D26 · main is guarded locally until the organization moves to GitHub Team
Accepted · 2026-10-05 · zuki · Superseded by D28
Decision: The GitHub organization that owns the repository stays on GitHub Free for now. Rulesets on a private repository need GitHub Team, so until the organization moves to it, two things stand in for a ruleset on main: a Lefthook pre-push guard that refuses pushes to main from zuki's Mac (TL-M0-14, path B, in [Runbook] v2 timeline), and Vercel's Deployment Checks, which hold each production deploy until CI's checks job passes on its commit (TL-M0-21). The organization moves to GitHub Team, and TL-M0-14 path A adds the ruleset, before anyone other than zuki, a person or an agent, gets write access to the repository.
Why: While zuki is the only one who can push and agents hold no credentials, a ruleset would mostly guard against zuki's own mistakes, which the local guard also catches. Moving the repository to a personal account would need GitHub Pro for the same rulesets and would lose the organization that Vercel, Supabase and Sentry connect to.
Consequences: Merging only through pull requests is a habit on GitHub Free, not a rule GitHub enforces: git push --no-verify skips the guard. TL-M0-14 has two paths, and the M0 exit check accepts path B. Giving a person or an agent write access to the repository waits for path A.