mirror of
https://github.com/Sea-Haven-Industries/engineering-handbook.git
synced 2026-09-30 05:43:15 +00:00
Document repository security and merge-setting baseline (#15)
Codify the org security + merge baseline: auto-merge and auto-delete head branch (no org default, set per-repo), and the secret-scanning / CodeQL / code-security surface carried by the 'Sea Haven Standard' org Code Security Configuration. Note docs-repo CodeQL exception and the shoc-backend/shoc-frontend-new exclusion.
This commit is contained in:
parent
132e4fe51d
commit
dc736da711
1 changed files with 21 additions and 0 deletions
|
|
@ -9,6 +9,27 @@
|
|||
- Dependabot alerts and security updates enabled on all active repos
|
||||
- Org-level defaults auto-enable alerts and security updates on new repos
|
||||
- Every repo with dependencies gets a `.github/dependabot.yml` for weekly version updates
|
||||
- Merge settings: enable **auto-merge** and **auto-delete head branch on merge** (`allow_auto_merge` + `delete_branch_on_merge`). These have no org-level default — set them per-repo at provisioning.
|
||||
|
||||
## Security & Merge Baseline
|
||||
|
||||
Every active repo runs the same baseline. The security half is meant to be carried by the org **Code Security Configuration "Sea Haven Standard"** (`enforced`, `default_for_new_repos: all`); attach it to the repo at creation so new repos inherit it instead of drifting. The merge half (`allow_auto_merge`, `delete_branch_on_merge`) is **not** covered by any org config and must be set per-repo.
|
||||
|
||||
| Setting | Baseline | Mechanism |
|
||||
|---|---|---|
|
||||
| `allow_auto_merge` | enabled | per-repo (`gh api repos/<org>/<repo> -X PATCH -F allow_auto_merge=true`) |
|
||||
| `delete_branch_on_merge` | enabled | per-repo (`-F delete_branch_on_merge=true`) |
|
||||
| `code_security` (advanced security) | enabled | Sea Haven Standard config |
|
||||
| Secret scanning + push protection | enabled | Sea Haven Standard config |
|
||||
| Secret scanning non-provider patterns + validity checks | enabled | per-repo until added to the config |
|
||||
| Dependabot alerts + security updates | enabled | org auto-enable default + config |
|
||||
| CodeQL default setup | configured | per-repo (`PATCH .../code-scanning/default-setup state=configured`) until added to the config |
|
||||
|
||||
Exceptions:
|
||||
- **Docs-only repos** (e.g. `engineering-handbook`) skip CodeQL — there is no compiled code to scan; `code_security` may stay off. Secret scanning still applies.
|
||||
- **`shoc-backend` / `shoc-frontend-new`** are excluded from org compliance tooling (see the `.github` org-config notes); leave their settings to the SHOC team.
|
||||
|
||||
To audit drift: `gh api repos/<org>/<repo> --jq '{allow_auto_merge, delete_branch_on_merge, security_and_analysis}'` and `gh api repos/<org>/<repo>/code-scanning/default-setup --jq .state`.
|
||||
|
||||
## Dependabot Configuration
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue