Hardening the Source: Scaling Branch Governance with Gemara, ComplyTime and Ampel
Inhaltsverzeichnis
“I thought we turned that on?” is a phrase no engineer wants to hear after a security incident. In a growing GitHub organization, branch protection rules – like mandatory PR reviews and signed commits – often suffer from configuration drift.
In this compact, demo-driven session, we moved beyond “manual checklists” to an automated governance model using the OpenSSF Gemara project. We demonstrated a “simple-by-design” architecture that uses Gemara to define policy, ComplyTime to manage the lifecycle, and Ampel to provide “Traffic Light” verification via signed attestations.
The secret sauce? GitHub Reusable Workflows. We showcased a live “Red-to-Green” transition, showing how any team can adopt these hardened controls instantly. Attendees left with a practical 25-minute blueprint for turning branch protection into a continuously monitored, verifiable asset of their software supply chain.