如何在GitHub为多个指定分支创建统一的分支保护规则?
Great question—having to manually set up identical branch protection rules for each branch is such a tedious, inefficient chore, especially when all your branches share the exact same requirements. Let’s break down the best ways to solve this without repeating work:
1. Use GitHub's Wildcard/Brace Expansion (Recommended, No Code Needed)
GitHub’s branch protection rules support glob patterns and brace expansion, which lets you target multiple specific branches with a single rule. This is the simplest, most built-in solution for your case.
Here’s how to set it up:
- Navigate to your repository’s Settings → Branches → Branch protection rules
- Click Add rule
- In the Branch name pattern field, enter this exact string:
This brace expansion will match all your target branches precisely (no accidental matches with other branches).{develop,master,sit,uat,testbed,preprod} - Configure all your required protection settings (e.g., required pull request reviews, status checks, code owner approvals)
- Save the rule—GitHub will automatically apply these settings to every branch in the brace list.
2. Automate with GitHub CLI (For Custom/Automated Workflows)
If you need more control or want to script the process (e.g., for bulk updates across multiple repos), use the GitHub CLI (gh) to apply rules via the GitHub API.
First, make sure you have the GitHub CLI installed and authenticated (gh auth login). Then use this shell script to apply identical rules to all your branches:
# List your target branches branches=("develop" "master" "sit" "uat" "testbed" "preprod") # Replace with your repo owner and name owner="your-username" repo="your-repo-name" # Define your protection settings (adjust these to match your needs) required_approvals=1 requires_status_checks=true required_checks=("build" "unit-test") # Example status checks # Loop through each branch and apply the rule for branch in "${branches[@]}"; do gh api repos/$owner/$repo/branches/$branch/protection \ -X PUT \ -f required_pull_request_reviews.required_approving_review_count=$required_approvals \ -f requires_status_checks=$requires_status_checks \ -f required_status_checks.contexts="$(IFS=,; echo "${required_checks[*]}")" \ # Add more flags here for additional settings (e.g., require_code_owner_reviews=true) done
3. Use GitHub Actions for Ongoing Automation
If you want to ensure any new instances of these branches (or future branches matching your list) automatically get the protection rules, set up a GitHub Actions workflow.
Create a file at .github/workflows/apply-branch-protection.yml with this content:
name: Auto-Apply Branch Protection on: create: branches: - develop - master - sit - uat - testbed - preprod jobs: protect-branch: runs-on: ubuntu-latest steps: - name: Set up GitHub CLI uses: actions/setup-gh@v2 with: gh-version: latest - name: Authenticate with GitHub run: echo "${{ secrets.GITHUB_TOKEN }}" | gh auth login --with-token - name: Apply protection rules run: | gh api repos/${{ github.repository }}/branches/${{ github.ref_name }}/protection \ -X PUT \ -f required_pull_request_reviews.required_approving_review_count=1 \ -f requires_status_checks=true \ -f required_status_checks.contexts='["build", "unit-test"]' # Add your custom settings here
This workflow will trigger automatically whenever one of your target branches is created, ensuring it gets the protection rules without any manual intervention.
For your specific scenario (fixed list of branches with identical rules), the brace expansion method is the fastest and easiest solution—no scripts or workflows required. The CLI and Actions options are great if you need to scale this across multiple repos or automate future branch setup.
内容的提问来源于stack exchange,提问作者Uma Mahiswari

