mirror of
https://github.com/Sea-Haven-Industries/engineering-handbook.git
synced 2026-09-30 10:23:13 +00:00
Documents the org-wide policy for dependabot.yml files: ecosystem selection, standard templates for single/multi-ecosystem repos and SAM projects, auto-assignment, and merge guidance.
3 KiB
3 KiB
GitHub Standards
Repository Defaults
- Default branch:
main - Every repo gets a one-line description
- Default to
privatevisibility for org repos - Dependabot alerts and security updates enabled on all active repos
- Org-level defaults auto-enable alerts and security updates on new repos
- Every repo with dependencies gets a
.github/dependabot.ymlfor weekly version updates
Dependabot Configuration
Every active repo with package dependencies must have a .github/dependabot.yml that covers all relevant ecosystems. All entries must assign PRs to amoussa1229.
Ecosystem Selection
Choose ecosystems based on what dependency files exist in the repo:
| File | Ecosystem |
|---|---|
package.json |
npm |
requirements.txt |
pip |
.csproj |
nuget |
.github/workflows/*.yml |
github-actions |
Standard Templates
Single ecosystem (npm or pip):
version: 2
updates:
- package-ecosystem: "npm" # or "pip", "nuget", "github-actions"
directory: "/"
schedule:
interval: "weekly"
assignees:
- "amoussa1229"
SAM project with per-function requirements.txt:
Add a separate entry for each directory containing a requirements.txt:
version: 2
updates:
- package-ecosystem: "pip"
directory: "/src/processor"
schedule:
interval: "weekly"
assignees:
- "amoussa1229"
- package-ecosystem: "pip"
directory: "/src/receiver"
schedule:
interval: "weekly"
assignees:
- "amoussa1229"
Mixed ecosystems (e.g., CDK in JS with Python Lambdas, or repos with GitHub Actions):
Add one entry per ecosystem/directory:
version: 2
updates:
- package-ecosystem: "npm"
directory: "/"
schedule:
interval: "weekly"
assignees:
- "amoussa1229"
- package-ecosystem: "pip"
directory: "/src"
schedule:
interval: "weekly"
assignees:
- "amoussa1229"
- package-ecosystem: "github-actions"
directory: "/"
schedule:
interval: "weekly"
assignees:
- "amoussa1229"
Merging Dependabot PRs
- Patch and minor bumps: Safe to merge without review in most cases
- Major version bumps: Review changelog for breaking changes before merging
- When merging multiple Dependabot PRs, merge one at a time — subsequent PRs will auto-rebase
Branch Protection
- Require a PR for merges to
main(no direct push) - No force push to
main - No branch deletion for
main
Repo Hygiene
- Delete feature branches after merge
- Archive repos that are no longer actively developed (close issues first)
- Don't delete repos unless truly disposable
- Scrub all company-specific info from git history before making any repo public
Public Repos
Before making a repo public, verify the entire git history contains no:
- Phone numbers or customer data
- API subdomains or internal URLs
- Webhook endpoints
- Employee names or internal identifiers
If sensitive data was committed at any point, start fresh with a clean git init rather than rewriting history.