Skip to content

docs: AGENTS.md references ChallengeAI only; dependabot monthly consolidated PR - #34

Merged
brianfunk merged 2 commits into
devfrom
docs/agents-challengeai
Oct 2, 2026
Merged

brianfunk merged 2 commits into
devfrom
docs/agents-challengeai

Conversation

@brianfunk

@brianfunk brianfunk commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • AGENTS.md: no tool-specific file or folder names. Points at CHALLENGEAI.md and .challengeai/ as the federal-standards layer and adds them to the reading order. Maintenance rule says not to create parallel agent files that need syncing.
  • .gitignore: neutral comment; also ignores .cursor/.
  • .challengeai/challenge-cli.md: the "In this repository" section described a CLAUDE.md-based setup and an AGENTS.md gap; rewritten to describe the single AGENTS.md entry point.
  • .github/dependabot.yml policy change: one consolidated version-update PR per month covering every npm dependency in / and /cli-package (patch, minor, and major), plus one monthly PR for GitHub Actions. open-pull-requests-limit: 1. Security advisories are the exception: Dependabot opens those individually and immediately, outside the schedule. (Dependabot cannot filter security PRs by severity, so low/medium advisories will also arrive individually.)

Closed as superseded: #16–#21 (bumped in #25), #26–#33 (first-run individual PRs under the old weekly config; they'll be regrouped into the monthly PR).

Remaining "Claude" mentions in the repo are end-user MCP setup lines (claude mcp add ...) in README, Docs page and llms.txt, and the ChallengeAI docs describing which runtimes the accelerator supports. Those are product/documentation content, not agent instructions.

Actions status

pull_request runs now fire (every Dependabot PR got a green CI run). push to dev still produces no run; CI on PRs is the effective gate.

Test plan

  • no code changes; CI runs on this PR via the pull_request trigger

… major bumps in dependabot

Remove tool-specific file names from AGENTS.md and the .gitignore comment,
add CHALLENGEAI.md and .challengeai/ to the reading order, and rewrite the
ChallengeCLI 'in this repository' section to describe the single
AGENTS.md entry point. Dependabot now ignores semver-major updates for
every npm dependency in both manifests.
…rate and immediate

Single monthly version-update PR for all npm dependencies across / and
/cli-package (patch, minor, major), one monthly PR for GitHub Actions.
Security advisories bypass the schedule and open individually.
@brianfunk brianfunk changed the title docs: AGENTS.md references ChallengeAI only; dependabot ignores all majors docs: AGENTS.md references ChallengeAI only; dependabot monthly consolidated PR Oct 2, 2026
@brianfunk
brianfunk merged commit 32094c5 into dev Oct 2, 2026
2 checks passed
@brianfunk
brianfunk deleted the docs/agents-challengeai branch October 2, 2026 05:07
@brianfunk brianfunk mentioned this pull request Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant