Skip to content

[PRE-11] feat: publish organization default community health files - #1

Merged
renan-dias-azion merged 1 commit into
mainfrom
feat/org-defaults
Sep 30, 2026
Merged

renan-dias-azion merged 1 commit into
mainfrom
feat/org-defaults

Conversation

@estefano-vechietti-azion

Copy link
Copy Markdown
Contributor

Description

Creates the organization defaults (PRE-11 / SO-4944). GitHub applies these files to every aziontech repository that does not have its own version.

File Purpose
SECURITY.md Disclosure via security@azion.com only (private vulnerability reporting is disabled by the org security configuration)
CONTRIBUTING.md Trunk-based flow, Conventional Commits titles (ticket prefix optional), SemVer bump
.github/ISSUE_TEMPLATE/ Bug report and feature request forms, blank issues off, security contact link
.github/pull_request_template.md Default PR description with bump and checklist
CODEOWNERS This repo only (CODEOWNERS is not inherited)
LICENSE MIT (Azion template for public repositories)
.github/dependabot.yml Version updates for actions (OSSF Dependency-Update-Tool)
.github/workflows/ossf-scorecard.yml Required check OSSF Scorecard of lifecycle-public (MODE=warn)

Public by GitHub requirement: "A repository for default files cannot be private". Nothing internal goes here. The secrets policy, break-glass and the reference CODEOWNERS will live in a private repository (to be decided).

Org settings changed alongside

  • Ruleset lifecycle-public: .github added to the repository list (2 approvals, CODEOWNERS, OSSF Scorecard).
  • Ruleset Engineering compliance inject … catch-all: .github excluded (its private actions cannot run on public repos, the required checks would never report).
  • Repo: secret scanning + push protection on, Dependabot alerts on, auto-merge off.

Pending (org owner)

The enforced security configuration Secret Scanning - Public Repositories keeps Dependabot security updates on (the public playbook asks for off), and private vulnerability reporting and CodeQL default setup off. It applies to all public repositories, so it was not changed here.

Type of change

  • feat: new feature

Bump

  • #minor

Related issues

PRE-11 · SO-4944

PRE-11 / SO-4944. Defaults used by every aziontech repository that has
no own version: SECURITY.md (disclosure via security@azion.com),
CONTRIBUTING.md, issue forms (blank issues disabled, security contact
link) and the pull request template. Adds CODEOWNERS, MIT LICENSE,
Dependabot for actions and the OSSF Scorecard gate required for public
repositories.
@estefano-vechietti-azion
estefano-vechietti-azion requested a review from a team September 29, 2026 20:31
renan-dias-azion added a commit that referenced this pull request Sep 30, 2026
…s and CODEOWNERS (#2)"

Revert da iniciativa que passou na frente do PR #1 (PRE-11, oficial, do dono do
card). O #1 e mais completo (dependabot, OSSF scorecard, LICENSE, formularios
YAML) e passa a ser a fonte unica dos defaults.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

@renan-dias-azion renan-dias-azion left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Aprovado. Revertido o #2 para o #1 ser a fonte unica dos defaults da org, conforme alinhado. Conteudo mais completo e oficial do PRE-11.

@renan-dias-azion
renan-dias-azion merged commit 89b12d5 into main Sep 30, 2026
1 check passed
@renan-dias-azion
renan-dias-azion deleted the feat/org-defaults branch September 30, 2026 14:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants