mapbox / mapbox/mapbox-navigation-android

Branch protection on main not adhering to best practices

Open
#7,774 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Kotlin
Stars
651
Forks
321
PR merge metrics
No merged PRs in 30d

Description

:wave: Hey there! It's [Changebot](https://github.com/mapbox/changebot), and I help repositories follow our [engineering](https://github.com/mapbox/engineering) best practices. My magic wand found some things I wanted to highlight for your review:

Item | Current status | Best practice guidelines
--- | --- | ---
main branch protection: Dismiss stale pull request approvals when new commits are pushed | Unchecked | Checked
main branch protection: Require review from Code Owners | Unchecked | Checked
main branch protection: Restrict who can dismiss pull request reviews | Unchecked | Checked
main branch protection: Require branches to be up to date before merging | Unchecked | Checked
main branch protection: Restrict who can push to this branch | Unchecked | Checked

Can you take a look at these best practices and make any adjustments if needed?

Please tag `@mapbox/security-and-compliance` on this issue if you have any questions

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Review the main branch protection settings in the mapbox-navigation-android repository against the five best-practice items listed in the issue. Confirm whether each setting should be enabled and check with @mapbox/security-and-compliance when policy or permissions are unclear. Done means the settings have been reviewed and any needed adjustments are documented or applied.

Written by the indexing model from the issue text.

Assessment

Tech stack
github
Domain
devops, security
Issue type
Feature
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.