This repository holds the organization-wide defaults for QuickCasa's public repositories on GitHub.
profile/README.mdis the page visitors see at github.com/QuickCasa.CODE_OF_CONDUCT.md,CONTRIBUTING.md,SECURITY.mdandSUPPORT.mdapply to any repository that doesn't have its own copy of that file..github/ISSUE_TEMPLATE/holds the default issue forms, and.github/pull_request_template.mdthe default pull request template. If a repository has any files in its own.github/ISSUE_TEMPLATEfolder, it uses only those.
Set each new public repository up the same way:
- Start from a fresh repository and copy the code in, so no internal history or configuration comes with it.
- Turn on private vulnerability reporting in the repository's security
settings.
SECURITY.mdsends reporters there, and the button only appears once it's on. - Turn off the wiki and projects, allow only squash and rebase merges, and turn on deleting branches after a merge.
- If GitHub Pages deploys from a release tag, add a
v*.*.*tag rule to thegithub-pagesenvironment. Without it, the deploy fails with an environment protection error. - If it publishes to npm under
@quickcasa, publish the first version by hand, because npm only lets a trusted publisher be added to a package that exists. Then, in the package's npm settings, add a GitHub Actions trusted publisher for the release workflow with onlynpm stage publishallowed. Releases are then staged by CI and go live once a maintainer approves them with 2FA. - Add the project to the list in
profile/README.md.