Shared GitHub configuration for the SylphxAI organization: the organization profile, default community health files (code of conduct, contributing guide, security policy, issue and pull request templates), and reusable GitHub Actions.
Use one from another repository with
uses: SylphxAI/.github/.github/actions/<name>@<commit> (or @main).
| Action | What it does |
|---|---|
| metadata-sync | Offline required-region/field patching with whole-plan validation and deterministic check/write; caller owns rendering (anymd/repomap adoption) |
| brand | Builds brand assets or checks provenance hashes and surface copies, with caller-owned masters and data |
| ci-ok | One required check that waits for every other GitHub Actions check on the commit and fails if any failed, a workflow failed to start, or no check ran |
| main-red-gate | Stop the line: while the trunk's newest conclusive Verify run is red and its way back is in motion, a merge group is admitted only for a revert, a live-outage fix or a pull request labelled main-red-fix; a red trunk with nothing in motion admits with a warning |
| needs-pass | The aggregate verdict of a workflow. A skipped job never counts as passing a required check outside merge_group: list PR-time jobs in required-unless-merge-group so a workflow_dispatch run cannot post a green check over a red one |
| secret-scan | Runs gitleaks over only the commits a push or pull request adds |
| plain-language | Warns about coined terms on the lines a pull request adds |
| identifiers | Fails when a change adds an id generator, or a text or serial primary key, that is not a UUIDv7 |
| chat-senders | Fails when a change adds a direct Telegram, Slack or Discord chat-API host outside the action's allow-list; products send chat through Notify |
| stack-conformance | Fails a change that adds a departure from the default stack, an agent-runtime part Sylphx Agents owns that policy/agent-runtime.json does not allow until a date, or a knowledge-graph or CRM table that policy/knowledge-tables.json does not allow until a date |
| zh-hant | Fails when a change adds a Simplified-only character to Traditional Chinese text |
| git-app-credentials | Creates a job-scoped GitHub App token for private git and cargo fetches |
| cache-toolchain | Dependency cache keyed per toolchain (cargo, bun, npm, pnpm, gradle, unity) |
| run-store | Hands a file or directory between the jobs of a run through the BuildCache gateway, keyed by run id; CI never depends on GitHub artifact storage |
| setup-keel-tools | The keel CLI at the title's KEEL_PIN and the wasm-bindgen CLI at its Cargo.lock version, cached per pin so a warm run takes seconds |
| setup-sylphx-cli | Installs a pinned @sylphx/cli |
| setup-changesets-publisher | Installs the Changesets publish command used by release workflows |
Reusable workflows are in .github/workflows; the CI fast-path recipe (changes.yml, cache-toolchain, ci-fast-path starter) is docs/ci-template.md.
disarm-auto-merge-on-push clears an
arm predating a new push without dequeuing an entry already on that head.
The image lane accepts source-sha for post-verification dispatches. Pass the
verified commit both as source-sha and tag; checkout and build evidence bind
that commit even when the dispatch runs after main advances. An omitted
source-sha keeps the triggering commit as the source.
Company repositories delete a pull request's head branch when it merges
(delete_branch_on_merge=true). The policy and the script that applies it are
in docs/repository-settings.md and
scripts/set-delete-branch-on-merge.sh.