chore: fleet hygiene (release automation, dependabot, community files) - #1
Merged
Merged
Conversation
added 2 commits
September 22, 2026 20:05
Add SECURITY.md (supported versions, private report path, and the subscription-key rotation story), CONTRIBUTING.md, CODE_OF_CONDUCT.md (sibling Covenant text), and issue + PR templates. Harden CI to the fleet standard: npm ci, Node 20/22/24 matrix, SHA-pinned actions, permissions: contents: read. Add grouped-weekly dependabot.yml (npm + github-actions). Closes the review P0 and P1 file items for opencode-muse-auth.
Node 20's test runner treats the quoted tests/*.test.ts glob
literally ('Could not find ... tests/*.test.ts'): glob support
landed in Node 21, and Node 20 cannot execute the TypeScript
suite at all (type-stripping needs 22.6+, default-on in late
22.x). Matrix is now [22, 24].
Add pretest -> build so bare 'npm test' works on a fresh clone:
tests/auth.test.ts imports ../dist/auth.js (compiled output) and
failed with ERR_MODULE_NOT_FOUND without a prior build.
No new test file: tests/auth.test.ts already covers real shim
logic (cache roundtrip/miss, deviceAuthorize field validation,
pollToken pending->success + terminal errors, mintKey
subscription/payment validation) - 6/6 passing.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fleet hygiene pass per repo review (2026-09-22 P0 + P1 file items).
What changed
SECURITY.md(new): supported versions + private report path + subscription-key rotation story (401 -> delete cache, re-/connect).CONTRIBUTING.md(new),CODE_OF_CONDUCT.md(new, sibling Covenant text copied fromchutes-media-mcp), issue + PR templates (adapted)..github/workflows/ci.yml:npm install->npm ci, single Node 24 -> 20/22/24 matrix, tag-pinned actions -> SHA pins, addedpermissions: contents: read..github/dependabot.yml(new): grouped-weekly updates fornpm+github-actions.Review items closed
SECURITY.md. P1 (file parts): CI hardening; copy CONTRIBUTING/CoC/templates from siblings.Owner actions (not file-based, left for you)
v0.1.0/v0.1.1as GitHub Releases (needs release notes sign-off; also listed under RELEASES below if tags exist); add topics (opencode,opencode-plugin,meta,muse-spark); README badges/troubleshooting.