ci: sync with netresearch/.github templates/skill - #149
Conversation
Auto-generated by scripts/sync-template.sh. Any changes you want to keep must be declared in .github/template.yaml's intentional-drift: list — the check-template-drift.yml job will otherwise revert them on next sync. Signed-off-by: Sebastian Mendel <info@sebastianmendel.de> Assisted-by: claude-code:claude-opus-5 Agent-Session: https://claude.ai/code/session_013GWpRpyiM13Rh1NMQMBJo5 Agent-Host: 0493f0
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (2)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe auto-merge workflow now passes project App credentials as explicit reusable-workflow inputs and limits secret propagation. The security workflow renames the scanning job to Priority: ⬇️ Low Change: Other Merge Risk: ⚪ Minimal · up to The workflow updates preserve existing trust and permission boundaries, and no current merge-blocking defect is established. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
✨ Simplify code
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Dependency ReviewThe following issues were found:
License Issues.github/workflows/security.yml
OpenSSF Scorecard
Scanned Files
|
|
Self-review: 4da970d The bot review this pull request demands is unsatisfiable (Copilot quota wall or repeated bot failures on this head). The diff on this head was reviewed by the PR author; this comment is the on-the-record attestation the merge gate reads back. It stops matching on the next push. |
|
Checked after the merge (this pull request was merged at 20:31 UTC by the session that opened it; this comment came later and reviews nothing before that merge):
Assisted by claude-code:claude-opus-5-5 — Session |



Merging this brings the repository in line with two template changes in
netresearch/.github, and nothing else.betterleaks / Secret Scanninginstead ofgitleaks / Secret Scanning, and the reusable is called asbetterleaks.yml.GITHUB_TOKEN, as today, with a warning.Where branch protection requires
gitleaks / Secret Scanning, the requirement is swapped tobetterleaks / Secret Scanningwhen this pull request is merged.The file list was checked mechanically against the two changes before this description was written; any other file would have stopped the rollout for this repository.
Assisted by claude-code:claude-opus-5 — Session