Skip to content

Add light AgentPMO skills, CodeQL, and Dependabot staging - #148

Merged
MelbourneDeveloper merged 1 commit into
mainfrom
chore/agentpmo-light
Oct 1, 2026
Merged

MelbourneDeveloper merged 1 commit into
mainfrom
chore/agentpmo-light

Conversation

@MelbourneDeveloper

Copy link
Copy Markdown
Owner

TLDR;

Add a light AgentPMO integration with seven repository skills, the existing .NET CI pipeline, CodeQL, and staged Dependabot updates.

Details

  • Install all seven AgentPMO skill templates under .agents/skills/, with RestClient.Net command context, upstream revision markers, and the MIT license. Document the light integration and map upstream Makefile commands to the existing dotnet and npm commands in AGENTS.md.
  • Rename the existing PR workflow to ci.yml, add read-only permissions, cancellation of superseded runs, a 15-minute timeout, and an explicit F# test step. Skip individual Dependabot PRs.
  • Add SHA-pinned CodeQL scanning for C#, JavaScript/TypeScript, and Actions on PRs to main and weekly. Expose the upstream optional reusable high/critical release gate.
  • Group weekly Actions, NuGet, and npm updates on dependabot-upgrades. Add the trusted-base sweep workflow, restricted to same-repository Dependabot PRs, to stage updates and retire their individual PRs.

How Do The Tests Prove The Changes Work?

CI retains the formatting check, warning-as-error builds, analyzers, 100% mutation gate, and solution tests with coverage. The new F# step explicitly runs RestClient.Net.FsTest, which is outside the solution. CodeQL analyzes all three configured languages on PRs to main; staged dependency updates receive these checks when submitted as a consolidation PR.

@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

@MelbourneDeveloper
MelbourneDeveloper merged commit 1d132f5 into main Oct 1, 2026
5 checks passed
@MelbourneDeveloper
MelbourneDeveloper deleted the chore/agentpmo-light branch October 1, 2026 21:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants