Skip to content

Security suggestion: enable branch protection rules to prevent unauthorized code changes #5969

Description

@Cuecuexiaoyu

Hi maintainers, thank you for all the work you do on UglifyJS!

I would like to suggest tightening the default repository settings to reduce the risk of malicious code being merged:

  1. Turn on “branch protection” for the default branch (master):
  • Require at least one approving review from a designated code-owner before merge
  • Dismiss stale approvals when new commits are pushed
  • Require status checks (CI) to pass before merge
  • Restrict pushes that bypass the rules to a small group of trusted maintainers
  1. Create a repository ruleset (or CODEOWNERS file) that automatically requests review from core contributors when sensitive areas (lib/, bin/, test/compress/) are modified.

  2. Consider enabling “require signed commits” or “require linear history” if feasible, to make tampering easier to detect.

These settings are free on GitHub and would add an extra layer of protection against accidental or malicious changes without placing a heavy burden on day-to-day development.

For step-by-step instructions please see the official GitHub guide:
https://docs.github.com/en/repositories/configuring-branches-and-merges-in-your-repository/managing-rulesets/creating-rulesets-for-a-repository

I am happy to open a PR that adds a sample CODEOWNERS file or documents the recommended branch-protection checklist if that helps.

Let me know your thoughts, and thanks again for maintaining this great project!

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions