Repository navigation
Align Repository Defaults with the agent onboarding model, workflow filename, and supported Dependabot ecosystems #507
Description
Activity
- added a commit that references this issue
on Aug 2, 2026 - changed the title
[-]Correct the workflow filename and Dependabot ecosystem in Repository Defaults[/-][+]Align Repository Defaults with the agent onboarding model, workflow filename, and supported Dependabot ecosystems[/+]on Aug 2, 2026 MariusStorhaug commented
on Aug 2, 2026 MemberAuthorMore actionsItem 2 is already fixed — no need to carry it here.
PSModule/docs#101 (open before this issue was filed, closing #506) already renames the row to
.github/workflows/Process-PSModule.ymland adds a Caller workflow and reusable workflow subsection with a role/repository/file table and theuses: PSModule/Process-PSModule/.github/workflows/workflow.yml@<sha>snippet, so the caller-versus-reusable distinction is explicit. It also names the caller file inModules/Process-PSModule/repository-structure.md, which previously described it only as "workflow entrypoint".Items 1 and 3 are now in that same pull request, rather than a second one against the same file:
- Item 1 —
.github/copilot-instructions.mdis removed from both the layout table and the required-files table, leavingAGENTS.md+CLAUDE.mdas the required set. One nuance worth recording: MSX guidance is not uniform on this. Ways of Working → Agentic Development lists onlyAGENTS.md, the importingCLAUDE.md, and path-scoped adapters, but the agentic development capability spec and its design page name.github/copilot-instructions.mdexplicitly as a client adapter that MAY add runtime-specific loading rules. Neither makes it mandatory, so the page now describes it as optional rather than forbidden, and says which source says what. Verified independently: 2 of 96 org repositories carry the file (PSModule/GitHubandPSModule/docs), andTemplate-PSModuledropped it in refactor: slim template scaffolding to minimum baseline Template-PSModule#33. - Item 3 — the
package-ecosystem: powershellexample is gone. Confirmed againstPACKAGE_MANAGER_LOOKUPindependabot-core'scommon/lib/dependabot/config/file.rband GitHub's options reference, neither of which containspowershell. The example is now whatTemplate-PSModulereally ships (github-actions, daily,cooldown.default-days: 7), withnugetdocumented for .NET dependencies asSodiumuses it, plus a subsection stating that no PowerShell ecosystem exists and that the entry must not be left in as a placeholder. Also confirmed that no repository ever adopted it, so this was drift rather than live breakage.
Fourth acceptance criterion — the
PSModule/Distributormanageddependabot.yml(Repos/Module/dependabot.yml/.github/dependabot.yml), which is where the page's snippet came from, still contains the invalid entry. That is outside this repository, so it is filed as MSXOrg/Distributor#16 with an explicit note not to port it intoMSXOrg/Custo.So this issue can be narrowed to items 1 and 3; PSModule/docs#101 closes it along with #506.
- Item 1 —
- added a commit that references this issue
on Aug 2, 2026
Problem
Three entries in Repository Defaults describe a state that does not match how PSModule module repositories actually work, so anyone following the page literally produces a broken or redundant repository.
1.
.github/copilot-instructions.mdis no longer the agent entry pointBoth the "Default repository layout" table and the "Required common files" table list
.github/copilot-instructions.mdas a required file.The agent onboarding model is
AGENTS.mdat the repository root, withCLAUDE.mdimporting it. Agent runtimes, including VS Code and GitHub Copilot, readAGENTS.mdnatively, so a separate Copilot-only pointer file is duplication that can drift. Agentic Development already describes the per-repository pointer files asAGENTS.md, theCLAUDE.mdthat imports it, and path-scoped instruction files — it does not mentioncopilot-instructions.md.The page's own "Agent onboarding files" section is already correct and lists only
AGENTS.mdandCLAUDE.md. The two tables contradict it.Only two repositories in the organization carry the file at all (
PSModule/docsandPSModule/GitHub), andTemplate-PSModuleremoved it in PSModule/Template-PSModule#33.2. Workflow filename
The "Default repository layout" table lists
.github/workflows/workflow.ymlas the "Reusable Process-PSModule workflow entry point".Every module repository actually uses
.github/workflows/Process-PSModule.yml. Surveyed 24 module repositories —GitHub,Context,Sodium,Utilities,Domeneshop,Ast,Base64,Jwt,Markdown,Yaml,Toml,Json,Path,PSSemVer,DynamicParams,Fonts,NerdFonts,Dns,PublicIP,Uri,CasingStyle,TimeSpan,PowerShellGallery, andLovdata— plusTemplate-PSModule. All 24 useProcess-PSModule.yml; none has aworkflow.yml.workflow.ymlis the filename of the called reusable workflow insidePSModule/Process-PSModule, not the caller in the module repository. The table has confused the callee with the caller.3. Dependabot ecosystems are documented as a fixed list containing one that does not exist
The "Supply-chain defaults" section shows a literal configuration block that module repositories should use, containing
package-ecosystem: "github-actions"andpackage-ecosystem: "powershell".Dependabot has no
powershellpackage ecosystem. As ofdependabot-core@dc2e4422d(2026-07-24) the supported ecosystems arebazel,bun,bundler,cargo,composer,conda,deno,devcontainers,docker,dotnet_sdk,elm,git_submodules,github_actions,go_modules,gradle,helm,hex,julia,maven,nix,npm_and_yarn,nuget,omnibus,opentofu,pre_commit,pub,python,rust_toolchain,sbt,swift,terraform,uv, andvcpkg. There is nothing for PowerShell or the PowerShell Gallery.A repository that adds the documented block gets a Dependabot configuration error and stops receiving update pull requests entirely, including the
github-actionsones it would otherwise get.No module repository uses it. Of the 24 surveyed, all configure
github-actions, andSodiumaddsnugetbecause it ships a .NET assembly. The only place thepowershellentry exists is the managed source inPSModule/Distributor(Repos/Module/dependabot.yml), which has never been distributed.The deeper problem is the shape of the guidance, not just the one wrong value. A hardcoded literal block goes stale every time Dependabot's ecosystem support changes, and it cannot express "this repository also ships a .NET assembly". The rule should be stated as a requirement, not a copy-paste snippet.
Desired outcome
Repository Defaults describes the agent onboarding model, layout, and supply-chain configuration that module repositories actually use, so
Template-PSModuleand generated repositories can match the page exactly, and so the supply-chain guidance stays correct as Dependabot evolves.Acceptance criteria
.github/copilot-instructions.mdis removed from both the layout table and the required-files table, leavingAGENTS.mdandCLAUDE.mdas the agent entry points, consistent with the page's own "Agent onboarding files" section..github/workflows/Process-PSModule.ymlas the workflow entry point.github-actions, plus every additional ecosystem that applies to the repository and is supported by the current version of Dependabot. It links to the supported ecosystems reference as the authority for what is currently available, so the page does not need editing each time Dependabot adds or removes support.powershellentry is removed. If PowerShell Gallery support is wanted, it is captured as a future capability that must not be configured today, with a note that adding an unsupported ecosystem breaks the entire Dependabot configuration.PSModule/Distributormanageddependabot.ymlis flagged for the same correction so the brokenpowershellentry is not carried intoMSXOrg/Custo.References
dependabot-core: https://github.com/dependabot/dependabot-core