Read-only org compliance checker on the shared substrate (no re-clone; scans existing mirrors). Checklist grounded in handbook/github-standards: kebab repo name, README, CI/CD, Dependabot config+alerts, tracked-.env secrets, branch protection, merge settings; handbook exceptions (docs-only, compliance-exempt) honored. Mode-600 reports, ALARM-only (clean=silent). Includes planted-drift canary (asserts 6). Review fixes folded in: branch-protection + dependabot are status-code-aware (only a real 404 is drift; transient API failure -> skip, no false alarm); secrets-committed fires only on secret-shaped values (not benign config). NOT scheduled (provisioning gated). |
||
|---|---|---|
| .. | ||
| applypatch-msg.sample | ||
| commit-msg.sample | ||
| fsmonitor-watchman.sample | ||
| post-update.sample | ||
| pre-applypatch.sample | ||
| pre-commit.sample | ||
| pre-merge-commit.sample | ||
| pre-push.sample | ||
| pre-rebase.sample | ||
| pre-receive.sample | ||
| prepare-commit-msg.sample | ||
| push-to-checkout.sample | ||
| sendemail-validate.sample | ||
| update.sample | ||