Org-wide defaults live here, once β the public profile, shared CI, workflow templates, and community health files β and propagate to every repository automatically.
bymaxone/.github is GitHub's special organization repository. Files placed here
become defaults for every repo in the org that doesn't define its own β so we
maintain them in one place instead of copy-pasting across dozens of repositories.
It is public because organization-wide defaults require a public repo.
| Path | What it is | Shows up⦠|
|---|---|---|
π profile/README.md |
The organization profile | On the org overview page |
π .github/workflows/node-ci.yml |
Reusable CI β Node example apps β lint Β· typecheck Β· format Β· coverage Β· e2e Β· export-audit Β· mutation | Called by each nest-*-example repo's ci.yml |
π .github/workflows/node-lib-ci.yml |
Reusable CI β Node libraries β lint Β· typecheck Β· format Β· unit+coverage Β· build Β· mutation | Called by each @bymax-one/nest-* library's ci.yml |
π¦ .github/workflows/rust-ci.yml |
Reusable CI β Rust workspaces β fmt Β· clippy Β· build & test Β· llvm-cov Β· MSRV Β· cargo-mutants | Called by rust-auth / rust-auth-example |
π‘οΈ .github/workflows/security.yml |
Reusable dependency-review (GitHub-owned action only) | Called on public-repo pull requests |
ποΈ .github/workflows/peer-advisory-drift.yml |
Reusable advisory-drift audit β cross-checks the ranges a package declares against the advisory database; files and closes its own tracking issue | Called weekly by each publishable repo |
π§© .github/actions/setup-node-pnpm |
Composite action β pnpm + Node + cache + local file: lib build + install |
Used by the reusable jobs |
π .github/workflow-templates/ |
Starter workflows + dependabot.yml |
In the repo "New workflow" gallery |
π€ .github/copilot-instructions.md Β· instructions/ Β· agents/ |
Copilot code-review reference set β org baseline + per-stack rules + reviewer agent | Copied into a repo (does not auto-propagate) |
π©Ί Community health files (
CONTRIBUTING,CODE_OF_CONDUCT,SECURITY, issue/PR templates) also belong here β they are the next addition and will apply org-wide.
Two independent layers configure Copilot review across the org:
- Automatic trigger β the org ruleset
copilot-code-reviewrequests a Copilot review on the default branch of every repo (~ALL), new ones included. No per-repo setup. - The rules Copilot applies β split by reach:
| Layer | Where it lives | Applies to |
|---|---|---|
| Universal baseline | Org β Settings β Copilot β Custom instructions | Every repo, automatically |
| Per-repo instruction files | each repo's own .github/copilot-instructions.md Β· .github/instructions/* Β· .github/agents/* |
Only that repo |
β οΈ Unlike community health files, Copilot instruction files do not propagate from this repo. GitHub reads them only from the repository under review. The set below is the canonical reference β copy what a new repo needs, then append its domain rules (supply-chain contract, crypto/tenant, PII, pixel parity, fiscal mathβ¦).
| File | For |
|---|---|
copilot-instructions.md |
org baseline (mirror of the org-settings text) |
instructions/code.rust.instructions.md |
Rust crates |
instructions/code.library.instructions.md |
@bymax-one/* libraries |
instructions/code.app.instructions.md |
apps consuming those libraries |
instructions/tests.instructions.md |
test suites |
agents/agent-code-reviewer.agent.md |
reviewer agent definition |
Define the toolchain and pipeline once; each repo becomes a thin caller. Fixing a step (a Node bump, an action allow-list workaround, a cache tweak) is a one-line change here that every repo inherits.
- β±οΈ Tests never run on a schedule β unit, e2e, and mutation are event-driven
(push / pull_request) or on-demand (
workflow_dispatch). - 𧬠Mutation is the deepest gate β it runs only on a default-branch push (or
manual dispatch), and only when application source changed (Stryker incremental for
Node,
cargo-mutants --in-difffor Rust). PRs stay gated by 100% coverage + e2e, which is fast. No mutation runs on a schedule or on the PR path anywhere in the org. - π€ Third-party dependency/security updates are handled by Dependabot on GitHub infrastructure (β zero Action minutes) β not a cron CI job.
- ποΈ One cron CI job exists, and only because Dependabot structurally cannot answer
the question:
peer-advisory-drift.yml. Dependabot audits what is installed in a repo β the lockfile β and stays quiet while a publishedpeerDependenciesrange still admits a version with an advisory. The range never changes and becomes wrong anyway, because the advisory database is what moves; the drift arrives with no commit and no alert. That is why it is scheduled rather than event-driven: the degradation happens between releases, when nothing is being pushed. It costs a handful of read-only GraphQL queries; it never builds, and never installs the caller's dependency tree β onlysemver, into a throwaway$RUNNER_TEMPdirectory, so the workspace it audits is left untouched.
