Repository package: v0.9.5
This checklist helps teams review GitHub-native controls around VCP adoption. It does not claim that VCP enables these controls automatically.
- GitHub Actions PR Gate
- branch protection
- required reviews
- CODEOWNERS
- issue templates
- PR templates
- release notes
- Dependabot
- CodeQL if available/enabled
- secret scanning if available/enabled
- security policy
- topics/about/description
- Discussions if community building is intended
Use this checklist before a pilot, before a client rollout, and before a team claims GitHub-side governance is actually in place.
- VCP does not auto-configure GitHub settings.
- VCP does not publish a Marketplace action.
- VCP does not certify branch protection, CodeQL, or secret scanning.
- VCP helps teams review and document whether those controls exist.