From ecab1d06ced5cb14f431460acda618d53852774c Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Thu, 18 Jun 2026 12:23:44 -0400 Subject: [PATCH] Document repository security and merge-setting baseline Codify the org security + merge baseline: auto-merge and auto-delete head branch (no org default, set per-repo), and the secret-scanning / CodeQL / code-security surface carried by the 'Sea Haven Standard' org Code Security Configuration. Note docs-repo CodeQL exception and the shoc-backend/shoc-frontend-new exclusion. --- github-standards.md | 21 +++++++++++++++++++++ 1 file changed, 21 insertions(+) diff --git a/github-standards.md b/github-standards.md index e96c774..4dcb0c7 100644 --- a/github-standards.md +++ b/github-standards.md @@ -9,6 +9,27 @@ - Dependabot alerts and security updates enabled on all active repos - Org-level defaults auto-enable alerts and security updates on new repos - Every repo with dependencies gets a `.github/dependabot.yml` for weekly version updates +- Merge settings: enable **auto-merge** and **auto-delete head branch on merge** (`allow_auto_merge` + `delete_branch_on_merge`). These have no org-level default — set them per-repo at provisioning. + +## Security & Merge Baseline + +Every active repo runs the same baseline. The security half is meant to be carried by the org **Code Security Configuration "Sea Haven Standard"** (`enforced`, `default_for_new_repos: all`); attach it to the repo at creation so new repos inherit it instead of drifting. The merge half (`allow_auto_merge`, `delete_branch_on_merge`) is **not** covered by any org config and must be set per-repo. + +| Setting | Baseline | Mechanism | +|---|---|---| +| `allow_auto_merge` | enabled | per-repo (`gh api repos// -X PATCH -F allow_auto_merge=true`) | +| `delete_branch_on_merge` | enabled | per-repo (`-F delete_branch_on_merge=true`) | +| `code_security` (advanced security) | enabled | Sea Haven Standard config | +| Secret scanning + push protection | enabled | Sea Haven Standard config | +| Secret scanning non-provider patterns + validity checks | enabled | per-repo until added to the config | +| Dependabot alerts + security updates | enabled | org auto-enable default + config | +| CodeQL default setup | configured | per-repo (`PATCH .../code-scanning/default-setup state=configured`) until added to the config | + +Exceptions: +- **Docs-only repos** (e.g. `engineering-handbook`) skip CodeQL — there is no compiled code to scan; `code_security` may stay off. Secret scanning still applies. +- **`shoc-backend` / `shoc-frontend-new`** are excluded from org compliance tooling (see the `.github` org-config notes); leave their settings to the SHOC team. + +To audit drift: `gh api repos// --jq '{allow_auto_merge, delete_branch_on_merge, security_and_analysis}'` and `gh api repos///code-scanning/default-setup --jq .state`. ## Dependabot Configuration