Skip to content

GitHub standards: Dependabot, default-branch ruleset, private-patterns check - #2

Merged
danjonesio merged 1 commit into
mainfrom
github-standards
Sep 18, 2026
Merged

danjonesio merged 1 commit into
mainfrom
github-standards

Conversation

@danjonesio

Copy link
Copy Markdown
Owner

What

/d-github run against this repo on 2026-09-18, all three standards. Facts came from skills/d-github/scripts/facts.sh.

standard result
Dependabot .github/dependabot.yml: one github-actions entry, version lane, monthly, two groups. Merges deploy nothing (plugin repo, every deploy signal empty), and the new workflow pins actions/checkout by SHA, which never moves unwatched. No commit-message prefix (0 of last 30 commits conventional). No pre-commit entry: the only hook is repo: local.
Branch protection .github/rulesets/default-branch.json: deletion, non_fast_forward, pull_request (0 approvals because collaborators = 1, threads must resolve, no code-owner review because no CODEOWNERS), no bypass. No required_status_checks: no check had ever reported on main. No required_linear_history: merge commits are allowed.
Secret protection .github/scripts/private-patterns.sh, .github/workflows/private-patterns.yml (actions/checkout pinned to 3d3c42e = v7.0.1), .pre-commit-config.yaml.

Already applied to the repo settings (approved in-session, not part of this diff)

  • Dependabot alerts: on. Dependabot security updates: enabled. Both verified by reading them back.
  • Ruleset default-branch created from the JSON in this PR: id 23647785, active. gh api repos/danjonesio/deej-stack/rules/branches/main lists deletion, non_fast_forward, pull_request. This PR is the first change to go through it.
  • secret_scanning and secret_scanning_push_protection were already enabled.

Did not work

  • secret_scanning_non_provider_patterns: PATCH returned 200 twice (once alone) and the value stayed disabled. No 422, so nothing confirms the cause; likely not offered for a user-owned public repo on this plan. Check Settings → Code security.

Deferred

  • The private-pattern list. ~/.config/deej-stack/private-patterns does not exist, so there is no PRIVATE_PATTERNS secret and no tree-hit scan was possible. Until both exist, the private-patterns job passes with a notice and checks nothing. To finish: create the file (one extended regex per line), then gh secret set PRIVATE_PATTERNS -R danjonesio/deej-stack < ~/.config/deej-stack/private-patterns.

Check on this PR and after merge

  • This PR's merge box shows a private-patterns check (its first ever run). Once it has reported, add { "context": "private-patterns" } under a required_status_checks rule in the ruleset file and re-apply; left out here because a required check that has never reported blocks merging.
  • After merge: Insights → Dependency graph → Dependabot shows no "configuration error" badge; Settings → Rules lists default-branch.

Follow-ups, not done here

  • required_linear_history: your call, it changes how every PR merges.
  • AGENTS.md and README still describe the ~/.cursor/plugins/local symlink as the Cursor dev loop; Cursor's plugin docs now say a symlink pointing outside that folder is skipped.

…rivate-patterns CI + pre-commit hook

Written by /d-github on 2026-09-18 from skills/d-github/scripts/facts.sh.

dependabot.yml: one github-actions entry in the version lane. Merges deploy
nothing (plugin repo; every deploy signal empty) and the new workflow pins
actions/checkout by SHA, which never moves unwatched. No commit-message
prefix: 0 of the last 30 commits are conventional. No pre-commit entry: the
only hook is repo: local.

rulesets/default-branch.json: the record of ruleset 23647785, already
applied. deletion and non_fast_forward always; pull_request with 0
approvals (collaborators: 1, and an author cannot approve their own PR),
no code-owner review (no CODEOWNERS), threads must resolve, no bypass.
No required_status_checks: no check had ever reported on main.
No required_linear_history: merge commits are allowed.

private-patterns script, workflow and pre-commit hook: grep the tree for
private hostnames from a list that never enters the repo. No list exists
yet, so the job passes with a notice until
~/.config/deej-stack/private-patterns and the PRIVATE_PATTERNS secret do.
@danjonesio
danjonesio merged commit 8a56ec3 into main Sep 18, 2026
1 check passed
@danjonesio
danjonesio deleted the github-standards branch September 18, 2026 08:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant