From b32c84de9d86fd7f0d727a992f8cf28471f63025 Mon Sep 17 00:00:00 2001 From: adebert Date: Fri, 8 May 2026 02:50:05 -0300 Subject: [PATCH 1/2] chore: onboard to canonical github policy files Drops in the stack-agnostic subset of arthur-debert/release's policy templates: CODEOWNERS, .github/dependabot.yml (github-actions freshness only, per portfolio policy), .github/workflows/copilot-review.yml (auto-request Copilot on PRs). Companion to: - main-branch-protection ruleset (just applied via apply-ruleset) - Dependabot security alerts + automated fixes (just enabled via API) Co-Authored-By: Claude Opus 4.7 (1M context) --- .github/CODEOWNERS | 1 + .github/dependabot.yml | 17 +++++++++++++++++ .github/workflows/copilot-review.yml | 15 +++++++++++++++ 3 files changed, 33 insertions(+) create mode 100644 .github/CODEOWNERS create mode 100644 .github/dependabot.yml create mode 100644 .github/workflows/copilot-review.yml diff --git a/.github/CODEOWNERS b/.github/CODEOWNERS new file mode 100644 index 0000000..9260520 --- /dev/null +++ b/.github/CODEOWNERS @@ -0,0 +1 @@ +* @arthur-debert diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..2983fef --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,17 @@ +# Dependabot config — see arthur-debert/release/README.md "Dependabot policy" +# +# Application-dependency freshness (cargo) is deliberately not enabled. +# Major-version sweeps are evaluated as development work, not pushed by a bot. +# Security exposure for cargo deps is covered by Dependabot security updates, +# which are enabled per-repo via the GitHub API (not this file). +# +# Only github-actions freshness is enabled — old action versions silently +# break when GitHub deprecates a runtime, so a low-volume freshness stream +# here is worth the cost. +version: 2 +updates: + - package-ecosystem: github-actions + directory: / + schedule: + interval: weekly + open-pull-requests-limit: 5 diff --git a/.github/workflows/copilot-review.yml b/.github/workflows/copilot-review.yml new file mode 100644 index 0000000..c04aeb1 --- /dev/null +++ b/.github/workflows/copilot-review.yml @@ -0,0 +1,15 @@ +name: Copilot Review + +on: + pull_request: + types: [opened, ready_for_review] + +jobs: + request: + if: github.event.pull_request.draft == false && github.event.pull_request.head.repo.fork == false + permissions: + contents: read + pull-requests: write + uses: arthur-debert/gh-dagentic/.github/workflows/copilot-review.yml@main + with: + pr_number: ${{ github.event.pull_request.number }} From 56f661d3146dcbb82bb4132d8868a5748dab1a89 Mon Sep 17 00:00:00 2001 From: adebert Date: Fri, 8 May 2026 06:18:53 -0300 Subject: [PATCH 2/2] fix(cmd): set Args=ArbitraryArgs on rootCmd MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Without this, Cobra interprets positional args that don't match a known subcommand as "unknown command" errors. Adding completion and man subcommands (in 9c61b74) silently broke TestRootCmd_FileNotFound — the test expected the file argument to flow into RunE, but it was being rejected as an unknown command first. RunE already validates len(args) == 2, so ArbitraryArgs is the right level. Co-Authored-By: Claude Opus 4.7 (1M context) --- cmd/app/main.go | 1 + 1 file changed, 1 insertion(+) diff --git a/cmd/app/main.go b/cmd/app/main.go index 9352f4f..95752cc 100644 --- a/cmd/app/main.go +++ b/cmd/app/main.go @@ -25,6 +25,7 @@ var rootCmd = &cobra.Command{ Short: "Get a value from a structured data file using a dotted path", Long: `dotcat allows you to read a value from a structured data file (JSON, YAML, TOML, or INI) using a dot-separated path to the desired key.`, + Args: cobra.ArbitraryArgs, RunE: func(cmd *cobra.Command, args []string) error { // If version flag is provided, print version and exit if showVersion {