如何在BitBucket Cloud中锁定敏感Git文件以阻止合并?
Got it, since you're using BitBucket Cloud (not Server) and need to lock down those untouched, sensitive old .java files so any PR modifying them gets blocked, here are the most reliable, actionable methods:
Method 1: Enforce Checks via BitBucket Pipelines + Branch Protection
This is the most straightforward and enforceable approach—we’ll set up a pipeline script that scans PR changes for your sensitive files, and block the merge if any are touched.
Step 1: Set Up Branch Protection Rules
- Go to your repository’s Settings > Branches
- Create a new branch protection rule for the branches you want to protect (e.g.,
main,release/*) - Enable the Require passing builds to merge option—this ensures PRs can only merge if your pipeline check passes.
Step 2: Add a Pipeline Script to Block Sensitive File Changes
Create a bitbucket-pipelines.yml file in your repo’s root directory with this script (tweak the sensitive file paths to match yours):
pipelines: pull-requests: '**': - step: name: Block Sensitive File Modifications script: # Get list of files changed in the PR CHANGED_FILES=$(git diff --name-only $BITBUCKET_PR_DESTINATION_BRANCH...$BITBUCKET_BRANCH) # Define your sensitive .java files here (add/remove as needed) SENSITIVE_FILES=( "src/main/java/com/yourorg/SensitiveLegacyFile1.java" "src/main/java/com/yourorg/SensitiveLegacyFile2.java" ) # Check if any sensitive file was modified for FILE in "${SENSITIVE_FILES[@]}"; do if echo "$CHANGED_FILES" | grep -q "^$FILE$"; then echo "❌ ERROR: Modifying $FILE is strictly prohibited. This PR cannot be merged." exit 1 fi done echo "✅ All checks passed: No sensitive files were modified."
Optional: Strict Hash Check (Prevent Any File Alteration)
If you want to ensure the files stay exactly as they are (even if someone edits and reverts changes), replace the check with a hash comparison:
for FILE in "${SENSITIVE_FILES[@]}"; do # Get the file's hash from the target branch DEST_HASH=$(git ls-tree $BITBUCKET_PR_DESTINATION_BRANCH $FILE | awk '{print $3}') # Get the file's hash from the PR branch CURRENT_HASH=$(git ls-tree $BITBUCKET_BRANCH $FILE | awk '{print $3}') if [ "$DEST_HASH" != "$CURRENT_HASH" ]; then echo "❌ ERROR: $FILE has been altered (hash mismatch). This PR cannot be merged." exit 1 fi done
Method 2: Supplement with Repository Access Controls (Extra Layer)
BitBucket Cloud doesn’t support granular file-level permissions, but you can add an extra safety net:
- Restrict branch write access to only trusted admins for protected branches (in Settings > Branches > Branch protection rules under "Restrict who can push and merge")
- This ensures only a small group can even push changes to protected branches, reducing the chance of accidental modifications to sensitive files.
Key Notes
- The pipeline check is mandatory for PR merges (if you’ve set up branch protection correctly), so even admins can’t bypass it unless you explicitly grant them "Bypass pull request approvals and checks" permission—limit this to only critical roles.
- Update the
SENSITIVE_FILESlist in the pipeline script whenever you need to add/remove locked files.
内容的提问来源于stack exchange,提问作者Kushagra Sahni

