repo settings protect-tag <owner/name> <glob> / unprotect-tag: matching tags are created once and refuse moves and deletion in pre-receive. Separately, a tag a release is anchored to refuses both while the release exists, protected or not, naming the release as what to delete first. Settings page section, settings show field, Users lines. Policy unit cases and an e2e covering both refusals, the unmatched tag, and the release path.
Closes #201
retargeted from require-mr to main: !339 merged
2026-09-08 02:35 UTC