Observed on ttorg/widget. An account with write ran git push origin :v0.0.1; the tag was deleted, the release stayed, and the releases page serves it with its assets. Protection covers refs/heads/ only.
Wants tag protection (a glob such as v*, refusing delete and non-fast-forward update), and a rule for a release whose tag is gone: refuse the delete while a release anchors the tag, or mark the release orphaned.
Ref #185
closed by commit 060109696d by cmc: policy, hookd, control, web, wiki: protected tags, and a release keeps its tag
2026-09-08 02:35 UTC