You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在BitBucket Cloud中锁定敏感Git文件以阻止合并?

How to Lock Sensitive .java Files in BitBucket Cloud (Block PRs with Changes to Them)

Got it, since you're using BitBucket Cloud (not Server) and need to lock down those untouched, sensitive old .java files so any PR modifying them gets blocked, here are the most reliable, actionable methods:

Method 1: Enforce Checks via BitBucket Pipelines + Branch Protection

This is the most straightforward and enforceable approach—we’ll set up a pipeline script that scans PR changes for your sensitive files, and block the merge if any are touched.

Step 1: Set Up Branch Protection Rules

  1. Go to your repository’s Settings > Branches
  2. Create a new branch protection rule for the branches you want to protect (e.g., main, release/*)
  3. Enable the Require passing builds to merge option—this ensures PRs can only merge if your pipeline check passes.

Step 2: Add a Pipeline Script to Block Sensitive File Changes

Create a bitbucket-pipelines.yml file in your repo’s root directory with this script (tweak the sensitive file paths to match yours):

pipelines:
  pull-requests:
    '**':
      - step:
          name: Block Sensitive File Modifications
          script:
            # Get list of files changed in the PR
            CHANGED_FILES=$(git diff --name-only $BITBUCKET_PR_DESTINATION_BRANCH...$BITBUCKET_BRANCH)
            
            # Define your sensitive .java files here (add/remove as needed)
            SENSITIVE_FILES=(
              "src/main/java/com/yourorg/SensitiveLegacyFile1.java"
              "src/main/java/com/yourorg/SensitiveLegacyFile2.java"
            )
            
            # Check if any sensitive file was modified
            for FILE in "${SENSITIVE_FILES[@]}"; do
              if echo "$CHANGED_FILES" | grep -q "^$FILE$"; then
                echo "❌ ERROR: Modifying $FILE is strictly prohibited. This PR cannot be merged."
                exit 1
              fi
            done
            
            echo "✅ All checks passed: No sensitive files were modified."

Optional: Strict Hash Check (Prevent Any File Alteration)

If you want to ensure the files stay exactly as they are (even if someone edits and reverts changes), replace the check with a hash comparison:

for FILE in "${SENSITIVE_FILES[@]}"; do
  # Get the file's hash from the target branch
  DEST_HASH=$(git ls-tree $BITBUCKET_PR_DESTINATION_BRANCH $FILE | awk '{print $3}')
  # Get the file's hash from the PR branch
  CURRENT_HASH=$(git ls-tree $BITBUCKET_BRANCH $FILE | awk '{print $3}')
  
  if [ "$DEST_HASH" != "$CURRENT_HASH" ]; then
    echo "❌ ERROR: $FILE has been altered (hash mismatch). This PR cannot be merged."
    exit 1
  fi
done

Method 2: Supplement with Repository Access Controls (Extra Layer)

BitBucket Cloud doesn’t support granular file-level permissions, but you can add an extra safety net:

  • Restrict branch write access to only trusted admins for protected branches (in Settings > Branches > Branch protection rules under "Restrict who can push and merge")
  • This ensures only a small group can even push changes to protected branches, reducing the chance of accidental modifications to sensitive files.

Key Notes

  • The pipeline check is mandatory for PR merges (if you’ve set up branch protection correctly), so even admins can’t bypass it unless you explicitly grant them "Bypass pull request approvals and checks" permission—limit this to only critical roles.
  • Update the SENSITIVE_FILES list in the pipeline script whenever you need to add/remove locked files.

内容的提问来源于stack exchange,提问作者Kushagra Sahni

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 06:52:59