Comfy-Org / Comfy-Org/comfy-cli

Enable branch protection — 13 workflows, none of them required

Open
#724 0 comments 0 reactions 1 assignee Claimed by @christian-byrne View on GitHub
audit:github effort:trivial priority:critical
Dominant language
Python
Stars
968
Forks
151
Avg merge
1d 9h
Merged PRs (30d)
77

Description

**What** — `main` has no branch protection rule, so none of the repo's 13 workflows is a required status check.

**Why it matters here** — This is a public package with 45 contributors and 30 published releases. pytest, ruff, build-and-test, and the mac/windows/GPU matrices all run on every PR and every one of them is advisory — a PR with a red test suite can be merged and published. The checks are already written and already run; they just do not block. Of the six repos swept this is the one where the gap costs the most, because releases go to PyPI.

**Evidence**

```
$ gh api repos/Comfy-Org/comfy-cli/branches/main/protection
gh: Branch not protected (HTTP 404)

$ ls .github/workflows/ | wc -l
13

$ gh api repos/Comfy-Org/comfy-cli -q '"contributors_visible releases=\(. )"' ; gh api repos/Comfy-Org/comfy-cli/releases -q length
30
```

**Fix**

Settings → Branches → rule for `main`: require a PR with at least one approval, require `pytest`, `ruff_check`, and `build-and-test` as status checks, block force pushes. Leave the GPU and mac/windows matrices advisory if they are flaky, but make the core three required.

---

Found by `repo-audit` during repo improvement sweep 2026-08-17. Parent: #723

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.