Editing a governed file
Ever had a teammate change code they clearly never read the docs for?
Couples an edit to a governed code surface to its owning document, so the two cannot drift apart in one change.
git commit
Ever pushed code that didn't even compile?
Refuses a commit that does not build or pass its own checks, before the broken state exists at all.
git push
Ever had someone accidentally push straight to main?
Refuses a push that would land straight on main, on the machine that attempted it.
Guards: publish the branch
Creating a pull request, or editing its title/description
Ever opened a PR that was missing half the info reviewers needed?
Refuses to open or edit a pull request until it carries everything a reviewer needs to judge it.
Guards: open a pull request, revise a pull request, grant a waiver
Creating a task Issue, or editing its title/description
Ever seen a ticket with zero context on why it exists?
Refuses to open or edit a task Issue until it carries the full reasoning behind the task.
Guards: create a task issue
Merging
Ever had a broken build get merged anyway?
Holds the merge on the forge side while anything the gates check is still failing.
Starting the Planner's…
Ever started work only to find out halfway it was blocked on something else?
Refuses to start work until every precondition for the task is checked live and found clear. Optionally (task 10, `PREMISE_FILE=<brief.md> vinaya check dispatch-readiness`), also re-asserts a local brief's `Premise:` pins against current on-disk state and fails on any pin that no longer holds.
Opening a task PR whose surface includes real code
Ever had a PR's description quietly stop matching what the code does?
Refuses a code-carrying pull request whose description no longer matches what it changes.
Opening a task PR (final self-check before creation)
Ever opened a PR and only then discovered the tests were failing?
Runs the whole exit check before a pull request is created, so failures surface first.
Spawning a check (vinaya check, ring-0 pre-push AND ring-1 CI)
Ever had a check quietly read a secret it had no business seeing, because nothing scoped what it could reach?
Governs which environment variables a spawned check's child process can see, instead of every check inheriting the full parent environment unconditionally.
vinaya check / vinaya check --plan (a CLI mechanism, not a git hook — this row names no hook path)
Ever had a config entry silently double-run alongside the core check it was meant to replace, with no way to see that from the outside?
Resolves core-registered and config-registered checks into one deterministic table before anything runs, instead of letting a config entry run alongside the core check it collides with, unannounced.
Pushing a task branch that matches no planned task
Ever pushed a task branch that belonged to no plan?
Refuses to push a task branch whose name matches no task row derived from the forge.
Pushing to a branch whose pull request already resolved
Ever pushed more commits to an already-merged branch?
Refuses a push to a task branch whose most recent pull request is already merged or closed.
Guards: open a pull request, revise a pull request, grant a waiver
A task branch's first push (dispatch re-check)
Ever found out mid-push that your task was never dispatchable?
Re-runs the dispatch-readiness gate once, on a task branch's first push, before its pull request exists.
A task branch's first push (Issue self-assignment)
Ever had no idea who was actually working a task?
Assigns the task's Issue to the authenticated pusher on the branch's genuinely first push — visibility automation, deliberately not a gate.
Committing or pushing while checked out on the default branch
Ever committed straight onto main because you forgot to cut a worktree first?
Refuses a commit or push whose current branch IS the repo's default branch — mechanizing the worktree-plus-PR rule at ring 0 for every adopter, not just this repository's own hand-written pre-push script (the `git push` row above, `repo-own`, predates this check and covers a different class: a push whose destination *ref* is the default branch, not a local checkout parked on it). Registered in `coreCheckRegistry()` (task 9), so `vinaya init` ships it to every adopter through the generated `check --all --local` hooks — closing the gap where this rule previously reached only this repo's own maintainers.
Committing when the token-metering adapter is wired but unreachable
Ever had a host that could genuinely meter itself silently report `—` because one specific path broke?
Refuses a commit when the token-metering probe finds a wiring point resolved — a transcript pointer naming a path — but cannot reach what it names. A host never wired to meter at all still passes unchanged.
Committing a check bin that nobody can execute
Ever had a script fail with a permission error on somebody else's machine, never your own?
Refuses a staged executable whose index mode is not `100755`, on the machine that staged it.