Skip to content

docs: mark a new example repository as a published copy - #236

Merged
arcjet-rei merged 1 commit into
mainfrom
rei/contributing-mark-published-copies
Oct 7, 2026
Merged

arcjet-rei merged 1 commit into
mainfrom
rei/contributing-mark-published-copies

Conversation

@arcjet-rei

Copy link
Copy Markdown
Contributor

Adds a step to "Publishing to a new repository": an organization owner sets the source_repository custom property to arcjet/examples on the new repository and applies the "Derived repo" code security configuration, which turns off its Dependabot alerts.

Each arcjet/example-* repository is overwritten on every publish, so its alerts repeat this repository's and a fix made in it doesn't survive the next publish. The 37 existing copies were marked this way on 2026-10-06; this step keeps new ones consistent.

🤖 Generated with Claude Code

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

@arcjet-review arcjet-review Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Arcjet Review — 🟢 Low Risk

Decision: Approved

Rationale: This PR only updates CONTRIBUTING.md with an additional procedural step for publishing example repositories. No code, dependencies, infrastructure, authentication, database schema, or executable configuration are changed. The security review checklist found no secrets, injection risks, cryptographic concerns, or access-control changes in the diff.

Summary of Changes

Adds documentation instructing maintainers to mark newly published example repositories as derived copies by setting the source_repository custom property and applying the Derived repo security configuration.

Review: 08154af3 | Model: openai/gpt-5.5 | Powered by Arcjet Review

@arcjet-review arcjet-review Bot added ready Ready to merge and removed ai-review-in-progress needs review Awaiting human review labels Oct 6, 2026
@arcjet-rei
arcjet-rei added this pull request to the merge queue Oct 7, 2026
Merged via the queue into main with commit 6f8dd4f Oct 7, 2026
23 checks passed
@arcjet-review arcjet-review Bot removed the ready Ready to merge label Oct 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant