We have many repos and many developers.
All repos have a branch restriction for our develop and master branch which is:
- Check for at least 2 approval
- Check for at least 1 approval from default reviewers
- deleting this branch not allowed
- rewriting branch history not allowed
- check for unresolved pull request tasks.
- Merge access via pull requests: everyone with access to the repo has merge access
The problem is any developer, who only has write permission (not admin), can merge their own pull requests with no reviewers.
Because we cannot enforce that at least one person has reviewed a given PR, we end up with unreviewed and unchecked code being merged.
Why does "check for at least X approval" not work? How can we enforce that PRs cant be merged to a given branch without approval?