies. Repository administrators can usually make a setting more restrictive, but they cannot bypass a higher-level restriction unless the higher-level policy explicitly permits it.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">1.1 Repository configuration hierarchy<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A practical precedence model is:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Enterprise policy\n        \u2193\nOrganization policy\n        \u2193\nRepository configuration\n        \u2193\nEnvironment protection\n        \u2193\nWorkflow \/ job permissions\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The lower layer cannot reliably be treated as more authoritative than the higher layer. For example, a repository cannot allow an Action that the organization has blocked.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">1.2 Repository ownership models<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">GitHub repositories can be owned by:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>A personal account<\/li>\n\n\n\n<li>An organization<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Organization repositories support richer access governance, including teams, outside collaborators, organization rulesets, custom repository roles, security managers, and enterprise policy inheritance.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">1.3 Repository visibility<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Visibility<\/th><th class=\"has-text-align-left\" data-align=\"left\">Who can normally see it<\/th><th class=\"has-text-align-left\" data-align=\"left\">Important note<\/th><\/tr><\/thead><tbody><tr><td>Public<\/td><td>Anyone<\/td><td>Code, Actions history\/logs, and public contribution surface are visible<\/td><\/tr><tr><td>Private<\/td><td>Explicitly authorized users and permitted organization members<\/td><td>Feature availability depends on plan<\/td><\/tr><tr><td>Internal<\/td><td>Enterprise members<\/td><td>Available for eligible enterprise-owned organizations<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Internal repositories are not simply \u201cprivate repositories with more users.\u201d They are designed for enterprise-wide discoverability and may grant read access broadly inside the enterprise.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">2. Prerequisites and Permissions<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Before changing repository settings, identify your role and the policy layer that owns the control.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">2.1 Common repository roles<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">For organization repositories, the standard repository roles are:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Role<\/th><th class=\"has-text-align-left\" data-align=\"left\">Typical use<\/th><th class=\"has-text-align-right\" data-align=\"right\">Can push code?<\/th><th class=\"has-text-align-left\" data-align=\"left\">Administrative capability<\/th><\/tr><\/thead><tbody><tr><td>Read<\/td><td>Viewers, auditors, non-code contributors<\/td><td class=\"has-text-align-right\" data-align=\"right\">No<\/td><td>Minimal<\/td><\/tr><tr><td>Triage<\/td><td>Issue and PR coordinators<\/td><td class=\"has-text-align-right\" data-align=\"right\">No<\/td><td>Manage issues\/PRs without code write access<\/td><\/tr><tr><td>Write<\/td><td>Developers<\/td><td class=\"has-text-align-right\" data-align=\"right\">Yes<\/td><td>Normal development operations<\/td><\/tr><tr><td>Maintain<\/td><td>Project\/repository maintainers<\/td><td class=\"has-text-align-right\" data-align=\"right\">Yes<\/td><td>Many management actions without destructive admin powers<\/td><\/tr><tr><td>Admin<\/td><td>Repository administrators<\/td><td class=\"has-text-align-right\" data-align=\"right\">Yes<\/td><td>Full repository administration, subject to org\/enterprise policy<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Organizations can also define custom repository roles on eligible plans.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">2.2 What you need for this tutorial<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Recommended:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>A GitHub organization test repository<\/li>\n\n\n\n<li>Admin access to that repository<\/li>\n\n\n\n<li>GitHub CLI installed and authenticated<\/li>\n\n\n\n<li>Git installed locally<\/li>\n\n\n\n<li>Optional: Terraform for GitHub provider examples<\/li>\n\n\n\n<li>Optional: a webhook test endpoint you control<\/li>\n\n\n\n<li>Optional: GitHub Actions enabled<\/li>\n\n\n\n<li>Optional: GitHub Advanced Security \/ Code Security \/ Secret Protection \/ Code Quality entitlements where exercises require them<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Authenticate GitHub CLI:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>gh auth login\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Confirm authentication:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>gh auth status\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Set reusable shell variables for later examples:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>export OWNER=\"your-org\"\nexport REPO=\"your-repo\"\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Verify repository access:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>gh repo view \"$OWNER\/$REPO\"\n<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">3. Repository Settings Navigation<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Open a repository and select&nbsp;<strong>Settings<\/strong>. Depending on your plan and enabled products, common areas include:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Settings area<\/th><th class=\"has-text-align-left\" data-align=\"left\">What you manage<\/th><\/tr><\/thead><tbody><tr><td>General<\/td><td>Name, default branch, releases, merge behavior, features, archives, pushes, issues, danger zone<\/td><\/tr><tr><td>Collaborators and teams<\/td><td>Direct and team access<\/td><\/tr><tr><td>Moderation<\/td><td>Interaction and review restrictions<\/td><\/tr><tr><td>Rulesets<\/td><td>Branch, tag, push, security, quality rules<\/td><\/tr><tr><td>Custom properties<\/td><td>Organization-defined repository metadata<\/td><\/tr><tr><td>Branches<\/td><td>Default branch and legacy branch protection rules<\/td><\/tr><tr><td>Tags<\/td><td>Tag-related controls where exposed<\/td><\/tr><tr><td>Actions<\/td><td>Actions permissions, workflow permissions, retention, cache, runners<\/td><\/tr><tr><td>Webhooks<\/td><td>Event delivery to external systems<\/td><\/tr><tr><td>Copilot<\/td><td>Repository Copilot controls, code review, MCP configuration<\/td><\/tr><tr><td>Planning<\/td><td>Issue templates and planning-related behavior<\/td><\/tr><tr><td>Environments<\/td><td>Deployment approvals, branches\/tags, secrets, variables<\/td><\/tr><tr><td>Pages<\/td><td>Static-site publishing<\/td><\/tr><tr><td>Advanced Security<\/td><td>Dependency, code, and secret security features<\/td><\/tr><tr><td>Code quality<\/td><td>GitHub Code Quality controls<\/td><\/tr><tr><td>Deploy keys<\/td><td>Repository-scoped SSH keys<\/td><\/tr><tr><td>Secrets and variables<\/td><td>Actions, Dependabot, Codespaces, agents where available<\/td><\/tr><tr><td>GitHub Apps<\/td><td>Apps with repository access<\/td><\/tr><tr><td>Email notifications<\/td><td>Push notification recipients<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>Important:<\/strong>&nbsp;GitHub periodically reorganizes settings navigation. Learn the underlying capability, not only the exact sidebar label.<\/p>\n<\/blockquote>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Part I \u2014 General Repository Administration<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">4. Repository Identity<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">What is it?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Repository identity includes the repository name, owner, URL, description, website, topics, and social preview.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Why does it matter?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Repository identity affects:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Clone URLs<\/li>\n\n\n\n<li>Documentation links<\/li>\n\n\n\n<li>CI\/CD references<\/li>\n\n\n\n<li>Package and deployment references<\/li>\n\n\n\n<li>Discovery and search<\/li>\n\n\n\n<li>External documentation<\/li>\n\n\n\n<li>Automation that hard-codes\u00a0<code>OWNER\/REPO<\/code><\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">4.1 Rename a repository<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Typical UI flow:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Open the repository.<\/li>\n\n\n\n<li>Select\u00a0<strong>Settings<\/strong>.<\/li>\n\n\n\n<li>Under\u00a0<strong>General<\/strong>, locate the repository name.<\/li>\n\n\n\n<li>Enter the new name.<\/li>\n\n\n\n<li>Confirm the rename.<\/li>\n\n\n\n<li>Update integrations that depend on the old path.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">GitHub generally redirects old repository web URLs and Git operations, but do not use redirects as a permanent dependency strategy.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Update a local remote after a rename:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>git remote set-url origin git@github.com:OWNER\/NEW_REPO.git\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Verify:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>git remote -v\n<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Best practices<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Recommended<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Use stable, descriptive repository names.<\/li>\n\n\n\n<li>Keep naming conventions consistent across an organization.<\/li>\n\n\n\n<li>Search CI\/CD, IaC, docs, badges, deployment systems, and package metadata before renaming.<\/li>\n\n\n\n<li>Update external consumers even when GitHub redirects continue to work.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Avoid<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Renaming repositories as a routine cosmetic operation.<\/li>\n\n\n\n<li>Depending indefinitely on old URLs.<\/li>\n\n\n\n<li>Embedding owner\/repository names in many unrelated scripts when a variable can be used.<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">5. Description, Website, Topics, and Social Preview<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Repository metadata improves discoverability and gives users immediate context.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Example metadata standard<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Field<\/th><th class=\"has-text-align-left\" data-align=\"left\">Example<\/th><\/tr><\/thead><tbody><tr><td>Repository<\/td><td><code>payment-api<\/code><\/td><\/tr><tr><td>Description<\/td><td><code>Payments API for checkout and settlement services<\/code><\/td><\/tr><tr><td>Website<\/td><td><code>https:\/\/docs.example.com\/payments<\/code><\/td><\/tr><tr><td>Topics<\/td><td><code>payments<\/code>,&nbsp;<code>golang<\/code>,&nbsp;<code>api<\/code>,&nbsp;<code>production<\/code><\/td><\/tr><tr><td>Custom property<\/td><td><code>service-tier=1<\/code><\/td><\/tr><tr><td>Custom property<\/td><td><code>owner=payments-platform<\/code><\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Use the social preview image when repository links are frequently shared in chat, documentation, or social networks.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">6. Template Repository<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A template repository provides a reusable starting point for creating new repositories.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">When to use it<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Use a template when many repositories should start with the same structure:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>.github\/\n  workflows\/\n  ISSUE_TEMPLATE\/\nCODEOWNERS\nCONTRIBUTING.md\nLICENSE\nREADME.md\nSECURITY.md\nsrc\/\ntests\/\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Typical platform-engineering use cases:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Microservice bootstrap<\/li>\n\n\n\n<li>Terraform module repository<\/li>\n\n\n\n<li>Internal library<\/li>\n\n\n\n<li>Documentation repository<\/li>\n\n\n\n<li>Standardized application repository<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Template vs fork<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Template<\/th><th class=\"has-text-align-left\" data-align=\"left\">Fork<\/th><\/tr><\/thead><tbody><tr><td>Creates an independent repository<\/td><td>Preserves fork relationship<\/td><\/tr><tr><td>No shared commit history required<\/td><td>Shares history\/network with upstream<\/td><\/tr><tr><td>Best for standardized starting structure<\/td><td>Best for contributing or maintaining a derivative<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">7. Default Branch<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The default branch is GitHub&#8217;s primary branch for operations such as pull request targets and repository browsing.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Commonly:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>main\n<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Change the default branch<\/h3>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Create the target branch if it does not exist.<\/li>\n\n\n\n<li>Open\u00a0<strong>Settings \u2192 Branches<\/strong>\u00a0or the current default-branch control.<\/li>\n\n\n\n<li>Change the default branch.<\/li>\n\n\n\n<li>Review branch protection\/rulesets.<\/li>\n\n\n\n<li>Update CI\/CD triggers, deployment rules, and external integrations.<\/li>\n\n\n\n<li>Update local clones if the branch was renamed.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">After renaming&nbsp;<code>master<\/code>&nbsp;to&nbsp;<code>main<\/code>&nbsp;locally:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>git branch -m master main\ngit fetch origin\ngit branch -u origin\/main main\ngit remote set-head origin -a\n<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">What can break?<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Workflows triggered only on the old branch<\/li>\n\n\n\n<li>Branch rules targeting the old name<\/li>\n\n\n\n<li>Pages publishing source<\/li>\n\n\n\n<li>Build\/deploy systems<\/li>\n\n\n\n<li>Documentation links<\/li>\n\n\n\n<li>Default comparison\/base behavior in external systems<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">8. Releases and Release Immutability<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">GitHub Releases combine a Git tag, release metadata, notes, and optional binary assets.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">8.1 Mutable release risk<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Without immutability, changing a release tag or replacing release assets can undermine assumptions about provenance and artifact integrity.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">8.2 Release immutability<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">GitHub now supports&nbsp;<strong>release immutability<\/strong>. When enabled, it applies to future releases and is intended to prevent changes to published release tags\/assets that would make a release no longer represent a fixed artifact set.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Typical flow:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Open\u00a0<strong>Settings \u2192 General<\/strong>.<\/li>\n\n\n\n<li>Locate\u00a0<strong>Releases<\/strong>.<\/li>\n\n\n\n<li>Enable release immutability.<\/li>\n\n\n\n<li>Publish releases only after validation is complete.<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">Recommended release flow<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>flowchart LR\n    C&#91;Commit] --&gt; T&#91;Create Tag]\n    T --&gt; B&#91;Build Artifact]\n    B --&gt; S&#91;Sign and Attest]\n    S --&gt; R&#91;Publish Release]\n    R --&gt; I&#91;Immutable Release]\n<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Best practice<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">For production software, combine:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Protected release tags or tag rulesets<\/li>\n\n\n\n<li>Release immutability<\/li>\n\n\n\n<li>Artifact attestations where applicable<\/li>\n\n\n\n<li>Pinned dependencies<\/li>\n\n\n\n<li>Reproducible build practices<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">9. Repository Features<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Repositories can expose optional collaboration features such as:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Issues<\/li>\n\n\n\n<li>Wikis<\/li>\n\n\n\n<li>Discussions<\/li>\n\n\n\n<li>Projects integration<\/li>\n\n\n\n<li>Actions<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Feature availability can depend on plan and policy.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">9.1 Wikis<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Use a repository Wiki for repository-specific documentation when you want Git-backed pages managed separately from the primary code tree.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Prefer&nbsp;<code>\/docs<\/code>&nbsp;or a dedicated documentation site when documentation must be versioned with application code, reviewed through pull requests, or published through a docs pipeline.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">9.2 Issues<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Issues support:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Bugs<\/li>\n\n\n\n<li>Feature requests<\/li>\n\n\n\n<li>Operational work<\/li>\n\n\n\n<li>Tasks<\/li>\n\n\n\n<li>Labels<\/li>\n\n\n\n<li>Assignees<\/li>\n\n\n\n<li>Milestones<\/li>\n\n\n\n<li>Parent\/sub-issue relationships where available<\/li>\n\n\n\n<li>Project integration<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">9.3 Discussions<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Use Discussions for conversations that should not immediately become tracked work:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Q&amp;A<\/li>\n\n\n\n<li>Design discussion<\/li>\n\n\n\n<li>Community support<\/li>\n\n\n\n<li>Announcements<\/li>\n\n\n\n<li>Ideas<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">9.4 Projects<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">GitHub Projects can organize issues, pull requests, and draft items into views and workflows. Repository settings can expose or connect planning surfaces, while most Project configuration itself belongs to the Project rather than the repository.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">10. Pull Request Merge Methods<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">GitHub commonly supports three merge strategies:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Method<\/th><th class=\"has-text-align-left\" data-align=\"left\">Result<\/th><th class=\"has-text-align-left\" data-align=\"left\">Best fit<\/th><\/tr><\/thead><tbody><tr><td>Merge commit<\/td><td>Preserves branch commits plus merge commit<\/td><td>Teams that value branch history<\/td><\/tr><tr><td>Squash merge<\/td><td>Combines PR into one commit<\/td><td>Clean main-branch history<\/td><\/tr><tr><td>Rebase merge<\/td><td>Replays commits linearly<\/td><td>Teams that want individual commits without merge commits<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">10.1 Merge commit configuration<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Repositories can control default merge commit title\/message behavior.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">10.2 Squash configuration<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Repositories can choose how the squash commit title\/message is generated from PR title, description, or commits.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">10.3 Which should you choose?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A common service repository policy is:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Squash merge: enabled\nMerge commit: disabled\nRebase merge: optional\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">This is not universally best. Libraries or repositories where individual commits carry meaningful history may prefer rebase or merge commits.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">11. Pull Request Update Behavior<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The repository can allow GitHub to suggest updating a pull request branch when the base branch advances.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is useful when:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Required status checks must run against recent base changes<\/li>\n\n\n\n<li>Merge requirements require the branch to be current<\/li>\n\n\n\n<li>Teams want fewer manual\u00a0<code>git merge main<\/code>\u00a0operations<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Do not confuse \u201csuggest update branch\u201d with a protection rule that requires branches to be up to date before merge.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">12. Auto-Merge<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Auto-merge lets a pull request merge automatically after all required conditions are satisfied.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Typical requirements:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Required reviews complete<\/li>\n\n\n\n<li>Required status checks pass<\/li>\n\n\n\n<li>Required deployments pass<\/li>\n\n\n\n<li>Ruleset\/branch-protection conditions satisfied<\/li>\n\n\n\n<li>No unresolved blocking conditions<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Use it to reduce waiting after a PR is already approved but still waiting for CI.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">13. Automatic Head-Branch Deletion<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Automatically deleting head branches after merge reduces stale branch clutter.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Recommended for most short-lived feature-branch workflows.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A deleted branch can often be restored from the merged pull request when GitHub still retains the relationship.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">14. Source Archives and Git LFS<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">GitHub can generate source archives such as ZIP and tarball downloads.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Repositories that use Git LFS can control whether LFS objects are included in generated archives.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Decision<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Requirement<\/th><th class=\"has-text-align-left\" data-align=\"left\">Recommendation<\/th><\/tr><\/thead><tbody><tr><td>Users expect a self-contained archive<\/td><td>Include required LFS objects<\/td><\/tr><tr><td>LFS assets are large and unnecessary for source review<\/td><td>Exclude them<\/td><\/tr><tr><td>Release requires deterministic binaries<\/td><td>Prefer explicit release artifacts rather than source archive behavior<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">15. Push Policy<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Repository push policy can limit how many branches and tags are updated in a single push.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is useful for reducing accidental large-scale ref updates and making unusually broad pushes more visible.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It is not a replacement for rulesets or branch protection.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">16. Web Commit Signoff<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">GitHub can require users making commits through the web interface to sign off commits.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A signoff commonly adds a trailer similar to:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Signed-off-by: Developer Name &lt;developer@example.com&gt;\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">This is commonly used with Developer Certificate of Origin style contribution policies.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">A signoff is not the same as cryptographic commit signing. A&nbsp;<code>Signed-off-by<\/code>&nbsp;trailer records an attestation statement; a signed commit uses GPG, SSH, or S\/MIME verification.<\/p>\n<\/blockquote>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">17. Automatic Issue Closing<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">GitHub can automatically close issues when a linked pull request is merged and closing syntax\/relationships are satisfied.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Common closing keywords include forms such as:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Fixes #123\nCloses #123\nResolves #123\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Repository settings can control whether linked issues are automatically closed when merged PRs complete.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Use explicit references in PR descriptions so issue lifecycle remains easy to audit.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">18. Autolink References<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Autolinks turn external identifiers into clickable links.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Example:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>JIRA-142\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">can become a link to:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>https:&#47;&#47;jira.example.com\/browse\/JIRA-142\n<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Use cases<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Jira<\/li>\n\n\n\n<li>Zendesk<\/li>\n\n\n\n<li>Internal change-management tickets<\/li>\n\n\n\n<li>Incident IDs<\/li>\n\n\n\n<li>Customer support references<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Best practice<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Use a distinctive prefix that does not collide with normal text.