Add a standalone ci workflow so handbook changes get an automated gate.
The job is named literally "ci / ci" to emit the exact status context the
org main-branch-protection ruleset requires.
- markdownlint-cli2 (.markdownlint-cli2.jsonc): MD013/MD060/MD040 relaxed
as noisy docs-style rules; fixed 3 MD032 blank-line-around-list issues.
- lychee link check (lychee.toml): internal + external links, tolerates 429.
Codify the org security + merge baseline: auto-merge and auto-delete
head branch (no org default, set per-repo), and the secret-scanning /
CodeQL / code-security surface carried by the 'Sea Haven Standard' org
Code Security Configuration. Note docs-repo CodeQL exception and the
shoc-backend/shoc-frontend-new exclusion.
Capture the org conventions rolled out in the INFRA-47 hygiene pass:
- github-standards.md: static-only README badges (dynamic shields break on
private repos; CI badge is member-only) and a lowercase-hyphenated repo
topic vocabulary, both part of new-repo provisioning.
- cicd.md: the central inline-config reusable PR labeler — pull_request
trigger, the three required caller permissions, no per-repo labeler.yml.
Exact pins remain (reproducibility) but the pinned version is kept
current by Dependabot version updates gated by CI + dependency review,
not by a number frozen in the handbook. Blanket dependabot ignore
entries are banned; version-specific ignores only, commented and
temporary. Bundled-dep vulnerabilities are a prompt to advance the
pin, never to dismiss the alert.
Pinning every Dependabot PR to a single assignee created noise and a
bottleneck. Remove the assignee requirement and the per-ecosystem
assignees blocks from the example configs.
Documents the org-wide policy for dependabot.yml files: ecosystem
selection, standard templates for single/multi-ecosystem repos and
SAM projects, auto-assignment, and merge guidance.