diff --git a/README.md b/README.md index dce7bca..135dc6c 100644 --- a/README.md +++ b/README.md @@ -193,7 +193,7 @@ Environments need the App's repository Administration permission, variables and `organization.rulesets` is added to every repository's `rulesets`, with the same replace, `~` opt-out and repository-only semantics as [environments](#environments). -Every ruleset protects the repository's default branch: changes only through a pull request (no approval required, so a single maintainer can merge their own), no force pushes, no deletion. No required status checks. On the GitHub Free plan, rulesets are available in public repositories only. +Every ruleset protects the repository's default branch: changes only through a pull request (no approval required, so a single maintainer can merge their own), no force pushes, no deletion, linear history, [conventional commit](https://www.conventionalcommits.org/) messages with a lowercase subject. No required status checks. On the GitHub Free plan, rulesets are available in public repositories only. `bypass_apps` lists GitHub App IDs that always bypass the ruleset, e.g. a release App pushing a changelog commit to the default branch. Pushes authenticated by `GITHUB_TOKEN` cannot bypass: a repository releasing with `GITHUB_TOKEN` must opt out. diff --git a/terraform/modules/repository/main.tf b/terraform/modules/repository/main.tf index 7d7224b..9028b38 100644 --- a/terraform/modules/repository/main.tf +++ b/terraform/modules/repository/main.tf @@ -75,8 +75,15 @@ resource "github_repository_ruleset" "this" { } rules { - deletion = true - non_fast_forward = true + deletion = true + non_fast_forward = true + required_linear_history = true + + commit_message_pattern { + name = "Conventional commit, lowercase subject" + operator = "regex" + pattern = "^(build|chore|ci|docs|feat|fix|perf|refactor|revert|style|test)(\\([a-z0-9._/-]+\\))?!?: [^A-Z\\n]+(\\n|$)" + } pull_request { required_approving_review_count = 0 diff --git a/terraform/modules/repository/tests/repository.tftest.hcl b/terraform/modules/repository/tests/repository.tftest.hcl index 78d3912..e218e60 100644 --- a/terraform/modules/repository/tests/repository.tftest.hcl +++ b/terraform/modules/repository/tests/repository.tftest.hcl @@ -537,6 +537,16 @@ run "ruleset" { error_message = "Expected deletion and force push blocked." } + assert { + condition = github_repository_ruleset.this["default-branch"].rules[0].required_linear_history + error_message = "Expected linear history required." + } + + assert { + condition = github_repository_ruleset.this["default-branch"].rules[0].commit_message_pattern[0].operator == "regex" && startswith(github_repository_ruleset.this["default-branch"].rules[0].commit_message_pattern[0].pattern, "^(build|chore|ci|docs|feat|fix|perf|refactor|revert|style|test)") + error_message = "Expected a conventional commit message pattern." + } + assert { condition = github_repository_ruleset.this["default-branch"].rules[0].pull_request[0].required_approving_review_count == 0 && length(github_repository_ruleset.this["default-branch"].rules[0].required_status_checks) == 0 error_message = "Expected a pull request with no approvals and no status checks."