# .github/workflows/ci.yml
name: CI
on:
push: { branches: [main] }
pull_request: { branches: [main] }
workflow_dispatch:
concurrency:
group: ci-${{ github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
ci:
uses: bymaxone/.github/.github/workflows/node-ci.yml@v1
with:
library-repo: bymaxone/nest-cache # a sibling file: dep; "" to skip
has-web: true
run-export-audit: true
run-mutation: true
security:
if: github.event_name == 'pull_request'
uses: bymaxone/.github/.github/workflows/security.yml@v1Then copy .github/workflow-templates/dependabot.yml
to your repo's .github/dependabot.yml.
| Input | Default | Notes |
|---|---|---|
node-version |
24 |
|
library-repo |
"" |
sibling file: library to check out + build |
has-web |
true |
web build + web coverage + Playwright e2e |
run-format-check |
true |
pnpm format:check |
run-e2e-api |
true |
pnpm test:e2e:api (Testcontainers) |
run-e2e-web |
true |
Playwright web smoke (needs has-web) |
run-export-audit |
false |
pnpm audit:exports (library export contract) |
run-mutation |
false |
Stryker on default-branch push / dispatch only |
mutation-source-globs |
api/web/src regex | which changed paths trigger mutation |
A library caller routes the generic jobs (lint Β· typecheck Β· format Β· unit+coverage Β·
build Β· mutation) through node-lib-ci.yml and keeps repo-specific jobs (verify
build+integrity+size, Testcontainers e2e, secret-scan) local, plus a
visibility-gated security job.
| Input | Default | Notes |
|---|---|---|
node-version |
24 |
|
library-repo |
"" |
sibling file: library to check out + build (usually empty for a library) |
run-format-check |
true |
pnpm format:check |
unit-command |
pnpm test:cov |
the gated unit+coverage command (e.g. pnpm test:cov:all) |
build-command |
pnpm build |
the library build command |
run-build |
true |
run the build job (set false when a local verify job builds) |
database-url |
"" |
DATABASE_URL for libs with a Prisma client (empty to skip) |
post-install |
"" |
command after install in every job (e.g. prisma generate) |
run-mutation |
false |
Stryker on default-branch push / dispatch only |
mutation-source-globs |
^(src/) |
which changed paths trigger mutation |
A Rust caller routes the universal Cargo gates (fmt Β· clippy Β· build & test Β·
cargo-llvm-cov Β· MSRV Β· cargo-mutants) through rust-ci.yml and keeps every
bespoke job (wasm, fuzz, feature matrix, supply-chain, public-api, npm/web bundles,
e2e) local.
| Input | Default | Notes |
|---|---|---|
run-build |
true |
cargo build before the test job |
run-coverage |
true |
cargo llvm-cov line+function gate |
coverage-fail-under |
100 |
minimum line & function coverage percent |
run-msrv |
true |
build on the declared MSRV floor |
msrv-version |
1.90 |
the MSRV toolchain (matches rust-version) |
run-mutation |
false |
cargo-mutants on default-branch push / dispatch only |
mutation-command |
cargo mutants --all-features --in-place |
the mutation command |
mutation-source-globs |
^(crates/|src/|bindings/) |
which changed paths trigger mutation |
Audits the ranges a package declares β what consumers are told they may install β rather than what its own lockfile pins. Reports one row per declared range with the floor to move to, opens a tracking issue, rewrites it as findings change, and closes it automatically once every range is clear.
| Input | Default | Notes |
|---|---|---|
manifest-path |
package.json |
the manifest whose declared ranges are audited |
dependency-types |
peerDependencies |
comma-separated manifest fields; every field listed is a public claim of support |
severity-threshold |
low |
lowest advisory severity to report β raise per repo rather than discovering later that a moderate finding was filtered |
issue-label |
peer-advisory-drift |
label on the tracking issue, and the key used to find it again |
fail-on-drift |
false |
also fail the job; off by default because a permanently red scheduled run trains people to ignore it |
| Output | Notes |
|---|---|
drift-count |
number of declared ranges that admit a vulnerable version β the number of lines to edit, not the number of advisories behind them |
advisory-count |
total advisory matches, for reporting |
The caller must grant issues: write: permissions on a reusable workflow can only
narrow what the caller granted.
