DEVX-1: fix: disable push whitelist, allow direct pushes to master
Post-merge / detect-type (push) Successful in 11s
Post-merge / validate-commit-msg (push) Successful in 8s
Post-merge / vikunja (push) Successful in 33s
Post-merge / configure-repo (push) Successful in 12s
Post-merge / release (push) Successful in 54s
Post-merge / sync-wiki (push) Successful in 1m0s
Post-merge / badges (push) Successful in 37s

This commit was merged in pull request #11.
This commit is contained in:
2026-06-22 17:03:41 +00:00
parent 0800119795
commit 07cca5de36
3 changed files with 6 additions and 18 deletions
-1
View File
@@ -221,7 +221,6 @@ jobs:
- name: Ensure branch protection and labels
env:
REPO_TOKEN: ${{ secrets.REPO_TOKEN }}
DEVX_PUSH_WHITELIST: "emil"
PYTHONPATH: src
run: python3 -m devx.tools.configure_repo --repo devx --owner oblachno-oss
- name: Notify on failure
+5 -6
View File
@@ -39,16 +39,15 @@ def _default_branch_protection_config() -> dict[str, Any]:
environment variable (comma-separated) or default to just the quality
check context.
The ``push_whitelist_usernames`` is read from ``DEVX_PUSH_WHITELIST``
(comma-separated) to allow the release bot to push directly to master.
Push whitelist is disabled — the release script pushes directly to
master (release commits). Since there are no manual reviews yet,
requiring PRs for every push adds complexity without benefit.
"""
push_whitelist = os.environ.get("DEVX_PUSH_WHITELIST", "")
whitelist = [u.strip() for u in push_whitelist.split(",") if u.strip()]
return {
"branch_name": "master",
"enable_push": True,
"enable_push_whitelist": True,
"push_whitelist_usernames": whitelist,
"enable_push_whitelist": False,
"push_whitelist_usernames": [],
"enable_status_check": True,
"status_check_contexts": _default_status_checks(),
"required_approvals": 0,
+1 -11
View File
@@ -31,7 +31,7 @@ class TestDefaultConfigs:
config = _default_branch_protection_config()
assert config["branch_name"] == "master"
assert config["enable_push"] is True
assert config["enable_push_whitelist"] is True
assert config["enable_push_whitelist"] is False
assert config["required_approvals"] == 0
assert isinstance(config["status_check_contexts"], list)
assert "CI / quality (pull_request)" in config["status_check_contexts"]
@@ -45,16 +45,6 @@ class TestDefaultConfigs:
config = _default_branch_protection_config()
assert config["status_check_contexts"] == ["check1", "check2", "check3"]
def test_push_whitelist_from_env(self) -> None:
with patch.dict("os.environ", {"DEVX_PUSH_WHITELIST": "emil, alice"}):
config = _default_branch_protection_config()
assert config["push_whitelist_usernames"] == ["emil", "alice"]
def test_push_whitelist_empty_by_default(self) -> None:
with patch.dict("os.environ", {}, clear=True):
config = _default_branch_protection_config()
assert config["push_whitelist_usernames"] == []
class TestConfigureRepo:
@patch.dict("os.environ", {"REPO_TOKEN": "tok"}, clear=True)