🔐 Branch Protection Rules
Follow these steps to protect important branches like main or production:
✅ Steps
-
Go to Your Repository
- Navigate to your repository on GitHub.
-
Open Settings
- Click on the "Settings" tab (requires admin access).
-
Select "Branches"
- In the left sidebar, click "Branches" under the "Code and automation" section.
-
Add a Branch Protection Rule
- Click the "Add branch ruleset" button.
-
Configure the Rule
- Branch name pattern: Enter the branch name (e.g.,
main,develop,release/*). - Enable the desired options:
- ✅ Restrict deletions
- ✅ Require a pull request before merging
- Required approvals: at least 1
- Require approval of the most recent reviewable push
- Require conversation resolution before merging
- ✅ Require status checks to pass
- Require branches to be up to date before merging
- Branch name pattern: Enter the branch name (e.g.,
-
Save Changes
- Click "Create" or "Save changes" at the bottom.
🔒 Recommended Settings for main or production
| Setting | Description |
|---|---|
| ✅ Require pull request reviews | Enforces code review before merging |
| ✅ Require status checks | Ensures CI/CD checks pass before merging |
| ✅ Require linear history | Keeps commit history clean (no merge commits) |
| ✅ Include administrators | Applies rules to admins as well |
| ✅ Block force pushes | Limits who can push directly to the branch |
Main branch ruleset example:
💡 Tips
- Use wildcards like
release/*to apply rules to multiple branches. - Combine with GitHub Actions for automated checks and workflows.
- Regularly review and update rules as your team grows.