# .github/workflows/peer-advisory-drift.yml
name: Peer Advisory Drift
on:
schedule:
- cron: '17 6 * * 1'
workflow_dispatch:
# Single-flight across the repository, deliberately NOT keyed by `github.ref`: the
# shared state is one tracking issue per repo, so a ref-scoped group would put a
# dispatch and the scheduled run in different groups and leave the race intact.
concurrency:
group: peer-advisory-drift
cancel-in-progress: false
permissions:
contents: read
issues: write
jobs:
drift:
# `workflow_dispatch` can fire from any branch; auditing an unmerged manifest
# would write findings that do not describe what the package declares.
if: github.ref_name == github.event.repository.default_branch
uses: bymaxone/.github/.github/workflows/peer-advisory-drift.yml@v1Pin callers to @v1 (a moving major tag): a deliberate v1.x release propagates to
every repo, while a breaking change lands as v2 behind an explicit bump. Never pin a
caller to @main.
| Stack | Reusable | Status |
|---|---|---|
π’ Node libraries β @bymax-one/nest-* |
node-lib-ci.yml Β· security.yml Β· peer-advisory-drift.yml |
β
Live (@v1) |
π’ Node example apps β nest-*-example |
node-ci.yml Β· security.yml |
β
Live (@v1) |
π¦ Rust β rust-auth (library) + rust-auth-example (app) |
rust-ci.yml Β· security.yml |
β
Live (@v1) |
ποΈ
peer-advisory-driftis Node-only. Example apps are not published, so nothing reads the ranges they declare. Rust is a genuine gap rather than an exclusion: the advisory database exposes the same data underecosystem: RUST, but auditing it means parsingCargo.tomland[workspace.dependencies]and honouring Cargo's version semantics, where a bare"1.2"already means^1.2.cargo-auditcovers the installed side there β the same blind spot Dependabot has on the Node side.
The org restricts Actions to GitHub-owned + verified-marketplace + an explicit
pattern allow-list (orgs/bymaxone/actions/permissions/selected-actions). GitHub's
verified-creator flag does not cover several actions the Node and Rust pipelines
depend on, so those are pattern-allowed explicitly. Current patterns_allowed:
pnpm/action-setup@* actions-rust-lang/setup-rust-toolchain@*
Swatinem/rust-cache@* taiki-e/install-action@*
ossf/scorecard-action@* dtolnay/rust-toolchain@*
dorny/paths-filter@* stefanzweifel/git-auto-commit-action@*
docker/build-push-action@* docker/login-action@*
docker/metadata-action@* docker/setup-buildx-action@*
trufflesecurity/trufflehog@*
Workflows still pin every action to a full commit SHA β @* here only permits the
action, it does not relax the pin.
Hard-won lessons from rolling these reusables across every repo β read before touching org-level Actions settings or a repo's security workflows.
gh api --method PUT orgs/bymaxone/actions/permissions/selected-actions replaces the
entire policy. A PUT that sends only the one pattern you're adding silently drops all
the others. A workflow that references a now-blocked action fails at startup
(startup_failure, "workflow file issue") with no job logs β and, worst of all, the
PR shows a misleading CLEAN mergeStateStatus with an empty check-run list, so it
would merge with zero CI. Always read the current patterns_allowed, append, and
PUT the full set. (verified_allowed: true does not cover taiki-e/install-action,
Swatinem/rust-cache, actions-rust-lang/setup-rust-toolchain, dtolnay/rust-toolchain,
dorny/paths-filter, ossf/scorecard-action, stefanzweifel/*, or docker/* β they
must be explicit.)
A repo cannot run both the code-scanning default setup and an advanced
.github/workflows/codeql.yml. When both are on, the advanced workflow fails its SARIF
upload with "CodeQL analyses from advanced configurations cannot be processed when the
default setup is enabled." Since the workflow is the source of truth, disable default
setup:
gh api --method PATCH repos/OWNER/REPO/code-scanning/default-setup -f state=not-configuredactions/dependency-review-action needs the dependency graph, which is free only on
public repos (or private + GitHub Advanced Security). Gate the security caller so it
stays green while a repo is private and activates automatically once it's public:
security:
if: github.event_name == 'pull_request' && github.event.repository.visibility == 'public'
uses: bymaxone/.github/.github/workflows/security.yml@v1The reusables are pinned by callers to the moving major @v1. After merging a change to a
reusable, advance the tag so callers pick it up:
git checkout main && git pull && git tag -f v1 && git push -f origin v1Bymax One β architecting AI-native systems for production. π Profile Β· π bymax.one