GitLab Releases Security & compliance Code quality

Branch protection too weak (GitLab)

Part of the GitLab project protection check · fix arrives as a guide

What it is

The default branch is protected but the rule is weak — developers can push directly, or force push is still allowed.

Why it matters

The settings page shows protection while the specific gap that matters stays open. Allowing developer push in particular means the merge request flow is optional rather than enforced.

How to fix it

Set the allowed-to-push role to no one and disallow force push. On GitLab Premium and above, also require at least one merge request approval and add a rule preventing authors from approving their own merge requests.

Run them all on your app

Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.