All skills
asyrafhussin avatar

/git-workflow

@b02a263

Git best practices, branching strategies, commit conventions, and PR workflows. Use when reviewing git history, writing commits, setting up branching strategy, or improving git practices. Triggers on "git best practices", "commit message", "branching strategy", or "PR workflow".

Use this Skill: https://skilld.dev/gh/asyrafhussin/agent-skills/git-workflow

This session only. Nothing lands on disk.

rulesbranch-main-protected.md

≈620 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Protected Main Branch

The main branch should be protected from direct pushes and require pull requests for all changes.

Bad Example

# Pushing directly to main
git checkout main
git commit -m "quick fix"
git push origin main

# Force pushing to main
git push --force origin main

# Bypassing branch protection
git push origin main --no-verify

# Merging locally and pushing
git checkout main
git merge feature/something
git push origin main

# Resetting main to different state
git checkout main
git reset --hard HEAD~5
git push --force origin main

Good Example

# All changes through pull requests
git checkout -b fix/login-issue
git commit -m "fix: resolve login timeout"
git push -u origin fix/login-issue
gh pr create --base main

# Wait for reviews and CI
gh pr checks
gh pr status

# Merge through GitHub/GitLab UI or CLI
gh pr merge --squash

# For hotfixes, still use PR (just expedited)
git checkout -b hotfix/security-patch
git commit -m "fix: patch XSS vulnerability"
git push -u origin hotfix/security-patch
gh pr create --base main --label "urgent"
# Request expedited review

Why

Protected main branch is crucial for code quality:

  1. Code Review: Every change is reviewed by at least one other person
  2. CI Verification: All tests must pass before merging
  3. Audit Trail: All changes are traceable through PRs
  4. Reduced Risk: Prevents accidental pushes of broken code
  5. Compliance: Required for many security and regulatory standards

Recommended protection rules:

# GitHub branch protection settings
main:
  required_pull_request_reviews:
    required_approving_review_count: 1
    dismiss_stale_reviews: true
    require_code_owner_reviews: true
  required_status_checks:
    strict: true
    contexts:
      - "ci/tests"
      - "ci/lint"
  enforce_admins: true
  required_linear_history: true
  allow_force_pushes: false
  allow_deletions: false

Protection levels:

  • Minimum: Require PR, 1 approval
  • Standard: Require PR, 1 approval, CI passing
  • Strict: Require PR, 2 approvals, CI passing, CODEOWNERS
  • Maximum: All above + enforce for admins, require linear history

Even maintainers and admins should follow the PR process to maintain consistency and set a good example.

Source: SKILL.md on GitHub

1 alert16d5 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    This skill provides a comprehensive and secure set of guidelines for managing Git workflows, including commit message standards, branching strategies, and pull request best practices. It promotes industry-standard tools and safety measures, such as protected branches and automated linting, with no malicious patterns detected.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer6mo

    19/32 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at b02a263. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub last month.

Steadyupdated 7 months ago
metadata
{
  "author": "AsyrafHussin",
  "version": "1.2.0"
}

README badge

README badge for asyrafhussin/agent-skills/git-workflow