Why: - branch protection now enforces PR-only flow, strict checks, blocked force pushes, and conversation resolution - required approving reviews and required code owner reviews remain deferred because the repo currently has only one review-capable collaborator What: - enable at least one required approving review once a second review-capable collaborator exists - turn on required code owner reviews for control-plane files after the reviewer surface exists - reassess whether classic branch protection should stay the primary platform control or move into rulesets at the same time Checks: - UV_PROJECT_ENVIRONMENT="$HOME/.venvs/tallylot-py312" uv run python -m tools.audit_delivery_guardrails
Why:
What:
Checks: