Skip to content

✨ Branch-Protection: treat GitHub merge queue rule as requiring up-to-date branches - #5281

Open
osterman wants to merge 1 commit into
ossf:mainfrom
cloudposse:osterman/ossf/scorecard-merge-queues-fix
Open

osterman wants to merge 1 commit into
ossf:mainfrom
cloudposse:osterman/ossf/scorecard-merge-queues-fix

Conversation

@osterman

@osterman osterman commented Oct 2, 2026

Copy link
Copy Markdown

What kind of change does this PR introduce?

Feature: Branch-Protection now counts a GitHub merge queue as meeting the "up-to-date branches" requirement.

What is the current behavior?

The requiresUpToDateBranches probe passes only when "Require branches to be up to date before merging" (strict required status checks) is on. Some repositories require a merge queue through a repository ruleset instead. Those repositories get Warn: 'up-to-date branches' is disabled, even though GitHub documents the merge queue as providing "the same benefits as the Require branches to be up to date before merging branch protection".

What is the new behavior (if this is a feature change)?

An active repository ruleset with a MERGE_QUEUE rule sets UpToDateBeforeMerge=true for the branches it targets.

  • The rule type is already returned by the existing rulesets GraphQL query. No new API call, query field, or token scope is needed.
  • Only ACTIVE rulesets count (the existing getActiveRuleSetsFrom filter).
  • Bypass actors on the merge queue ruleset are handled the same way as for every other ruleset rule today: they set EnforceAdmins=false. This affects the "applies to administrators" probe, not this one.
  • The flag is set after all rules in a ruleset are processed. A non-strict REQUIRED_STATUS_CHECKS rule in the same ruleset therefore can't override it.

Example: cloudposse/atmos enforces a merge queue on main via a ruleset with no bypass actors:

Branch-Protection up-to-date branches
before 5 / 10 Warn: 'up-to-date branches' is disabled on branch 'main'
after 8 / 10 Info: 'up-to-date branches' is required to merge on branch 'main'
  • Tests for the changes have been added (for bug fixes/features)

New Test_applyRepoRules cases:

  • merge queue, no bypass
  • merge queue with bypass
  • merge queue plus a non-strict status check rule in the same ruleset
  • merge queue ruleset plus a separate non-strict status check ruleset

applyRepoRules has 100% statement coverage. All four new cases fail if the fix is removed.

Which issue(s) this PR fixes

Fixes #3678

Special notes for your reviewer

  • Merge queues configured through classic branch protection are out of scope. The GraphQL BranchProtectionRule object has no merge-queue field. Supporting it would need an extra repository.mergeQueue(branch:) query, which could be a follow-up.
  • Docs were updated in docs/checks/internal/checks.yaml and probes/requiresUpToDateBranches/def.yml, and docs/checks.md / docs/probes.md were regenerated with make generate-docs.

Does this PR introduce a user-facing change?

Branch-Protection now treats a GitHub merge queue required by an active repository ruleset as satisfying "require branches to be up to date before merging".

🤖 Generated with Claude Code

…-date branches

An active repository ruleset with a MERGE_QUEUE rule now sets
UpToDateBeforeMerge, so the requiresUpToDateBranches probe passes for
branches that use a merge queue instead of strict status checks.
GitHub documents the merge queue as providing the same benefits as
"Require branches to be up to date before merging".

The rule type is already returned by the existing rulesets GraphQL
query, so no new API call or token scope is needed. Bypass actors
continue to be reflected through EnforceAdmins, as for other rules.

Fixes ossf#3678

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: Erik Osterman <erik@cloudposse.com>
@osterman
osterman requested a review from a team as a code owner October 2, 2026 02:04
@osterman
osterman requested review from justaugustus and spencerschrock and removed request for a team October 2, 2026 02:04

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: No status

Development

Successfully merging this pull request may close these issues.

Allow merge queue instead of an up to date branch for the branch protection check

1 participant