TemplateRepository
TemplateRepository is a scaffolder. It renders the layer every serious repository needs — governance, security policy, CI, release automation, and a documentation site — into a new or existing project, so none of it has to be rewritten by hand a second time.
Scaffold a Repository Language Profiles GitHub Repository
It merges, it does not overwrite
Pointed at a repository that already exists, the scaffolder writes only the files that are missing. Nothing you have already written is replaced, so running it against a live project is an additive operation.
What It Renders
-
Governance
GOVERNANCE.md,MAINTAINERS.md(roles, access, bus factor, offboarding),CODE_OF_CONDUCT.md,CONTRIBUTING.mdwith the DCO, coding standards and test policy, andSUPPORT.md. -
Security Policy
SECURITY.mdwith a private disclosure route and a response SLA, plus the SAST, SCA, secrets and dynamic-analysis policies and a STRIDE skeleton indocs/security-assessment.md. -
CI/CD
ci.yml,codeql.yml,scorecard.yml,dependency-review.yml,dco.yml,fuzzing.yml,docs.yml,stale.yml, and arelease.ymlthat produces an SBOM, checksums and Sigstore signatures. -
A Makefile Contract
The same target names in every repository:
verify,lint,test,docs-build,release-check. Language specifics live behind a singlelang-*fragment.
The Two Commands
# A new project
make new TARGET=../MyNewTool PROFILE=python
# How close is any repository to the OpenSSF badge?
make audit REPO=../TransparentTorProxy
make dry-run takes the same arguments and writes nothing.
Where To Go Next
| You want to | Read |
|---|---|
| Run the scaffolder | Scaffold a Repository |
| Know what each script and target does | Interfaces |
| See which variables get substituted | Placeholders |
Compare python, node, rust, generic |
Language Profiles |
| Understand what the scaffolder trusts | Security Assessment |
| Map the output to the OpenSSF badge | OpenSSF Criterion Mapping |