Organization-wide default community health files for DragonSecurity.
GitHub falls back to the files here for any repository in the organization that does not ship its own copy. A repository's own file always wins.
| File | Applies to |
|---|---|
CONTRIBUTING.md |
Contribution process, and the DCO sign-off requirement |
CODE_OF_CONDUCT.md |
Contributor Covenant 2.1 |
SECURITY.md |
Vulnerability reporting and disclosure |
.github/PULL_REQUEST_TEMPLATE.md |
Default PR template |
Licensing is not a community health file — GitHub cannot apply one org-wide, so each repository carries its own copy.
| File | Purpose |
|---|---|
templates/LICENSE.apache2 |
Canonical Apache-2.0. Copy to LICENSE in new repositories |
scripts/license-audit.sh |
Checks every repo for that exact text |
.github/workflows/license-audit.yml |
Runs the audit weekly, opens an issue on drift |
The audit reads every repository in the organization, which the default
GITHUB_TOKEN cannot do — it is scoped to this repository alone and
cannot see the private ones. The workflow mints a token from the
org-wide CI GitHub App instead, using the CI_APP_ID variable and
CI_APP_PRIVATE_KEY secret. The app must be installed on all
repositories with Contents: read.
This repository is public because GitHub only applies default community
health files from a public .github repository. It contains no code and
nothing sensitive.
Contributions across the organization are certified under the
Developer Certificate of Origin
rather than a CLA. Commit with -s:
git commit -s -m "docs: fix a typo"A DCO status check enforces this on the default branch of every
repository. See CONTRIBUTING.md for automation and
for how to repair a branch you forgot to sign.