Prevent direct commits on master branch in git repository and accept merges only?

17,223

Solution 1

Not a direct answer: consider using repos instead of branches for this. Imagine three repos: local, dev, and blessed. Local = your own repo where you work. Dev = the repo you push all your commits to and the one that your build process is monitoring for changes. Blessed = the repo that only the build process can push to and which you pull from. Thus you commit into local and push changes to dev. Auto-build does all it's testing of the commits you pushed and on success, pushes them to blessed. Then you (or anyone else) can pick them up from blessed and continue work from there.

Solution 2

If you're using GitHub, they have a feature to protect branches. Go to the GitHub settings for the repository, then branches and see the protected branches settings.

You can choose which branches you want to protect, and for each branch how you want to protect it. You can just prevent force pushes, require changes to be merged from another branch, or even require that your automated tests have passed.

See https://help.github.com/articles/defining-the-mergeability-of-pull-requests/

Bitbucket offer a similar feature.

Solution 3

You may want to use a commit-msg hook that checks whether the word merge occurs in the message for a tentative commit. Something like

grep -iq merge "$1" || exit 1

after a check for the branch. You may want to make the RE stricter than this. This is only a heuristic, of course, and anyone with write access to the central repo can circumvent this check.

Solution 4

Consider using a git access control layer like gitolite

Share:
17,223
alexbilbie
Author by

alexbilbie

Updated on June 15, 2022

Comments

  • alexbilbie
    alexbilbie almost 2 years

    My git repository has two branches, 'master' and 'dev'.

    Code committed to 'dev' goes through an automated build process before it is tested. Code that passes this is then merged into the 'master' branch.

    Is it possible, using hooks or something else, to prevent normal direct commits on the 'master' branch and only accept merges from 'dev' to 'master'?