Skip to content

chore: onboard to canonical github policy files - #13

Merged
arthur-debert merged 2 commits into
mainfrom
onboard-policy
May 8, 2026
Merged

arthur-debert merged 2 commits into
mainfrom
onboard-policy

Conversation

@arthur-debert

Copy link
Copy Markdown
Owner

Summary

Onboards this repo to arthur-debert/release's canonical policy.

Adds the stack-agnostic subset of policy templates:

  • .github/CODEOWNERS — single-owner mapping
  • .github/dependabot.yml — github-actions freshness only (portfolio policy: app-dep freshness disabled; security via API toggle)
  • .github/workflows/copilot-review.yml — auto-request Copilot review on PRs

Companion changes already applied on GitHub side:

  • main-branch-protection ruleset (PR required, linear history, no force-push, no delete)
  • Dependabot security alerts + automated security fixes enabled via API

After this lands, install-release-token and enable-dependabot-security will auto-discover this repo via the ruleset.

Test plan

  • CI green
  • Copilot review auto-requested on this PR (smoke-test the new workflow)

Drops in the stack-agnostic subset of arthur-debert/release's policy
templates: CODEOWNERS, .github/dependabot.yml (github-actions
freshness only, per portfolio policy), .github/workflows/copilot-review.yml
(auto-request Copilot on PRs).

Companion to:
- main-branch-protection ruleset (just applied via apply-ruleset)
- Dependabot security alerts + automated fixes (just enabled via API)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Onboards the repository to a canonical set of GitHub policy files (ownership, Dependabot configuration, and an automation workflow to request Copilot review on PR creation/ready-for-review).

Changes:

  • Added .github/CODEOWNERS to define a single default code owner.
  • Added .github/dependabot.yml enabling weekly GitHub Actions update PRs.
  • Added .github/workflows/copilot-review.yml to request a Copilot review on eligible PR events.

Reviewed changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated 1 comment.

File Description
.github/workflows/copilot-review.yml Adds an action workflow that delegates to a reusable workflow to auto-request Copilot review on PR open/ready-for-review.
.github/dependabot.yml Configures Dependabot to update GitHub Actions dependencies on a weekly cadence.
.github/CODEOWNERS Establishes default repo-wide ownership for review routing.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

permissions:
contents: read
pull-requests: write
uses: arthur-debert/gh-dagentic/.github/workflows/copilot-review.yml@main
Without this, Cobra interprets positional args that don't match a
known subcommand as "unknown command" errors. Adding completion
and man subcommands (in 9c61b74) silently broke
TestRootCmd_FileNotFound — the test expected the file argument to
flow into RunE, but it was being rejected as an unknown command
first. RunE already validates len(args) == 2, so ArbitraryArgs is
the right level.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@arthur-debert
arthur-debert merged commit bb8a382 into main May 8, 2026
2 checks passed
@arthur-debert
arthur-debert deleted the onboard-policy branch May 8, 2026 09:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants