問題文
An enterprise wants to standardize on a branching approach where all work happens on short-lived branches created from the default branch, is reviewed through a pull request, and is deployed after merge. Which additional control best ensures that the review step is not skipped?
選択肢
- Enable Dependabot version updates so that dependency changes always arrive as pull requests.
- Document the branching model in the repository's contributing guide and ask developers to follow it, since the guide is shown to contributors when they open a pull request.
- Require pull requests before merging to the default branch, enforced through a ruleset or branch protection.
- Set the repository visibility to internal so that only enterprise members can push.