Skip to content

GitHub Recommendations and Best Practices

  1. Single GitHub Organization (mbari-org)
  2. Defaults
    1. Private repos
    2. Required reviews
    3. Status checks
    4. Branch protection
  3. CI
    1. Self-hosted runners for heavy workloads
    2. GitHub-hosted runners for lightweight jobs
  4. Security:
    1. Dependabot everywhere
    2. Secret scanning on all public repos
    3. Code scanning on critical public repos