Bypass Actors

Bypass Actors and Emergency Overrides

A ruleset's bypass list names who may ignore it: repository roles (admin is role id 5), teams, GitHub 29 Apps, deploy keys, and in organizations the org admins. In mode always the actor may push directly and merge past failed rules; in mode pull_request only merges bypass, and direct pushes stay blocked. Sam adds the admin role to both rulesets, merges #10 past the missing approval and check, then commits a two-line README note on main and pushes it directly:

Adding the admin role as a bypass actor, then using it twice
for id in 23992928 23992941; do
  gh api -X PUT repos/{owner}/{repo}/rulesets/$id --input - \
    --jq '"\(.name): \(.bypass_actors)"' <<'EOF'
{ "bypass_actors": [ { "actor_id": 5, "actor_type": "RepositoryRole", "bypass_mode": "always" } ] }
EOF
done
gh pr merge 10 --admin --squash
git switch -q main && git pull -q
git commit -qam "Say in the README that main is protected" && git push origin main
Output
Protect main: [{"actor_id":5,"actor_type":"RepositoryRole","bypass_mode":"always"}]
Require tests: [{"actor_id":5,"actor_type":"RepositoryRole","bypass_mode":"always"}]
✓ Squashed and merged pull request binarybehemoth/booknest#10 (Add a CODEOWNERS file)
remote: Bypassed rule violations for refs/heads/main:
remote:
remote: - Changes must be made through a pull request.
...
   c40e167..8cdbe7f  main -> main

Every bypass is recorded: Settings, Rules, Insights (or the API's rulesets/rule-suites) listed three pushes, the rejected one from Rulesets as fail and these two as bypass. Keep bypass lists short, prefer pull_request mode, and treat each bypass as an incident to explain. BookNest keeps its admin bypass because Sam works alone. He also sets Protect main back to 0 approvals and disables Require tests until a check reports it: gh 29 api -X PUT repos/{owner}/{repo}/rulesets/23992941 -f enforcement=disabled.