●───●
\ m e c h u b
●───●───● deterministic decides · the model explains · a human approves
Default community health files for mechubsec.
GitHub applies the files here to any public repository under this organization that
does not provide its own:
SECURITY.md— how to report a vulnerability (GitHub Private Vulnerability Reporting)CONTRIBUTING.md— contribution guidelinesCODE_OF_CONDUCT.md— expected conduct
A repository can override any of these by committing its own copy.
Some configuration files must live in each repository and cannot be inherited:
dependabot/— Dependabot version update configuration template. Copydependabot/dependabot.ymlto your repo's.github/dependabot.yml.
See each template directory's README for usage instructions.
-
.github/workflows/gitleaks.yml— secret scan with the pinned gitleaks binary (no license needed). Call it from any mechubsec repo, pinned to a commit SHA:jobs: secrets: uses: mechubsec/.github/.github/workflows/gitleaks.yml@<commit sha>
It scans the PR (base..head) or push (before..after) range, as gitleaks-action did; manual/scheduled runs scan full history. It picks up the caller's
.gitleaks.tomlif present. Bump the gitleaks version here, once, then update callers' pinned SHA.