Code branch protection access control system, method, device and medium based on continuous integration status

Through the code branch protection access control system based on continuous integration status, the automated processing and real-time status synchronization of code merge requests are achieved, which solves the problems of manual dependence and information lag in the traditional code branch protection mechanism and improves code quality and development efficiency.

CN120560630BActive Publication Date: 2025-10-03GUANGZHOU CANWAY TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511072953.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-08-01
Publication Date
2025-10-03
Estimated Expiration
2045-08-01

AI Technical Summary

Technical Problem

Traditional code branch protection mechanisms rely on manual review, resulting in delayed merging processes, information lags, and complex configurations. They also lack automated merging capabilities, making it difficult to improve code quality and development efficiency.

Method used

A code branch protection access control system based on continuous integration status is adopted. Through automated rule configuration, real-time status monitoring and dynamic access control, intelligent verification and automated processing of code merge requests are achieved. It includes a rule configuration module, a request parsing module, an event monitoring module, a dynamic binding engine and a rule execution module, achieving integrated process management and real-time status synchronization.

Benefits of technology

It improves the automation level of the code merging process, reduces manual waiting time, ensures real-time synchronization of CI results and review processes, simplifies configuration management, improves development efficiency and collaboration transparency, and is particularly suitable for multi-branch management of large projects.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120560630B_ABST
    Figure CN120560630B_ABST
Patent Text Reader

Abstract

The present application proposes a code branch protection access control system, method, device and medium based on continuous integration status, which belongs to the field of software development technology. The system includes: a rule configuration module, which uses regular expressions to batch define protection branches and configure CI status checks and manual review exemption rules; a request parsing module, which automatically identifies the target branch of the merge request and extracts the associated pipeline identifier; an event monitoring module, which captures pipeline status changes in real time based on Webhook; a dynamic binding engine, which establishes a real-time mapping between merge requests and pipeline results; a rule execution module, which automatically evaluates access control conditions and releases or merges according to configuration rules. The present invention achieves deep integration of code branch management and CI tool chain through automated rule control and real-time status synchronization, solves the problems of low manual review efficiency, process fragmentation, and status lag in traditional mechanisms, and improves the automation level of code quality control and development collaboration efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of software development technology, and in particular to a code branch protection access control system, method, device and medium based on continuous integration status, which is suitable for code quality control and automated merge process management in a modern DevOps environment. Background Art

[0002] In the software development process, code branch management is a critical step in ensuring code quality and team collaboration efficiency. In particular, for master branches, release branches, and feature branches, strict control over code merging is often required to avoid stability risks caused by the introduction of low-quality code.

[0003] Traditional branch protection mechanisms rely primarily on manual review, which has the following pain points:

[0004] Manual review dependency: After developers submit a merge request, they must wait for manual review, which may significantly delay the merge process.

[0005] Fragmented management processes: Code review before branch merging is usually separated from the continuous integration (CI) process, and merge request reviews cannot be linked to CI execution results in real time.

[0006] Status synchronization delay: CI execution results, code review reports, test reports, and other outputs, as the basis for review, require reviewers to access CI tools or modules to obtain them, resulting in information lag.

[0007] Although some existing systems support using CI status as a merge condition, they have the following shortcomings:

[0008] The configuration is complex and needs to be set up separately for each branch, making it difficult to manage in batches;

[0009] The code check execution results are not synchronized in real time, and there is information lag;

[0010] Lacks automated merging capabilities and still requires manual triggering. Summary of the Invention

[0011] This application proposes a code branch protection access control system, method, device and medium based on continuous integration status. Through automated rule configuration, real-time status monitoring and dynamic access control, it realizes intelligent verification and automated processing of code merge requests, thereby improving code quality and development efficiency.

[0012] The technical solution adopted in the present invention is as follows:

[0013] In a first aspect, an embodiment of the present application provides a code branch protection access control system based on continuous integration status, the system comprising:

[0014] The rule configuration module is used to protect branch settings and merge request release rule settings. It can set the access conditions for opening the continuous integration state as merge requests, and can set the cancellation of manual review dependencies and automatically release based on pipeline results.

