feat(gitflow): remove the origin copy of a branch once its merge is verified
`gitflow_delete` now ends with `_gitflow_delete_remote`: after the local copy is gone, the remote tip is read with `ls-remote --exit-code`, checked against develop/main with the same ancestor test, and only then removed with `push origin --delete`. Same contract as the pushes (BDR-095): best effort, warn never fail. No origin, `GITFLOW_NO_PUSH=1` or `gitflow.autopush false` skip it; an unreachable origin or a remote tip holding commits the bases lack keeps the remote branch, loudly. A base is never targeted, by construction and by an explicit guard. The static deny on hand `git push --delete` stays: it matches the Bash tool's command string, the lib is the sanctioned path. Prose (hard_deny, environment), doctrine, gitflow SKILL (table, op, warning row), SETTINGS.md and CHANGELOG updated. T24: 9 checks (finish removes the copy, bases untouched, unmerged remote tip kept, never pushed silent, unreachable origin loud, autopush opt-out). 161/163, the 2 failures are the pre-existing T16a (gitleaks absent on this host).
This commit is contained in:
@@ -155,7 +155,9 @@ Push discipline lives in `lib/gitflow.sh`: `start` pushes the branch,
|
||||
push every commit as it lands (warn, never block, on failure). `finish`
|
||||
deletes the merged branch through `gitflow_delete`, which refuses
|
||||
`main`/`develop` and any branch not merged into develop or main (`git branch
|
||||
-d` alone proves nothing once the branch has an auto-pushed upstream). A
|
||||
-d` alone proves nothing once the branch has an auto-pushed upstream), then
|
||||
removes the `origin/` copy once its tip passes the same check (best effort:
|
||||
unreachable origin or an unmerged remote tip keeps it, loudly). A
|
||||
fourth hook, `reference-transaction`, vetoes any deletion or rename of
|
||||
`main`/`develop` at the ref layer. The hooks
|
||||
reach every repo two ways: `make link` generates `githooks/` from the lib
|
||||
|
||||
Reference in New Issue
Block a user