Branch protection

Requiring review before code merges turns a team convention into something that is actually enforced.

Its value depends entirely on the exceptions. Administrators who can bypass it, automation with write access, and branches that are not covered are all ways the rule quietly does not apply. A protected main branch with three unprotected release branches is protecting the least important thing.

Checked against the primary source.

More on Software supply chain & DevSecOps