fix: remove shadowed CODEOWNERS + stray funding file, repair dependabot stub - #9
Conversation
…ot stub
Three defects found while modelling metadatastician/.github on this repo.
1. ROOT CODEOWNERS DELETED -- it violated policy and was already dead.
Two CODEOWNERS existed. GitHub's precedence is .github/ -> root ->
docs/, so .github/CODEOWNERS won and the root file never took effect.
That masked the real problem: the root file carried
* @hyperpolymath
which CODEOWNERS-POLICY.adoc Rule 1 explicitly forbids -- 'a
repository whose only code owner would be the sole maintainer MUST NOT
contain a catch-all (*) line'. That rule exists because GitHub
auto-requests review from every matching entry on every PR including
Dependabot's, which produced a recurring notification flood across ~18
repos (standards#55).
So the root file was not merely redundant: delete the nested one and
the flood resumes. The surviving .github/CODEOWNERS is the compliant
one (zero owner lines).
2. .github/funding.yml DELETED -- it pointed at the WRONG ORG.
Inside hyperpolymath's own .github repo, this file read
'github: metadatastician'. It was added by an automated sweep
('sweep4', 2026-07-18). It is also lowercase, where GitHub documents
the exact-case FUNDING.yml, so it was inert -- but it is misleading
cruft that a future reader or sweep could act on. The correct root
FUNDING.yml (hyperpolymath handles) is untouched.
3. .github/dependabot.yml REPAIRED -- it did nothing.
It carried the scaffold default 'package-ecosystem: ""', an empty
string, so Dependabot ignored the file entirely. Set to
'github-actions', which is the one ecosystem this repo actually has
(it ships two workflows). Added a note that dependabot.yml is NOT an
inheritable community-health file, since that is easy to assume in a
.github repo.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
|
Caution Review failedThe pull request is closed. ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Pro Plus Run ID: 📒 Files selected for processing (3)
📝 WalkthroughSummary by CodeRabbit
WalkthroughThe Dependabot configuration now enables weekly GitHub Actions updates. The funding configuration and CODEOWNERS file were removed. ChangesRepository configuration
Estimated code review effort: 1 (Trivial) | ~3 minutes Poem
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Up to standards ✅🟢 Issues
|
There was a problem hiding this comment.
Pull Request Overview
The pull request aligns with the maintenance requirements for repository cleanup. It removes the shadowed root CODEOWNERS and the stray .github/funding.yml while repairing the .github/dependabot.yml stub to track GitHub Actions correctly.
Codacy results indicate that the changes are up to standards with no new quality issues. No major logic bugs or security flaws were detected that would prevent merging.
Test suggestions
- Verify root CODEOWNERS file is removed
- Verify .github/funding.yml is removed
- Verify dependabot.yml is configured for github-actions
- Verify inheritance warning is present in dependabot.yml
TIP Improve review quality by adding custom instructions
TIP How was this review? Give us feedback
Three defects found while modelling
metadatastician/.githubon this repo.1. Root
CODEOWNERS— deleted. It violated policy and was already dead.Two
CODEOWNERSfiles existed. GitHub's precedence is.github/→ root →docs/, so.github/CODEOWNERSwon and the root file never took effect.That masked the real problem. The root file carried:
which
CODEOWNERS-POLICY.adocRule 1 explicitly forbids — "a repository whose only code owner would be the sole maintainer MUST NOT contain a catch-all (*) line". That rule exists because GitHub auto-requests review from every matching entry on every PR including Dependabot's, which produced a recurring notification flood across ~18 repos (standards#55).So the root file wasn't merely redundant — remove the nested one and the flood resumes. The surviving
.github/CODEOWNERSis the compliant one, with zero owner lines.2.
.github/funding.yml— deleted. It pointed at the wrong org.Inside hyperpolymath's own
.githubrepo, this file read:Added by an automated sweep (
sweep4, 2026-07-18). It is also lowercase, where GitHub documents the exact-caseFUNDING.yml— so it was inert. But it is misleading cruft that a future reader or sweep could act on.The correct root
FUNDING.yml(hyperpolymath handles) is untouched.3.
.github/dependabot.yml— repaired. It did nothing.It carried the scaffold default
package-ecosystem: ""— an empty string, so Dependabot ignored the file entirely. Set togithub-actions, the one ecosystem this repo actually has (it ships two workflows).Added a note that
dependabot.ymlis not an inheritable community-health file, since that's an easy assumption to make in a.githubrepo.Found while building hyperpolymath/metadatastician's equivalent — deliberately not replicated there.
🤖 Generated with Claude Code