Skip to content

fix: remove shadowed CODEOWNERS + stray funding file, repair dependabot stub - #9

Merged
hyperpolymath merged 1 commit into
mainfrom
fix/codeowners-funding-dependabot
Aug 26, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
fix/codeowners-funding-dependabot

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Three defects found while modelling metadatastician/.github on this repo.

1. Root CODEOWNERS — deleted. It violated policy and was already dead.

Two CODEOWNERS files existed. GitHub's precedence is .github/ → root → docs/, so .github/CODEOWNERS won and the root file never took effect.

That masked the real problem. The root file carried:

*    @hyperpolymath

which CODEOWNERS-POLICY.adoc Rule 1 explicitly forbids — "a repository whose only code owner would be the sole maintainer MUST NOT contain a catch-all (*) line". That rule exists because GitHub auto-requests review from every matching entry on every PR including Dependabot's, which produced a recurring notification flood across ~18 repos (standards#55).

So the root file wasn't merely redundant — remove the nested one and the flood resumes. The surviving .github/CODEOWNERS is the compliant one, with zero owner lines.

2. .github/funding.yml — deleted. It pointed at the wrong org.

Inside hyperpolymath's own .github repo, this file read:

github: metadatastician

Added by an automated sweep (sweep4, 2026-07-18). It is also lowercase, where GitHub documents the exact-case FUNDING.yml — so it was inert. But it is misleading cruft that a future reader or sweep could act on.

The correct root FUNDING.yml (hyperpolymath handles) is untouched.

3. .github/dependabot.yml — repaired. It did nothing.

It carried the scaffold default package-ecosystem: "" — an empty string, so Dependabot ignored the file entirely. Set to github-actions, the one ecosystem this repo actually has (it ships two workflows).

Added a note that dependabot.yml is not an inheritable community-health file, since that's an easy assumption to make in a .github repo.


Found while building hyperpolymath/metadatastician's equivalent — deliberately not replicated there.

🤖 Generated with Claude Code

…ot stub

Three defects found while modelling metadatastician/.github on this repo.

1. ROOT CODEOWNERS DELETED -- it violated policy and was already dead.

   Two CODEOWNERS existed. GitHub's precedence is .github/ -> root ->
   docs/, so .github/CODEOWNERS won and the root file never took effect.
   That masked the real problem: the root file carried

       *    @hyperpolymath

   which CODEOWNERS-POLICY.adoc Rule 1 explicitly forbids -- 'a
   repository whose only code owner would be the sole maintainer MUST NOT
   contain a catch-all (*) line'. That rule exists because GitHub
   auto-requests review from every matching entry on every PR including
   Dependabot's, which produced a recurring notification flood across ~18
   repos (standards#55).

   So the root file was not merely redundant: delete the nested one and
   the flood resumes. The surviving .github/CODEOWNERS is the compliant
   one (zero owner lines).

2. .github/funding.yml DELETED -- it pointed at the WRONG ORG.

   Inside hyperpolymath's own .github repo, this file read
   'github: metadatastician'. It was added by an automated sweep
   ('sweep4', 2026-07-18). It is also lowercase, where GitHub documents
   the exact-case FUNDING.yml, so it was inert -- but it is misleading
   cruft that a future reader or sweep could act on. The correct root
   FUNDING.yml (hyperpolymath handles) is untouched.

3. .github/dependabot.yml REPAIRED -- it did nothing.

   It carried the scaffold default 'package-ecosystem: ""', an empty
   string, so Dependabot ignored the file entirely. Set to
   'github-actions', which is the one ecosystem this repo actually has
   (it ships two workflows). Added a note that dependabot.yml is NOT an
   inheritable community-health file, since that is easy to assume in a
   .github repo.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@hyperpolymath
hyperpolymath merged commit 663d5f4 into main Aug 26, 2026
2 of 4 checks passed
@hyperpolymath
hyperpolymath deleted the fix/codeowners-funding-dependabot branch August 26, 2026 15:48
@coderabbitai

coderabbitai Bot commented Aug 26, 2026 •

Copy link
Copy Markdown

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 7fa70368-5951-476e-a4d0-2a7b6112ae60

📥 Commits

Reviewing files that changed from the base of the PR and between 9f543ca and d8abe06.

📒 Files selected for processing (3)
  • .github/dependabot.yml
  • .github/funding.yml
  • CODEOWNERS

📝 Walkthrough

Summary by CodeRabbit

  • Chores
    • Updated automated dependency update settings, including explicit support for GitHub Actions and licensing information.
    • Removed repository funding configuration.
    • Removed repository code ownership and review assignment rules.
    • Continued weekly dependency update checks for the repository root.

Walkthrough

The Dependabot configuration now enables weekly GitHub Actions updates. The funding configuration and CODEOWNERS file were removed.

Changes

Repository configuration

Layer / File(s) Summary
Dependabot and repository metadata
.github/dependabot.yml, .github/funding.yml, CODEOWNERS
Dependabot now uses the github-actions ecosystem and keeps the weekly root schedule. The funding and CODEOWNERS files were removed.

Estimated code review effort: 1 (Trivial) | ~3 minutes

Poem

A rabbit checked the YAML with care
GitHub Actions updates now run there
Funding leaves the burrow
Owners no longer queue
Clean files make a tidy lair


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@gitar-bot

gitar-bot Bot commented Aug 26, 2026

Copy link
Copy Markdown

Important

You are using the Gitar free plan. Upgrade to unlock code review, CI analysis, auto-apply, custom automations, and more.

Gitar

@codacy-production

Copy link
Copy Markdown

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

AI Reviewer: first review requested successfully. AI can make mistakes. Always validate suggestions.

Run reviewer

TIP This summary will be updated as you push new changes.

@codacy-production codacy-production Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

The pull request aligns with the maintenance requirements for repository cleanup. It removes the shadowed root CODEOWNERS and the stray .github/funding.yml while repairing the .github/dependabot.yml stub to track GitHub Actions correctly.

Codacy results indicate that the changes are up to standards with no new quality issues. No major logic bugs or security flaws were detected that would prevent merging.

Test suggestions

  • Verify root CODEOWNERS file is removed
  • Verify .github/funding.yml is removed
  • Verify dependabot.yml is configured for github-actions
  • Verify inheritance warning is present in dependabot.yml

TIP Improve review quality by adding custom instructions
TIP How was this review? Give us feedback

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant