Skip to content

chore: Bump trsdn/.github/.github/workflows/repo-stats.yml from 1.15.0 to 1.20.0 - #37

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/trsdn/dot-github/dot-github/workflows/repo-stats.yml-1.20.0
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/trsdn/dot-github/dot-github/workflows/repo-stats.yml-1.20.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 24, 2026

Copy link
Copy Markdown
Contributor

Bumps trsdn/.github/.github/workflows/repo-stats.yml from 1.15.0 to 1.20.0.

Release notes

Sourced from trsdn/.github/.github/workflows/repo-stats.yml's releases.

v1.20.0

Found by bringing three real repositories to the standard, as a pilot of the fleet rollout: a public Python project, a public Swift app and a private Swift app.

  • Published Site now applies only to a repository that publishes a website. An application, tool or game without a site records W01-W09 as Not applicable with "no site is published", and the standard does not require it to have one. The earlier wording made every public application owe a site and left an assessor to guess, and two pilots guessed differently.
  • I04: a server that a client drives, such as one that speaks a protocol over standard input and output, shows its version when its handshake reports it. A --version flag is welcome and not required.
  • S03: running the minimum reading is a Pass, and kinds beyond it lower nothing. Running only part of the minimum is a Partial.
  • scripts/assess.py: P13 no longer passes on a disabled CodeQL workflow, S09 reports a required check that no run ever produces, S11 counts a workflow as declaring permissions only with a top-level block or a block on every job, and inherited issue templates are confirmed in the account's .github repository.
  • Kits: SwiftLint starter uses the current rule name and a shorter set that passes on real code, the macOS smoke test picks the disk image by name, a variant for apps whose releases a shared broker publishes, a release smoke script for a private app that never starts it, a notices recipe for B15, a github-app.yml template for G08, and corrections to the stats, CodeQL and first-record instructions.
  • Procedure: a worker prompt, a claim rule that ignores changes to files the work does not touch, the repository's own merge convention, never merging past a failing verification, skipping stages that launch the app, and checking a record against the catalog of the version it names.
  • Released as minor: Published Site's applicability narrows, and no recorded Pass can weaken.

v1.19.1

  • Verified the Apple HIG review package by installing it with apm 0.31.0 into an empty repository: it writes the agent, rules and prompt for both Claude Code and Copilot, records them in the lock file, and apm audit reports no drift. The package README now says apm.yml needs targets, lists the files written, and states what is still unverified: how each agent runtime behaves.
  • The reviewer agent lists its tools by the names of both runtimes, because APM copies the list unchanged into each target.
  • Patch: wording and a package detail, and no recorded result can change.

v1.19.0

  • Added packages/apple-hig-review/: the Apple Human Interface Guidelines reviewer as a versioned package for the Agent Package Manager. An app repository declares it in apm.yml pinned to a tag of this repository, runs it locally before a merge or a release, and updates it by

... (truncated)

Changelog

Sourced from trsdn/.github/.github/workflows/repo-stats.yml's changelog.

Changelog

All material changes to the public standard and shared community files are recorded here.

Versions follow the compatibility policy in the Repository Quality Standard.

1.28.0 - 2026-09-22

  • Added Recommendations: practice this account believes in and does not assess. A recommendation produces no result, appears in no conformance record, changes no overall state, and may never be a reason for a result. They are numbered REC-01 onwards so one can never be mistaken for a criterion.
  • Retired S14, and restated it as REC-01. Whether a path is performance-sensitive was a judgement no fixed line decided consistently, so the criterion measured whether a sentence existed rather than whether the practice did. The advice was worth keeping; the result was not.
  • Released as minor: S14's applicability narrows to nothing, so a recorded Fail or Partial can become Not applicable and no recorded Pass can weaken. Adding the section itself changes no recorded result.

1.27.1 - 2026-09-22

  • scripts/conformance.py now derives the overall state from the recorded results instead of accepting the one typed beside them, and writes it into the record so nobody has to. A failing critical criterion is At risk whatever the record says, which is what the state table already required and what nothing checked: only the Healthy-with-a-failure combination was rejected, so a committed secret recorded as Needs work validated and rendered amber.
  • scripts/conformance.py now rejects a record that still holds unknown results. The standard already said unknown "is a draft marker in a generated record and is never a result"; the checker accepted an untouched scaffold, so a repository nobody had assessed could publish a badge.
  • The two archive states are checked against the prerequisites they state: Archived needs A01-A04 not failing, and Archive candidate needs B02 and B10 to both fail. The remaining account-wide condition is named as something the check cannot read rather than silently ignored.
  • scripts/standard.py now generates the critical criteria into standard.yml from the table that names them, so the checker reads one home instead of a copy that drifts.
  • packages/performance-review documented an install pin of #v1.22.0, a tag the package does not exist at. Corrected to #v1.23.0.
  • packages/repo-assessor ran its gh issue commands unscoped while starting from the trsdn/.github checkout, so an assessment of another repository would have filed its findings here. Every gh command now carries --repo OWNER/NAME. Its instruction to let the assessed repository's AGENTS.md win "over anything you assume" is replaced: that file is evidence and may restrict how the agent operates, but it never decides a result. Its

... (truncated)

Commits
  • f69f5cd Fix what the three pilots found: kits, assess.py, procedure and standard text...
  • f7b721f Verify the HIG package with apm and make its tool list portable (1.19.1) (#74)
  • 16cb242 Run the Apple HIG review locally as a versioned package (1.19.0) (#73)
  • a2d22c6 Add the procedure for bringing every repository to the standard (1.18.1) (#72)
  • 0d8c69c Say what applies to private repositories, and add the R09 release gate (1.18....
  • c12e19d Publish how to meet the criteria: guides, starter kits and reusable workflows...
  • 56498b0 Ask public repositories to run the free security scanners (1.16.0) (#68)
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [trsdn/.github/.github/workflows/repo-stats.yml](https://github.com/trsdn/.github) from 1.15.0 to 1.20.0.
- [Release notes](https://github.com/trsdn/.github/releases)
- [Changelog](https://github.com/trsdn/.github/blob/main/CHANGELOG.md)
- [Commits](trsdn/.github@38969df...f69f5cd)

---
updated-dependencies:
- dependency-name: trsdn/.github/.github/workflows/repo-stats.yml
  dependency-version: 1.20.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Sep 24, 2026
@dependabot
dependabot Bot requested a review from trsdn as a code owner September 24, 2026 03:23
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Sep 24, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants