adherence:
assessment-plans:
- evaluation-methods:
- id: ampel-config
mode: Automated
type: Intent
frequency: on-demand
id: BP-1.01
requirement-id: BP-1.01
- evaluation-methods:
- id: ampel-config
mode: Automated
type: Intent
frequency: on-demand
id: BP-2.01
requirement-id: BP-2.01
- evaluation-methods:
- id: ampel-config
mode: Automated
type: Intent
frequency: on-demand
id: BP-3.01
requirement-id: BP-3.01
- evaluation-methods:
- id: ampel-config
mode: Automated
type: Intent
frequency: on-demand
id: BP-4.01
requirement-id: BP-4.01
- evaluation-methods:
- id: ampel-config
mode: Automated
type: Intent
frequency: on-demand
id: BP-5.01
requirement-id: BP-5.01
enforcement-methods:
- description: AMPEL automated branch protection enforcement gate
executor:
id: ampel
name: AMPEL
type: Software
id: ampel-gate
mode: Automated
type: Gate
evaluation-methods:
- description: AMPEL automated check to determine branch protection configuration
executor:
id: ampel
name: AMPEL
type: Software
id: ampel-config
mode: Automated
type: Intent
contacts:
accountable:
- name: Security Team
responsible:
- name: Repository Administrator
imports:
catalogs:
- reference-id: repo-branch-protection
metadata:
author:
id: complytime
name: ComplyTime
type: Software Assisted
description: Automated evaluation policy for branch protection controls using AMPEL
gemara-version: 1.1.0
id: ampel-branch-protection-policy
mapping-references:
- description: Control catalog for branch protection rules
id: repo-branch-protection
title: Branch Protection Controls
url: https://github.com/complytime/complytime-policies/blob/main/governance/catalogs/ampel-branch-protection-catalog.yaml
version: 1.0.0
type: Policy
version: dev-20260527
scope:
in:
technologies:
- GitHub
- GitLab
users:
- Repository maintainers
title: AMPEL Branch Protection Policy
Search / complytime/ampel-branch-protection-policy / dev-20260527
Release · dev-20260527
complytime/ampel-branch-protection-policy Policy
complytime/ampel-branch-protection-policy
Automated evaluation policy for branch protection controls using AMPEL
Published by ComplyTime
License No license declared
Install
OCI v1.1$grcli unpack --repository complytime/ampel-branch-protection-policy --version dev-20260527 grcli unpack verifies this signature against the
recorded identity below and fails closed before writing
any files — no separate verify step needed. Pass
--no-verify to skip.
- Coordinate
- oci.grc.store/complytime/ampel-branch-protection-policy:dev-20260527
- Manifest digest
- sha256:f5999cf019190ca5dfdb282e4e0b206a8f03240b2a139874fef51e166b943ea4
- Signed by
- no signature recorded
Identity recorded by this hub when the version was published;
unpack (above) checks the signature against it.
Verify in CI — check the signature without downloading
$grcli verify --repository complytime/ampel-branch-protection-policy --version dev-20260527 Read-only: downloads nothing and exits non-zero if the signature or the recorded identity doesn't match — use it as an admission/policy gate.
Provenance
1 layer| Digest | Media type | Size |
|---|---|---|
| 890e284300d4… | application/vnd.gemara.artifact.v1+yaml | 2.6 KiB |
Bundle config blob
{
"bundle-version": "1.0",
"gemara-version": "1.1.0",
"metadata": {
"provenance": {
"buildDefinition": {
"buildType": "https://grc.store/grcli/buildtype/v0",
"externalParameters": {
"artifact": {
"id": "ampel-branch-protection-policy",
"type": "Policy"
},
"target": {
"registry": "oci.grc.store",
"repository": "complytime/ampel-branch-protection-policy",
"tag": "dev-20260527"
}
},
"internalParameters": {
"CI": "true",
"GITHUB_ACTIONS": "true",
"GITHUB_ACTOR": "eddie-knight",
"GITHUB_REF": "refs/heads/main",
"GITHUB_REPOSITORY": "eddie-knight/complytime-policies",
"GITHUB_RUN_ATTEMPT": "2",
"GITHUB_RUN_ID": "26524275168",
"GITHUB_SHA": "35c30860a105d3c2572aade482dfdaa8a28312cc",
"GITHUB_WORKFLOW": "Publish to grc.store",
"RUNNER_OS": "Linux"
},
"resolvedDependencies": [
{
"name": "governance/policies/ampel-branch-protection-policy.yaml",
"uri": "file://governance/policies/ampel-branch-protection-policy.yaml",
"digest": {
"sha256": "890e284300d4e0ea18c2b36523a803ab451e73f8115075651b048788cbc10e1d"
}
},
{
"name": "source",
"uri": "git+https://github.com/eddie-knight/complytime-policies@35c30860a105d3c2572aade482dfdaa8a28312cc",
"digest": {
"gitCommit": "35c30860a105d3c2572aade482dfdaa8a28312cc"
}
}
]
},
"runDetails": {
"builder": {
"id": "https://github.com/eddie-knight/complytime-policies/actions/runs/26524275168",
"version": {
"go": "go1.25.0",
"go-arch": "amd64",
"go-os": "linux",
"grcli": "v0.1.2"
}
},
"metadata": {
"invocationId": "26524275168-2",
"startedOn": "2026-05-27T16:29:34.720938119Z",
"finishedOn": "2026-05-27T16:29:35.231147085Z"
},
"byproducts": [
{
"name": "ampel-branch-protection-policy.yaml",
"digest": {
"sha256": "890e284300d4e0ea18c2b36523a803ab451e73f8115075651b048788cbc10e1d"
}
}
]
}
}
},
"artifacts": [
{
"name": "ampel-branch-protection-policy.yaml",
"type": "Policy",
"id": "ampel-branch-protection-policy",
"role": "artifact"
}
]
} No rich preview yet
This UI can't render Policy artifacts richly yet. The raw content is shown below, and the artifact stays pullable via the coordinate above.