From d8abe06fd330587c23faf65a4f4a950552f7d96c Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Wed, 26 Aug 2026 16:48:10 +0100 Subject: [PATCH] fix: remove shadowed CODEOWNERS + stray funding file, repair dependabot stub Three defects found while modelling metadatastician/.github on this repo. 1. ROOT CODEOWNERS DELETED -- it violated policy and was already dead. Two CODEOWNERS existed. GitHub's precedence is .github/ -> root -> docs/, so .github/CODEOWNERS won and the root file never took effect. That masked the real problem: the root file carried * @hyperpolymath which CODEOWNERS-POLICY.adoc Rule 1 explicitly forbids -- 'a repository whose only code owner would be the sole maintainer MUST NOT contain a catch-all (*) line'. That rule exists because GitHub auto-requests review from every matching entry on every PR including Dependabot's, which produced a recurring notification flood across ~18 repos (standards#55). So the root file was not merely redundant: delete the nested one and the flood resumes. The surviving .github/CODEOWNERS is the compliant one (zero owner lines). 2. .github/funding.yml DELETED -- it pointed at the WRONG ORG. Inside hyperpolymath's own .github repo, this file read 'github: metadatastician'. It was added by an automated sweep ('sweep4', 2026-07-18). It is also lowercase, where GitHub documents the exact-case FUNDING.yml, so it was inert -- but it is misleading cruft that a future reader or sweep could act on. The correct root FUNDING.yml (hyperpolymath handles) is untouched. 3. .github/dependabot.yml REPAIRED -- it did nothing. It carried the scaffold default 'package-ecosystem: ""', an empty string, so Dependabot ignored the file entirely. Set to 'github-actions', which is the one ecosystem this repo actually has (it ships two workflows). Added a note that dependabot.yml is NOT an inheritable community-health file, since that is easy to assume in a .github repo. Co-Authored-By: Claude Opus 5 --- .github/dependabot.yml | 16 ++++++++-------- .github/funding.yml | 4 ---- CODEOWNERS | 17 ----------------- 3 files changed, 8 insertions(+), 29 deletions(-) delete mode 100644 .github/funding.yml delete mode 100644 CODEOWNERS diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 121d32a..bf6583c 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -1,11 +1,11 @@ -# To get started with Dependabot version updates, you'll need to specify which -# package ecosystems to update and where the package manifests are located. -# Please see the documentation for all configuration options: -# https://docs.github.com/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file - +# SPDX-License-Identifier: MPL-2.0 +# SPDX-FileCopyrightText: 2026 Jonathan D.A. Jewell (hyperpolymath) +# +# Applies to THIS repository only. dependabot.yml is not one of GitHub's +# inheritable community-health files -- every repository needs its own. version: 2 updates: - - package-ecosystem: "" # See documentation for possible values - directory: "/" # Location of package manifests + - package-ecosystem: "github-actions" + directory: "/" schedule: - interval: "weekly" + interval: "weekly" diff --git a/.github/funding.yml b/.github/funding.yml deleted file mode 100644 index e4f7c07..0000000 --- a/.github/funding.yml +++ /dev/null @@ -1,4 +0,0 @@ -# Funding Configuration -# See: https://docs.github.com/en/repositories/managing-your-repositorys-custom-fields/displaying-a-sponsor-button-in-your-repository - -github: metadatastician diff --git a/CODEOWNERS b/CODEOWNERS deleted file mode 100644 index 48e73f7..0000000 --- a/CODEOWNERS +++ /dev/null @@ -1,17 +0,0 @@ -# SPDX-License-Identifier: MPL-2.0 -# Copyright (c) Jonathan D.A. Jewell -# -# CODEOWNERS for hyperpolymath/.github -# Note: CODEOWNERS is NOT inherited org-wide — it governs review on THIS repo only. -# See: https://docs.github.com/articles/about-code-owners - -# Everything here is maintainer-reviewed: changes cascade to every repository in -# the organization, so review is deliberately centralised. -* @hyperpolymath - -# High-blast-radius surface — templates and policy -/.github/ISSUE_TEMPLATE/ @hyperpolymath -/.github/DISCUSSION_TEMPLATE/ @hyperpolymath -/SECURITY.md @hyperpolymath -/CODE_OF_CONDUCT.md @hyperpolymath -/GOVERNANCE.md @hyperpolymath