Repository navigation
[repo] chore: Dependabot, security policy, templates, weekly CI - #34
Merged
Merged
Conversation
… weekly CI - SECURITY.md routes reports to GitHub private vulnerability reporting - issue forms (bug, feature) + PR template with a scrub checklist - weekly scheduled CI run + manual dispatch so the badge reflects drift - dependabot: ignore dotenv semver-major; 18.x breaks the stdout-transport guard in tests/env-loading.test.ts (cause of the red PR #30) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Reviews every same-repo PR; answers @claude from the repo owner only, so a public commenter cannot spend the token. Exits green when the CLAUDE_CODE_OAUTH_TOKEN secret is absent, and skips fork/Dependabot PRs, which receive no secrets. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Repository polish, config and docs only.
.github/dependabot.yml: weekly grouped version updates (Actions + this repo's ecosystem)SECURITY.md: private vulnerability reporting via the Security tabworkflow_dispatchso the status badge reflects dependency driftChecks: YAML parses, actionlint clean (pre-existing info-level only), gitleaks clean.
🤖 Generated with Claude Code
Also: ignores
dotenvsemver-major. dotenv 18 breakstests/env-loading.test.ts(the stdout-transport guard), which is why #30 is red. After merging, comment@dependabot recreateon #30.