[0015] A request parsing module, configured to receive a merge request for a protected branch and parse a continuous integration pipeline identifier set associated with the merge request;

[0016] An event monitoring module, used to monitor events associated with the pipeline identifier in real time and capture changes in the execution status of each pipeline;

[0017] A dynamic binding engine establishes a real-time mapping relationship between merge requests and pipeline execution results, where pipeline status change events trigger instant updates to access control conditions;

[0018] The rule execution module automatically releases merge requests that meet the following conditions based on the pre-configured branch protection rule engine: the final status of all associated pipelines is successful; and automatically merges merge requests that meet the following conditions: the manual review exemption switch is turned on and the final status of all associated pipelines is successful.

[0019] In some embodiments, the rule configuration module includes a branch matching unit and a rule switch matrix, wherein:

[0020] The branch matching unit uses regular expression matching to name branches that meet the rules and dynamically marks the branches that meet the rules as protected branches;

[0021] The rule switch matrix independently configures the CI status check switch and the manual review exemption switch for each protection branch; after the CI status check switch is turned on, all associated pipeline states are forced to be successful; after the manual review exemption switch is turned on, requests are automatically merged when all pipelines are successful.

[0022] In some embodiments, the request parsing module includes a branch verification unit and a pipeline identifier extractor, wherein:

[0023] The branch verification unit verifies whether the target branch of the merge request belongs to the protected branch defined by the rule configuration module;

[0024] The pipeline identifier extractor is configured with a pipeline that is triggered by a code base merge request to create or update an event. The code base and branch filtered by the trigger plug-in are protected branches. The associated pipelines are matched and the pipeline identifier group is extracted; the pipeline identifier group includes the pipeline name, ID, and event status.

[0025] In some embodiments, the event monitoring module includes an event-driven access control module that captures state change events of the merge request associated pipeline through a Webhook callback mechanism.

[0026] In some embodiments, the dynamic binding engine includes synchronously updating the access condition status of the merge request in seconds when the pipeline status changes, and displaying the pipeline execution status and results, and pipeline execution outputs in real time on the merge request details page; the pipeline execution outputs include code scanning reports and test reports.

[0027] In some embodiments, the rule execution module includes: based on the protection branch pre-configured by the rule configuration module, when its rule opens the continuous integration status as the access control condition for the merge request, the rule execution module synchronizes the associated pipeline status with the dynamic binding engine according to the event monitoring module. If the final status of all associated pipelines is successful, the merge request access is opened to allow developers to operate the merge request merge.

[0028] In some embodiments, the code branch protection access control system based on continuous integration status is characterized by a lightweight process implementation. The protection branch pre-configured by the rule configuration module skips the manual review code link when its rule turns on the manual review exemption, and only relies on the success status of the pipeline to generate a merge operation, that is, if the final status of all associated pipelines is successful, the merge request completes the automatic merge.

[0029] In a second aspect, an embodiment of the present application provides a code branch protection access control method based on continuous integration status, comprising the following steps:

[0030] Step 1: Use regular expressions to match branch naming specifications and register branches that meet the specifications as protected branches.

[0031] Step 2: Configure the CI status check switch and manual review exemption switch for the protection branch;

[0032] Step 3: Receive a merge request for the protected branch and verify the protection status of the target branch;

[0033] Step 4: Parse the continuous integration pipeline identifier set associated with the merge request;

[0034] Step 5: Create or update a merge request to automatically trigger the execution of the associated pipeline;

[0035] Step 6: Monitor pipeline status change events and update access control condition status in real time;

[0036] Step 7: Dynamically bind the merge request and the pipeline execution results, and present the pipeline execution output through a visualization page;

[0037] Step 8: Rule execution: When the manual review exemption switch is turned on and all pipeline statuses are successful, code merging is automatically performed; when only the CI status check switch is turned on, the access control is opened to allow manual triggering of the merge operation.

[0038] In a third aspect, embodiments of the present application further provide an electronic device comprising: a memory and a processor. The memory stores a program, which is loaded and executed by the processor to implement the method of any of the above-mentioned embodiments. The memory and the processor communicate with each other via an internal connection path.

[0039] In a fourth aspect, an embodiment of the present application further provides a computer-readable storage medium, in which a computer program is stored. When the computer program is executed by a computer, the method in any one of the above-mentioned embodiments is implemented.

[0040] The advantages or beneficial effects of the above technical solution include at least:

[0041] 1. Reduce manual reliance and improve process efficiency: A fully automated merging process is implemented through the manual review exemption switch, reducing manual waiting time. This is particularly suitable for high-frequency iteration scenarios and solves the development bottleneck problem caused by manual review delays in traditional mechanisms.

[0042] 2. Break down process barriers and achieve integrated management and control: Deeply link code merge requests, CI pipeline execution, and access control verification to avoid the separation of code review and CI process in the traditional model, and ensure that the review basis and CI results are synchronized in real time.

[0043] 3. Real-time status synchronization, eliminating information lag: Based on the Webhook event-driven mechanism and dynamic binding engine, pipeline status synchronization is achieved in seconds. Developers can obtain real-time verification progress on the merge request interface without switching tools, solving the pain point of CI results being out of sync with the review process.

[0044] 4. Simplify configuration management and support batch operations: Batch define and protect branches through regular expressions, replacing the tedious process of configuring branches one by one in traditional systems, improving configuration efficiency, and is especially suitable for multi-branch management scenarios of large projects.

[0045] 5. Improve process transparency and optimize the collaborative experience: The merge request details page displays pipeline execution status, access control verification results, test reports, code scanning reports and other outputs in real time, allowing developers and reviewers to clearly understand process nodes and reduce cross-role communication costs.

[0046] The above summary is for illustrative purposes only and is not intended to be limiting in any way. In addition to the illustrative aspects, embodiments and features described above, further aspects, embodiments and features of the present application will be readily apparent by reference to the accompanying drawings and the following detailed description. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments. In the accompanying drawings, unless otherwise specified, the same reference numerals throughout multiple drawings represent the same or similar parts or elements. These drawings are not necessarily drawn to scale. It should be understood that the following drawings only illustrate certain embodiments of the present application and should not be regarded as limiting the scope. For those of ordinary skill in the art, other relevant drawings can also be obtained based on these drawings without paying creative work.

[0048] Figure 1 This is a schematic diagram of the structure of a code branch protection access control system based on continuous integration status of the present invention;

[0049] Figure 2 The present invention is a flowchart of a code branch protection access control method based on continuous integration status. DETAILED DESCRIPTION

[0050] Hereinafter, only certain exemplary embodiments are briefly described. As will be appreciated by those skilled in the art, the described embodiments may be modified in various ways without departing from the spirit or scope of the present application. Therefore, the drawings and description are to be regarded as illustrative in nature and not restrictive.

[0051] As attached Figure 1 As shown, the present invention provides a code branch protection access control system based on continuous integration status. The system includes a rule configuration module, a request parsing module, an event monitoring module, a dynamic binding engine, and a rule execution module. The following is a detailed introduction to each module:

[0052] 1. The rule configuration module is used to protect branch settings and merge request release rule settings. It can set the access conditions for opening the continuous integration state as merge requests, and can set the cancellation of manual review dependencies and automatically release based on pipeline results;

[0053] (1) Branch matching unit, which matches and names branches that meet the rules through regular expressions and dynamically marks branches that meet the rules as protected branches;

[0054] (2) Regular switch matrix, independently configured for each protection branch:

[0055] CI status check switch (when enabled, forces all associated pipelines to be in the success state);

[0056] Manual review exemption switch (once turned on, pull requests will be automatically merged if all pipelines succeed);

[0057] The rule configuration module synchronously protects the branch list and rule data to the request parsing module.

[0058] 2. A request parsing module, configured to receive a merge request for a protected branch and parse the continuous integration pipeline identifier set associated with the merge request;

[0059] (1) Branch verification unit, which verifies whether the target branch of the merge request belongs to the protected branch defined by the rule configuration module;

[0060] (2) Pipeline identifier extractor, which configures a pipeline with a code base merge request creation or update event as a trigger condition, and the code base and branch filtered by the trigger plug-in as the protection branch, matches the associated pipeline and extracts the pipeline identifier group (including but not limited to: pipeline name, ID, event status).

[0061] The request parsing module passes the merge request ID and pipeline identification group to the event listening module.

[0062] 3. An event monitoring module is used to monitor events associated with the pipeline identifier in real time and capture changes in the execution status of each pipeline. Event-driven access control captures state change events of pipelines associated with merge requests through a Webhook callback mechanism. The event monitoring module pushes pipeline state change events to the dynamic binding engine.

[0063] 4. The dynamic binding engine establishes a real-time mapping relationship between merge requests and pipeline execution results. When the pipeline status changes, the access condition status of the merge request is updated synchronously in seconds. The pipeline execution status, results, and pipeline execution artifacts (including but not limited to code scanning reports and test reports) are displayed in real time on the merge request details page. The dynamic binding engine triggers the rule execution module to modify the merge request access status.

[0064] 5. The rule execution module automatically releases merge requests that meet the conditions based on the pre-configured branch protection rule engine. Based on the protection branch pre-configured by the rule configuration module, when its rule turns on the continuous integration status as the access condition for the merge request, the rule execution module will open the merge request access based on the associated pipeline status synchronized by the event monitoring module and the dynamic binding engine. If the final status of all associated pipelines is success, the developer is allowed to merge the merge request. When the protection branch pre-configured by the rule configuration module has a rule that turns on manual review exemption: the manual code review link is skipped, and the merge operation is generated only based on the pipeline success status. That is, if the final status of all associated pipelines is success, the merge request is automatically merged.

[0065] As another embodiment, the present invention provides a code branch protection access control method based on continuous integration status, as shown in the attached Figure 2 As shown, the process steps include the following:

[0066] S101. The user matches the branch naming specification with a regular expression and registers the branches that meet the specification as protected branches.

[0067] S102. The user configures the CI status check switch and the manual review exemption switch for the protection branch;

[0068] S103. The system receives a merge request for a protected branch and verifies the protection status of the target branch;

[0069] S104. The system parses the continuous integration pipeline identifier set associated with the merge request;

[0070] S105. The user creates or updates a merge request, automatically triggering the execution of the associated pipeline;

[0071] S106. The system monitors pipeline status change events and updates access control condition status in real time;

[0072] S107. The system dynamically binds the merge request with the pipeline execution results and presents the pipeline execution output (including but not limited to: code scanning report, test report) through a visual page;

[0073] S108. System rule execution: When the manual review exemption switch is turned on and all pipeline statuses are successful, code merging is automatically performed; when only the CI status check switch is turned on, the access control is opened to allow manual triggering of the merge operation.

[0074] In addition, the present invention also provides an electronic device, including a processor and a memory, wherein the memory stores a program, and the processor is used to run the program, and when the program runs, the method provided by the above invention is executed.

[0075] Furthermore, the present invention also provides another computer-readable storage medium, in which a computer program is stored. When the computer program is executed by a processor, the method provided by the above invention is implemented.

[0076] The above-described embodiments merely illustrate several implementations of the present invention. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present invention. It should be noted that a person skilled in the art would be able to make numerous variations and improvements without departing from the spirit of the present invention, and all such variations and improvements fall within the scope of protection of the present invention.

Claims

1. A code branch protection access control system based on continuous integration status, characterized in that: include: The rule configuration module is used to protect branch settings. It can match branches as protected branches based on user-configured regular expressions and set merge request release rules for protected branches, including enabling gate conditions for merge requests in the continuous integration state. It can also be set to cancel manual review dependencies and automatically release based on pipeline results. The rule configuration module includes: a branch matching unit, which matches branches named according to the rules through a user-set regular expression and dynamically marks the branches that meet the rules as protected branches; a rule switch matrix, which independently configures a CI status check switch and a manual review exemption switch for each protected branch; when the CI status check switch is turned on, it is mandatory that the final status of all pipelines associated with merge requests merged into the protected branch is successful before the merge request is automatically released; when the manual review exemption switch is turned on, it is mandatory that the final status of all pipelines associated with merge requests merged into the protected branch is successful before the merge request is automatically merged; A request parsing module is used to verify that the target branch of the merge request is a protected branch set in the rule configuration module, and to parse the identifier set of the continuous integration pipeline associated with the merge request event; the request parsing module includes: a branch verification unit, which verifies whether the target branch of the merge request belongs to the protected branch defined by the rule configuration module; a pipeline identifier extractor, which matches the associated pipelines and extracts the pipeline identifier set by configuring the pipeline with the creation or update event of the protection branch merge request as the trigger condition; the pipeline identifier set includes the pipeline name, ID, and event status; An event monitoring module is used to monitor merge request events associated with the pipeline configuration in real time and capture execution status changes of each pipeline; the event monitoring module includes: event-driven access control, which captures status change events of merge request-related pipelines through a webhook callback mechanism; A dynamic binding engine establishes a real-time mapping relationship between merge requests and pipeline execution results, where pipeline status change events trigger instant updates to access control conditions and display pipeline execution results on the merge request details page. The dynamic binding engine includes: when the pipeline status changes, it synchronously updates the access control condition status of the merge request in seconds, and displays the pipeline execution status, results, and pipeline execution outputs in real time on the merge request details page; the pipeline execution outputs include code scan reports and test reports. The rule execution module, based on the pre-configured branch protection rule engine, if the continuous integration status is the access condition for merge requests and the final status of all associated pipelines is success, the merge request is automatically released; if the manual review exemption is enabled and the final status of all associated pipelines is success, the merge request is automatically merged; the rule execution module includes: based on the protection branch pre-configured by the rule configuration module, when its rule enables the continuous integration status as the access condition for merge requests, the rule execution module, based on the associated pipeline status synchronized by the event monitoring module and the dynamic binding engine, if the final status of all associated pipelines is success, the merge request access is opened to allow developers to operate the merge request merge.

2. The code branch protection access control system based on continuous integration status according to claim 1 is characterized in that Lightweight process implementation: The rule configuration module pre-configures the protection branch. When its rule enables manual review exemption, the manual code review step is skipped and the merge operation is generated only based on the success status of the pipeline. That is, if the final status of all related pipelines is success, the merge request is automatically merged.

3. A code branch protection access control method based on continuous integration status, characterized in that: A system according to any one of claims 1 to 2, comprising: Step 1: Use regular expressions to match branch naming specifications and register branches that meet the specifications as protected branches. Step 2: Configure the CI status check switch and manual review exemption switch for the protection branch; Step 3: Receive a merge request for the protected branch and verify the protection status of the target branch; Step 4: Parse the continuous integration pipeline identifier set associated with the merge request; Step 5: Create or update a merge request to automatically trigger the execution of the associated pipeline; Step 6: Monitor pipeline status change events and update access control condition status in real time; Step 7: Dynamically bind the merge request and the pipeline execution results, and present the pipeline execution output through a visualization page; Step 8: Rule execution: When the manual review exemption switch is turned on and all pipeline statuses are successful, code merging is automatically performed; when only the CI status check switch is turned on, the access control is opened to allow manual triggering of the merge operation.

4. An electronic device, characterized in that: include: A processor and a memory, wherein the memory stores a program, and the processor is used to run the program, and the method according to claim 3 is executed when the program is run.

5. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, which implements the method according to claim 3 when executed by a processor.

Citation Information

Patent Citations

  • Process management method, system and equipment based on DevOps

    CN119597424A

  • Automated check for ticket status of merged code

    US20210089297A1