Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 12 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,27 +4,39 @@ updates:
- package-ecosystem: github-actions
directory: /
labels: []
commit-message:
prefix: chore
include: scope
schedule:
interval: daily
time: "10:00"
timezone: "Europe/Berlin"
- package-ecosystem: pre-commit
directory: /
labels: []
commit-message:
prefix: chore
include: scope
schedule:
interval: daily
time: "10:00"
timezone: "Europe/Berlin"
- package-ecosystem: pip
directory: /
labels: []
commit-message:
prefix: chore
include: scope
schedule:
interval: daily
time: "10:00"
timezone: "Europe/Berlin"
- package-ecosystem: bundler
directory: /
labels: []
commit-message:
prefix: chore
include: scope
schedule:
interval: daily
time: "10:00"
Expand Down
12 changes: 12 additions & 0 deletions .github/workflows/commit-shared.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,12 @@
name: Commit (shared)
on:
workflow_call:
jobs:
pull-request-title:
runs-on: ubuntu-slim
permissions:
pull-requests: read
steps:
- uses: amannn/action-semantic-pull-request@v6
env:
GITHUB_TOKEN: ${{ github.token }}
9 changes: 9 additions & 0 deletions .github/workflows/commit.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
name: Commit
on:
# Baseline uses pull_request so changes to the shared workflow validate themselves.
# Consumers should use pull_request_target to load trusted workflow code from main.
pull_request:
types: [opened, reopened, edited, synchronize]
jobs:
pull-request-title:
uses: ./.github/workflows/commit-shared.yml
4 changes: 3 additions & 1 deletion AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ Use the emoji to identify the agent:

- `🤖` Codex
- `🧠` Claude Code
- `🖊️` Cursor
- `🖱️` Cursor
- `🥽` GitHub Copilot
- `🧩` unknown or other agent

Expand Down Expand Up @@ -70,7 +70,9 @@ tools to already be installed in the developer environment.
- `.github/actions/check-precommit/` — composite action: verifies pre-commit hooks match detected CI linters
- `.github/actions/setup-runtimes/` — installs Python packages, Ruby, and standalone binaries for requested linters; Python is provided by the runner
- `.github/workflows/lint-shared.yml` — reusable workflow exported for consuming repos: setup + lint
- `.github/workflows/commit-shared.yml` — reusable workflow exported for Conventional Commit pull request titles
- `.github/workflows/embedder-shared.yml` — reusable workflow exported for required content validation
- `.github/workflows/commit.yml` — baseline caller for its Conventional Commit pull request title check
- `.github/workflows/lint.yml` — baseline self-lint (uses local `./` references, not `@vX`)
- `.github/workflows/prepare-release.yml` — dispatch workflow: calls `rubykatzen/releaser` to prepare `release/vX.Y.Z`
- `.github/workflows/publish-release.yml` — publishes merged `release/*` PRs via `rubykatzen/releaser`
Expand Down
51 changes: 44 additions & 7 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ repositories install runtimes and linter binaries only for local pre-commit use.

Replace `VERSION` in all examples with the latest release tag from
[github.com/rubykatzen/baseline/releases](https://github.com/rubykatzen/baseline/releases).
After initial setup, [Dependabot](#3-dependabot) keeps the pin current automatically.
After initial setup, [Dependabot](#6-dependabot) keeps the pin current automatically.

### 1. Lint workflow

Expand Down Expand Up @@ -61,8 +61,9 @@ jobs:
```

The shared workflow checks repository settings against `config/github.yml`.
The initial policy requires the wiki to be disabled, auto-merge to be enabled,
and merged branches to be deleted automatically.
The policy requires the wiki to be disabled, auto-merge to be enabled, merged
branches to be deleted automatically, and pull requests to use squash-only
merging with the pull request title as the complete resulting commit message.

Skip checks explicitly when a repository needs an exception:

Expand All @@ -76,7 +77,34 @@ jobs:

The `skip` input must be a JSON array. Unknown check names fail the workflow.

### 3. Embedded content
### 3. Commit workflow

Create `.github/workflows/commit.yml`:

```yaml
name: Commit
on:
# Load trusted workflow code from the default branch when validating fork PRs.
pull_request_target:
types: [opened, reopened, edited, synchronize]
jobs:
pull-request-title:
uses: rubykatzen/baseline/.github/workflows/commit-shared.yml@VERSION
```

The shared workflow requires pull request titles to follow Conventional Commits:

```text
<type>[optional scope][!]: <description>
```

Only the pull request title is validated. Intermediate branch commits may use
any format because the GitHub repository policy squashes the pull request and
uses only its title for the single commit added to the default branch. Use `!`
for a breaking change, for example
`refactor!: remove legacy workflow inputs`.

### 4. Embedded content

Create `.github/workflows/embedder.yml`:

Expand Down Expand Up @@ -110,7 +138,7 @@ jobs:

The `skip` input must be a JSON array. Unknown fragment names fail the workflow.

### 4. Pre-commit hooks
### 5. Pre-commit hooks

Copy `.pre-commit-config.yaml.example` to your repo or add to your existing config.
Include only the hooks relevant to your stack:
Expand Down Expand Up @@ -142,7 +170,7 @@ Ruby hooks use `bundle exec`; install Ruby and run `bundle install` in the
consuming repository first. `rubocop` and `erb_lint` must be available through
the [`rubykatzen-baseline`](#ruby-gem-rubocop--erb_lint) gem.

### 5. Dependabot
### 6. Dependabot

Add `.github/dependabot.yml` to keep GitHub Actions and pre-commit pins
current automatically:
Expand All @@ -153,20 +181,29 @@ updates:
- package-ecosystem: github-actions
directory: /
labels: []
commit-message:
prefix: chore
include: scope
schedule:
interval: daily
time: "10:00"
timezone: "Europe/Berlin"
- package-ecosystem: pre-commit
directory: /
labels: []
commit-message:
prefix: chore
include: scope
schedule:
interval: daily
time: "10:00"
timezone: "Europe/Berlin"
```

Dependabot opens pull requests for version bumps. Pair with
The commit message configuration also prefixes pull request titles with
`chore(deps):`, so they pass the commit workflow without creating a release by
default. Rename a release-worthy dependency update to `fix(deps):` to request a
patch release. Pair Dependabot with
`dependabot-automerge` if you want patch/minor updates merged automatically.

---
Expand Down
14 changes: 13 additions & 1 deletion config/embedder.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ fragments:

- `🤖` Codex
- `🧠` Claude Code
- `🖊️` Cursor
- `🖱️` Cursor
- `🥽` GitHub Copilot
- `🧩` unknown or other agent

Expand Down Expand Up @@ -60,27 +60,39 @@ fragments:
- package-ecosystem: github-actions
directory: /
labels: []
commit-message:
prefix: chore
include: scope
schedule:
interval: daily
time: "10:00"
timezone: "Europe/Berlin"
- package-ecosystem: pre-commit
directory: /
labels: []
commit-message:
prefix: chore
include: scope
schedule:
interval: daily
time: "10:00"
timezone: "Europe/Berlin"
- package-ecosystem: pip
directory: /
labels: []
commit-message:
prefix: chore
include: scope
schedule:
interval: daily
time: "10:00"
timezone: "Europe/Berlin"
- package-ecosystem: bundler
directory: /
labels: []
commit-message:
prefix: chore
include: scope
schedule:
interval: daily
time: "10:00"
Expand Down
5 changes: 5 additions & 0 deletions config/github.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,3 +2,8 @@ config:
hasWikiEnabled: false
autoMergeAllowed: true
deleteBranchOnMerge: true
mergeCommitAllowed: false
rebaseMergeAllowed: false
squashMergeAllowed: true
squashMergeCommitTitle: PR_TITLE
squashMergeCommitMessage: BLANK
14 changes: 13 additions & 1 deletion test/test_github_config.py
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,19 @@ def setUp(self):
def test_loads_repository_config(self):
checks = CHECK_GITHUB_CONFIG.load_config(BASELINE_ROOT / "config" / "github.yml")

self.assertEqual(set(checks), {"hasWikiEnabled", "autoMergeAllowed", "deleteBranchOnMerge"})
self.assertEqual(
set(checks),
{
"hasWikiEnabled",
"autoMergeAllowed",
"deleteBranchOnMerge",
"mergeCommitAllowed",
"rebaseMergeAllowed",
"squashMergeAllowed",
"squashMergeCommitMessage",
"squashMergeCommitTitle",
},
)

def test_rejects_invalid_repository_config(self):
with tempfile.NamedTemporaryFile(mode="w", suffix=".yml") as config:
Expand Down