Imported from xsyetopz/easel.js (
.github/AGENTS.md). Install upstream withnpx skills add xsyetopz/easel.js --skill .github. Copyright stays with the author.
GitHub automation and templates
Scope: .github/. These files describe hosted behavior but do not grant permission to perform external actions; the root policy still applies.
Ownership map
workflows/ci.ymlmirrors repository checks;cloudflare-pages.ymlandpages.ymldeploydist/www;release.ymlexclusively publishes npm/JSR and creates tags/releases.ISSUE_TEMPLATE/,PULL_REQUEST_TEMPLATE.md, anddependabot.ymlown contribution intake and dependency update metadata.
Change rules
- Preserve least-privilege permissions, bounded timeouts, concurrency controls, frozen installs, and release identity/version/provenance checks.
- Pin every external action
uses:reference to a full 40-character commit SHA; CI's governance job enforces this. - Do not add local publishing or bypass
release.yml; release initiation remains an explicitly authorized maintainer action underCONTRIBUTING.md. - Keep CI commands aligned with
package.jsonrather than duplicating their implementation in shell. - Parse changed YAML locally and run the package commands affected by workflow changes; use
bun run release:checkfor broad gate changes.
