Skip to content

[repo] chore: Dependabot, security policy, templates, weekly CI - #34

Merged
effecet merged 2 commits into
mainfrom
chore/github-polish
Oct 2, 2026
Merged

effecet merged 2 commits into
mainfrom
chore/github-polish

Conversation

@effecet

@effecet effecet commented Oct 2, 2026

Copy link
Copy Markdown
Owner

Repository polish, config and docs only.

  • .github/dependabot.yml: weekly grouped version updates (Actions + this repo's ecosystem)
  • SECURITY.md: private vulnerability reporting via the Security tab
  • Issue forms (bug / feature) and a PR template
  • Weekly scheduled CI + workflow_dispatch so the status badge reflects dependency drift

Checks: YAML parses, actionlint clean (pre-existing info-level only), gitleaks clean.

🤖 Generated with Claude Code

Also: ignores dotenv semver-major. dotenv 18 breaks tests/env-loading.test.ts (the stdout-transport guard), which is why #30 is red. After merging, comment @dependabot recreate on #30.

effecet and others added 2 commits October 1, 2026 23:25
… weekly CI

- SECURITY.md routes reports to GitHub private vulnerability reporting
- issue forms (bug, feature) + PR template with a scrub checklist
- weekly scheduled CI run + manual dispatch so the badge reflects drift
- dependabot: ignore dotenv semver-major; 18.x breaks the stdout-transport
  guard in tests/env-loading.test.ts (cause of the red PR #30)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Reviews every same-repo PR; answers @claude from the repo owner only, so a
public commenter cannot spend the token. Exits green when the
CLAUDE_CODE_OAUTH_TOKEN secret is absent, and skips fork/Dependabot PRs,
which receive no secrets.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@effecet
effecet merged commit 6263835 into main Oct 2, 2026
8 checks passed
@effecet
effecet deleted the chore/github-polish branch October 2, 2026 04:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant