Goal
Teach learners to turn security scanning from advisory feedback into an enforceable pull-request policy.
Scope
Create a repository ruleset for the default branch that requires the tested security checks and prevents a vulnerable pull request from merging. Explain check naming, merge-base behavior, bypass governance, and plan-dependent alternatives.
Acceptance criteria
Goal
Teach learners to turn security scanning from advisory feedback into an enforceable pull-request policy.
Scope
Create a repository ruleset for the default branch that requires the tested security checks and prevents a vulnerable pull request from merging. Explain check naming, merge-base behavior, bypass governance, and plan-dependent alternatives.
Acceptance criteria