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Part II \u2014 Danger Zone and Repository Lifecycle Actions<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">19. Change Repository Visibility<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Visibility changes can have major side effects.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Important consequences<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Depending on the direction of the change, GitHub may change or remove:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Stars and watchers<\/li>\n\n\n\n<li>Fork network relationships<\/li>\n\n\n\n<li>Push rulesets<\/li>\n\n\n\n<li>Pages behavior<\/li>\n\n\n\n<li>Code scanning availability<\/li>\n\n\n\n<li>Dependabot custom rules<\/li>\n\n\n\n<li>Actions log visibility<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">For example, changing a private or internal repository to public exposes the code and Actions history\/logs publicly and disables push rulesets that are limited to private\/internal fork networks.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Safe change procedure<\/h3>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Inventory forks.<\/li>\n\n\n\n<li>Inventory Pages\/custom domains.<\/li>\n\n\n\n<li>Review Actions logs for sensitive information.<\/li>\n\n\n\n<li>Review security feature licensing impact.<\/li>\n\n\n\n<li>Review organization\/enterprise policy.<\/li>\n\n\n\n<li>Communicate the change.<\/li>\n\n\n\n<li>Change visibility.<\/li>\n\n\n\n<li>Re-validate security controls.<\/li>\n<\/ol>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">20. Transfer a Repository<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A repository can be transferred to another eligible user or organization.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Transferred content generally includes important repository resources such as:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Git history<\/li>\n\n\n\n<li>Issues<\/li>\n\n\n\n<li>Pull requests<\/li>\n\n\n\n<li>Wiki<\/li>\n\n\n\n<li>Releases<\/li>\n\n\n\n<li>Stars\/watchers<\/li>\n\n\n\n<li>Webhooks<\/li>\n\n\n\n<li>Secrets<\/li>\n\n\n\n<li>Deploy keys<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Package behavior can vary by package registry and permission model, so validate package ownership separately.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Transfer checklist<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>&#91; ] Destination allows repository creation\/transfer\n&#91; ] No destination name conflict\n&#91; ] Teams\/access model reviewed\n&#91; ] Organization default permissions reviewed\n&#91; ] Apps\/integrations reviewed\n&#91; ] Packages reviewed\n&#91; ] Actions\/reusable workflow access reviewed\n&#91; ] Secrets and environment policies reviewed\n&#91; ] External webhooks and allowlists reviewed\n<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">21. Archive a Repository<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Archiving makes a repository read-only and signals that active maintenance has ended.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Before archiving:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Close or document open issues and pull requests.<\/li>\n\n\n\n<li>Add a deprecation or successor notice to the README.<\/li>\n\n\n\n<li>Disable or retire external automation where appropriate.<\/li>\n\n\n\n<li>Document ownership.<\/li>\n\n\n\n<li>Confirm downstream consumers have migrated.<\/li>\n\n\n\n<li>Archive the repository.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Archived content becomes read-only. Secret scanning availability for archived repositories depends on enabled security products.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">22. Delete and Restore a Repository<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Deletion is destructive. Organization\/enterprise policy can restrict who may delete repositories.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Key behavior<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Deleting a private\/internal repository deletes its forks.<\/li>\n\n\n\n<li>Deleting a public repository does not necessarily delete public forks.<\/li>\n\n\n\n<li>Team permissions are permanently deleted with the repository.<\/li>\n\n\n\n<li>Some deleted repositories can be restored within\u00a0<strong>90 days<\/strong>.<\/li>\n\n\n\n<li>Restoration has limitations for non-empty fork networks.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Production deletion checklist<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>&#91; ] Business owner approval\n&#91; ] Repository archived\/exported if required\n&#91; ] Packages checked\n&#91; ] Releases\/artifacts backed up if required\n&#91; ] Secrets revoked\n&#91; ] Deploy keys revoked\n&#91; ] Webhooks disabled\n&#91; ] CI\/CD dependencies mapped\n&#91; ] Downstream code dependencies mapped\n&#91; ] Fork impact reviewed\n&#91; ] Retention\/compliance requirement reviewed\n<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Part III \u2014 Access Management and Moderation<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">23. Repository Access Model<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Organization repositories may receive access from several paths:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>flowchart TD\n    U&#91;User] --&gt; D&#91;Direct Repository Access]\n    U --&gt; T&#91;Team Membership]\n    T --&gt; R&#91;Repository Role]\n    U --&gt; O&#91;Organization Base Permission]\n    O --&gt; R\n    D --&gt; R\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">A user can therefore have multiple routes to the same repository. Always troubleshoot&nbsp;<strong>effective access<\/strong>, not just direct access.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">23.1 Direct access<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Direct access is useful for exceptional cases but becomes hard to govern at scale.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">23.2 Team access<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Preferred for stable organizational access:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Team: payments-developers \u2192 Write\nTeam: payments-maintainers \u2192 Maintain\nTeam: security-reviewers \u2192 Read\nTeam: platform-admins \u2192 Admin\n<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">23.3 Outside collaborators<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Outside collaborators can be granted repository access without organization membership. Treat them as a distinct lifecycle:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Sponsor required<\/li>\n\n\n\n<li>Explicit expiration\/review<\/li>\n\n\n\n<li>Least privilege<\/li>\n\n\n\n<li>2FA\/identity requirements according to organization policy<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">24. Access Review Procedure<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">At least periodically:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Open\u00a0<strong>Settings \u2192 Collaborators and teams<\/strong>.<\/li>\n\n\n\n<li>Export or record people and teams with access where supported.<\/li>\n\n\n\n<li>Identify direct collaborators.<\/li>\n\n\n\n<li>Identify outside collaborators.<\/li>\n\n\n\n<li>Check inherited\/base access.<\/li>\n\n\n\n<li>Validate team ownership.<\/li>\n\n\n\n<li>Reduce over-privileged roles.<\/li>\n\n\n\n<li>Remove stale access.<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">Access review table<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Actor<\/th><th class=\"has-text-align-left\" data-align=\"left\">Access source<\/th><th class=\"has-text-align-left\" data-align=\"left\">Current role<\/th><th class=\"has-text-align-left\" data-align=\"left\">Needed role<\/th><th class=\"has-text-align-left\" data-align=\"left\">Action<\/th><\/tr><\/thead><tbody><tr><td><code>payments-dev<\/code><\/td><td>Team<\/td><td>Write<\/td><td>Write<\/td><td>Keep<\/td><\/tr><tr><td><code>alice<\/code><\/td><td>Direct<\/td><td>Admin<\/td><td>Maintain<\/td><td>Reduce<\/td><\/tr><tr><td><code>vendor-user<\/code><\/td><td>Outside collaborator<\/td><td>Write<\/td><td>Read<\/td><td>Reduce<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">25. Moderation and Interaction Limits<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Public repositories may need controls against spam or contribution floods.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">GitHub interaction limits can temporarily restrict users based on categories such as:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Newer\/existing-user status<\/li>\n\n\n\n<li>Prior contribution history<\/li>\n\n\n\n<li>Collaborator status<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Common durations include temporary windows from one day through several months.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Current GitHub also supports controls that can limit the number of concurrent open pull requests from users without write access, with bypasses for trusted contributors.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">When to use moderation controls<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Spam wave<\/li>\n\n\n\n<li>Coordinated abuse<\/li>\n\n\n\n<li>Event-driven contribution spike<\/li>\n\n\n\n<li>CI exhaustion caused by excessive PR creation<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Avoid<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Do not keep emergency interaction limits enabled forever without review. Long-lived governance should be handled with contribution policy, access controls, automation, and moderation processes.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">26. Pull Request Review Restrictions<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">For applicable public-repository workflows, GitHub can restrict who may approve or request changes on pull requests.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Use this when review actions must come from trusted collaborators rather than any external participant.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Part IV \u2014 Rulesets, Branches, and Tags<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">27. Rulesets Fundamentals<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Rulesets are GitHub&#8217;s modern policy mechanism for branches, tags, and pushes.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Rulesets improve on legacy branch protection in several ways:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Multiple rulesets can apply simultaneously.<\/li>\n\n\n\n<li>Rules are aggregated.<\/li>\n\n\n\n<li>Read users can inspect applicable active rules.<\/li>\n\n\n\n<li>Organization-level rulesets can target multiple repositories.<\/li>\n\n\n\n<li>Push rulesets can protect an entire private\/internal fork network.<\/li>\n\n\n\n<li>Rule insights can show pass, fail, and bypass activity.<\/li>\n\n\n\n<li>Evaluate mode can test rules without blocking contributors where supported.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">27.1 Ruleset targets<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Ruleset type<\/th><th class=\"has-text-align-left\" data-align=\"left\">Protects<\/th><\/tr><\/thead><tbody><tr><td>Branch ruleset<\/td><td>Selected branches<\/td><\/tr><tr><td>Tag ruleset<\/td><td>Selected tags<\/td><\/tr><tr><td>Push ruleset<\/td><td>Push content across a private\/internal repository fork network<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">27.2 Enforcement states<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Common states are:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Active<\/strong>\u00a0\u2014 enforce now<\/li>\n\n\n\n<li><strong>Evaluate<\/strong>\u00a0\u2014 observe would-pass\/would-fail behavior where available<\/li>\n\n\n\n<li><strong>Disabled<\/strong>\u00a0\u2014 neither enforce nor evaluate<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Availability of Evaluate can depend on ownership\/plan.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">28. Ruleset Targeting<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Branch and tag rulesets support include\/exclude targeting and pattern matching.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Examples:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>main\nrelease\/*\nreleases\/**\/*\nv*\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">GitHub uses&nbsp;<code>fnmatch<\/code>&nbsp;semantics for relevant branch\/tag targeting controls.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Example policy<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>Include: default branch\nInclude: release\/*\nExclude: release\/sandbox\/*\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Keep patterns understandable. A policy nobody can reason about is difficult to audit.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">29. Ruleset Bypass<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A ruleset can grant bypass capability to eligible actors such as:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Repository admins \/ organization or enterprise owners where eligible<\/li>\n\n\n\n<li>Selected repository roles<\/li>\n\n\n\n<li>Teams<\/li>\n\n\n\n<li>GitHub Apps<\/li>\n\n\n\n<li>Dependabot in supported cases<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">GitHub can also support a&nbsp;<strong>pull-request-only<\/strong>&nbsp;bypass mode, which permits a trusted actor to bypass certain rules through PR flow without granting unrestricted direct push behavior.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Best practice<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Treat bypass as break-glass access:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Small bypass group\n        +\nAuditable reason\n        +\nRule Insights review\n        +\nPeriodic access review\n<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">30. Branch and Tag Rules<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Available rules vary, but important controls include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Restrict creations<\/li>\n\n\n\n<li>Restrict updates<\/li>\n\n\n\n<li>Restrict deletions<\/li>\n\n\n\n<li>Require pull requests before merging<\/li>\n\n\n\n<li>Require approvals<\/li>\n\n\n\n<li>Require code-owner review<\/li>\n\n\n\n<li>Require status checks<\/li>\n\n\n\n<li>Require deployments<\/li>\n\n\n\n<li>Require conversation resolution as part of applicable PR rules<\/li>\n\n\n\n<li>Require signed commits<\/li>\n\n\n\n<li>Require linear history<\/li>\n\n\n\n<li>Block force pushes<\/li>\n\n\n\n<li>Require code scanning results<\/li>\n\n\n\n<li>Require secret scanning resolution<\/li>\n\n\n\n<li>Require Code Quality results<\/li>\n\n\n\n<li>Restrict code coverage<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Production default-branch baseline<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A reasonable starting baseline for many teams is:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Target: default branch\nRequire pull request: yes\nRequired approvals: 1 or 2 based on risk\nRequire code owners: for sensitive paths\nDismiss stale approvals: based on risk\nRequire status checks: build + test + security\nRequire conversation resolution: yes\nBlock force push: yes\nRestrict deletion: yes\nRequire signed commits: optional based on identity model\nRequire deployments: only when merge policy depends on staged validation\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Do not blindly apply every control. Every requirement adds friction and should map to a real risk.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">31. Push Rules<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Push rulesets can block pushes based on content such as:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>File paths<\/li>\n\n\n\n<li>File path length<\/li>\n\n\n\n<li>File extensions<\/li>\n\n\n\n<li>File size<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">They apply to private\/internal repositories and their fork networks where the feature is available.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Example uses<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Block accidental binaries:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>*.exe\n*.dll\n*.iso\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Block sensitive local configuration:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>.env\nsecrets\/**\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Protect CI definitions from broad unreviewed changes by combining path rules with branch\/PR governance rather than relying on a single control.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">32. Security and Quality Rules<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Rulesets can make security\/quality analysis part of merge governance.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">32.1 Require code scanning results<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Use when a required scanner such as CodeQL must complete and stay below a configured severity threshold.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">32.2 Require secret scanning alerts resolved<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Use to stop merging when relevant newly introduced secrets remain unresolved.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">32.3 Require Code Quality results<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Use to block pull requests when GitHub Code Quality exceeds a selected severity threshold.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">32.4 Restrict code coverage<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Use when coverage is collected and a defined coverage rule should be enforced.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">33. Ruleset Administration<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Typical lifecycle:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>flowchart LR\n    D&#91;Design Rule] --&gt; E&#91;Evaluate]\n    E --&gt; I&#91;Inspect Insights]\n    I --&gt; T&#91;Tune Rule]\n    T --&gt; A&#91;Activate]\n    A --&gt; M&#91;Monitor Bypasses]\n<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Recommended rollout<\/h3>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Document desired policy.<\/li>\n\n\n\n<li>Create ruleset.<\/li>\n\n\n\n<li>Use Evaluate mode where supported.<\/li>\n\n\n\n<li>Review rule insights.<\/li>\n\n\n\n<li>Fix workflows or unnecessary blockers.<\/li>\n\n\n\n<li>Activate.<\/li>\n\n\n\n<li>Review bypass and failure trends.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Rulesets can also be imported\/exported and managed via REST\/GraphQL APIs.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">34. Custom Properties<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Custom properties are organization-defined structured metadata attached to repositories.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Supported property types include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Text<\/li>\n\n\n\n<li>True\/false<\/li>\n\n\n\n<li>Single select<\/li>\n\n\n\n<li>Multi select<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Useful property schema<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Property<\/th><th class=\"has-text-align-left\" data-align=\"left\">Type<\/th><th class=\"has-text-align-left\" data-align=\"left\">Example<\/th><\/tr><\/thead><tbody><tr><td><code>owner_team<\/code><\/td><td>Single select<\/td><td><code>payments<\/code><\/td><\/tr><tr><td><code>service_tier<\/code><\/td><td>Single select<\/td><td><code>tier-1<\/code><\/td><\/tr><tr><td><code>production<\/code><\/td><td>Boolean<\/td><td><code>true<\/code><\/td><\/tr><tr><td><code>data_classification<\/code><\/td><td>Single select<\/td><td><code>confidential<\/code><\/td><\/tr><tr><td><code>lifecycle<\/code><\/td><td>Single select<\/td><td><code>active<\/code><\/td><\/tr><tr><td><code>technology<\/code><\/td><td>Multi select<\/td><td><code>go<\/code>,&nbsp;<code>postgres<\/code><\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">Why properties matter<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">They can support:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Repository discovery<\/li>\n\n\n\n<li>Ruleset targeting<\/li>\n\n\n\n<li>Governance<\/li>\n\n\n\n<li>Automation<\/li>\n\n\n\n<li>Ownership reporting<\/li>\n\n\n\n<li>Compliance inventory<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">A mature organization should prefer structured properties over encoding all metadata in repository names.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">35. Branch Administration<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Typical branch operations include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Rename<\/li>\n\n\n\n<li>Delete<\/li>\n\n\n\n<li>Restore<\/li>\n\n\n\n<li>Change default branch<\/li>\n\n\n\n<li>View protection\/rules<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Branch naming example<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>feature\/ABC-123-add-tax-rule\nbugfix\/ABC-456-fix-rounding\nrelease\/2026.09\nhotfix\/ABC-999-payment-timeout\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Branch naming conventions should support humans and automation without becoming unnecessarily rigid.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">36. Legacy Branch Protection vs Rulesets<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Legacy branch protection remains supported, but rulesets provide a more composable governance model.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Branch protection<\/th><th class=\"has-text-align-left\" data-align=\"left\">Rulesets<\/th><\/tr><\/thead><tbody><tr><td>Only one matching branch-protection rule ultimately applies<\/td><td>Multiple rulesets can apply together<\/td><\/tr><tr><td>Older policy model<\/td><td>Newer policy model<\/td><\/tr><tr><td>Repository-focused<\/td><td>Repository and organization governance<\/td><\/tr><tr><td>Limited aggregate visibility<\/td><td>Better rule visibility and insights<\/td><\/tr><tr><td>No push-content ruleset model<\/td><td>Push rulesets available where eligible<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">GitHub provides conversion flows from branch protection to rulesets.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Migration approach<\/h3>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Identify existing branch protection.<\/li>\n\n\n\n<li>Convert to ruleset.<\/li>\n\n\n\n<li>Use Evaluate mode if available.<\/li>\n\n\n\n<li>Compare behavior.<\/li>\n\n\n\n<li>Delete the old protection only after validation.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Be aware that not every legacy setting maps one-to-one in every scenario.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">37. Tags and Tag Rulesets<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Tags frequently represent release boundaries, so tag mutation should be treated as a supply-chain concern.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A tag ruleset can restrict:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Tag creation<\/li>\n\n\n\n<li>Tag updates<\/li>\n\n\n\n<li>Tag deletion<\/li>\n\n\n\n<li>Matching tag patterns<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Example:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>v*\nrelease-*\nprod-*\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">For production release tags, combine tag governance with release immutability.<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">Part V \u2014 GitHub Actions Repository Settings<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">38. Actions Permissions<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Repository Actions settings control whether workflows can run and which Actions or reusable workflows they may call.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Common policy choices include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Disable Actions entirely<\/li>\n\n\n\n<li>Allow all actions and reusable workflows<\/li>\n\n\n\n<li>Allow actions\/reusable workflows owned by your organization<\/li>\n\n\n\n<li>Allow selected actions\/reusable workflows<\/li>\n\n\n\n<li>Allow GitHub-owned actions<\/li>\n\n\n\n<li>Allow verified Marketplace creators where policy permits<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Higher-level organization or enterprise policy can restrict these options.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Why this matters<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Every third-party Action is code executed inside your CI\/CD trust boundary. Treat it like a software dependency.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Recommended model<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>Enterprise baseline\n        \u2193\nOrganization allowlist\n        \u2193\nRepository-specific narrowing\n        \u2193\nWorkflow-level least privilege\n<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Example allowlist philosophy<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>Allow:\n- actions\/checkout pinned to a trusted version or SHA\n- actions\/setup-node pinned\n- actions\/cache pinned\n- organization-owned reusable workflows\n\nReview before allowing:\n- Unverified third-party actions\n- Actions with broad token permissions\n- Actions that download\/execute remote scripts\n<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">39. Workflow Permissions and&nbsp;<code>GITHUB_TOKEN<\/code><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Every GitHub Actions job can receive a repository-scoped&nbsp;<code>GITHUB_TOKEN<\/code>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Repository settings provide a default permission model, commonly either:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Restricted read access<\/li>\n\n\n\n<li>Read\/write access<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Workflow YAML can then further reduce permissions.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Recommended pattern<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Set a restrictive repository default, then grant only what a workflow requires.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>name: CI\n\non:\n  pull_request:\n  push:\n    branches:\n      - main\n\npermissions:\n  contents: read\n\njobs:\n  test:\n    runs-on: ubuntu-latest\n    steps:\n      - uses: actions\/checkout@v7\n      - run: echo \"Run tests here\"\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">A release workflow may need more:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>permissions:\n  contents: write\n  id-token: write\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\"><code>id-token: write<\/code>&nbsp;is commonly used for OIDC federation to cloud providers. It does not by itself grant cloud permissions; the cloud trust policy decides what the issued identity may do.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Pull request creation\/approval<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Repository settings can also control whether GitHub Actions is allowed to create and approve pull requests with&nbsp;<code>GITHUB_TOKEN<\/code>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Keep this disabled unless automation genuinely requires it.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">40. Fork Pull Request Workflows<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Workflows triggered from forks are a special security boundary because the contributor may control code executed by the workflow.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Key questions:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Does the workflow receive a write-capable token?<\/li>\n\n\n\n<li>Are repository secrets available?<\/li>\n\n\n\n<li>Does a maintainer need to approve the run?<\/li>\n\n\n\n<li>Is the event\u00a0<code>pull_request<\/code>\u00a0or\u00a0<code>pull_request_target<\/code>?<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Safe principle<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Treat code from an untrusted fork as untrusted input.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Never expose production credentials simply because a pull request needs CI.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">41. Private Actions and Reusable Workflow Access<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A private repository can contain:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Composite\/Docker\/JavaScript Actions<\/li>\n\n\n\n<li>Reusable workflows<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Repository settings can control whether other repositories in the same user\/organization context can access them.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Real-world pattern<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>platform-workflows\n  .github\/workflows\/build.yml\n  .github\/workflows\/deploy.yml\n\nservice-a\n  calls platform-workflows\/build.yml\n\nservice-b\n  calls platform-workflows\/build.yml\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Central reusable workflows reduce policy drift but create a shared dependency. Protect the reusable-workflow repository with stronger change control than an ordinary application repository.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">42. Workflow, Check, Status, Artifact, and Log Retention<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">GitHub lets repository administrators configure retention for workflow-related data subject to organization\/enterprise maximums.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Current September 2026 note<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">GitHub documentation states that beginning&nbsp;<strong>October 1, 2026<\/strong>, configured retention policies will also apply to checks, workflow runs, and commit statuses. Until that date, those objects may be retained for 400+ days even when a shorter retention setting is configured. Artifacts and logs already follow the configured retention behavior.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Typical configured ranges:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Repository type<\/th><th class=\"has-text-align-left\" data-align=\"left\">Configurable retention<\/th><\/tr><\/thead><tbody><tr><td>Public<\/td><td>1\u201390 days<\/td><\/tr><tr><td>Private\/internal<\/td><td>1\u2013400 days<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The default is commonly 90 days, subject to higher-level policy.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Choosing retention<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Repository<\/th><th class=\"has-text-align-left\" data-align=\"left\">Example policy<\/th><\/tr><\/thead><tbody><tr><td>Public OSS<\/td><td>30\u201390 days<\/td><\/tr><tr><td>Standard internal app<\/td><td>30\u201390 days<\/td><\/tr><tr><td>Regulated release pipeline<\/td><td>Align with audit evidence requirement<\/td><\/tr><tr><td>High-volume test repository<\/td><td>Shorter if compliance allows<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Do not use Actions retention as your only long-term audit archive when legal or regulatory evidence must be preserved independently.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">43. Actions Cache Settings<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">GitHub can configure repository cache retention and a total cache size eviction limit.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Current documented defaults include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Cache retention: 7 days<\/li>\n\n\n\n<li>Total cache size limit: 10 GB<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">For eligible plans, administrators can raise limits within GitHub and organization maximums. GitHub documentation currently describes up to 90 days for public repositories and 365 days for private\/internal repositories, with repository cache-size limits up to higher account-specific maximums.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Cache is not artifact storage<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Cache<\/th><th class=\"has-text-align-left\" data-align=\"left\">Artifact<\/th><\/tr><\/thead><tbody><tr><td>Speeds future workflow runs<\/td><td>Preserves workflow output<\/td><\/tr><tr><td>Eviction expected<\/td><td>Retained for configured evidence\/output period<\/td><\/tr><tr><td>Key-based retrieval<\/td><td>Run-associated download<\/td><\/tr><tr><td>Should be reproducible<\/td><td>May contain release\/test evidence<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">44. Repository Runners<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A repository can use:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>GitHub-hosted runners<\/li>\n\n\n\n<li>Repository self-hosted runners<\/li>\n\n\n\n<li>Organization runners<\/li>\n\n\n\n<li>Enterprise runners<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Repository-scoped self-hosted runner<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Use only when the runner should be dedicated to one repository.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Organization runner<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Prefer when multiple repositories need the same controlled execution environment.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Security rule<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A self-hosted runner executes repository-controlled workflow code on infrastructure you operate. Protect it accordingly.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Recommended<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Ephemeral runners for untrusted or high-risk workloads<\/li>\n\n\n\n<li>Network segmentation<\/li>\n\n\n\n<li>Minimal credentials<\/li>\n\n\n\n<li>Short-lived OIDC credentials<\/li>\n\n\n\n<li>Patch automation<\/li>\n\n\n\n<li>Runner groups for scope control<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Avoid<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Long-lived cloud keys on the host<\/li>\n\n\n\n<li>Shared production network access for arbitrary PR jobs<\/li>\n\n\n\n<li>Reusing a dirty workspace for unrelated security domains<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Part VI \u2014 Webhooks<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">45. Repository Webhooks<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Webhooks send HTTP requests to external services when selected GitHub events occur.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Core settings<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Payload URL<\/li>\n\n\n\n<li>Content type<\/li>\n\n\n\n<li>Secret<\/li>\n\n\n\n<li>SSL verification<\/li>\n\n\n\n<li>Event subscriptions<\/li>\n\n\n\n<li>Active\/inactive state<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Typical events<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><code>push<\/code><\/li>\n\n\n\n<li><code>pull_request<\/code><\/li>\n\n\n\n<li><code>issues<\/code><\/li>\n\n\n\n<li><code>release<\/code><\/li>\n\n\n\n<li><code>deployment<\/code><\/li>\n\n\n\n<li>workflow-related events<\/li>\n\n\n\n<li>package events<\/li>\n\n\n\n<li>repository events<\/li>\n\n\n\n<li>security events where supported<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Architecture<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>flowchart LR\n    G&#91;GitHub Event] --&gt; W&#91;Webhook Delivery]\n    W --&gt; A&#91;Receiver API]\n    A --&gt; V&#91;Verify Signature]\n    V --&gt; Q&#91;Queue or Worker]\n    Q --&gt; B&#91;Business Logic]\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Do not perform expensive processing before validating the request.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">46. Webhook Security<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Use HTTPS and configure a strong webhook secret.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">GitHub signs webhook payloads. The receiver should verify the signature from the&nbsp;<code>X-Hub-Signature-256<\/code>&nbsp;header using HMAC SHA-256.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Python verification example<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>import hashlib\nimport hmac\n\n\ndef valid_signature(secret: bytes, body: bytes, header: str) -&gt; bool:\n    expected = \"sha256=\" + hmac.new(\n        secret,\n        body,\n        hashlib.sha256,\n    ).hexdigest()\n\n    return hmac.compare_digest(expected, header)\n<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Important controls<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Verify the signature before parsing trusted fields.<\/li>\n\n\n\n<li>Use constant-time comparison.<\/li>\n\n\n\n<li>Keep the webhook secret out of source code.<\/li>\n\n\n\n<li>Reject unexpected content types.<\/li>\n\n\n\n<li>Consider idempotency\/replay handling.<\/li>\n\n\n\n<li>Log the GitHub delivery ID for troubleshooting.<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">47. Webhook Delivery Operations<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">GitHub provides delivery history that can show:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Request headers<\/li>\n\n\n\n<li>Request payload<\/li>\n\n\n\n<li>Response status<\/li>\n\n\n\n<li>Response body<\/li>\n\n\n\n<li>Delivery duration<\/li>\n\n\n\n<li>Redelivery controls<\/li>\n\n\n\n<li>Ping\/test deliveries<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Troubleshooting flow<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>flowchart TD\n    F&#91;Webhook Failed] --&gt; D&#91;Open Delivery]\n    D --&gt; S{HTTP Status}\n    S --&gt;|2xx| L&#91;Inspect Receiver Logic]\n    S --&gt;|4xx| A&#91;Check Auth or Payload]\n    S --&gt;|5xx| E&#91;Check Server Error]\n    S --&gt;|Timeout| N&#91;Check Network and Latency]\n<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Part VII \u2014 Copilot Repository Settings<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">48. Copilot Repository Controls<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Copilot repository settings are increasingly important because GitHub now supports repository-level behavior for code review and cloud agents.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Availability depends on:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Copilot plan<\/li>\n\n\n\n<li>Organization\/enterprise policy<\/li>\n\n\n\n<li>Feature rollout<\/li>\n\n\n\n<li>Repository eligibility<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">49. Copilot Code Review<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Copilot code review can review pull requests and use repository-specific instructions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Repository admins can control whether custom instructions are used for Copilot reviews.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Repository-wide instruction file<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>.github\/copilot-instructions.md\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Example:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># Repository review instructions\n\n- Prefer small, backward-compatible changes.\n- Flag SQL queries that do not use parameter binding.\n- Require unit tests for new business logic.\n- Do not suggest changing public API behavior without documenting migration impact.\n<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Path-specific instructions<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">GitHub supports path-specific instruction files under patterns such as:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>.github\/instructions\/*.instructions.md\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Use these when different areas of a monorepo need different standards.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Agent instruction files<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">GitHub Copilot features can also consume agent-oriented repository context such as&nbsp;<code>AGENTS.md<\/code>, depending on the Copilot experience being used.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The source syllabus also lists&nbsp;<code>CLAUDE.md<\/code>&nbsp;and&nbsp;<code>GEMINI.md<\/code>; these are agent\/tool-specific files rather than universal GitHub repository settings. Do not assume every GitHub Copilot surface consumes every third-party agent file. Verify support for the exact Copilot feature before standardizing around them.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">50. Copilot MCP Servers<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">GitHub supports repository-level Model Context Protocol configuration for Copilot cloud agent and Copilot code review.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What MCP does<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">MCP allows Copilot to call approved tools exposed by configured MCP servers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Examples:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Internal documentation search<\/li>\n\n\n\n<li>Issue tracker lookup<\/li>\n\n\n\n<li>Service catalog lookup<\/li>\n\n\n\n<li>Test tools<\/li>\n\n\n\n<li>Incident context<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Security warning<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Configured MCP tools can be invoked autonomously by supported Copilot agents. Treat an MCP server as privileged integration code.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Recommended<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Allowlist specific tools<\/li>\n\n\n\n<li>Prefer read-only tools for review use cases<\/li>\n\n\n\n<li>Scope secrets narrowly<\/li>\n\n\n\n<li>Validate tool output<\/li>\n\n\n\n<li>Avoid broad filesystem\/network access<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">GitHub currently documents built-in GitHub and Playwright MCP integrations in this area, and repository MCP configuration can be shared between Copilot cloud agent and code review.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Current limitation to understand<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Support differs by Copilot surface. For example, code review applies safety constraints to tools and expects read-only semantics for supported MCP review tools.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">51. Copilot Cloud Agent \/ Coding Agent<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Repository configuration for cloud agents may include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Repository access<\/li>\n\n\n\n<li>Development environment setup<\/li>\n\n\n\n<li>Agent instructions<\/li>\n\n\n\n<li>Agent secrets<\/li>\n\n\n\n<li>Agent variables<\/li>\n\n\n\n<li>MCP configuration<\/li>\n\n\n\n<li>Pull request creation behavior<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Safe agent design<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>Read code\n   \u2193\nUnderstand instructions\n   \u2193\nCreate isolated change\n   \u2193\nRun tests\n   \u2193\nOpen pull request\n   \u2193\nHuman review + repository rules\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Do not bypass branch governance just because a change was created by an AI agent.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Part VIII \u2014 Planning and Issue Configuration<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">52. Issue Templates<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Issue templates improve input quality and reduce repeated clarification.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Markdown template example<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>---\nname: Bug report\nabout: Report a reproducible defect\nlabels: bug\n---\n\n## What happened?\n\n## Expected behavior\n\n## Steps to reproduce\n\n1.\n2.\n3.\n\n## Environment\n\n## Logs or screenshots\n<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">53. Issue Forms<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Issue Forms provide structured YAML-driven input.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Example:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>name: Bug report\ndescription: Report a reproducible product defect\ntitle: \"&#91;Bug]: \"\nlabels:\n  - bug\nbody:\n  - type: markdown\n    attributes:\n      value: \"Thanks for helping us improve the project.\"\n\n  - type: textarea\n    id: description\n    attributes:\n      label: What happened?\n      description: Describe the problem.\n    validations:\n      required: true\n\n  - type: input\n    id: version\n    attributes:\n      label: Version\n      placeholder: \"v2.3.1\"\n    validations:\n      required: true\n\n  - type: dropdown\n    id: environment\n    attributes:\n      label: Environment\n      options:\n        - Development\n        - Staging\n        - Production\n    validations:\n      required: true\n<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Template chooser configuration<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Use&nbsp;<code>.github\/ISSUE_TEMPLATE\/config.yml<\/code>&nbsp;for options such as blank-issue behavior and external contact links.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">54. Issue Metadata<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Repository planning commonly uses:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Labels<\/li>\n\n\n\n<li>Assignees<\/li>\n\n\n\n<li>Milestones<\/li>\n\n\n\n<li>Issue types where available<\/li>\n\n\n\n<li>Parent\/sub-issue relationships<\/li>\n\n\n\n<li>Project fields<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Keep labels small and meaningful<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Good:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>kind\/bug\nkind\/feature\npriority\/p1\npriority\/p2\narea\/api\narea\/frontend\nstatus\/blocked\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Avoid hundreds of overlapping labels that nobody understands.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">55. Automatic Planning Behavior<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Repositories can connect work through:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Issue \u2192 Branch \u2192 Pull Request \u2192 Review \u2192 Merge \u2192 Issue closure \u2192 Project automation\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Use consistent issue\/PR relationships so reporting and automation have reliable signals.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Part IX \u2014 Deployment Environments<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">56. What Is a GitHub Environment?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">An environment represents a deployment target such as:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><code>development<\/code><\/li>\n\n\n\n<li><code>staging<\/code><\/li>\n\n\n\n<li><code>uat<\/code><\/li>\n\n\n\n<li><code>production<\/code><\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">An environment can provide:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Required reviewers<\/li>\n\n\n\n<li>Wait timers<\/li>\n\n\n\n<li>Deployment branch\/tag restrictions<\/li>\n\n\n\n<li>Custom protection rules<\/li>\n\n\n\n<li>Environment secrets<\/li>\n\n\n\n<li>Environment variables<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">A job references an environment:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>jobs:\n  deploy:\n    environment: production\n    runs-on: ubuntu-latest\n    steps:\n      - run: echo \"Deploy production\"\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Protection rules are evaluated before the job gets access to the environment&#8217;s protected secrets.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">57. Required Reviewers<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Required reviewers create a human approval gate before deployment.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">GitHub documentation currently supports selecting up to six users or teams as reviewers for an environment; only one approval is required for the deployment to proceed unless your broader process adds additional controls.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You can also prevent self-review.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Use case<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>Deployment initiated by developer\n        \u2193\nProduction environment gate\n        \u2193\nSRE or release team approval\n        \u2193\nEnvironment secrets released to job\n        \u2193\nDeployment runs\n<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">58. Wait Timers<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A wait timer delays a deployment for a configured period.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Use cases:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Observation window<\/li>\n\n\n\n<li>Change freeze delay<\/li>\n\n\n\n<li>Staged rollout<\/li>\n\n\n\n<li>Manual cancellation opportunity<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Current GitHub documentation allows wait timers from 1 minute up to 43,200 minutes (30 days) where the plan supports them.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">59. Deployment Branches and Tags<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Environment rules can restrict which refs may deploy.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Typical choices include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>No restriction<\/li>\n\n\n\n<li>Protected branches only<\/li>\n\n\n\n<li>Selected branch\/tag patterns<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Production example<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>Allowed:\nmain\nv*\n\nDenied:\nfeature\/*\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">A release process can therefore require both:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Repository rule allows merge\/tag operation.<\/li>\n\n\n\n<li>Environment rule allows deployment from the resulting ref.<\/li>\n<\/ol>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">60. Custom Deployment Protection Rules<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">GitHub Apps can implement external deployment gates.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Examples:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Change-management ticket approved<\/li>\n\n\n\n<li>Monitoring health acceptable<\/li>\n\n\n\n<li>Security scan passed<\/li>\n\n\n\n<li>Maintenance window open<\/li>\n\n\n\n<li>External release orchestrator approved<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">This is a powerful extension point for enterprise release governance.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">61. Environment Secrets<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Environment secrets are only made available to jobs that reference the environment and satisfy its protection requirements.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Example access:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>- name: Use deployment credential\n  env:\n    DEPLOY_TOKEN: ${{ secrets.DEPLOY_TOKEN }}\n  run: .\/deploy.sh\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Prefer OIDC for cloud authentication where possible so long-lived cloud keys do not need to be stored as environment secrets.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">62. Environment Variables<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Environment variables are non-secret configuration values exposed through the&nbsp;<code>vars<\/code>&nbsp;context.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Example:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>- run: echo \"Deploying to ${{ vars.REGION }}\"\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Good uses:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Region<\/li>\n\n\n\n<li>Environment name<\/li>\n\n\n\n<li>Feature toggle defaults<\/li>\n\n\n\n<li>Non-sensitive endpoint names<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Do not place credentials in variables.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Part X \u2014 GitHub Pages<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">63. GitHub Pages<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">GitHub Pages publishes static websites from repository content.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Common uses:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Project documentation<\/li>\n\n\n\n<li>Internal documentation on eligible enterprise configurations<\/li>\n\n\n\n<li>Static product sites<\/li>\n\n\n\n<li>Training material<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Publishing methods<\/h3>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Deploy from a branch<\/li>\n\n\n\n<li>Deploy with GitHub Actions<\/li>\n<\/ol>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">64. Branch Publishing Source<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Branch publishing can use:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Repository root\u00a0<code>\/<\/code><\/li>\n\n\n\n<li><code>\/docs<\/code>\u00a0directory<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Example:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>main\n\u2514\u2500\u2500 docs\/\n    \u251c\u2500\u2500 index.html\n    \u2514\u2500\u2500 assets\/\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Use branch publishing when you do not need a custom build pipeline.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">65. GitHub Actions Pages Deployment<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Use Actions when the site must be built first.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Typical flow:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>flowchart LR\n    P&#91;Push] --&gt; B&#91;Build Site]\n    B --&gt; U&#91;Upload Pages Artifact]\n    U --&gt; D&#91;Deploy Pages]\n    D --&gt; W&#91;Website]\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">GitHub&#8217;s Pages workflow typically uses a&nbsp;<code>github-pages<\/code>&nbsp;environment.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">66. Custom Domains<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A Pages site can use a custom domain.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Common DNS records:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><code>CNAME<\/code>\u00a0for a subdomain<\/li>\n\n\n\n<li><code>A<\/code>\/<code>AAAA<\/code>\u00a0or DNS-provider-supported apex configuration for root domains<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Critical security practice<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Verify the domain and remove stale DNS when a Pages site or repository is retired. Abandoned DNS records can create domain takeover risk.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">67. HTTPS<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Use HTTPS enforcement when available.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">GitHub provisions TLS certificates for supported Pages custom-domain configurations after DNS is correctly configured.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Troubleshoot HTTPS problems by checking:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>DNS correctness<\/li>\n\n\n\n<li>CAA restrictions<\/li>\n\n\n\n<li>Existing conflicting records<\/li>\n\n\n\n<li>Domain ownership\/verification<\/li>\n\n\n\n<li>Certificate provisioning delay<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">68. Pages Visibility<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Do not assume a Pages site inherits repository visibility.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">GitHub Pages behavior depends on plan and enterprise configuration. Public Pages can be internet-accessible even when the source repository is private. Eligible enterprise configurations can support privately published Pages.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Always verify the Pages site&#8217;s effective visibility independently from repository visibility.<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">Part XI \u2014 Advanced Security<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">69. Security and Analysis Overview<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Repository security settings can include several distinct products and controls. GitHub&#8217;s 2026 terminology increasingly separates capabilities into products such as Code Security and Secret Protection, while the repository navigation still groups many controls under&nbsp;<strong>Advanced Security<\/strong>&nbsp;or&nbsp;<strong>Security and quality<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Think in layers:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>flowchart TD\n    D&#91;Dependency Risk] --&gt; DG&#91;Dependency Graph and Dependabot]\n    C&#91;Code Risk] --&gt; CS&#91;Code Scanning and AI Scan]\n    S&#91;Secret Risk] --&gt; SS&#91;Secret Scanning and Push Protection]\n    Q&#91;Quality Risk] --&gt; CQ&#91;Code Quality]\n    DG --&gt; G&#91;Merge Governance]\n    CS --&gt; G\n    SS --&gt; G\n    CQ --&gt; G\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Do not assume all private repositories receive all advanced features automatically. Availability depends on visibility, plan, and the security products enabled for the organization\/enterprise.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">70. Dependency Graph<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The dependency graph parses supported manifest and lock files to understand direct and transitive dependencies.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Examples include ecosystem files such as:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>package.json\npackage-lock.json\npom.xml\nbuild.gradle\nrequirements.txt\npoetry.lock\nGemfile.lock\ngo.mod\nCargo.lock\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The exact list varies by ecosystem and evolves over time.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Why it matters<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The dependency graph is foundational for:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Dependabot alerts<\/li>\n\n\n\n<li>Security updates<\/li>\n\n\n\n<li>Dependency review<\/li>\n\n\n\n<li>Dependency inventory<\/li>\n\n\n\n<li>Supply-chain visibility<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">71. Dependabot Alerts<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Dependabot alerts notify repository maintainers when a dependency is affected by a known vulnerability in GitHub&#8217;s advisory data.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Alert workflow<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>Manifest\/lock file\n      \u2193\nDependency graph\n      \u2193\nKnown vulnerable version\n      \u2193\nDependabot alert\n      \u2193\nTriage \/ upgrade \/ dismiss with reason\n<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Best practices<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Assign ownership for alerts.<\/li>\n\n\n\n<li>Prioritize exploitable\/runtime dependencies over blanket severity-only handling.<\/li>\n\n\n\n<li>Record dismissal reasons.<\/li>\n\n\n\n<li>Keep manifests and lock files committed where appropriate.<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">72. Dependabot Security Updates<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Dependabot security updates can automatically open pull requests that upgrade vulnerable dependencies to a secure version where GitHub can determine an update path.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Use security updates together with normal CI and repository rules. Automation should not bypass tests or review.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">73. Dependabot Version Updates<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Version updates are configured with:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>.github\/dependabot.yml\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Example:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>version: 2\nupdates:\n  - package-ecosystem: npm\n    directory: \"\/\"\n    schedule:\n      interval: weekly\n    open-pull-requests-limit: 5\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">For private registries, use Dependabot-specific credentials rather than assuming Actions repository secrets are available.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">74. Dependency Review<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Dependency review analyzes dependency changes introduced by a pull request.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Useful checks include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Newly introduced vulnerable dependency<\/li>\n\n\n\n<li>Version change<\/li>\n\n\n\n<li>License information<\/li>\n\n\n\n<li>Dependency additions\/removals<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">A mature PR policy asks not only \u201cdoes the code compile?\u201d but also \u201cwhat new software supply-chain risk does this PR introduce?\u201d<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">75. Code Scanning<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Code scanning identifies potential vulnerabilities and coding errors.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Setup models<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">GitHub supports:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Default setup<\/strong>\u00a0\u2014 low-maintenance CodeQL configuration<\/li>\n\n\n\n<li><strong>Advanced setup<\/strong>\u00a0\u2014 workflow-driven, highly customizable scanning<\/li>\n\n\n\n<li><strong>Third-party SARIF upload<\/strong>\u00a0\u2014 integrate supported scanners through SARIF<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Recommended starting point<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Use default setup unless you have a concrete reason to need advanced workflow customization.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">SARIF<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">SARIF is a JSON-based static-analysis result format. GitHub currently supports the relevant subset of SARIF 2.1.0 for code scanning integrations.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Typical third-party flow:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>flowchart LR\n    C&#91;Code] --&gt; T&#91;Third Party Scanner]\n    T --&gt; S&#91;SARIF File]\n    S --&gt; G&#91;GitHub Code Scanning]\n    G --&gt; A&#91;Alert]\n<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">76. CodeQL Default Setup<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Default setup is designed to minimize workflow maintenance.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It can scan supported languages on:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Pushes to the default\/protected branches<\/li>\n\n\n\n<li>Pull requests targeting relevant protected\/default branches<\/li>\n\n\n\n<li>Scheduled analysis according to GitHub behavior<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Use the tool-status view when troubleshooting coverage or scan errors.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">77. CodeQL Advanced Setup<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Use advanced setup when you need capabilities beyond default setup, for example:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Custom build steps<\/li>\n\n\n\n<li>Matrix behavior<\/li>\n\n\n\n<li>More granular triggers<\/li>\n\n\n\n<li>Custom query packs\/suites<\/li>\n\n\n\n<li>Complex generated-code handling<\/li>\n\n\n\n<li>External CI orchestration<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The tradeoff is more configuration and more long-term maintenance.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">78. AI Scan for Pull Requests<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">As of September 2026,&nbsp;<strong>AI Scan for pull requests is in public preview<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Its purpose is to extend security detection to languages and frameworks that CodeQL does not cover well or at all.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Current important characteristics:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Runs on pull requests<\/li>\n\n\n\n<li>Complements CodeQL rather than replacing it<\/li>\n\n\n\n<li>Findings are PR-oriented rather than a full default-branch backlog equivalent<\/li>\n\n\n\n<li>Requires code scanning to be enabled<\/li>\n\n\n\n<li>As of the September 16, 2026 update, it no longer requires CodeQL default setup<\/li>\n\n\n\n<li>Public preview availability currently depends on GitHub Advanced Security eligibility and Copilot licensing\/AI-credit conditions described by GitHub<\/li>\n\n\n\n<li>Not supported on GitHub Enterprise Server for this preview release<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Treat preview behavior as subject to change.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">79. Secret Scanning<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Secret scanning detects credentials and secret-like values committed to supported GitHub surfaces.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Detection can include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Provider patterns<\/li>\n\n\n\n<li>Non-provider patterns<\/li>\n\n\n\n<li>Custom patterns<\/li>\n\n\n\n<li>Generic AI-assisted detection where available<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Response lifecycle<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>Secret detected\n    \u2193\nDetermine validity\n    \u2193\nRevoke \/ rotate credential\n    \u2193\nRemove exposure if appropriate\n    \u2193\nClose alert with reason\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Removing a secret from the latest commit is not enough if the credential is still valid.&nbsp;<strong>Rotation\/revocation is the primary response.<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">80. Push Protection<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Push protection attempts to stop supported secrets before they enter the repository.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A contributor may be blocked when GitHub detects a secret in the push.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Organizations can define bypass workflows and, in some configurations, review bypass requests or exempt trusted actors.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Best practice<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Keep bypass narrow and auditable. If a secret must be bypassed because it is a false positive, document the reason rather than teaching developers to bypass every block.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Part XII \u2014 GitHub Code Quality<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">81. What Is GitHub Code Quality?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">GitHub Code Quality is a repository\/organization feature that analyzes code for quality concerns such as maintainability and reliability and integrates findings into pull request and default-branch workflows.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As of September 2026, GitHub documents Code Quality for GitHub Team and GitHub Enterprise Cloud customers, subject to enterprise enablement and billing\/licensing conditions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">GitHub&#8217;s current implementation combines deterministic CodeQL quality queries with AI-powered analysis in supported scenarios.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">82. Enabling Code Quality<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Typical repository flow:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Open\u00a0<strong>Settings<\/strong>.<\/li>\n\n\n\n<li>Open\u00a0<strong>Code quality<\/strong>\u00a0under the security\/quality area.<\/li>\n\n\n\n<li>Enable Code Quality.<\/li>\n\n\n\n<li>Select supported languages if exposed.<\/li>\n\n\n\n<li>Choose runner type if required.<\/li>\n\n\n\n<li>Save.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">GitHub Actions must be enabled because Code Quality analysis uses Actions execution.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">83. Code Quality Pull Request Controls<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Code Quality can feed rulesets.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A branch ruleset can enable&nbsp;<strong>Require code quality results<\/strong>&nbsp;and define the lowest result severity that must be resolved before merge.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Rollout model<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>Enable Code Quality\n      \u2193\nObserve findings\n      \u2193\nTune team workflow\n      \u2193\nRuleset in Evaluate mode\n      \u2193\nSet quality threshold\n      \u2193\nActivate merge protection\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Do not turn on a strict blocking threshold across hundreds of repositories before measuring the baseline.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">84. Code Coverage<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">GitHub Code Quality can integrate code coverage into the repository quality experience and ruleset governance.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Use coverage to answer:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Which changed code is untested?<\/li>\n\n\n\n<li>Is coverage decreasing?<\/li>\n\n\n\n<li>Should a pull request be blocked below a defined threshold?<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Coverage percentage is a signal, not proof of test quality. High coverage with weak assertions can still provide poor protection.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Part XIII \u2014 Deploy Keys, Secrets, and Variables<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">85. Deploy Keys<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A deploy key is an SSH public key attached directly to one repository.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The corresponding private key normally lives on a machine or deployment system.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Deploy keys can be:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Read-only<\/li>\n\n\n\n<li>Write-enabled<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Common use case<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A legacy deployment server needs to clone one private repository without acting as a human user.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Security characteristics<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Advantages<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Repository-scoped<\/li>\n\n\n\n<li>Simple SSH model<\/li>\n\n\n\n<li>No user account required for the key itself<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Risks<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Private key may be long-lived<\/li>\n\n\n\n<li>Rotation is manual<\/li>\n\n\n\n<li>Write access can be dangerous<\/li>\n\n\n\n<li>Poor fit for dynamic multi-repository automation<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Prefer GitHub Apps or OIDC-capable automation when you need scalable, short-lived, centrally governable authentication.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">86. Deploy Key Rotation<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Recommended procedure:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Generate a new SSH key pair.<\/li>\n\n\n\n<li>Install the new public key as a deploy key.<\/li>\n\n\n\n<li>Update the consumer with the new private key.<\/li>\n\n\n\n<li>Verify access.<\/li>\n\n\n\n<li>Remove the old deploy key.<\/li>\n\n\n\n<li>Destroy the old private key.<\/li>\n\n\n\n<li>Record rotation evidence.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Example key generation:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>ssh-keygen -t ed25519 -C \"deploy-payment-api\" -f .\/payment-api-deploy\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Protect the private key with appropriate host and secret-management controls.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">87. Actions Repository Secrets<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Repository secrets are encrypted values intended for workflow use.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Create with GitHub CLI:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>gh secret set API_TOKEN --repo \"$OWNER\/$REPO\"\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">List secret names:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>gh secret list --repo \"$OWNER\/$REPO\"\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">GitHub does not return secret plaintext after storage.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Best practice<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Use secret scope deliberately:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Scope<\/th><th class=\"has-text-align-left\" data-align=\"left\">Use<\/th><\/tr><\/thead><tbody><tr><td>Organization<\/td><td>Shared secret across selected repositories<\/td><\/tr><tr><td>Repository<\/td><td>Secret applies to whole repository<\/td><\/tr><tr><td>Environment<\/td><td>Secret only for a deployment environment<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Prefer the narrowest practical scope.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">88. Actions Variables<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Variables are for non-sensitive configuration.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Create:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>gh variable set REGION --body \"ap-northeast-1\" --repo \"$OWNER\/$REPO\"\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Use in workflow:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>- run: echo \"Region is ${{ vars.REGION }}\"\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Never rely on a variable being masked as a secret.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">89. Dependabot Secrets<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Dependabot uses its own secret store for authentication to private package registries and related update operations.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This separation matters because Dependabot-triggered workflows do not automatically receive normal Actions secrets in the same way as trusted Actions events.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">90. Codespaces Secrets<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Codespaces can use repository\/user\/organization scoped secrets for development environments.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Use them for development-time credentials that should not be committed to the repository.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Do not turn Codespaces secrets into a substitute for production deployment credential management.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">91. Copilot \/ Agent Secrets and Variables<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">GitHub&#8217;s current repository settings may expose secrets and variables for cloud agents and MCP-related use cases.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Treat these credentials as privileged automation credentials:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Scope them to the smallest system surface<\/li>\n\n\n\n<li>Prefer read-only access where practical<\/li>\n\n\n\n<li>Rotate them<\/li>\n\n\n\n<li>Avoid sharing production credentials with agent tooling unless the use case is explicitly designed and reviewed for it<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">92. OIDC Instead of Long-Lived Cloud Secrets<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">For cloud deployments, prefer OpenID Connect where the cloud provider supports it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Workflow:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>flowchart LR\n    W&#91;GitHub Workflow] --&gt; O&#91;OIDC Token]\n    O --&gt; C&#91;Cloud Identity Provider]\n    C --&gt; R&#91;Short Lived Role]\n    R --&gt; D&#91;Deploy]\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Minimal permission block:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>permissions:\n  contents: read\n  id-token: write\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Then constrain the cloud trust policy by repository, branch, environment, or other supported claims.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Part XIV \u2014 GitHub Apps and Email Notifications<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">93. Installed GitHub Apps<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A GitHub App can be installed on an account and granted access to:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>All repositories<\/li>\n\n\n\n<li>Selected repositories<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The app receives only the repository and organization permissions it requests and the installation grants.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Repository settings can show Apps that currently have access to the repository, but changing an installation may redirect you to the owning account&#8217;s app installation configuration because app access is managed at installation scope.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Review checklist<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>&#91; ] Is this app still needed?\n&#91; ] Does it need all repositories?\n&#91; ] Are requested permissions justified?\n&#91; ] Can write\/admin permissions be reduced?\n&#91; ] Is the publisher trusted?\n&#91; ] Is there an owner for the integration?\n<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">94. GitHub App Permissions<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Repository permissions can cover areas such as:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Contents<\/li>\n\n\n\n<li>Issues<\/li>\n\n\n\n<li>Pull requests<\/li>\n\n\n\n<li>Actions<\/li>\n\n\n\n<li>Checks<\/li>\n\n\n\n<li>Deployments<\/li>\n\n\n\n<li>Environments<\/li>\n\n\n\n<li>Metadata<\/li>\n\n\n\n<li>Security events<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The exact permission set evolves. Review the app&#8217;s requested permissions at installation time and during periodic audits.