Account-wide defaults and shared building blocks for the repositories owned by husterk.
| Path | What it is | How a repository uses it |
|---|---|---|
SECURITY.md, CONTRIBUTING.md, .github/ISSUE_TEMPLATE/, .github/pull_request_template.md |
Default community health files | GitHub shows them in every husterk repository, public or private, that has no copy of its own |
renovate/default.json |
Base Renovate config | "extends": ["github>husterk/.github//renovate/default#vX.Y.Z"] |
renovate/mise.json |
Groups for mise tools, and the 1Password CLI lookup | "extends": ["github>husterk/.github//renovate/mise#vX.Y.Z"] |
actions/linked-issue/ |
Fails a PR whose body does not close an open issue | uses: husterk/.github/actions/linked-issue@<sha> # vX.Y.Z in a job named Linked issue |
templates/ |
Ruleset JSON, renovate.json, pr-policy.yml, CLAUDE.md skeleton |
Copied into a repository when it is created or audited |
scripts/audit-repo.sh |
Read-only comparison of a repository with the baseline | mise run audit -- husterk/<repo> |
docs/ |
The guides for creating and auditing public and private repositories, and for sites hosted on Cloudflare | Read by people and agents |
Changes merge to main and ship as signed vMAJOR.MINOR.PATCH tags. Other
repositories pin a tag, so a new release reaches each of them as a Renovate
pull request that runs that repository's own CI. A major version marks a
breaking change, such as a renamed check or a removed preset option.
The default community health files are the exception: GitHub reads them from
main, so they change in every repository as soon as a pull request merges.
mise install
mise run check # formatting, shellcheck, actionlint, US spelling, Renovate config validation
mise run self-test # Renovate lookup against test/renovate-fixture with the presets in this treeEvery change starts from an issue and lands through a pull request. See CLAUDE.md.