[PRE-11] feat: publish organization default community health files - #1
Merged
Merged
Conversation
PRE-11 / SO-4944. Defaults used by every aziontech repository that has no own version: SECURITY.md (disclosure via security@azion.com), CONTRIBUTING.md, issue forms (blank issues disabled, security contact link) and the pull request template. Adds CODEOWNERS, MIT LICENSE, Dependabot for actions and the OSSF Scorecard gate required for public repositories.
renan-dias-azion
approved these changes
Sep 30, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Creates the organization defaults (PRE-11 / SO-4944). GitHub applies these files to every
aziontechrepository that does not have its own version.SECURITY.mdCONTRIBUTING.md.github/ISSUE_TEMPLATE/.github/pull_request_template.mdCODEOWNERSLICENSE.github/dependabot.yml.github/workflows/ossf-scorecard.ymlOSSF Scorecardoflifecycle-public(MODE=warn)Public by GitHub requirement: "A repository for default files cannot be private". Nothing internal goes here. The secrets policy, break-glass and the reference CODEOWNERS will live in a private repository (to be decided).
Org settings changed alongside
lifecycle-public:.githubadded to the repository list (2 approvals, CODEOWNERS,OSSF Scorecard).Engineering compliance inject … catch-all:.githubexcluded (its private actions cannot run on public repos, the required checks would never report).Pending (org owner)
The enforced security configuration Secret Scanning - Public Repositories keeps Dependabot security updates on (the public playbook asks for off), and private vulnerability reporting and CodeQL default setup off. It applies to all public repositories, so it was not changed here.
Type of change
feat:new featureBump
#minorRelated issues
PRE-11 · SO-4944