apache / apache/cloudstack

We should use repository rulesets to prevent the deletion or modification of released tags and critical release branches

未關閉
#14,134 1 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
type:improvement
主要語言
Java
星號
3.1k
分支
1.4k
平均合併
6 天 19 小時
30 天內合併 PR
32

描述

We can setup rules for released tags and also other branches. See our rules:

https://github.com/apache/cloudstack/rules/

Not 100% sure but seems like anyone with write access can delete releases and checkout the pictures attached

See Apache Flume they have tag protection setup in their `.asf.yaml`:

https://github.com/apache/logging-flume/blob/7b41e071caf1566bf73add2f40b530875d61da10/.asf.yaml#L94

Image

---

Yes, an Apache Software Foundation (ASF) project should use repository rulesets to prevent the deletion or modification of released tags and critical release branches.

### Benefits of Using Rulesets for Releases
* **Supply Chain Security:** Restricting deletions and updates on tags prevents malicious or accidental tampering with published software artifacts.
* **Flexibility and Targeting:** Unlike legacy branch protection, [GitHub Rulesets](https://github.com) can target tags using naming patterns (e.g., `v*` or specific release tags) alongside branches.
* **Audit Transparency:** Anyone with read access can view active rulesets, helping project auditors verify compliance and governance without requiring admin privileges.
* **Preventing Force Pushes:** Rulesets allow projects to block force-pushes and restrict deletions to designated release managers or PMC members.

### Recommended Practices
* Set rulesets to **Active** enforcement for any matching patterns of released tags or stable maintenance branches.
* Restrict bypass permissions strictly to trusted release officers or infrastructure administrators.

貢獻指南

開啟貢獻指南

研究方向

首先檢視 issue 中連結的儲存庫規則,以及 Apache Flume 的 .asf.yaml 中的標籤保護範例。確認哪些已發佈標籤和關鍵發佈分支需要保護,然後設定作用中的規則集,以封鎖刪除和修改,同時限制繞過存取權限。完成的標準是:符合的規則和允許的繞過角色已記錄並經過驗證。

由索引模型根據 Issue 內容生成。

評估

技術堆疊
github
領域
release, security
Issue 類型
功能
難度
4/5
預估耗時
3-5 天
活躍度
活躍
描述清晰度
基本清楚
新手友好度
45/100

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。