Organization-wide community-health defaults for the
melodic-software GitHub organization.
GitHub falls back to these files for any repository without its own, so every repository inherits one contribution and disclosure workflow.
They are the file-based governance defaults GitHub's API cannot express.
Everything the Pulumi GitHub provider can express (repository settings, custom
properties, rulesets, and labels) is infrastructure-as-code in the private
github-iac repository. That name is deliberately not a link: it 404s for
readers outside the organization, and lychee.toml excludes it from the online
link lane for the same reason.
- Policies:
CODE_OF_CONDUCT.md,CONTRIBUTING.md,GOVERNANCE.md,SECURITY.md, andSUPPORT.md. A repository that ships its own copy overrides the default; everything else inherits these. - Templates:
.github/ISSUE_TEMPLATE/(bug report, feature request, task, and the chooser config that disables blank issues) and.github/PULL_REQUEST_TEMPLATE.md. - Profile:
profile/README.mdrenders as the organization's public profile page. Other repositories do not inherit it. - This repository's own CI:
.github/workflows/and.github/scripts/.ci.ymlruns the SHA-pinned lint and hygiene lanes fromci-workflowsand aggregates them into the singleci-statuscheck the org ruleset requires. The pull-request contract itself (Conventional Commits title,do-not-mergelabel, issue linkage) is thepr-contractstep inside theci-statusjob, so there are no separate caller workflows for it. Thepr-section-driftlane is a local script (.github/scripts/pr-section-drift.mjsand its tests) that compares.github/PULL_REQUEST_TEMPLATE.mdand.claude/source-control.mdagainst thepr-contractcomposite at the SHA.github/workflows/ci.ymlpins..github/dependabot.ymlkeepsactions/checkoutcurrent; theci-workflowspins move by hand (see itsignoreblock).- Give every action pin a
# vX.Y.Ztag comment. Standards' pin-comment convention also permits a short-sha-and-date fallback, but Dependabot reads the current version out of that comment, so the fallback form leaves an action silently un-updated.
- Give every action pin a
- Quality configs: the root dotfiles the CI lanes run against.
.editorconfig,.gitattributes,.markdownlint-cli2.jsonc,_typos.toml,.gitleaks.toml,lychee.toml, and.editorconfig-checker.jsonare synced fromstandards;.gitignoreis owned by this repository. Change a lint or hygiene rule instandardsand let the sync land it here. An edit made directly to one of these files survives only until the next sync commit overwrites it..shellcheckrcis the exception: a byte-identical copy of the canonical file, but this repository is not on theshellcheckcomponent's managed list, so nothing syncs or overwrites it. It drifts silently until the component is adopted upstream. - Agent config:
.claude/settings.jsondeclares themelodic-softwareplugin marketplace and the SessionStart hook that runs.claude/cloud-bootstrap.sh, itself synced fromstandardsand extended per-repo by an optional.claude/cloud-bootstrap.local.sh. It also denies Read on secret files (.env*,secrets/, keys)..claude/source-control.mdis the tracked team layer of the source-control convention (commit and PR-title pattern, required PR-body sections, merge lane);.work-item-tracker.jsonbinds the work-items tracker provider..claude/source-control.mdand.work-item-tracker.jsoneach resolve an optional gitignored*.local.*overlay for per-operator deviations..claude/rules/pr-body-contract.md, synced fromstandards, states the pull-request body contract;.claude/ai-slop.jsonconfigures the AI-writing audit for this repository.CLAUDE.mdis the agent-loaded entry point: it routes to this file rather than restating it, and carries only what no other file states. - Cloud Agent environment:
.cursor/environment.jsonis the repo-managed Cursor Cloud Agent config and the highest-precedence environment source. Itsinstallruns.cursor/install.sh, which installs the same lint/hygiene tools.github/workflows/ci.ymlruns, each pinned to the version the SHA-pinnedci-workflowsaction uses, so.cursor/check.shreproduces the gating CI lanes and theirci-statusaggregate locally, plus the advisorypr-section-drift.
The inventory above covers every tracked file, and no check enforces that. When a file is added or removed, update this section in the same change.
Editing a policy here changes it for every repository that has not overridden it, so treat these files as org-wide.