Problem
The demo has useful hosted checks, but none are required by the effective main-branch rules. Contributors can merge broken learning examples or incompatible consumers while preserving the appearance of a validated reference application.
Verified evidence
Reviewed on 2026-09-12 at 2de6b83f21ccacae04f8050f5691d0dd8159fda1; the local checkout matches GitHub main.
Read-only GitHub API inspection on 2026-09-12:
GET /repos/basefoundry/base-cli-demo/rules/branches/main returns pull_request, deletion, and non_fast_forward rules. It has no required_status_checks rule, and required_approving_review_count is 0. The older branch-protection endpoint returns 404 because protection uses rulesets; this finding concerns missing required checks, not an unprotected branch claim.
Sources:
Acceptance criteria
- Require the main consumer test gate and minimum/latest supported installed-wheel compatibility checks, including branch-policy enforcement as appropriate.
- Use stable aggregate check names if matrix expansion makes individual names brittle.
- Read back the effective rules and demonstrate a failed required check prevents merge in a safe fixture/PR.
- Document any necessary solo-maintainer review exception without disabling test enforcement.
Project fields
- Status: Backlog
- Priority: P1
- Area: CI
- Initiative: Base-CLI Demo
- Size: S
- Assignee: @codeforester
- Milestone: v0.1.0
- Target date: unscheduled
Problem
The demo has useful hosted checks, but none are required by the effective main-branch rules. Contributors can merge broken learning examples or incompatible consumers while preserving the appearance of a validated reference application.
Verified evidence
Reviewed on 2026-09-12 at
2de6b83f21ccacae04f8050f5691d0dd8159fda1; the local checkout matches GitHub main.Read-only GitHub API inspection on 2026-09-12:
GET /repos/basefoundry/base-cli-demo/rules/branches/mainreturns pull_request, deletion, and non_fast_forward rules. It has no required_status_checks rule, and required_approving_review_count is 0. The older branch-protection endpoint returns 404 because protection uses rulesets; this finding concerns missing required checks, not an unprotected branch claim.Sources:
Acceptance criteria
Project fields