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">GitHub App vs PAT<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">GitHub App<\/th><th class=\"has-text-align-left\" data-align=\"left\">Personal access token<\/th><\/tr><\/thead><tbody><tr><td>App identity<\/td><td>User identity<\/td><\/tr><tr><td>Installation-scoped<\/td><td>User\/account-scoped<\/td><\/tr><tr><td>Fine-grained permissions<\/td><td>Depends on token type<\/td><\/tr><tr><td>Short-lived installation tokens<\/td><td>PAT often longer-lived<\/td><\/tr><tr><td>Better for platform integrations<\/td><td>Useful for user-driven tooling<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">For service automation, GitHub Apps are generally easier to govern at scale than a shared human PAT.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">95. Push Email Notifications<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Repository administrators can configure email notifications for pushes.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Current GitHub documentation supports up to two destination addresses directly. A group mailbox can be used when more recipients are needed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Push emails include useful metadata such as:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Repository<\/li>\n\n\n\n<li>Branch<\/li>\n\n\n\n<li>Commit SHA<\/li>\n\n\n\n<li>Author<\/li>\n\n\n\n<li>Commit message<\/li>\n\n\n\n<li>Changed files\/diff links<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">GitHub also supports an approved header value that a receiving system can use as an additional trust signal.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Part XV \u2014 Policy Inheritance and Governance Architecture<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">96. Organization Policy Overrides<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Organization-level controls can affect repository behavior for areas including:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Actions<\/li>\n\n\n\n<li>Rulesets<\/li>\n\n\n\n<li>Security configurations<\/li>\n\n\n\n<li>Custom properties<\/li>\n\n\n\n<li>Base repository permissions<\/li>\n\n\n\n<li>Copilot policy<\/li>\n\n\n\n<li>GitHub App policy<\/li>\n\n\n\n<li>Repository visibility and lifecycle operations<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">A repository admin may therefore encounter a locked setting with an explanation that organization policy controls it.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">97. Enterprise Policy Overrides<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Enterprise controls can add another policy layer for:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Actions<\/li>\n\n\n\n<li>Identity<\/li>\n\n\n\n<li>Repository visibility<\/li>\n\n\n\n<li>Security products<\/li>\n\n\n\n<li>Network controls<\/li>\n\n\n\n<li>Apps\/integrations<\/li>\n\n\n\n<li>Copilot<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Troubleshooting rule<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">When a repository setting appears impossible to change, inspect policy from the top down:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Enterprise \u2192 Organization \u2192 Repository \u2192 Environment \u2192 Workflow\n<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">98. Repository Governance Architecture<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A scalable repository model separates concerns:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>flowchart TD\n    I&#91;Identity and Access] --&gt; R&#91;Repository]\n    P&#91;Policy and Rulesets] --&gt; R\n    S&#91;Security Configuration] --&gt; R\n    A&#91;Actions Standards] --&gt; R\n    R --&gt; C&#91;Code Change]\n    C --&gt; T&#91;Tests and Scans]\n    T --&gt; M&#91;Merge]\n    M --&gt; E&#91;Environment Gate]\n    E --&gt; D&#91;Deployment]\n<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Access model<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Prefer:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Organization membership\n      \u2193\nTeam membership\n      \u2193\nRepository role\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Use direct collaborators as exceptions, not the normal architecture.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Security model<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Layer:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Rulesets<\/li>\n\n\n\n<li>CODEOWNERS<\/li>\n\n\n\n<li>Required checks<\/li>\n\n\n\n<li>Code scanning<\/li>\n\n\n\n<li>Secret scanning<\/li>\n\n\n\n<li>Push protection<\/li>\n\n\n\n<li>Code Quality<\/li>\n\n\n\n<li>Protected environments<\/li>\n\n\n\n<li>Deployment approvals<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">No single control replaces the others.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">99. CI\/CD Governance Model<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A strong repository pipeline uses multiple enforcement points:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Action allowlist\n      \u2193\nMinimal GITHUB_TOKEN\n      \u2193\nPinned dependencies\/actions\n      \u2193\nProtected default branch\n      \u2193\nRequired CI checks\n      \u2193\nOIDC authentication\n      \u2193\nProtected environment\n      \u2193\nDeployment approval\n<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Supply-chain baseline<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Pin critical third-party Actions to immutable commits where practical.<\/li>\n\n\n\n<li>Review action source and maintainer trust.<\/li>\n\n\n\n<li>Prefer organization-owned reusable workflows.<\/li>\n\n\n\n<li>Use artifact attestations\/provenance where appropriate.<\/li>\n\n\n\n<li>Protect workflow files through CODEOWNERS and rules.<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Part XVI \u2014 Repository APIs and CLI Administration<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">100. REST API Fundamentals<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">GitHub&#8217;s REST API is versioned. As of this guide, current documentation examples use:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>X-GitHub-Api-Version: 2026-03-10\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">When using&nbsp;<code>gh api<\/code>, GitHub CLI handles authentication for you.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Read repository configuration<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>gh api \\\n  -H \"X-GitHub-Api-Version: 2026-03-10\" \\\n  \"\/repos\/$OWNER\/$REPO\"\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Extract selected values:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>gh api \\\n  -H \"X-GitHub-Api-Version: 2026-03-10\" \\\n  \"\/repos\/$OWNER\/$REPO\" \\\n  --jq '{name,visibility,default_branch,archived,has_issues,has_wiki}'\n<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">101. Update Repository Settings with REST<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Many General settings are exposed through the repository update endpoint.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Example:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>gh api \\\n  --method PATCH \\\n  -H \"X-GitHub-Api-Version: 2026-03-10\" \\\n  \"\/repos\/$OWNER\/$REPO\" \\\n  -f has_wiki=false \\\n  -f delete_branch_on_merge=true\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Before scripting a setting at scale, confirm the current REST field and plan requirements in GitHub&#8217;s endpoint documentation.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">102. Collaborators API<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">List collaborators:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>gh api \\\n  -H \"X-GitHub-Api-Version: 2026-03-10\" \\\n  \"\/repos\/$OWNER\/$REPO\/collaborators\"\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Check a specific user&#8217;s permission with the appropriate collaborators-permission endpoint when building access audits.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For organization repositories, remember that direct-collaborator data is only part of the effective-access picture; teams and base permissions matter too.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">103. Rulesets API<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">List repository rulesets:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>gh api \\\n  -H \"X-GitHub-Api-Version: 2026-03-10\" \\\n  \"\/repos\/$OWNER\/$REPO\/rulesets\"\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Use API automation for:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Repository bootstrap<\/li>\n\n\n\n<li>Policy drift detection<\/li>\n\n\n\n<li>Ruleset inventory<\/li>\n\n\n\n<li>Migration reporting<\/li>\n\n\n\n<li>Rule insights\/rule suite analysis<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Keep desired-state policy in version control rather than constructing large JSON bodies manually in shell history.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">104. Actions Administration API<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Repository Actions APIs can manage or inspect areas such as:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Actions permissions<\/li>\n\n\n\n<li>Workflow permissions<\/li>\n\n\n\n<li>Runners<\/li>\n\n\n\n<li>Caches<\/li>\n\n\n\n<li>Artifacts<\/li>\n\n\n\n<li>Secrets metadata<\/li>\n\n\n\n<li>Variables<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Example: inspect repository Actions permissions:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>gh api \\\n  -H \"X-GitHub-Api-Version: 2026-03-10\" \\\n  \"\/repos\/$OWNER\/$REPO\/actions\/permissions\"\n<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">105. Environment API<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">REST endpoints support creating\/configuring deployment environments and associated protection\/deployment policies.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Use APIs when environments must be standardized across many repositories.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Typical desired state:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>{\n  \"environment\": \"production\",\n  \"prevent_self_review\": true,\n  \"allowed_refs\": &#91;\"main\", \"v*\"]\n}\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The JSON above is conceptual; use the current GitHub REST schema for actual API requests because reviewer and deployment-policy payloads have specific endpoint structures.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">106. Webhooks API<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Repository webhook APIs support:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Create<\/li>\n\n\n\n<li>Update<\/li>\n\n\n\n<li>Delete<\/li>\n\n\n\n<li>List hooks<\/li>\n\n\n\n<li>Inspect deliveries<\/li>\n\n\n\n<li>Redeliver supported deliveries<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Automating webhooks is useful when every service repository must integrate with the same platform system.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">107. AI Scan API<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">As of September 2026, GitHub has public-preview REST endpoints to inspect and update AI Scan enablement at organization and repository scope.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Example read path documented by GitHub:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\/repos\/{owner}\/{repo}\/code-scanning\/ai-scan\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Because this endpoint is preview functionality, verify the current API contract immediately before production automation.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">108. GitHub CLI Administration<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Useful command families include:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>gh repo view\ngh repo edit\ngh repo archive\ngh repo delete\ngh secret list\ngh secret set\ngh variable list\ngh variable set\ngh api\n<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Example repository edit<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>gh repo edit \"$OWNER\/$REPO\" --delete-branch-on-merge\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Use&nbsp;<code>gh api<\/code>&nbsp;when a setting is not exposed by a first-class CLI subcommand.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">109. GraphQL Administration<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">GitHub GraphQL is useful for querying connected repository metadata in fewer round trips.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Typical uses:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Repository inventory<\/li>\n\n\n\n<li>Branch protection data<\/li>\n\n\n\n<li>Collaborator\/permission relationships<\/li>\n\n\n\n<li>Deployments<\/li>\n\n\n\n<li>Projects<\/li>\n\n\n\n<li>Security-related reporting where fields are exposed<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">GraphQL and REST do not have identical feature coverage. Choose the API that exposes the capability cleanly rather than forcing all automation into one style.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Part XVII \u2014 Infrastructure as Code<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">110. Terraform GitHub Provider<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The official community-supported&nbsp;<code>integrations\/github<\/code>&nbsp;Terraform provider can manage many repository controls.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As of September 2026, Terraform Registry shows provider version&nbsp;<strong>6.13.0<\/strong>&nbsp;as the latest published version in the retrieved provider index. Always verify the current version before pinning.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Common resources include:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>github_repository\ngithub_branch_default\ngithub_repository_ruleset\ngithub_team_repository\ngithub_repository_collaborator\ngithub_repository_collaborators\ngithub_actions_repository_permissions\ngithub_actions_secret\ngithub_actions_variable\ngithub_repository_environment\ngithub_repository_environment_deployment_policy\ngithub_actions_environment_secret\ngithub_actions_environment_variable\ngithub_dependabot_secret\ngithub_repository_webhook\ngithub_repository_deploy_key\ngithub_repository_pages\n<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">111. Terraform Repository Example<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>terraform {\n  required_providers {\n    github = {\n      source  = \"integrations\/github\"\n      version = \"~&gt; 6.13\"\n    }\n  }\n}\n\nprovider \"github\" {\n  owner = var.github_owner\n}\n\nresource \"github_repository\" \"app\" {\n  name                   = \"payment-api\"\n  description            = \"Payment service API\"\n  visibility             = \"private\"\n  has_issues             = true\n  has_wiki               = false\n  delete_branch_on_merge = true\n\n  allow_merge_commit = false\n  allow_squash_merge = true\n  allow_rebase_merge = false\n}\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Pin a provider range intentionally and review provider release notes before major upgrades.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">112. Terraform Actions Permissions<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>resource \"github_actions_repository_permissions\" \"app\" {\n  repository      = github_repository.app.name\n  enabled         = true\n  allowed_actions = \"selected\"\n\n  allowed_actions_config {\n    github_owned_allowed = true\n    verified_allowed     = false\n    patterns_allowed = &#91;\n      \"actions\/checkout@*\",\n      \"actions\/cache@*\",\n    ]\n  }\n}\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">For high-assurance supply-chain policy, consider whether your organization should require SHA pinning instead of broad tag patterns.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">113. Terraform Ruleset Example<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>resource \"github_repository_ruleset\" \"main\" {\n  name        = \"protect-main\"\n  repository  = github_repository.app.name\n  target      = \"branch\"\n  enforcement = \"active\"\n\n  conditions {\n    ref_name {\n      include = &#91;\"~DEFAULT_BRANCH\"]\n      exclude = &#91;]\n    }\n  }\n\n  rules {\n    deletion                = true\n    non_fast_forward        = true\n    required_linear_history = true\n\n    pull_request {\n      required_approving_review_count = 1\n      require_code_owner_review       = true\n      required_review_thread_resolution = true\n    }\n  }\n}\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Provider schemas evolve. Validate nested rule names against the pinned provider version before applying production configuration.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">114. Terraform Environment Example<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>resource \"github_repository_environment\" \"production\" {\n  repository  = github_repository.app.name\n  environment = \"production\"\n\n  prevent_self_review = true\n\n  deployment_branch_policy {\n    protected_branches     = false\n    custom_branch_policies = true\n  }\n}\n\nresource \"github_repository_environment_deployment_policy\" \"main\" {\n  repository     = github_repository.app.name\n  environment    = github_repository_environment.production.environment\n  branch_pattern = \"main\"\n}\n<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">115. Terraform Secret Warning<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Terraform can manage GitHub secrets, but secret values can still become sensitive Terraform state data depending on how they are provided.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Treat state as a secret-bearing system.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Recommended<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Encrypted remote state<\/li>\n\n\n\n<li>Strict state access<\/li>\n\n\n\n<li>Avoid plaintext secrets in\u00a0<code>.tf<\/code>\u00a0files<\/li>\n\n\n\n<li>Prefer external secret injection or encrypted values where practical<\/li>\n\n\n\n<li>Rotate credentials if state exposure occurs<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">116. Repository as Code<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A mature organization can standardize repository provisioning:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Repository request\n      \u2193\nApproved metadata\n      \u2193\nTerraform module\n      \u2193\nRepository + teams\n      \u2193\nRulesets\n      \u2193\nActions policy\n      \u2193\nEnvironments\n      \u2193\nSecurity configuration\n      \u2193\nContinuous drift check\n<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">What belongs in desired state<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Name\/description\/visibility<\/li>\n\n\n\n<li>Topics\/custom properties<\/li>\n\n\n\n<li>Teams and permissions<\/li>\n\n\n\n<li>Rulesets<\/li>\n\n\n\n<li>Actions policy<\/li>\n\n\n\n<li>Environments<\/li>\n\n\n\n<li>Webhooks<\/li>\n\n\n\n<li>Pages when applicable<\/li>\n\n\n\n<li>Security configuration where provider\/API coverage exists<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Not every GitHub feature has immediate Terraform-provider parity. Use APIs only where needed and track the gap explicitly.<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">Part XVIII \u2014 Repository Standardization<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">117. Repository Templates and Standard Structure<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A standardized repository should make common expectations obvious before a developer reads internal documentation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Example:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>.github\/\n  CODEOWNERS\n  ISSUE_TEMPLATE\/\n  workflows\/\n  copilot-instructions.md\nCODE_OF_CONDUCT.md\nCONTRIBUTING.md\nLICENSE\nREADME.md\nSECURITY.md\nsrc\/\ntests\/\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Not every repository needs every file. Use the minimum set that supports the repository&#8217;s users and risk profile.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Recommended baseline files<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">File<\/th><th class=\"has-text-align-left\" data-align=\"left\">Purpose<\/th><\/tr><\/thead><tbody><tr><td><code>README.md<\/code><\/td><td>What the repository is and how to use it<\/td><\/tr><tr><td><code>CONTRIBUTING.md<\/code><\/td><td>Contribution workflow<\/td><\/tr><tr><td><code>SECURITY.md<\/code><\/td><td>Vulnerability reporting policy<\/td><\/tr><tr><td><code>CODEOWNERS<\/code><\/td><td>Review ownership for sensitive paths<\/td><\/tr><tr><td><code>LICENSE<\/code><\/td><td>Reuse\/legal terms where appropriate<\/td><\/tr><tr><td><code>.github\/ISSUE_TEMPLATE\/*<\/code><\/td><td>Structured issue intake<\/td><\/tr><tr><td><code>.github\/workflows\/*<\/code><\/td><td>CI\/CD automation<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">118. CODEOWNERS<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><code>CODEOWNERS<\/code>&nbsp;maps file paths to responsible reviewers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Example:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># Default owners\n* @example\/platform\n\n# Security-sensitive workflows\n.github\/workflows\/ @example\/platform-security\n\n# Payments domain\nsrc\/payments\/ @example\/payments-team\n\n# Infrastructure\nterraform\/ @example\/cloud-platform\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">CODEOWNERS alone does not force a review. Pair it with a branch\/ruleset rule that requires code-owner review.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">119. Repository Metadata Standards<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A platform team should standardize metadata just as it standardizes CI.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Example minimum:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Metadata<\/th><th class=\"has-text-align-right\" data-align=\"right\">Required?<\/th><th class=\"has-text-align-left\" data-align=\"left\">Example<\/th><\/tr><\/thead><tbody><tr><td>Description<\/td><td class=\"has-text-align-right\" data-align=\"right\">Yes<\/td><td><code>Customer profile API<\/code><\/td><\/tr><tr><td>Owner team<\/td><td class=\"has-text-align-right\" data-align=\"right\">Yes<\/td><td><code>identity-platform<\/code><\/td><\/tr><tr><td>Service tier<\/td><td class=\"has-text-align-right\" data-align=\"right\">Yes for services<\/td><td><code>tier-1<\/code><\/td><\/tr><tr><td>Data classification<\/td><td class=\"has-text-align-right\" data-align=\"right\">Yes where relevant<\/td><td><code>confidential<\/code><\/td><\/tr><tr><td>Lifecycle<\/td><td class=\"has-text-align-right\" data-align=\"right\">Yes<\/td><td><code>active<\/code><\/td><\/tr><tr><td>Documentation URL<\/td><td class=\"has-text-align-right\" data-align=\"right\">Recommended<\/td><td>Internal docs URL<\/td><\/tr><tr><td>Topics<\/td><td class=\"has-text-align-right\" data-align=\"right\">Recommended<\/td><td><code>go<\/code>,&nbsp;<code>api<\/code>,&nbsp;<code>production<\/code><\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Custom properties are preferable to free-form README metadata when the information must drive automation.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">120. Repository Protection Standard<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Example baseline for a production service:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Default branch protected by ruleset\nPull request required\n1-2 approvals based on risk\nCode owner review for sensitive paths\nRequired CI checks\nCode\/secret scanning gate where licensed\nForce push blocked\nDeletion restricted\nAuto-delete merged branches enabled\nProduction deployment through protected environment\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Keep stronger profiles for critical repositories and lighter profiles for prototypes.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Part XIX \u2014 Repository Security Hardening<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">121. Least Privilege<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Apply least privilege to every actor:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Human users<\/li>\n\n\n\n<li>Teams<\/li>\n\n\n\n<li>GitHub Apps<\/li>\n\n\n\n<li><code>GITHUB_TOKEN<\/code><\/li>\n\n\n\n<li>Deploy keys<\/li>\n\n\n\n<li>PATs<\/li>\n\n\n\n<li>CI runners<\/li>\n\n\n\n<li>Environment credentials<\/li>\n\n\n\n<li>MCP\/agent tools<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Practical hierarchy<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>Read &lt; Triage &lt; Write &lt; Maintain &lt; Admin\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Do not grant Admin simply because someone needs one administrative operation. Use custom roles or controlled workflows where available.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">122. Credential Hardening<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Recommended order for automation identity:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>OIDC federation for cloud credentials<\/li>\n\n\n\n<li>GitHub App installation token for GitHub automation<\/li>\n\n\n\n<li>Fine-grained PAT when a user identity is genuinely required<\/li>\n\n\n\n<li>Deploy key for narrow SSH repository access<\/li>\n\n\n\n<li>Classic PAT only when no better mechanism fits<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">Rotate these regularly<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Deploy keys<\/li>\n\n\n\n<li>PATs<\/li>\n\n\n\n<li>Webhook secrets<\/li>\n\n\n\n<li>External registry credentials<\/li>\n\n\n\n<li>App private keys<\/li>\n\n\n\n<li>Long-lived repository\/environment secrets<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">123. Supply-Chain Security<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A strong repository baseline combines:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Dependency graph<\/li>\n\n\n\n<li>Dependabot alerts<\/li>\n\n\n\n<li>Dependabot security updates<\/li>\n\n\n\n<li>Dependency review<\/li>\n\n\n\n<li>Code scanning<\/li>\n\n\n\n<li>Secret scanning<\/li>\n\n\n\n<li>Push protection<\/li>\n\n\n\n<li>Release immutability<\/li>\n\n\n\n<li>Artifact attestations where relevant<\/li>\n\n\n\n<li>SHA-pinned third-party Actions for high-assurance workflows<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Threat flow<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>flowchart LR\n    D&#91;Dependency] --&gt; B&#91;Build]\n    A&#91;Action] --&gt; B\n    C&#91;Source Code] --&gt; B\n    B --&gt; X&#91;Artifact]\n    X --&gt; R&#91;Release]\n    R --&gt; P&#91;Production]\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">A compromise at any upstream point can reach production. Repository settings should therefore protect both source and automation.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">124. Workflow File Protection<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Workflow files are privileged code because they can access tokens, runners, OIDC, secrets, and deployment environments.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Protect:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>.github\/workflows\/**\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">with:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>CODEOWNERS<\/li>\n\n\n\n<li>Required code-owner review<\/li>\n\n\n\n<li>Rulesets<\/li>\n\n\n\n<li>Minimal Actions permissions<\/li>\n\n\n\n<li>Controlled reusable workflows<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">125. Self-Hosted Runner Hardening<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If self-hosted runners are used:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Keep runner scope as narrow as practical.<\/li>\n\n\n\n<li>Prefer ephemeral runners.<\/li>\n\n\n\n<li>Separate trusted and untrusted workloads.<\/li>\n\n\n\n<li>Restrict network paths.<\/li>\n\n\n\n<li>Patch the host image frequently.<\/li>\n\n\n\n<li>Do not persist cloud credentials.<\/li>\n\n\n\n<li>Destroy workspaces after jobs.<\/li>\n\n\n\n<li>Monitor runner registration and usage.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Public-repository pull requests and long-lived privileged runners are a particularly risky combination.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Part XX \u2014 Repository Lifecycle<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">126. Creation Phase<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A new repository should not spend weeks in an insecure default state.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Creation checklist<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>&#91; ] Correct owner and visibility\n&#91; ] Description and metadata\n&#91; ] Owner team\n&#91; ] Default branch\n&#91; ] Merge strategy\n&#91; ] Ruleset\/protection\n&#91; ] Actions policy\n&#91; ] Security configuration\n&#91; ] CODEOWNERS\n&#91; ] CI workflow\n&#91; ] Environment controls\n&#91; ] Dependabot configuration\n&#91; ] Documentation\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Automate this baseline with templates\/IaC where possible.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">127. Active Operations Phase<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Regular repository operations should include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Access review<\/li>\n\n\n\n<li>Ruleset review<\/li>\n\n\n\n<li>CI health review<\/li>\n\n\n\n<li>Runner review<\/li>\n\n\n\n<li>Dependency maintenance<\/li>\n\n\n\n<li>Security alert triage<\/li>\n\n\n\n<li>Secret rotation<\/li>\n\n\n\n<li>App\/integration review<\/li>\n\n\n\n<li>Environment reviewer review<\/li>\n\n\n\n<li>Metadata ownership validation<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">128. Deprecation Phase<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A repository that is no longer strategic should move through a controlled deprecation stage rather than disappearing suddenly.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Recommended:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Add a deprecation notice.<\/li>\n\n\n\n<li>Name the replacement repository\/service.<\/li>\n\n\n\n<li>Stop feature development.<\/li>\n\n\n\n<li>Migrate consumers.<\/li>\n\n\n\n<li>Retire deployment automation.<\/li>\n\n\n\n<li>Revoke unused credentials.<\/li>\n\n\n\n<li>Close remaining issues\/PRs.<\/li>\n\n\n\n<li>Archive when dependencies are gone.<\/li>\n<\/ol>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">129. Archival Phase<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">When archiving:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Record the owning team.<\/li>\n\n\n\n<li>Record the replacement\/successor.<\/li>\n\n\n\n<li>Keep a useful README.<\/li>\n\n\n\n<li>Verify package\/deployment dependencies.<\/li>\n\n\n\n<li>Preserve compliance evidence externally if required.<\/li>\n\n\n\n<li>Review whether security scanning on the archived code is required.<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">130. Deletion Phase<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Deletion should be exceptional for business repositories.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Use approval and evidence:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Owner approval\nSecurity\/compliance check\nDependency check\nBackup\/export decision\nCredential revocation\nDeletion\nPost-delete verification\n<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Part XXI \u2014 Troubleshooting Guide<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">131. Access Troubleshooting<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Problem<\/th><th class=\"has-text-align-left\" data-align=\"left\">Likely cause<\/th><th class=\"has-text-align-left\" data-align=\"left\">Diagnose<\/th><th class=\"has-text-align-left\" data-align=\"left\">Solution<\/th><\/tr><\/thead><tbody><tr><td>User cannot clone private repo<\/td><td>No effective Read access<\/td><td>Check direct, team, base access<\/td><td>Add appropriate team\/role<\/td><\/tr><tr><td>User has more access than expected<\/td><td>Multiple access paths<\/td><td>Review teams and base permissions<\/td><td>Remove excess path<\/td><\/tr><tr><td>Cannot add outside collaborator<\/td><td>Org\/enterprise policy<\/td><td>Check organization policy<\/td><td>Use approved invitation path<\/td><\/tr><tr><td>User cannot change setting<\/td><td>Higher-level enforcement<\/td><td>Check org\/enterprise policy<\/td><td>Change policy at owning layer<\/td><\/tr><tr><td>Collaborator invitation pending<\/td><td>Not accepted \/ identity policy<\/td><td>Check access page<\/td><td>Reinvite or satisfy identity requirement<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">Debug principle<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Do not ask only \u201cwhat role does the user have?\u201d Ask:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>What are all paths that grant this user access?\n<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">132. Ruleset Troubleshooting<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Problem<\/th><th class=\"has-text-align-left\" data-align=\"left\">Likely cause<\/th><th class=\"has-text-align-left\" data-align=\"left\">Diagnose<\/th><th class=\"has-text-align-left\" data-align=\"left\">Solution<\/th><\/tr><\/thead><tbody><tr><td>Push blocked unexpectedly<\/td><td>Branch\/tag\/push ruleset<\/td><td>Open repository rules \/ rule insights<\/td><td>Identify matching rule<\/td><\/tr><tr><td>Merge blocked<\/td><td>Required review\/check\/deployment<\/td><td>Check PR merge box<\/td><td>Complete missing condition<\/td><\/tr><tr><td>Required check missing<\/td><td>Job renamed or workflow not triggered<\/td><td>Inspect Actions run and ruleset check name<\/td><td>Restore check or update rule<\/td><\/tr><tr><td>Admin cannot bypass<\/td><td>No bypass or rule applies to admins<\/td><td>Inspect bypass list<\/td><td>Add approved bypass actor<\/td><\/tr><tr><td>Fork push blocked<\/td><td>Root push ruleset<\/td><td>Inspect source repository rules<\/td><td>Change root policy if justified<\/td><\/tr><tr><td>Conversion behaves differently<\/td><td>Legacy rule not 1:1 mapped<\/td><td>Compare branch protection and ruleset<\/td><td>Tune converted ruleset<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">Rule debugging order<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>1. Which ref is targeted?\n2. Which rulesets match?\n3. Is legacy branch protection also active?\n4. Which rule is most restrictive?\n5. Is an organization ruleset layered on top?\n6. Is bypass actually granted to this actor?\n<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">133. Actions Settings Troubleshooting<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Problem<\/th><th class=\"has-text-align-left\" data-align=\"left\">Likely cause<\/th><th class=\"has-text-align-left\" data-align=\"left\">Diagnose<\/th><th class=\"has-text-align-left\" data-align=\"left\">Solution<\/th><\/tr><\/thead><tbody><tr><td>Workflow never starts<\/td><td>Actions disabled<\/td><td>Settings \u2192 Actions<\/td><td>Enable if policy permits<\/td><\/tr><tr><td>Action denied<\/td><td>Allowlist policy<\/td><td>Check failure message and Actions policy<\/td><td>Allow approved action<\/td><\/tr><tr><td><code>GITHUB_TOKEN<\/code>&nbsp;permission denied<\/td><td>Token too restricted<\/td><td>Inspect workflow&nbsp;<code>permissions<\/code><\/td><td>Grant minimal required scope<\/td><\/tr><tr><td>Reusable workflow inaccessible<\/td><td>Private workflow access not granted<\/td><td>Check source repo Actions access<\/td><td>Grant org\/repo access<\/td><\/tr><tr><td>Cache constantly evicted<\/td><td>Cache limit too small<\/td><td>Inspect cache usage<\/td><td>Increase limit or improve keys<\/td><\/tr><tr><td>Runner offline<\/td><td>Host\/registration\/network failure<\/td><td>Runner settings and host logs<\/td><td>Restore or re-register runner<\/td><\/tr><tr><td>Secret empty<\/td><td>Event or scope restriction<\/td><td>Check event and secret scope<\/td><td>Use correct environment\/repo secret<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">Example permissions failure<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">If a workflow tries to create a release with:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>permissions:\n  contents: read\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">it will not have the required write capability. Grant only the needed permission:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>permissions:\n  contents: write\n<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">134. Environment Troubleshooting<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Problem<\/th><th class=\"has-text-align-left\" data-align=\"left\">Likely cause<\/th><th class=\"has-text-align-left\" data-align=\"left\">Diagnose<\/th><th class=\"has-text-align-left\" data-align=\"left\">Solution<\/th><\/tr><\/thead><tbody><tr><td>Deployment waits indefinitely<\/td><td>Required reviewer<\/td><td>Open deployment review UI<\/td><td>Approve with eligible reviewer<\/td><\/tr><tr><td>Initiator cannot approve<\/td><td>Prevent self-review enabled<\/td><td>Check environment protection<\/td><td>Use another reviewer<\/td><\/tr><tr><td>Branch cannot deploy<\/td><td>Branch\/tag restriction<\/td><td>Compare ref with environment rule<\/td><td>Update ref or approved policy<\/td><\/tr><tr><td>Secret not available<\/td><td>Job not using environment<\/td><td>Inspect workflow job<\/td><td>Add&nbsp;<code>environment:<\/code><\/td><\/tr><tr><td>Protection App blocks deployment<\/td><td>External gate failed<\/td><td>Inspect protection rule response<\/td><td>Fix external condition<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">135. Advanced Security Troubleshooting<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Problem<\/th><th class=\"has-text-align-left\" data-align=\"left\">Likely cause<\/th><th class=\"has-text-align-left\" data-align=\"left\">Diagnose<\/th><th class=\"has-text-align-left\" data-align=\"left\">Solution<\/th><\/tr><\/thead><tbody><tr><td>Code scanning option unavailable<\/td><td>Visibility\/license\/product issue<\/td><td>Check plan and security configuration<\/td><td>Enable required product<\/td><\/tr><tr><td>Default setup cannot enable<\/td><td>Actions disabled or unsupported repo<\/td><td>Check prerequisites<\/td><td>Enable Actions \/ use eligible repository<\/td><\/tr><tr><td>Secret scanning missing<\/td><td>Product\/policy not enabled<\/td><td>Check Advanced Security config<\/td><td>Enable Secret Protection\/eligible feature<\/td><\/tr><tr><td>Dependabot alerts absent<\/td><td>Dependency graph unavailable\/disabled<\/td><td>Check dependency graph<\/td><td>Enable and commit supported manifests<\/td><\/tr><tr><td>AI Scan not available<\/td><td>Preview eligibility\/licensing<\/td><td>Check GHAS\/Copilot\/policy<\/td><td>Enable only if eligible<\/td><\/tr><tr><td>Code Quality unavailable<\/td><td>Plan\/enterprise policy<\/td><td>Check entitlement and policy<\/td><td>Enable where supported<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">136. Pages Troubleshooting<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Problem<\/th><th class=\"has-text-align-left\" data-align=\"left\">Likely cause<\/th><th class=\"has-text-align-left\" data-align=\"left\">Diagnose<\/th><th class=\"has-text-align-left\" data-align=\"left\">Solution<\/th><\/tr><\/thead><tbody><tr><td>Site not publishing<\/td><td>Wrong source<\/td><td>Pages settings \/ Actions<\/td><td>Correct branch or workflow<\/td><\/tr><tr><td>404<\/td><td>Missing index or wrong path<\/td><td>Inspect published artifact<\/td><td>Add valid site root<\/td><\/tr><tr><td>Custom domain fails<\/td><td>DNS wrong<\/td><td>DNS lookup + Pages settings<\/td><td>Correct record<\/td><\/tr><tr><td>HTTPS unavailable<\/td><td>DNS\/CAA\/certificate issue<\/td><td>Check domain and certificate state<\/td><td>Fix DNS\/CAA and retry<\/td><\/tr><tr><td>Old domain points to deleted site<\/td><td>Stale DNS<\/td><td>DNS audit<\/td><td>Remove\/update record immediately<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">137. Webhook Troubleshooting<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Symptom<\/th><th class=\"has-text-align-left\" data-align=\"left\">Likely cause<\/th><th class=\"has-text-align-left\" data-align=\"left\">What to inspect<\/th><\/tr><\/thead><tbody><tr><td>401\/403<\/td><td>Signature\/auth failure<\/td><td>Secret and signature verification<\/td><\/tr><tr><td>404<\/td><td>Wrong endpoint<\/td><td>Payload URL<\/td><\/tr><tr><td>5xx<\/td><td>Receiver application error<\/td><td>Server logs<\/td><\/tr><tr><td>Timeout<\/td><td>Receiver slow\/unreachable<\/td><td>Network and processing time<\/td><\/tr><tr><td>Duplicate processing<\/td><td>Redelivery\/retry\/idempotency issue<\/td><td>Delivery ID and idempotency key<\/td><\/tr><tr><td>Missing event<\/td><td>Event not subscribed<\/td><td>Webhook event settings<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Part XXII \u2014 Best Practices<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">138. Access Best Practices<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Recommended<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Grant access through teams.<\/li>\n\n\n\n<li>Use least privilege.<\/li>\n\n\n\n<li>Minimize direct collaborators.<\/li>\n\n\n\n<li>Review outside collaborators.<\/li>\n\n\n\n<li>Keep Admin role rare.<\/li>\n\n\n\n<li>Audit access periodically.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Avoid<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Permanent admin access \u201cjust in case.\u201d<\/li>\n\n\n\n<li>Shared GitHub accounts.<\/li>\n\n\n\n<li>Stale contractor access.<\/li>\n\n\n\n<li>Making every team a direct collaborator on every repository.<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">139. Branch and Ruleset Best Practices<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Recommended<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Protect the default branch.<\/li>\n\n\n\n<li>Require pull requests.<\/li>\n\n\n\n<li>Require meaningful CI checks.<\/li>\n\n\n\n<li>Require code-owner reviews for sensitive paths.<\/li>\n\n\n\n<li>Block force pushes to protected production branches.<\/li>\n\n\n\n<li>Use Evaluate mode before broad ruleset rollout.<\/li>\n\n\n\n<li>Review bypass events.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Avoid<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Rules nobody can explain.<\/li>\n\n\n\n<li>Dozens of overlapping status checks.<\/li>\n\n\n\n<li>Broad bypass groups.<\/li>\n\n\n\n<li>Keeping legacy protections and new rulesets indefinitely without understanding their combined effect.<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">140. CI\/CD Best Practices<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Recommended<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Restrictive default\u00a0<code>GITHUB_TOKEN<\/code>.<\/li>\n\n\n\n<li>Explicit workflow\u00a0<code>permissions<\/code>.<\/li>\n\n\n\n<li>OIDC for cloud access.<\/li>\n\n\n\n<li>Protected environments.<\/li>\n\n\n\n<li>SHA-pinned critical third-party Actions.<\/li>\n\n\n\n<li>Organization reusable workflows.<\/li>\n\n\n\n<li>Ephemeral runners for sensitive workloads.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Avoid<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Long-lived cloud keys in repository secrets.<\/li>\n\n\n\n<li><code>write-all<\/code>\u00a0permissions by default.<\/li>\n\n\n\n<li>Unreviewed third-party Actions.<\/li>\n\n\n\n<li>Production deployment from arbitrary feature branches.<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">141. Security Best Practices<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Use defense in depth:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Dependencies \u2192 Dependabot + Dependency Review\nSource       \u2192 Code Scanning + AI Scan where eligible\nSecrets      \u2192 Secret Scanning + Push Protection\nQuality      \u2192 Code Quality + Coverage\nChanges      \u2192 Rulesets + Reviews + CODEOWNERS\nReleases     \u2192 Protected Tags + Immutability\nDeployments  \u2192 Environments + OIDC + Approvals\n<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">142. Lifecycle Best Practices<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Assign an owner to every repository.<\/li>\n\n\n\n<li>Record lifecycle status.<\/li>\n\n\n\n<li>Deprecate before archiving.<\/li>\n\n\n\n<li>Archive before deleting when practical.<\/li>\n\n\n\n<li>Revoke credentials during retirement.<\/li>\n\n\n\n<li>Maintain a documented deletion policy.<\/li>\n\n\n\n<li>Back up only what the organization actually needs to retain.<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Part XXIII \u2014 Common Mistakes<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">143. Common Repository Administration Mistakes<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Mistake<\/th><th class=\"has-text-align-left\" data-align=\"left\">Why it happens<\/th><th class=\"has-text-align-left\" data-align=\"left\">Impact<\/th><th class=\"has-text-align-left\" data-align=\"left\">Better approach<\/th><\/tr><\/thead><tbody><tr><td>Giving Admin to all developers<\/td><td>Convenience<\/td><td>Excess destructive power<\/td><td>Write\/Maintain + controlled admin<\/td><\/tr><tr><td>Protecting only&nbsp;<code>main<\/code>&nbsp;with old branch rule<\/td><td>Legacy setup<\/td><td>Weak coverage and hard-to-see overlap<\/td><td>Migrate thoughtfully to rulesets<\/td><\/tr><tr><td>Requiring too many checks<\/td><td>\u201cMore is safer\u201d<\/td><td>Slow PRs, flaky merges<\/td><td>Require only policy-critical checks<\/td><\/tr><tr><td>Storing cloud keys in secrets forever<\/td><td>Easy initial setup<\/td><td>Credential exposure risk<\/td><td>OIDC federation<\/td><\/tr><tr><td>Allowing every Marketplace Action<\/td><td>Convenience<\/td><td>Supply-chain exposure<\/td><td>Allowlist and pin<\/td><\/tr><tr><td>Unprotected workflow files<\/td><td>Forgotten privilege boundary<\/td><td>CI credential compromise<\/td><td>CODEOWNERS + rules<\/td><\/tr><tr><td>Using variables for secrets<\/td><td>Misunderstanding<\/td><td>Secret disclosure<\/td><td>Use secrets<\/td><\/tr><tr><td>Using repository secret for prod without environment<\/td><td>Simplicity<\/td><td>Broader credential access<\/td><td>Production environment secret<\/td><\/tr><tr><td>No access review<\/td><td>Access only grows<\/td><td>Stale privilege<\/td><td>Periodic review<\/td><\/tr><tr><td>Deleting instead of archiving<\/td><td>Cleanup pressure<\/td><td>Loss of reference\/history<\/td><td>Deprecate \u2192 archive \u2192 delete if justified<\/td><\/tr><tr><td>Ignoring visibility-change side effects<\/td><td>UI looks simple<\/td><td>Fork\/log\/security surprises<\/td><td>Pre-change checklist<\/td><\/tr><tr><td>Treating preview features as stable<\/td><td>New feature excitement<\/td><td>Automation breakage<\/td><td>Pin expectations and monitor changelog<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Part XXIV \u2014 Beginner \u2192 Intermediate \u2192 Advanced Learning Map<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">144. Learning Levels<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Level<\/th><th class=\"has-text-align-left\" data-align=\"left\">What to learn<\/th><\/tr><\/thead><tbody><tr><td>Beginner<\/td><td>General settings, default branch, Issues, PR merge options, collaborators, basic branch protection<\/td><\/tr><tr><td>Intermediate<\/td><td>Rulesets, Actions permissions, environments, webhooks, Pages, Dependabot, secrets\/variables<\/td><\/tr><tr><td>Advanced<\/td><td>Organization\/enterprise inheritance, security merge gates, Code Quality, AI Scan, APIs, Terraform, governance architecture<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">Suggested progression<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>Repository basics\n    \u2193\nAccess + pull requests\n    \u2193\nRulesets\n    \u2193\nActions\n    \u2193\nEnvironments\n    \u2193\nSecurity\n    \u2193\nAutomation\/IaC\n    \u2193\nOrganization-scale governance\n<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Part XXV \u2014 Quick Reference \/ Cheat Sheet<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">145. High-Value UI Paths<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Task<\/th><th class=\"has-text-align-left\" data-align=\"left\">Common path<\/th><\/tr><\/thead><tbody><tr><td>Rename repo<\/td><td>Settings \u2192 General<\/td><\/tr><tr><td>Change visibility<\/td><td>Settings \u2192 General \u2192 Danger Zone<\/td><\/tr><tr><td>Manage access<\/td><td>Settings \u2192 Collaborators and teams<\/td><\/tr><tr><td>Create ruleset<\/td><td>Settings \u2192 Rulesets \/ Rules<\/td><\/tr><tr><td>Legacy branch protection<\/td><td>Settings \u2192 Branches<\/td><\/tr><tr><td>Actions permissions<\/td><td>Settings \u2192 Actions \u2192 General<\/td><\/tr><tr><td>Runners<\/td><td>Settings \u2192 Actions \u2192 Runners<\/td><\/tr><tr><td>Webhooks<\/td><td>Settings \u2192 Webhooks<\/td><\/tr><tr><td>Environments<\/td><td>Settings \u2192 Environments<\/td><\/tr><tr><td>Pages<\/td><td>Settings \u2192 Pages<\/td><\/tr><tr><td>Advanced Security<\/td><td>Settings \u2192 Advanced Security<\/td><\/tr><tr><td>Code Quality<\/td><td>Settings \u2192 Code quality<\/td><\/tr><tr><td>Deploy keys<\/td><td>Settings \u2192 Deploy keys<\/td><\/tr><tr><td>Actions secrets<\/td><td>Settings \u2192 Secrets and variables \u2192 Actions<\/td><\/tr><tr><td>GitHub Apps<\/td><td>Settings \u2192 GitHub Apps<\/td><\/tr><tr><td>Push email<\/td><td>Settings \u2192 Email notifications<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">UI names can vary as GitHub reorganizes navigation.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">146. High-Value GitHub CLI Commands<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code><em># View repository<\/em>\ngh repo view OWNER\/REPO\n\n<em># Edit common settings<\/em>\ngh repo edit OWNER\/REPO --delete-branch-on-merge\n\n<em># List secrets<\/em>\ngh secret list --repo OWNER\/REPO\n\n<em># Create\/update secret<\/em>\ngh secret set TOKEN --repo OWNER\/REPO\n\n<em># List variables<\/em>\ngh variable list --repo OWNER\/REPO\n\n<em># Create\/update variable<\/em>\ngh variable set REGION --body \"ap-northeast-1\" --repo OWNER\/REPO\n\n<em># Query REST API<\/em>\ngh api \/repos\/OWNER\/REPO\n\n<em># List rulesets<\/em>\ngh api \/repos\/OWNER\/REPO\/rulesets\n\n<em># Inspect Actions permission policy<\/em>\ngh api \/repos\/OWNER\/REPO\/actions\/permissions\n<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">147. Permission Reminders<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>Human access:\nRead \u2192 Triage \u2192 Write \u2192 Maintain \u2192 Admin\n\nWorkflow security:\nRepository default \u2192 Workflow permissions \u2192 Job behavior\n\nPolicy hierarchy:\nEnterprise \u2192 Organization \u2192 Repository \u2192 Environment \u2192 Workflow\n<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">148. Repository Security Baseline Cheat Sheet<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>&#91; ] Team-based access\n&#91; ] Protected default branch\n&#91; ] Pull request required\n&#91; ] Required CI checks\n&#91; ] CODEOWNERS for sensitive paths\n&#91; ] Minimal GITHUB_TOKEN\n&#91; ] Trusted\/pinned Actions\n&#91; ] Dependency graph + Dependabot\n&#91; ] Code scanning where eligible\n&#91; ] Secret scanning + push protection where eligible\n&#91; ] Protected production environment\n&#91; ] OIDC for cloud access\n&#91; ] Release\/tag integrity controls\n&#91; ] Periodic app\/access review\n<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Part XXVI \u2014 Hands-On Exercises<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">149. Exercise 1 \u2014 Beginner: Configure a Safe Development Repository<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Objective<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Configure basic repository behavior for a small development team.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Tasks<\/h3>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Create or choose a test repository.<\/li>\n\n\n\n<li>Set a clear description.<\/li>\n\n\n\n<li>Enable Issues.<\/li>\n\n\n\n<li>Disable Wiki if the team does not use it.<\/li>\n\n\n\n<li>Set\u00a0<code>main<\/code>\u00a0as the default branch.<\/li>\n\n\n\n<li>Enable squash merge.<\/li>\n\n\n\n<li>Enable automatic deletion of merged branches.<\/li>\n\n\n\n<li>Add a teammate with Write access through a team if using an organization.<\/li>\n\n\n\n<li>Create a simple branch protection\/ruleset requiring a pull request.<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">Expected outcome<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Developers cannot casually push unreviewed changes to the protected default branch, and merged feature branches are cleaned up automatically.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Verification<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Create a test branch and attempt to merge without the required condition.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">150. Exercise 2 \u2014 Intermediate: Secure a CI Workflow<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Objective<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Create a CI workflow with minimal token permissions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Create:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>.github\/workflows\/ci.yml\n<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>name: CI\n\non:\n  pull_request:\n  push:\n    branches:\n      - main\n\npermissions:\n  contents: read\n\njobs:\n  test:\n    runs-on: ubuntu-latest\n    steps:\n      - uses: actions\/checkout@v7\n      - name: Test\n        run: echo \"Replace with real tests\"\n<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Tasks<\/h3>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Commit the workflow.<\/li>\n\n\n\n<li>Confirm Actions is enabled.<\/li>\n\n\n\n<li>Set the repository&#8217;s default workflow permission to restricted\/read.<\/li>\n\n\n\n<li>Create a ruleset that requires the CI check before merge.<\/li>\n\n\n\n<li>Open a pull request.<\/li>\n\n\n\n<li>Confirm the check runs.<\/li>\n\n\n\n<li>Confirm merge is blocked until the check succeeds.<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">Expected outcome<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">CI is mandatory, but the workflow itself does not have unnecessary write permissions.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">151. Exercise 3 \u2014 Intermediate: Protect Production Deployment<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Objective<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Use an environment to control production deployment.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Workflow:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>name: Deploy\n\non:\n  workflow_dispatch:\n\npermissions:\n  contents: read\n  id-token: write\n\njobs:\n  deploy:\n    environment: production\n    runs-on: ubuntu-latest\n    steps:\n      - uses: actions\/checkout@v7\n      - run: echo \"Deploy production\"\n<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Tasks<\/h3>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Create the\u00a0<code>production<\/code>\u00a0environment.<\/li>\n\n\n\n<li>Add a required reviewer where your plan supports it.<\/li>\n\n\n\n<li>Prevent self-review where available.<\/li>\n\n\n\n<li>Restrict deployment to\u00a0<code>main<\/code>.<\/li>\n\n\n\n<li>Add a non-secret variable such as\u00a0<code>REGION<\/code>.<\/li>\n\n\n\n<li>If testing with a cloud provider, use OIDC instead of a static credential.<\/li>\n\n\n\n<li>Run the workflow manually.<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">Expected outcome<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The job pauses at the environment gate before executing deployment steps.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">152. Exercise 4 \u2014 Advanced: Create a Repository Ruleset<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Objective<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Build a realistic default-branch ruleset.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Policy<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>Target: default branch\nRequire pull request: yes\nApprovals: 1\nCode owner review: yes\nRequired check: CI\nBlock force pushes: yes\nRestrict deletion: yes\n<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Tasks<\/h3>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Create a\u00a0<code>CODEOWNERS<\/code>\u00a0file.<\/li>\n\n\n\n<li>Create the ruleset in Evaluate mode if available.<\/li>\n\n\n\n<li>Open a pull request without approval.<\/li>\n\n\n\n<li>Review Rule Insights.<\/li>\n\n\n\n<li>Approve the PR and let CI pass.<\/li>\n\n\n\n<li>Activate the ruleset.<\/li>\n\n\n\n<li>Test again.<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">Expected outcome<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">You understand the difference between observing rule impact and actively enforcing it.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">153. Exercise 5 \u2014 Advanced: Automate Repository Inventory<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Objective<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Use GitHub CLI and REST to inventory key repository settings.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Example:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>gh api \\\n  -H \"X-GitHub-Api-Version: 2026-03-10\" \\\n  \"\/repos\/$OWNER\/$REPO\" \\\n  --jq '{\n    name,\n    visibility,\n    default_branch,\n    archived,\n    has_issues,\n    has_wiki,\n    delete_branch_on_merge\n  }'\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Then inspect rulesets:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>gh api \\\n  -H \"X-GitHub-Api-Version: 2026-03-10\" \\\n  \"\/repos\/$OWNER\/$REPO\/rulesets\" \\\n  --jq '.&#91;] | {name,enforcement,target}'\n<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Challenge<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Create a script that checks 10 repositories and reports:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Visibility<\/li>\n\n\n\n<li>Default branch<\/li>\n\n\n\n<li>Whether merged branches are deleted<\/li>\n\n\n\n<li>Number of rulesets<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Do not mutate production repositories during the exercise.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Part XXVII \u2014 Complete Practical Project<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">154. Project \u2014 Build a Production-Ready Repository Baseline<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Requirement<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A platform team needs a secure standard for new production services.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The repository must support:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Team-based access<\/li>\n\n\n\n<li>Pull-request-only default branch<\/li>\n\n\n\n<li>CI requirement<\/li>\n\n\n\n<li>Dependency\/security controls<\/li>\n\n\n\n<li>Protected production deployment<\/li>\n\n\n\n<li>GitHub Actions least privilege<\/li>\n\n\n\n<li>Repository metadata<\/li>\n\n\n\n<li>IaC management<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Architecture<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>flowchart TD\n    DEV&#91;Developer] --&gt; PR&#91;Pull Request]\n    PR --&gt; CI&#91;CI Checks]\n    CI --&gt; SEC&#91;Security and Quality Checks]\n    SEC --&gt; REV&#91;Review and CODEOWNERS]\n    REV --&gt; M&#91;Merge to Main]\n    M --&gt; ENV&#91;Production Environment]\n    ENV --&gt; APP&#91;Deployment Approval]\n    APP --&gt; OIDC&#91;OIDC Cloud Role]\n    OIDC --&gt; PROD&#91;Production]\n<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Step 1 \u2014 Repository metadata<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Set:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Name: payment-api\nVisibility: private\nDescription: Payment service API\nOwner team: payments-platform\nService tier: tier-1\nLifecycle: active\n<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Step 2 \u2014 Access<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>payments-developers \u2192 Write\npayments-maintainers \u2192 Maintain\nplatform-admins \u2192 Admin\nsecurity-reviewers \u2192 Read\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Avoid individual direct collaborators unless justified.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Step 3 \u2014 Merge model<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>Squash merge: enabled\nMerge commit: disabled\nRebase merge: disabled\nDelete merged branch: enabled\n<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Step 4 \u2014 CODEOWNERS<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>* @example\/payments-maintainers\n.github\/workflows\/ @example\/platform-security\nterraform\/ @example\/cloud-platform\n<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Step 5 \u2014 Ruleset<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Protect the default branch with:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Pull request required\n1 approval\nCode owner review required\nCI required\nConversation resolution required\nForce push blocked\nDeletion restricted\n<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Step 6 \u2014 Actions policy<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Keep\u00a0<code>GITHUB_TOKEN<\/code>\u00a0read-only by default.<\/li>\n\n\n\n<li>Allow only approved actions.<\/li>\n\n\n\n<li>Use reusable organization workflows where practical.<\/li>\n\n\n\n<li>Pin sensitive third-party actions.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Step 7 \u2014 Security<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Enable eligible controls:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Dependency graph\nDependabot alerts\nDependabot security updates\nCode scanning\nSecret scanning\nPush protection\nCode Quality if licensed and adopted\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Evaluate AI Scan separately because it is currently preview functionality.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Step 8 \u2014 Environment<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Create&nbsp;<code>production<\/code>:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Required reviewer: release\/platform team\nPrevent self-review: enabled where supported\nAllowed branch: main\nSecrets: minimal\nCloud auth: OIDC\n<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Step 9 \u2014 IaC<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Manage the baseline with Terraform or a platform provisioning system.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Store desired state in a dedicated governance repository and review changes through pull requests.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Step 10 \u2014 Validation<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Test all of the following:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&#91; ] Direct push to main blocked\n&#91; ] PR without review blocked\n&#91; ] PR without CI blocked\n&#91; ] Workflow cannot write with read-only token\n&#91; ] Production job pauses for approval\n&#91; ] Feature branch cannot deploy to production\n&#91; ] Secret push is blocked where enabled\n&#91; ] Unauthorized Action is denied\n&#91; ] Ruleset bypass is logged\n<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Improvement ideas<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Organization-level rulesets<\/li>\n\n\n\n<li>Repository custom-property policy<\/li>\n\n\n\n<li>Automated repository scorecard<\/li>\n\n\n\n<li>GitHub App based drift remediation<\/li>\n\n\n\n<li>Artifact attestations<\/li>\n\n\n\n<li>Central reusable workflows<\/li>\n\n\n\n<li>Periodic access review automation<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Part XXVIII \u2014 Interview and Knowledge-Check Questions<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">155. Conceptual Questions<\/h2>\n\n\n\n<ol class=\"wp-block-list\">\n<li>What is the difference between Read, Triage, Write, Maintain, and Admin?<\/li>\n\n\n\n<li>How does an organization policy affect repository settings?<\/li>\n\n\n\n<li>What is the difference between branch protection and rulesets?<\/li>\n\n\n\n<li>Why are multiple matching rulesets easier to reason about than multiple legacy branch rules?<\/li>\n\n\n\n<li>What is the purpose of a push ruleset?<\/li>\n\n\n\n<li>Why should\u00a0<code>GITHUB_TOKEN<\/code>\u00a0use least privilege?<\/li>\n\n\n\n<li>What is the difference between a secret and a variable?<\/li>\n\n\n\n<li>Why are environment secrets stronger than broad repository secrets for production?<\/li>\n\n\n\n<li>What is the difference between CodeQL default setup and advanced setup?<\/li>\n\n\n\n<li>What problem does release immutability solve?<\/li>\n\n\n\n<li>Why is a webhook secret necessary?<\/li>\n\n\n\n<li>What is the difference between a deploy key and a GitHub App?<\/li>\n\n\n\n<li>Why should workflow files be protected with CODEOWNERS?<\/li>\n\n\n\n<li>What does OIDC improve compared with static cloud credentials?<\/li>\n\n\n\n<li>How do custom properties help repository governance?<\/li>\n<\/ol>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">156. Scenario Questions<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Scenario 1<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A developer has Write access but GitHub says the repository is read-only.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Think about:<\/strong>&nbsp;is the repository archived?<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Scenario 2<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">An admin cannot merge a PR even though they normally bypass branch protection.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Think about:<\/strong>&nbsp;ruleset bypass configuration, organization rulesets, and \u201capply to admins\u201d\/bypass behavior.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Scenario 3<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A workflow can read code but cannot create a release.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Think about:<\/strong>&nbsp;<code>GITHUB_TOKEN<\/code>&nbsp;<code>contents<\/code>&nbsp;permission.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Scenario 4<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A production secret is empty during a deployment job.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Think about:<\/strong>&nbsp;whether the job references the environment and has passed its protection rules.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Scenario 5<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A private repository is changed to public and a push-content rule disappears.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Think about:<\/strong>&nbsp;push rulesets are intended for private\/internal repositories and fork networks.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Scenario 6<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Code scanning is available in one repository but not another in the same organization.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Think about:<\/strong>&nbsp;visibility, security-product enablement, organization configuration, and plan eligibility.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Scenario 7<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A Copilot code review can access an internal tool through MCP.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Think about:<\/strong>&nbsp;allowlisted tools, read-only constraints, MCP credentials, and autonomous invocation risk.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Part XXIX \u2014 FAQ<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">157. Should we use rulesets or branch protection?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">For new governance designs, rulesets are generally the more scalable model because they layer, expose insights, support organization governance, and include push rulesets. Legacy branch protection remains valid and may continue to exist during migration.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">158. Can repository admins override organization rules?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Not when the organization or enterprise policy is enforced in a way that prevents the repository from loosening it. Repository admins operate inside the higher-level policy boundary.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">159. Should every developer have Admin?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">No. Most developers need Write. Maintainers who manage repository behavior may need Maintain. Admin should be limited to people who genuinely administer the repository.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">160. Should we use repository secrets for AWS\/Azure\/GCP credentials?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Prefer OIDC federation when the cloud provider supports it. Use stored secrets only for credentials that cannot be replaced with short-lived identity.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">161. Is squash merge always best?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">No. It is a common default because it keeps main history compact, but repositories that value individual commit history may prefer rebase or merge commits.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">162. Is a&nbsp;<code>Signed-off-by<\/code>&nbsp;line a cryptographic signature?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">No. Commit signoff and verified commit signing are different mechanisms.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">163. Does a private repository always produce a private GitHub Pages site?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">No. Pages visibility depends on plan and Pages configuration. Verify the site visibility independently.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">164. Does deleting a repository permanently remove it immediately?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">GitHub can restore some deleted repositories within 90 days, subject to fork-network and other restoration constraints. Do not treat restoration as a backup strategy.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">165. Is AI Scan a replacement for CodeQL?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">No. As of September 2026 it is a public-preview, pull-request-focused feature intended to extend coverage for languages\/frameworks beyond CodeQL. It complements code scanning.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">166. Does enabling Code Quality automatically block bad pull requests?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">No. Analysis and enforcement are separate. Use a ruleset with the appropriate Code Quality rule\/threshold if you want merge blocking.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">167. Can a repository setting be different from the organization default?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Often yes, when the higher-level policy allows local choice. If the organization or enterprise enforces a setting, the repository cannot loosen it.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">168. Should we manage repositories with Terraform?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Use IaC when you need repeatable multi-repository governance. For a handful of simple repositories, UI\/API management may be enough. The important requirement is consistent, reviewable desired state.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Part XXX \u2014 Reference Architecture for Enterprise Repository Governance<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">169. Recommended Layering<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>flowchart TD\n    EP&#91;Enterprise Policy] --&gt; OP&#91;Organization Policy]\n    OP --&gt; CP&#91;Custom Properties]\n    CP --&gt; OR&#91;Organization Rulesets]\n    OR --&gt; RR&#91;Repository Rulesets]\n    RR --&gt; CI&#91;Required CI]\n    CI --&gt; SQ&#91;Security and Quality]\n    SQ --&gt; ENV&#91;Protected Environment]\n    ENV --&gt; OIDC&#91;OIDC Deployment]\n<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Enterprise layer<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Use for broad guardrails:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Identity<\/li>\n\n\n\n<li>Actions policy<\/li>\n\n\n\n<li>Security-product policy<\/li>\n\n\n\n<li>App policy<\/li>\n\n\n\n<li>Visibility policy<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Organization layer<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Use for portfolio governance:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Teams<\/li>\n\n\n\n<li>Base permissions<\/li>\n\n\n\n<li>Custom properties<\/li>\n\n\n\n<li>Organization rulesets<\/li>\n\n\n\n<li>Security configurations<\/li>\n\n\n\n<li>Runner groups<\/li>\n\n\n\n<li>Reusable workflows<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Repository layer<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Use for service-specific behavior:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Merge model<\/li>\n\n\n\n<li>Repository rulesets<\/li>\n\n\n\n<li>Environment configuration<\/li>\n\n\n\n<li>Webhooks<\/li>\n\n\n\n<li>Repository-specific secrets\/variables<\/li>\n\n\n\n<li>Pages<\/li>\n\n\n\n<li>Repo-specific Apps<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Part XXXI \u2014 Repository Administration Operating Model<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">170. Who Should Own What?<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Control<\/th><th class=\"has-text-align-left\" data-align=\"left\">Suggested owner<\/th><\/tr><\/thead><tbody><tr><td>Repository metadata<\/td><td>Service owner \/ platform<\/td><\/tr><tr><td>Team access<\/td><td>Engineering manager \/ platform<\/td><\/tr><tr><td>Admin access<\/td><td>Platform \/ repository owner<\/td><\/tr><tr><td>Rulesets<\/td><td>Platform + service team<\/td><\/tr><tr><td>Actions allowlist<\/td><td>Platform\/security<\/td><\/tr><tr><td>Reusable workflows<\/td><td>Platform\/DevOps<\/td><\/tr><tr><td>Code scanning<\/td><td>Security\/platform<\/td><\/tr><tr><td>Secret scanning<\/td><td>Security\/platform<\/td><\/tr><tr><td>Code Quality<\/td><td>Engineering\/platform<\/td><\/tr><tr><td>Environments<\/td><td>Platform\/release engineering<\/td><\/tr><tr><td>Production reviewers<\/td><td>Service\/release owner<\/td><\/tr><tr><td>GitHub Apps<\/td><td>Platform\/security<\/td><\/tr><tr><td>Webhooks<\/td><td>Platform\/integration owner<\/td><\/tr><tr><td>Repository retirement<\/td><td>Business + service owner<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The exact organization model varies, but ambiguous ownership is itself a governance risk.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Part XXXII \u2014 Complete Settings Coverage Map<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">The following map connects the supplied 151-topic syllabus to the chapters in this guide.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">171. Basic and General Settings Coverage<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Syllabus topic<\/th><th class=\"has-text-align-left\" data-align=\"left\">Covered in<\/th><\/tr><\/thead><tbody><tr><td>1. GitHub Repository Administration<\/td><td>Sections 1\u20133<\/td><\/tr><tr><td>2. Repository Settings Navigation<\/td><td>Section 3<\/td><\/tr><tr><td>3. Repository Identity<\/td><td>Sections 4\u20135<\/td><\/tr><tr><td>4. Template Repository<\/td><td>Section 6<\/td><\/tr><tr><td>5. Default Branch<\/td><td>Section 7<\/td><\/tr><tr><td>6. Releases<\/td><td>Section 8<\/td><\/tr><tr><td>7. Social Preview<\/td><td>Section 5<\/td><\/tr><tr><td>8. Wikis<\/td><td>Section 9<\/td><\/tr><tr><td>9. Issues<\/td><td>Sections 9, 52\u201355<\/td><\/tr><tr><td>10. Pull Requests<\/td><td>Sections 10\u201313<\/td><\/tr><tr><td>11. Discussions<\/td><td>Section 9<\/td><\/tr><tr><td>12. GitHub Projects<\/td><td>Sections 9, 54\u201355<\/td><\/tr><tr><td>13. Merge Methods<\/td><td>Section 10<\/td><\/tr><tr><td>14. Merge Commit Configuration<\/td><td>Section 10<\/td><\/tr><tr><td>15. Squash Merge Configuration<\/td><td>Section 10<\/td><\/tr><tr><td>16. Pull Request Update Behavior<\/td><td>Section 11<\/td><\/tr><tr><td>17. Auto-Merge<\/td><td>Section 12<\/td><\/tr><tr><td>18. Head Branch Cleanup<\/td><td>Section 13<\/td><\/tr><tr><td>19. Source Archives<\/td><td>Section 14<\/td><\/tr><tr><td>20. Git LFS in Archives<\/td><td>Section 14<\/td><\/tr><tr><td>21. Push Policy<\/td><td>Section 15<\/td><\/tr><tr><td>22. Web Commit Signoff<\/td><td>Section 16<\/td><\/tr><tr><td>23. Automatic Issue Closing<\/td><td>Section 17<\/td><\/tr><tr><td>24. Autolink References<\/td><td>Section 18<\/td><\/tr><tr><td>25. Repository Visibility<\/td><td>Section 19<\/td><\/tr><tr><td>26. Repository Transfer<\/td><td>Section 20<\/td><\/tr><tr><td>27. Repository Archive<\/td><td>Sections 21, 129<\/td><\/tr><tr><td>28. Repository Deletion<\/td><td>Sections 22, 130<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">172. Access, Moderation, Rules, Branches, Tags Coverage<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Syllabus topic<\/th><th class=\"has-text-align-left\" data-align=\"left\">Covered in<\/th><\/tr><\/thead><tbody><tr><td>29. Repository Access Management<\/td><td>Sections 23\u201324<\/td><\/tr><tr><td>30. Repository Roles<\/td><td>Sections 2, 23<\/td><\/tr><tr><td>31. Collaborator Management<\/td><td>Sections 23\u201324<\/td><\/tr><tr><td>32. Team Management<\/td><td>Sections 23\u201324<\/td><\/tr><tr><td>33. Repository Moderation<\/td><td>Section 25<\/td><\/tr><tr><td>34. Interaction Limits<\/td><td>Section 25<\/td><\/tr><tr><td>35. Contribution Moderation<\/td><td>Section 25<\/td><\/tr><tr><td>36. Pull Request Review Restrictions<\/td><td>Section 26<\/td><\/tr><tr><td>37. Rulesets Fundamentals<\/td><td>Section 27<\/td><\/tr><tr><td>38. Ruleset Status<\/td><td>Section 27<\/td><\/tr><tr><td>39. Ruleset Targeting<\/td><td>Section 28<\/td><\/tr><tr><td>40. Ruleset Bypass<\/td><td>Section 29<\/td><\/tr><tr><td>41. Branch and Tag Rules<\/td><td>Section 30<\/td><\/tr><tr><td>42. Push Rules<\/td><td>Section 31<\/td><\/tr><tr><td>43. Security and Quality Rules<\/td><td>Section 32<\/td><\/tr><tr><td>44. Ruleset Administration<\/td><td>Section 33<\/td><\/tr><tr><td>45. Repository Custom Properties<\/td><td>Section 34<\/td><\/tr><tr><td>46. Custom Property Use Cases<\/td><td>Section 34<\/td><\/tr><tr><td>47. Custom Properties and Governance<\/td><td>Sections 34, 118\u2013119<\/td><\/tr><tr><td>48. Branch Administration<\/td><td>Section 35<\/td><\/tr><tr><td>49. Branch Protection Rules<\/td><td>Sections 30, 36<\/td><\/tr><tr><td>50. Branch Protection vs Rulesets<\/td><td>Section 36<\/td><\/tr><tr><td>51. Tag Administration<\/td><td>Section 37<\/td><\/tr><tr><td>52. Tag Rulesets<\/td><td>Section 37<\/td><\/tr><tr><td>53. Immutable Release Tags<\/td><td>Sections 8, 37<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">173. Actions and Webhooks Coverage<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Syllabus topic<\/th><th class=\"has-text-align-left\" data-align=\"left\">Covered in<\/th><\/tr><\/thead><tbody><tr><td>54. Actions Permissions<\/td><td>Section 38<\/td><\/tr><tr><td>55. Workflow Permissions<\/td><td>Section 39<\/td><\/tr><tr><td>56. Fork Pull Request Workflows<\/td><td>Section 40<\/td><\/tr><tr><td>57. Reusable Workflow and Action Access<\/td><td>Section 41<\/td><\/tr><tr><td>58. Workflow Retention<\/td><td>Section 42<\/td><\/tr><tr><td>59. Actions Cache Settings<\/td><td>Section 43<\/td><\/tr><tr><td>60. Repository Runners<\/td><td>Section 44<\/td><\/tr><tr><td>61. Repository Webhooks<\/td><td>Section 45<\/td><\/tr><tr><td>62. Webhook Events<\/td><td>Section 45<\/td><\/tr><tr><td>63. Webhook Operations<\/td><td>Section 47<\/td><\/tr><tr><td>64. Webhook Security<\/td><td>Section 46<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">174. Copilot and Planning Coverage<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Syllabus topic<\/th><th class=\"has-text-align-left\" data-align=\"left\">Covered in<\/th><\/tr><\/thead><tbody><tr><td>65. GitHub Copilot Repository Controls<\/td><td>Section 48<\/td><\/tr><tr><td>66. Copilot Code Review<\/td><td>Section 49<\/td><\/tr><tr><td>67. Repository Custom Instructions<\/td><td>Section 49<\/td><\/tr><tr><td>68. Copilot MCP Servers<\/td><td>Section 50<\/td><\/tr><tr><td>69. Copilot Coding Agent<\/td><td>Section 51<\/td><\/tr><tr><td>70. Repository Planning Features<\/td><td>Sections 52\u201355<\/td><\/tr><tr><td>71. Issue Templates<\/td><td>Section 52<\/td><\/tr><tr><td>72. Issue Metadata<\/td><td>Section 54<\/td><\/tr><tr><td>73. Automatic Planning Behavior<\/td><td>Section 55<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">175. Environments and Pages Coverage<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Syllabus topic<\/th><th class=\"has-text-align-left\" data-align=\"left\">Covered in<\/th><\/tr><\/thead><tbody><tr><td>74. Deployment Environments<\/td><td>Section 56<\/td><\/tr><tr><td>75. Required Reviewers<\/td><td>Section 57<\/td><\/tr><tr><td>76. Wait Timers<\/td><td>Section 58<\/td><\/tr><tr><td>77. Deployment Branches and Tags<\/td><td>Section 59<\/td><\/tr><tr><td>78. Custom Deployment Protection Rules<\/td><td>Section 60<\/td><\/tr><tr><td>79. Environment Secrets<\/td><td>Section 61<\/td><\/tr><tr><td>80. Environment Variables<\/td><td>Section 62<\/td><\/tr><tr><td>81. GitHub Pages<\/td><td>Section 63<\/td><\/tr><tr><td>82. Pages Branch Source<\/td><td>Section 64<\/td><\/tr><tr><td>83. Custom Domains<\/td><td>Section 66<\/td><\/tr><tr><td>84. HTTPS<\/td><td>Section 67<\/td><\/tr><tr><td>85. Pages Visibility<\/td><td>Section 68<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">176. Security and Quality Coverage<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Syllabus topic<\/th><th class=\"has-text-align-left\" data-align=\"left\">Covered in<\/th><\/tr><\/thead><tbody><tr><td>86. Security and Analysis<\/td><td>Section 69<\/td><\/tr><tr><td>87. Dependency Graph<\/td><td>Section 70<\/td><\/tr><tr><td>88. Dependabot Alerts<\/td><td>Section 71<\/td><\/tr><tr><td>89. Dependabot Security Updates<\/td><td>Section 72<\/td><\/tr><tr><td>90. Dependabot Version Updates<\/td><td>Section 73<\/td><\/tr><tr><td>91. Dependency Review<\/td><td>Section 74<\/td><\/tr><tr><td>92. Code Scanning<\/td><td>Sections 75\u201377<\/td><\/tr><tr><td>93. AI Scan<\/td><td>Section 78<\/td><\/tr><tr><td>94. Secret Scanning<\/td><td>Section 79<\/td><\/tr><tr><td>95. Push Protection<\/td><td>Section 80<\/td><\/tr><tr><td>96. GitHub Code Quality<\/td><td>Sections 81\u201384<\/td><\/tr><tr><td>97. Code Quality Pull Request Controls<\/td><td>Section 83<\/td><\/tr><tr><td>98. Code Coverage<\/td><td>Section 84<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">177. Keys, Secrets, Apps, Notifications Coverage<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Syllabus topic<\/th><th class=\"has-text-align-left\" data-align=\"left\">Covered in<\/th><\/tr><\/thead><tbody><tr><td>99. Deploy Keys<\/td><td>Section 85<\/td><\/tr><tr><td>100. Deploy Key Security<\/td><td>Section 86<\/td><\/tr><tr><td>101. Actions Secrets<\/td><td>Section 87<\/td><\/tr><tr><td>102. Actions Variables<\/td><td>Section 88<\/td><\/tr><tr><td>103. Dependabot Secrets<\/td><td>Section 89<\/td><\/tr><tr><td>104. Codespaces Secrets<\/td><td>Section 90<\/td><\/tr><tr><td>105. Copilot\/Agents Secrets and Variables<\/td><td>Section 91<\/td><\/tr><tr><td>106. Installed GitHub Apps<\/td><td>Section 93<\/td><\/tr><tr><td>107. GitHub App Repository Permissions<\/td><td>Section 94<\/td><\/tr><tr><td>108. GitHub App Administration<\/td><td>Sections 93\u201394<\/td><\/tr><tr><td>109. Push Email Notifications<\/td><td>Section 95<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">178. Policy, Governance, API, CLI, IaC Coverage<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Syllabus topic<\/th><th class=\"has-text-align-left\" data-align=\"left\">Covered in<\/th><\/tr><\/thead><tbody><tr><td>110. Organization Policy Overrides<\/td><td>Section 96<\/td><\/tr><tr><td>111. Enterprise Policy Overrides<\/td><td>Section 97<\/td><\/tr><tr><td>112. Configuration Precedence<\/td><td>Sections 1, 97<\/td><\/tr><tr><td>113. Repository Access Model<\/td><td>Sections 23, 98<\/td><\/tr><tr><td>114. Repository Security Model<\/td><td>Sections 98, 121\u2013125<\/td><\/tr><tr><td>115. Repository CI\/CD Governance<\/td><td>Section 99<\/td><\/tr><tr><td>116. Repositories REST API<\/td><td>Sections 100\u2013101<\/td><\/tr><tr><td>117. Collaborators API<\/td><td>Section 102<\/td><\/tr><tr><td>118. Rules API<\/td><td>Section 103<\/td><\/tr><tr><td>119. Actions Administration API<\/td><td>Section 104<\/td><\/tr><tr><td>120. Environment API<\/td><td>Section 105<\/td><\/tr><tr><td>121. Webhooks API<\/td><td>Section 106<\/td><\/tr><tr><td>122. GraphQL Repository Administration<\/td><td>Section 109<\/td><\/tr><tr><td>123. GitHub CLI<\/td><td>Section 108<\/td><\/tr><tr><td>124. Terraform GitHub Provider<\/td><td>Sections 110\u2013115<\/td><\/tr><tr><td>125. Repository as Code<\/td><td>Section 116<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">179. Standardization, Security, Lifecycle, Troubleshooting Coverage<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Syllabus topic<\/th><th class=\"has-text-align-left\" data-align=\"left\">Covered in<\/th><\/tr><\/thead><tbody><tr><td>126. Repository Templates<\/td><td>Section 117<\/td><\/tr><tr><td>127. Repository Metadata Standards<\/td><td>Sections 118\u2013119<\/td><\/tr><tr><td>128. Repository Protection Standards<\/td><td>Section 120<\/td><\/tr><tr><td>129. Least Privilege<\/td><td>Section 121<\/td><\/tr><tr><td>130. Credential Hardening<\/td><td>Section 122<\/td><\/tr><tr><td>131. Supply Chain Security<\/td><td>Sections 123\u2013125<\/td><\/tr><tr><td>132. Repository Creation<\/td><td>Section 126<\/td><\/tr><tr><td>133. Active Repository Operations<\/td><td>Section 127<\/td><\/tr><tr><td>134. Repository Deprecation<\/td><td>Section 128<\/td><\/tr><tr><td>135. Repository Archival<\/td><td>Section 129<\/td><\/tr><tr><td>136. Repository Deletion<\/td><td>Section 130<\/td><\/tr><tr><td>137. Access Troubleshooting<\/td><td>Section 131<\/td><\/tr><tr><td>138. Ruleset Troubleshooting<\/td><td>Section 132<\/td><\/tr><tr><td>139. Actions Settings Troubleshooting<\/td><td>Section 133<\/td><\/tr><tr><td>140. Environment Troubleshooting<\/td><td>Section 134<\/td><\/tr><tr><td>141. Security Troubleshooting<\/td><td>Section 135<\/td><\/tr><tr><td>142. Access Best Practices<\/td><td>Section 138<\/td><\/tr><tr><td>143. Branch Governance Best Practices<\/td><td>Section 139<\/td><\/tr><tr><td>144. CI\/CD Best Practices<\/td><td>Section 140<\/td><\/tr><tr><td>145. Security Best Practices<\/td><td>Section 141<\/td><\/tr><tr><td>146. Repository Lifecycle Best Practices<\/td><td>Section 142<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">180. Exact Settings Areas Coverage<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Syllabus topic<\/th><th class=\"has-text-align-left\" data-align=\"left\">Covered in<\/th><\/tr><\/thead><tbody><tr><td>147. General<\/td><td>Parts I\u2013II<\/td><\/tr><tr><td>148. Access<\/td><td>Part III<\/td><\/tr><tr><td>149. Code, Planning, and Automation<\/td><td>Parts IV\u2013X<\/td><\/tr><tr><td>150. Security and Quality<\/td><td>Parts XI\u2013XIII<\/td><\/tr><tr><td>151. Integrations<\/td><td>Part XIV<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Part XXXIII \u2014 Summary<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">181. What You Should Remember<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">GitHub Repository Settings are not a collection of unrelated toggles. They form a layered repository control system.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The most important mental model is:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Who can access?\n      \u2193\nHow may code change?\n      \u2193\nWhat automation may execute?\n      \u2193\nWhat security\/quality evidence is required?\n      \u2193\nWho may deploy?\n      \u2193\nHow is the repository governed through its lifecycle?\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">For most production repositories, prioritize these controls first:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Team-based least-privilege access<\/li>\n\n\n\n<li>Protected default branch using rulesets<\/li>\n\n\n\n<li>Required pull request and CI checks<\/li>\n\n\n\n<li>Minimal\u00a0<code>GITHUB_TOKEN<\/code><\/li>\n\n\n\n<li>Trusted\/pinned Actions and reusable workflows<\/li>\n\n\n\n<li>Dependency, code, and secret security controls<\/li>\n\n\n\n<li>Protected deployment environments<\/li>\n\n\n\n<li>OIDC for cloud access<\/li>\n\n\n\n<li>Repository metadata and ownership<\/li>\n\n\n\n<li>Automation\/IaC for repeatable governance<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">GitHub changes quickly. Re-check plan availability, preview status, API versions, and organization\/enterprise policy before rolling a setting out broadly.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">References<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">The following authoritative sources were used to verify the current behavior described in this guide.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Repository settings and lifecycle<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>GitHub Docs \u2014 Managing your repository&#8217;s settings and features<br><a href=\"https:\/\/docs.github.com\/en\/repositories\/managing-your-repositorys-settings-and-features\">https:\/\/docs.github.com\/en\/repositories\/managing-your-repositorys-settings-and-features<\/a><\/li>\n\n\n\n<li>GitHub Docs \u2014 Managing repository settings<br><a href=\"https:\/\/docs.github.com\/en\/repositories\/managing-your-repositorys-settings-and-features\/managing-repository-settings\">https:\/\/docs.github.com\/en\/repositories\/managing-your-repositorys-settings-and-features\/managing-repository-settings<\/a><\/li>\n\n\n\n<li>GitHub Docs \u2014 Setting repository visibility<br><a href=\"https:\/\/docs.github.com\/en\/repositories\/managing-your-repositorys-settings-and-features\/managing-repository-settings\/setting-repository-visibility\">https:\/\/docs.github.com\/en\/repositories\/managing-your-repositorys-settings-and-features\/managing-repository-settings\/setting-repository-visibility<\/a><\/li>\n\n\n\n<li>GitHub Docs \u2014 Transferring a repository<br><a href=\"https:\/\/docs.github.com\/en\/repositories\/creating-and-managing-repositories\/transferring-a-repository\">https:\/\/docs.github.com\/en\/repositories\/creating-and-managing-repositories\/transferring-a-repository<\/a><\/li>\n\n\n\n<li>GitHub Docs \u2014 Deleting a repository<br><a href=\"https:\/\/docs.github.com\/en\/repositories\/creating-and-managing-repositories\/deleting-a-repository\">https:\/\/docs.github.com\/en\/repositories\/creating-and-managing-repositories\/deleting-a-repository<\/a><\/li>\n\n\n\n<li>GitHub Docs \u2014 Restoring a deleted repository<br><a href=\"https:\/\/docs.github.com\/en\/repositories\/creating-and-managing-repositories\/restoring-a-deleted-repository\">https:\/\/docs.github.com\/en\/repositories\/creating-and-managing-repositories\/restoring-a-deleted-repository<\/a><\/li>\n\n\n\n<li>GitHub Docs \u2014 Preventing changes to your releases<br><a href=\"https:\/\/docs.github.com\/en\/code-security\/how-tos\/secure-your-supply-chain\/establish-provenance-and-integrity\/prevent-release-changes\">https:\/\/docs.github.com\/en\/code-security\/how-tos\/secure-your-supply-chain\/establish-provenance-and-integrity\/prevent-release-changes<\/a><\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Access, branches, and rulesets<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>GitHub Docs \u2014 Managing repository roles<br><a href=\"https:\/\/docs.github.com\/en\/organizations\/managing-user-access-to-your-organizations-repositories\/managing-repository-roles\">https:\/\/docs.github.com\/en\/organizations\/managing-user-access-to-your-organizations-repositories\/managing-repository-roles<\/a><\/li>\n\n\n\n<li>GitHub Docs \u2014 Limiting interactions in your repository<br><a href=\"https:\/\/docs.github.com\/en\/communities\/moderating-comments-and-conversations\/limiting-interactions-in-your-repository\">https:\/\/docs.github.com\/en\/communities\/moderating-comments-and-conversations\/limiting-interactions-in-your-repository<\/a><\/li>\n\n\n\n<li>GitHub Docs \u2014 About rulesets<br><a href=\"https:\/\/docs.github.com\/en\/repositories\/configuring-branches-and-merges-in-your-repository\/managing-rulesets\/about-rulesets\">https:\/\/docs.github.com\/en\/repositories\/configuring-branches-and-merges-in-your-repository\/managing-rulesets\/about-rulesets<\/a><\/li>\n\n\n\n<li>GitHub Docs \u2014 Creating rulesets for a repository<br><a href=\"https:\/\/docs.github.com\/en\/repositories\/configuring-branches-and-merges-in-your-repository\/managing-rulesets\/creating-rulesets-for-a-repository\">https:\/\/docs.github.com\/en\/repositories\/configuring-branches-and-merges-in-your-repository\/managing-rulesets\/creating-rulesets-for-a-repository<\/a><\/li>\n\n\n\n<li>GitHub Docs \u2014 Available rules for rulesets<br><a href=\"https:\/\/docs.github.com\/en\/repositories\/configuring-branches-and-merges-in-your-repository\/managing-rulesets\/available-rules-for-rulesets\">https:\/\/docs.github.com\/en\/repositories\/configuring-branches-and-merges-in-your-repository\/managing-rulesets\/available-rules-for-rulesets<\/a><\/li>\n\n\n\n<li>GitHub Docs \u2014 Converting branch protections to rulesets<br><a href=\"https:\/\/docs.github.com\/en\/repositories\/configuring-branches-and-merges-in-your-repository\/managing-rulesets\/converting-branch-protections-to-rulesets\">https:\/\/docs.github.com\/en\/repositories\/configuring-branches-and-merges-in-your-repository\/managing-rulesets\/converting-branch-protections-to-rulesets<\/a><\/li>\n\n\n\n<li>GitHub Docs \u2014 About protected branches<br><a href=\"https:\/\/docs.github.com\/en\/repositories\/configuring-branches-and-merges-in-your-repository\/managing-protected-branches\/about-protected-branches\">https:\/\/docs.github.com\/en\/repositories\/configuring-branches-and-merges-in-your-repository\/managing-protected-branches\/about-protected-branches<\/a><\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Actions and deployments<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>GitHub Docs \u2014 Managing GitHub Actions settings for a repository<br><a href=\"https:\/\/docs.github.com\/en\/repositories\/managing-your-repositorys-settings-and-features\/enabling-features-for-your-repository\/managing-github-actions-settings-for-a-repository\">https:\/\/docs.github.com\/en\/repositories\/managing-your-repositorys-settings-and-features\/enabling-features-for-your-repository\/managing-github-actions-settings-for-a-repository<\/a><\/li>\n\n\n\n<li>GitHub Docs \u2014 Managing environments for deployment<br><a href=\"https:\/\/docs.github.com\/en\/actions\/how-tos\/deploy\/configure-and-manage-deployments\/manage-environments\">https:\/\/docs.github.com\/en\/actions\/how-tos\/deploy\/configure-and-manage-deployments\/manage-environments<\/a><\/li>\n\n\n\n<li>GitHub Docs \u2014 Deployments and environments<br><a href=\"https:\/\/docs.github.com\/en\/actions\/reference\/workflows-and-actions\/deployments-and-environments\">https:\/\/docs.github.com\/en\/actions\/reference\/workflows-and-actions\/deployments-and-environments<\/a><\/li>\n\n\n\n<li>GitHub Docs \u2014 Using secrets in GitHub Actions<br><a href=\"https:\/\/docs.github.com\/en\/actions\/how-tos\/write-workflows\/choose-what-workflows-do\/use-secrets\">https:\/\/docs.github.com\/en\/actions\/how-tos\/write-workflows\/choose-what-workflows-do\/use-secrets<\/a><\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Copilot<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>GitHub Docs \u2014 Adding repository custom instructions for GitHub Copilot<br><a href=\"https:\/\/docs.github.com\/en\/copilot\/how-tos\/copilot-on-github\/customize-copilot\/add-custom-instructions\/add-repository-instructions\">https:\/\/docs.github.com\/en\/copilot\/how-tos\/copilot-on-github\/customize-copilot\/add-custom-instructions\/add-repository-instructions<\/a><\/li>\n\n\n\n<li>GitHub Docs \u2014 Configure MCP servers for your repository<br><a href=\"https:\/\/docs.github.com\/en\/copilot\/how-tos\/copilot-on-github\/customize-copilot\/configure-mcp-servers\">https:\/\/docs.github.com\/en\/copilot\/how-tos\/copilot-on-github\/customize-copilot\/configure-mcp-servers<\/a><\/li>\n\n\n\n<li>GitHub Docs \u2014 About GitHub Copilot code review<br><a href=\"https:\/\/docs.github.com\/en\/copilot\/concepts\/agents\/code-review\">https:\/\/docs.github.com\/en\/copilot\/concepts\/agents\/code-review<\/a><\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Pages<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>GitHub Docs \u2014 Configuring a publishing source for GitHub Pages<br><a href=\"https:\/\/docs.github.com\/en\/pages\/getting-started-with-github-pages\/configuring-a-publishing-source-for-your-github-pages-site\">https:\/\/docs.github.com\/en\/pages\/getting-started-with-github-pages\/configuring-a-publishing-source-for-your-github-pages-site<\/a><\/li>\n\n\n\n<li>GitHub Docs \u2014 About custom domains and GitHub Pages<br><a href=\"https:\/\/docs.github.com\/en\/pages\/configuring-a-custom-domain-for-your-github-pages-site\/about-custom-domains-and-github-pages\">https:\/\/docs.github.com\/en\/pages\/configuring-a-custom-domain-for-your-github-pages-site\/about-custom-domains-and-github-pages<\/a><\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Security and quality<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>GitHub Docs \u2014 Quickstart for securing your repository<br><a href=\"https:\/\/docs.github.com\/en\/code-security\/getting-started\/quickstart-for-securing-your-repository\">https:\/\/docs.github.com\/en\/code-security\/getting-started\/quickstart-for-securing-your-repository<\/a><\/li>\n\n\n\n<li>GitHub Docs \u2014 About setup types for code scanning<br><a href=\"https:\/\/docs.github.com\/en\/code-security\/concepts\/code-scanning\/setup-types\">https:\/\/docs.github.com\/en\/code-security\/concepts\/code-scanning\/setup-types<\/a><\/li>\n\n\n\n<li>GitHub Docs \u2014 Configuring advanced setup for code scanning<br><a href=\"https:\/\/docs.github.com\/en\/code-security\/how-tos\/find-and-fix-code-vulnerabilities\/configure-code-scanning\/configuring-advanced-setup-for-code-scanning\">https:\/\/docs.github.com\/en\/code-security\/how-tos\/find-and-fix-code-vulnerabilities\/configure-code-scanning\/configuring-advanced-setup-for-code-scanning<\/a><\/li>\n\n\n\n<li>GitHub Docs \u2014 About SARIF files for code scanning<br><a href=\"https:\/\/docs.github.com\/en\/code-security\/concepts\/code-scanning\/sarif-files\">https:\/\/docs.github.com\/en\/code-security\/concepts\/code-scanning\/sarif-files<\/a><\/li>\n\n\n\n<li>GitHub Docs \u2014 AI Scan for pull requests<br><a href=\"https:\/\/docs.github.com\/en\/code-security\/concepts\/code-scanning\/ai-powered-security-detections\">https:\/\/docs.github.com\/en\/code-security\/concepts\/code-scanning\/ai-powered-security-detections<\/a><\/li>\n\n\n\n<li>GitHub Changelog \u2014 Code scanning AI Scan no longer requires CodeQL default setup, September 16, 2026<br><a href=\"https:\/\/github.blog\/changelog\/2026-09-16-code-scanning-ai-scan-no-longer-requires-codeql-default-setup\/\">https:\/\/github.blog\/changelog\/2026-09-16-code-scanning-ai-scan-no-longer-requires-codeql-default-setup\/<\/a><\/li>\n\n\n\n<li>GitHub Docs \u2014 Enabling push protection for your repository<br><a href=\"https:\/\/docs.github.com\/en\/code-security\/how-tos\/secure-your-secrets\/prevent-future-leaks\/enable-push-protection\">https:\/\/docs.github.com\/en\/code-security\/how-tos\/secure-your-secrets\/prevent-future-leaks\/enable-push-protection<\/a><\/li>\n\n\n\n<li>GitHub Docs \u2014 Enabling GitHub Code Quality<br><a href=\"https:\/\/docs.github.com\/en\/code-security\/how-tos\/maintain-quality-code\/enable-code-quality\">https:\/\/docs.github.com\/en\/code-security\/how-tos\/maintain-quality-code\/enable-code-quality<\/a><\/li>\n\n\n\n<li>GitHub Docs \u2014 Setting code quality thresholds for pull requests<br><a href=\"https:\/\/docs.github.com\/en\/code-security\/how-tos\/maintain-quality-code\/set-pr-thresholds\">https:\/\/docs.github.com\/en\/code-security\/how-tos\/maintain-quality-code\/set-pr-thresholds<\/a><\/li>\n\n\n\n<li>GitHub Docs \u2014 GitHub security and quality AI features application card<br><a href=\"https:\/\/docs.github.com\/en\/code-security\/responsible-use\/security-and-quality-ai-features\">https:\/\/docs.github.com\/en\/code-security\/responsible-use\/security-and-quality-ai-features<\/a><\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">GitHub Apps and custom properties<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>GitHub Docs \u2014 Reviewing and modifying installed GitHub Apps<br><a href=\"https:\/\/docs.github.com\/en\/apps\/using-github-apps\/reviewing-and-modifying-installed-github-apps\">https:\/\/docs.github.com\/en\/apps\/using-github-apps\/reviewing-and-modifying-installed-github-apps<\/a><\/li>\n\n\n\n<li>GitHub Docs \u2014 Managing custom properties for repositories in your organization<br><a href=\"https:\/\/docs.github.com\/en\/organizations\/managing-organization-settings\/managing-custom-properties-for-repositories-in-your-organization\">https:\/\/docs.github.com\/en\/organizations\/managing-organization-settings\/managing-custom-properties-for-repositories-in-your-organization<\/a><\/li>\n\n\n\n<li>GitHub Docs \u2014 About email notifications for pushes<br><a href=\"https:\/\/docs.github.com\/en\/repositories\/managing-your-repositorys-settings-and-features\/managing-repository-settings\/about-email-notifications-for-pushes-to-your-repository\">https:\/\/docs.github.com\/en\/repositories\/managing-your-repositorys-settings-and-features\/managing-repository-settings\/about-email-notifications-for-pushes-to-your-repository<\/a><\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">APIs and Terraform<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>GitHub Docs \u2014 REST API<br><a href=\"https:\/\/docs.github.com\/en\/rest\">https:\/\/docs.github.com\/en\/rest<\/a><\/li>\n\n\n\n<li>GitHub Docs \u2014 REST API endpoints for deployment environments<br><a href=\"https:\/\/docs.github.com\/en\/rest\/deployments\/environments\">https:\/\/docs.github.com\/en\/rest\/deployments\/environments<\/a><\/li>\n\n\n\n<li>GitHub Docs \u2014 REST API endpoints for deploy keys<br><a href=\"https:\/\/docs.github.com\/en\/rest\/deploy-keys\/deploy-keys\">https:\/\/docs.github.com\/en\/rest\/deploy-keys\/deploy-keys<\/a><\/li>\n\n\n\n<li>GitHub Docs \u2014 REST API endpoints for custom properties<br><a href=\"https:\/\/docs.github.com\/en\/rest\/repos\/custom-properties\">https:\/\/docs.github.com\/en\/rest\/repos\/custom-properties<\/a><\/li>\n\n\n\n<li>Terraform Registry \u2014 integrations\/github provider<br><a href=\"https:\/\/registry.terraform.io\/providers\/integrations\/github\/latest\/docs\">https:\/\/registry.terraform.io\/providers\/integrations\/github\/latest\/docs<\/a><\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>Final operational principle:<\/strong>&nbsp;configure repositories so that the safe path is the easiest path. Good repository governance should prevent common mistakes automatically while keeping normal developer work fast and understandable.<\/p>\n<\/blockquote>\n","protected":false},"excerpt":{"rendered":"<p>Last Verified:&nbsp;September 2026Platform:&nbsp;GitHub.com \/ GitHub Enterprise Cloud unless stated otherwiseAudience:&nbsp;Developers, DevOps engineers, repository administrators, security engineers, platform engineers, team leads, and trainers GitHub repository settings are the&#8230; <\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-1195","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/www.devopsschool.com\/tutorials\/wp-json\/wp\/v2\/posts\/1195","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.devopsschool.com\/tutorials\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.devopsschool.com\/tutorials\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.devopsschool.com\/tutorials\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.devopsschool.com\/tutorials\/wp-json\/wp\/v2\/comments?post=1195"}],"version-history":[{"count":1,"href":"https:\/\/www.devopsschool.com\/tutorials\/wp-json\/wp\/v2\/posts\/1195\/revisions"}],"predecessor-version":[{"id":1196,"href":"https:\/\/www.devopsschool.com\/tutorials\/wp-json\/wp\/v2\/posts\/1195\/revisions\/1196"}],"wp:attachment":[{"href":"https:\/\/www.devopsschool.com\/tutorials\/wp-json\/wp\/v2\/media?parent=1195"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.devopsschool.com\/tutorials\/wp-json\/wp\/v2\/categories?post=1195"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.devopsschool.com\/tutorials\/wp-json\/wp\/v2\/tags?post=1195"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}