严重度:P1
证据
gh api repos/libinyam/engineering-vibe-coding/branches/master/protection 返回 404;0 workflow、0 run。直推 master 无任何检查。solo Early MVP 阶段可理解,但推广前须补。
建议
- 启用 master 分支保护:require PR、require status checks;
- 配合 D-002 的 CI 落地后,将测试设为必需检查;
- 注意 issue#24 有效性核查:required status check 的 context 名必须与 Actions 实际 job 名一致,否则名义存在实际不拦。
验收标准
— 来自角色 G(Security & DevOps)发现 G-002
严重度:P1
证据
gh api repos/libinyam/engineering-vibe-coding/branches/master/protection返回 404;0 workflow、0 run。直推 master 无任何检查。solo Early MVP 阶段可理解,但推广前须补。建议
验收标准
— 来自角色 G(Security & DevOps)发现 G-002