This public repository holds the files that GitHub can apply across the
seankoji-com organization.
Repositories use these defaults when they do not define their own version:
CODE_OF_CONDUCT.mdCONTRIBUTING.mdSECURITY.mdSUPPORT.md.github/ISSUE_TEMPLATE/.github/PULL_REQUEST_TEMPLATE.md
A repository should keep a local override only when its project needs different instructions or fields. GitHub does not copy inherited files into a repository, its clones, or release archives.
The workflows under .github/workflows/ provide shared implementations for CI,
static analysis, pull-request gating, dependency automation, link checking, and
release markers. GitHub Actions workflows are not inherited automatically.
Each repository still needs a small local caller for every shared workflow it
wants to run.
Available reusable workflows include:
-
reusable-node-ci.yml -
reusable-shellspec.yml -
reusable-docker-build-push.yml -
reusable-static-analysis.yml -
reusable-agent-readiness.yml -
reusable-pr-gatekeeper.yml -
reusable-dependabot-automerge.yml -
reusable-issue-triage.yml -
reusable-link-check.yml -
reusable-review-event.yml -
reusable-persona-recovery-request.yml -
released.yml -
Node CI accepts
pnpm,npm, oryarn. An existing.nvmrctakes precedence over thenode-versioninput. -
Docker builds require
image-name. Cache scope defaults to that image name; usecache-scopefor multiple variants. Scope must be nonempty and contain only letters, digits, dot, underscore, slash, colon,@or hyphen. -
ShellSpec uses a pinned version on a GitHub-hosted runner with zsh available. The caller's
.shellspecselects the shell, for example--shell /bin/zsh. The workflow needscontents: read. -
Issue triage and release markers use
actions/github-script. Callers selecting self-hosted runners must use Actions runner v2.327.1 or newer. Issue triage needsissues: write(andpull-requests: readfor the PR-sync job).
For example, a deployment workflow can publish the standard release marker:
jobs:
mark-released:
permissions:
deployments: write
uses: seankoji-com/.github/.github/workflows/released.yml@mainUse the local gatekeeper caller
as the trigger and permissions reference. Its head_sha input identifies the
commit to evaluate; retain the PR seed, workflow completion and review-event
triggers when adapting it.
The gate also waits for the latest Actions runs on the evaluated commit, including queued workflows that have not created job checks yet. It cannot detect a test workflow that was never triggered; keep required test callers and their trigger coverage under repository review.
When the Actions variable PERSONA_REVIEW_REQUIRED is true, the gate also
requires an approval from Grumpy Engineer on the current PR head. Missing,
stale, dismissed, and unreadable reviews block merging. Requested changes
remain blocking. Review execution is managed by the private control plane;
this public workflow reads only reviews in its calling repository. Submitted,
edited, and dismissed reviews trigger a read-only signal, followed by a gate
evaluation from the default branch. The private reconciler recovers missed events.
This repository is intentionally public. It must not contain credentials, secret-manager item identifiers, private service addresses, private hostnames, personal data, or incident logs. Store private operator records in the private control-plane archive instead.
Report vulnerabilities using the instructions in SECURITY.md.
With Python 3, Node.js and Bash installed and the test dependency set up
(python3 -m pip install -r requirements-test.txt), run from the repository
root:
python3 -m unittest discover -s tests -p 'test_*.py'Pinned tool versions are refreshed automatically; see docs/tool-pins.md.