# GitHub Standards ## Repository Defaults - Default branch: `main` - Every repo gets a one-line description - Default to `private` visibility for org repos - Dependabot alerts and security updates enabled on all active repos ## Branch Protection - Require a PR for merges to `main` (no direct push) - No force push to `main` - No branch deletion for `main` ## Repo Hygiene - Delete feature branches after merge - Archive repos that are no longer actively developed (close issues first) - Don't delete repos unless truly disposable - Scrub all company-specific info from git history before making any repo public ## Public Repos Before making a repo public, verify the entire git history contains no: - Phone numbers or customer data - API subdomains or internal URLs - Webhook endpoints - Employee names or internal identifiers If sensitive data was committed at any point, start fresh with a clean `git init` rather than rewriting history.