Search / complytime/ampel-branch-protection-policy / dev-20260527

Release · dev-20260527

complytime/ampel-branch-protection-policy Policy

complytime/ampel-branch-protection-policy

Automated evaluation policy for branch protection controls using AMPEL

Published by ComplyTime

License No license declared

Install

OCI v1.1
$grcli unpack --repository complytime/ampel-branch-protection-policy --version dev-20260527

grcli unpack verifies this signature against the recorded identity below and fails closed before writing any files — no separate verify step needed. Pass --no-verify to skip.

Coordinate
oci.grc.store/complytime/ampel-branch-protection-policy:dev-20260527
Manifest digest
sha256:f5999cf019190ca5dfdb282e4e0b206a8f03240b2a139874fef51e166b943ea4
Signed by
no signature recorded

Identity recorded by this hub when the version was published; unpack (above) checks the signature against it.

Verify in CI — check the signature without downloading
$grcli verify --repository complytime/ampel-branch-protection-policy --version dev-20260527

Read-only: downloads nothing and exits non-zero if the signature or the recorded identity doesn't match — use it as an admission/policy gate.

Provenance

1 layer
Digest Media type Size
890e284300d4… application/vnd.gemara.artifact.v1+yaml 2.6 KiB
Bundle config blob
{
  "bundle-version": "1.0",
  "gemara-version": "1.1.0",
  "metadata": {
    "provenance": {
      "buildDefinition": {
        "buildType": "https://grc.store/grcli/buildtype/v0",
        "externalParameters": {
          "artifact": {
            "id": "ampel-branch-protection-policy",
            "type": "Policy"
          },
          "target": {
            "registry": "oci.grc.store",
            "repository": "complytime/ampel-branch-protection-policy",
            "tag": "dev-20260527"
          }
        },
        "internalParameters": {
          "CI": "true",
          "GITHUB_ACTIONS": "true",
          "GITHUB_ACTOR": "eddie-knight",
          "GITHUB_REF": "refs/heads/main",
          "GITHUB_REPOSITORY": "eddie-knight/complytime-policies",
          "GITHUB_RUN_ATTEMPT": "2",
          "GITHUB_RUN_ID": "26524275168",
          "GITHUB_SHA": "35c30860a105d3c2572aade482dfdaa8a28312cc",
          "GITHUB_WORKFLOW": "Publish to grc.store",
          "RUNNER_OS": "Linux"
        },
        "resolvedDependencies": [
          {
            "name": "governance/policies/ampel-branch-protection-policy.yaml",
            "uri": "file://governance/policies/ampel-branch-protection-policy.yaml",
            "digest": {
              "sha256": "890e284300d4e0ea18c2b36523a803ab451e73f8115075651b048788cbc10e1d"
            }
          },
          {
            "name": "source",
            "uri": "git+https://github.com/eddie-knight/complytime-policies@35c30860a105d3c2572aade482dfdaa8a28312cc",
            "digest": {
              "gitCommit": "35c30860a105d3c2572aade482dfdaa8a28312cc"
            }
          }
        ]
      },
      "runDetails": {
        "builder": {
          "id": "https://github.com/eddie-knight/complytime-policies/actions/runs/26524275168",
          "version": {
            "go": "go1.25.0",
            "go-arch": "amd64",
            "go-os": "linux",
            "grcli": "v0.1.2"
          }
        },
        "metadata": {
          "invocationId": "26524275168-2",
          "startedOn": "2026-05-27T16:29:34.720938119Z",
          "finishedOn": "2026-05-27T16:29:35.231147085Z"
        },
        "byproducts": [
          {
            "name": "ampel-branch-protection-policy.yaml",
            "digest": {
              "sha256": "890e284300d4e0ea18c2b36523a803ab451e73f8115075651b048788cbc10e1d"
            }
          }
        ]
      }
    }
  },
  "artifacts": [
    {
      "name": "ampel-branch-protection-policy.yaml",
      "type": "Policy",
      "id": "ampel-branch-protection-policy",
      "role": "artifact"
    }
  ]
}

No rich preview yet

This UI can't render Policy artifacts richly yet. The raw content is shown below, and the artifact stays pullable via the coordinate above.

adherence:
  assessment-plans:
    - evaluation-methods:
        - id: ampel-config
          mode: Automated
          type: Intent
      frequency: on-demand
      id: BP-1.01
      requirement-id: BP-1.01
    - evaluation-methods:
        - id: ampel-config
          mode: Automated
          type: Intent
      frequency: on-demand
      id: BP-2.01
      requirement-id: BP-2.01
    - evaluation-methods:
        - id: ampel-config
          mode: Automated
          type: Intent
      frequency: on-demand
      id: BP-3.01
      requirement-id: BP-3.01
    - evaluation-methods:
        - id: ampel-config
          mode: Automated
          type: Intent
      frequency: on-demand
      id: BP-4.01
      requirement-id: BP-4.01
    - evaluation-methods:
        - id: ampel-config
          mode: Automated
          type: Intent
      frequency: on-demand
      id: BP-5.01
      requirement-id: BP-5.01
  enforcement-methods:
    - description: AMPEL automated branch protection enforcement gate
      executor:
        id: ampel
        name: AMPEL
        type: Software
      id: ampel-gate
      mode: Automated
      type: Gate
  evaluation-methods:
    - description: AMPEL automated check to determine branch protection configuration
      executor:
        id: ampel
        name: AMPEL
        type: Software
      id: ampel-config
      mode: Automated
      type: Intent
contacts:
  accountable:
    - name: Security Team
  responsible:
    - name: Repository Administrator
imports:
  catalogs:
    - reference-id: repo-branch-protection
metadata:
  author:
    id: complytime
    name: ComplyTime
    type: Software Assisted
  description: Automated evaluation policy for branch protection controls using AMPEL
  gemara-version: 1.1.0
  id: ampel-branch-protection-policy
  mapping-references:
    - description: Control catalog for branch protection rules
      id: repo-branch-protection
      title: Branch Protection Controls
      url: https://github.com/complytime/complytime-policies/blob/main/governance/catalogs/ampel-branch-protection-catalog.yaml
      version: 1.0.0
  type: Policy
  version: dev-20260527
scope:
  in:
    technologies:
      - GitHub
      - GitLab
    users:
      - Repository maintainers
title: AMPEL Branch Protection Policy