Requested change
Update the active MainProtector repository ruleset for the default branch to require the GitHub Actions check Investigation privacy scan (use this exact check context).
Why this is needed
PR #497 added changed-path CI classification so platform validation runs only when relevant files change. The separate Investigation privacy scan protects parity ledgers, research notes, evidence, screenshots, and other files under investigation/ from accidental disclosure of sensitive information.
The scan already runs successfully in CI, but it is not currently required. This means a pull request could merge despite the privacy scan failing or not completing. Making it required preserves the CI optimization while ensuring investigation and parity-document changes cannot bypass privacy validation.
Administrator steps
- Open Repository settings → Rules → Rulesets.
- Edit the active
MainProtector ruleset (ruleset ID 20328158), which targets ~DEFAULT_BRANCH.
- Under required status checks, add Investigation privacy scan.
- Exact context:
Investigation privacy scan
- GitHub Actions integration/app ID:
15368
- Preserve every existing rule and required check.
- Save the ruleset.
- Verify the exact check context is required on a subsequent pull request.
Existing required checks to preserve
DCO sign-off
Linux build
macos
validate
windows-spikes
windows-shell
Deterministic hardening (windows-2022, pwsh)
Deterministic hardening (windows-2025, pwsh)
Evidence
Acceptance criteria
Investigation privacy scan appears in MainProtector as a required status check.
- All eight existing required checks remain required.
- No other ruleset behavior changes.
- A subsequent pull request shows the exact check as required and reports it successfully.
Requested change
Update the active
MainProtectorrepository ruleset for the default branch to require the GitHub Actions check Investigation privacy scan (use this exact check context).Why this is needed
PR #497 added changed-path CI classification so platform validation runs only when relevant files change. The separate Investigation privacy scan protects parity ledgers, research notes, evidence, screenshots, and other files under
investigation/from accidental disclosure of sensitive information.The scan already runs successfully in CI, but it is not currently required. This means a pull request could merge despite the privacy scan failing or not completing. Making it required preserves the CI optimization while ensuring investigation and parity-document changes cannot bypass privacy validation.
Administrator steps
MainProtectorruleset (ruleset ID20328158), which targets~DEFAULT_BRANCH.Investigation privacy scan15368Existing required checks to preserve
DCO sign-offLinux buildmacosvalidatewindows-spikeswindows-shellDeterministic hardening (windows-2022, pwsh)Deterministic hardening (windows-2025, pwsh)Evidence
Investigation privacy scancompleted successfully on the final PR ci: skip platform validation for unrelated pull request paths #497 head.Acceptance criteria
Investigation privacy scanappears inMainProtectoras a required status check.