Existing files under /versions/ should remain unchanged once they reach main, while new archive files can still be added. This includes archived documents and files under /versions/sidebars/.
Implement an append-only policy for /versions/:
- Add a required check that compares the proposed result against the current
main tree. Reject modifications, deletions, renames, and file-type or mode changes to existing files under /versions/. Allow new files and changes outside that directory.
- Compare against the current base, not only the branch's original merge base, so an outdated PR cannot overwrite an archive file added by another merged PR. Require the branch to be up to date before merging, or use an equivalently validated merge queue.
- Configure an active ruleset for
main requiring pull requests and the archive check, with no bypass actors. Block force pushes and branch deletion.
- Protect the check's implementation and configuration from being weakened by the same PR it evaluates. Use a trusted check source and document how changes to the enforcement mechanism are reviewed.
A workflow triggered after a direct push cannot prevent that push. Under this proposal, direct commits to main must therefore be blocked for everyone subject to the ruleset, including commits that only touch files outside /versions/. Ordinary edits outside /versions/ remain allowed through pull requests.
Acceptance criteria:
Do not archive the entire repository, since that would also prevent new documents and ongoing work. A blanket path restriction on /versions/** would also block additions, so it would not implement the intended append-only behavior.
GitHub references:
Existing files under
/versions/should remain unchanged once they reachmain, while new archive files can still be added. This includes archived documents and files under/versions/sidebars/.Implement an append-only policy for
/versions/:maintree. Reject modifications, deletions, renames, and file-type or mode changes to existing files under/versions/. Allow new files and changes outside that directory.mainrequiring pull requests and the archive check, with no bypass actors. Block force pushes and branch deletion.A workflow triggered after a direct push cannot prevent that push. Under this proposal, direct commits to
mainmust therefore be blocked for everyone subject to the ruleset, including commits that only touch files outside/versions/. Ordinary edits outside/versions/remain allowed through pull requests.Acceptance criteria:
/versions/can pass./versions/can pass.main, and deletion ofmain, are rejected by the active ruleset.Do not archive the entire repository, since that would also prevent new documents and ongoing work. A blanket path restriction on
/versions/**would also block additions, so it would not implement the intended append-only behavior.GitHub references: