Skip to content

chore: establish GitHub governance and security routing - #70

Draft
zenithruneblade wants to merge 4 commits into
devfrom
codex/github-governance-foundation
Draft

zenithruneblade wants to merge 4 commits into
devfrom
codex/github-governance-foundation

Conversation

@zenithruneblade

Copy link
Copy Markdown
Contributor

Summary

  • publish a pre-release security reporting policy;
  • route default review ownership to @hexanomicon/core;
  • route questions to Discussions and security reports away from public issues;
  • add bounded weekly Dependabot groups for Python, web, and GitHub Actions.

Operator actions before merge

  • Confirm [email protected] exists, routes to the founder plus one trusted backup, and both accounts use MFA.
  • Enable GitHub Private vulnerability reporting for this repository.
  • Confirm GitHub Discussions is enabled; otherwise remove or replace the Discussions contact link.

Deliberate non-changes

This PR does not enable mandatory review gates or change branch permissions. Those repository settings are rolled out separately so the founder's current exact-SHA dev → main promotion path is not broken.

Verification

  • YAML files are declarative GitHub configuration only.
  • No source, generated frontend artifact, lockfile, or existing local worktree change is included.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant