| name | lisa-setup-github-repo |
| description | Apply Lisa's GitHub repository… |
| allowed-tools | ["Bash","Read","AskUserQuestion"] |
Setup GitHub Repository Governance
Apply the fleet-standard GitHub repository configuration to this project's repo. The settings, rulesets, and deploy key that used to be clicked together by hand for every new repo are applied here as one scripted flow.
What gets applied
- Repository settings (
scripts/lisa-github-repo-settings.sh)
- Rulesets (
scripts/lisa-github-rulesets.sh) from Lisa's <type>/github-rulesets/ templates, matched by project type:
base — deletion/force-push protection on main/dev/staging + default, PRs required (0 approvals, review-thread resolution required, merge method = merge only), required checks: CodeRabbit + GitGuardian
quality checks — the stack's CI checks (TypeScript emoji names or Rails names)
prevent delete, protect tags (v*), plus stack overlays (cdk validation, staging-only playwright)
- Repos without
.github/workflows/ get only app-based required checks — an Actions check that can never report would block every PR forever
- Deploy key (
scripts/setup-deploy-key.sh --yes) — write-access deploy key + DEPLOY_KEY secret, skipped when already configured. The base ruleset's DeployKey: always bypass is what lets CI version-bump pushes through protected branches.
Workflow
Step 1 — Locate the scripts
In the Lisa repo itself, use scripts/ directly. In a downstream project, use the installed package:
LISA_SCRIPTS=$(ls -d node_modules/@codyswann/lisa/scripts 2>/dev/null || echo scripts)
Step 2 — Dry-run and show the plan
bash "$LISA_SCRIPTS/lisa-github-repo-setup.sh" --dry-run .
Present what would change. If the repo already matches the baseline, say so and stop.
Step 3 — Apply
bash "$LISA_SCRIPTS/lisa-github-repo-setup.sh" .
Requires gh authenticated with admin permission on the repo. A 403 on rulesets means the plan doesn't support them (private repo on a free personal plan) — settings and deploy key still apply; the script skips rulesets gracefully.
Step 4 — Verify
gh api "repos/$(gh repo view --json nameWithOwner -q .nameWithOwner)" \
--jq '{allow_squash_merge, allow_auto_merge, delete_branch_on_merge, allow_update_branch}'
gh api "repos/$(gh repo view --json nameWithOwner -q .nameWithOwner)/rulesets" --jq '[.[].name]'
Report the applied settings and ruleset names. If any step failed, surface the error — do not mark the setup complete.