Skip to content

Require Investigation privacy scan in the main branch ruleset #498

Description

@coneilen

Requested change

Update the active MainProtector repository ruleset for the default branch to require the GitHub Actions check Investigation privacy scan (use this exact check context).

Why this is needed

PR #497 added changed-path CI classification so platform validation runs only when relevant files change. The separate Investigation privacy scan protects parity ledgers, research notes, evidence, screenshots, and other files under investigation/ from accidental disclosure of sensitive information.

The scan already runs successfully in CI, but it is not currently required. This means a pull request could merge despite the privacy scan failing or not completing. Making it required preserves the CI optimization while ensuring investigation and parity-document changes cannot bypass privacy validation.

Administrator steps

  1. Open Repository settings → Rules → Rulesets.
  2. Edit the active MainProtector ruleset (ruleset ID 20328158), which targets ~DEFAULT_BRANCH.
  3. Under required status checks, add Investigation privacy scan.
    • Exact context: Investigation privacy scan
    • GitHub Actions integration/app ID: 15368
  4. Preserve every existing rule and required check.
  5. Save the ruleset.
  6. Verify the exact check context is required on a subsequent pull request.

Existing required checks to preserve

  • DCO sign-off
  • Linux build
  • macos
  • validate
  • windows-spikes
  • windows-shell
  • Deterministic hardening (windows-2022, pwsh)
  • Deterministic hardening (windows-2025, pwsh)

Evidence

Acceptance criteria

  • Investigation privacy scan appears in MainProtector as a required status check.
  • All eight existing required checks remain required.
  • No other ruleset behavior changes.
  • A subsequent pull request shows the exact check as required and reports it successfully.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions