engineering-handbook/github-standards.md
Adam Moussa e00055b8e2 Drop Dependabot PR assignee from GitHub standards
Pinning every Dependabot PR to a single assignee created noise and a
bottleneck. Remove the assignee requirement and the per-ecosystem
assignees blocks from the example configs.
2026-06-02 19:36:09 -04:00

2.8 KiB

GitHub Standards

Repository Defaults

  • Default branch: main
  • Every repo gets a one-line description
  • Default to private visibility for org repos
  • Dependabot alerts and security updates enabled on all active repos
  • Org-level defaults auto-enable alerts and security updates on new repos
  • Every repo with dependencies gets a .github/dependabot.yml for weekly version updates

Dependabot Configuration

Every active repo with package dependencies must have a .github/dependabot.yml that covers all relevant ecosystems.

Ecosystem Selection

Choose ecosystems based on what dependency files exist in the repo:

File Ecosystem
package.json npm
requirements.txt pip
.csproj nuget
.github/workflows/*.yml github-actions

Standard Templates

Single ecosystem (npm or pip):

version: 2
updates:
  - package-ecosystem: "npm"  # or "pip", "nuget", "github-actions"
    directory: "/"
    schedule:
      interval: "weekly"

SAM project with per-function requirements.txt:

Add a separate entry for each directory containing a requirements.txt:

version: 2
updates:
  - package-ecosystem: "pip"
    directory: "/src/processor"
    schedule:
      interval: "weekly"
  - package-ecosystem: "pip"
    directory: "/src/receiver"
    schedule:
      interval: "weekly"

Mixed ecosystems (e.g., CDK in JS with Python Lambdas, or repos with GitHub Actions):

Add one entry per ecosystem/directory:

version: 2
updates:
  - package-ecosystem: "npm"
    directory: "/"
    schedule:
      interval: "weekly"
  - package-ecosystem: "pip"
    directory: "/src"
    schedule:
      interval: "weekly"
  - package-ecosystem: "github-actions"
    directory: "/"
    schedule:
      interval: "weekly"

Merging Dependabot PRs

  • Patch and minor bumps: Safe to merge without review in most cases
  • Major version bumps: Review changelog for breaking changes before merging
  • When merging multiple Dependabot PRs, merge one at a time — subsequent PRs will auto-rebase

Branch Protection

  • Require a PR for merges to main (no direct push)
  • No force push to main
  • No branch deletion for main

Repo Hygiene

  • Delete feature branches after merge
  • Archive repos that are no longer actively developed (close issues first)
  • Don't delete repos unless truly disposable
  • Scrub all company-specific info from git history before making any repo public

Public Repos

Before making a repo public, verify the entire git history contains no:

  • Phone numbers or customer data
  • API subdomains or internal URLs
  • Webhook endpoints
  • Employee names or internal identifiers

If sensitive data was committed at any point, start fresh with a clean git init rather than rewriting history.