From 12e70a2279c5a81a448f8c4394e293e62bf5dfaa Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Tue, 4 Aug 2026 11:16:48 -0400 Subject: [PATCH] ci: add released PR policy self-caller (#116) Refs: PLAT-62 --- .github/workflows/policy.yaml | 22 ++++++++++++++++++++ .github/workflows/release-on-merge.yaml | 1 + README.md | 10 ++++----- workflow-templates/pr-policy.properties.json | 7 +++++++ workflow-templates/pr-policy.yml | 21 +++++++++++++++++++ 5 files changed, 56 insertions(+), 5 deletions(-) create mode 100644 .github/workflows/policy.yaml create mode 100644 workflow-templates/pr-policy.properties.json create mode 100644 workflow-templates/pr-policy.yml diff --git a/.github/workflows/policy.yaml b/.github/workflows/policy.yaml new file mode 100644 index 0000000..eba1158 --- /dev/null +++ b/.github/workflows/policy.yaml @@ -0,0 +1,22 @@ +name: PR Policy + +on: + pull_request: + types: [opened, reopened, synchronize, edited, labeled, unlabeled, ready_for_review] + +concurrency: + group: "policy-${{ github.event.pull_request.number }}" + cancel-in-progress: true + +permissions: + contents: read + issues: read + pull-requests: read + +jobs: + policy: + uses: Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml@9c1ecf942894b19aba5c71b85b41906c6c83b749 # v1.0.5 + secrets: + JIRA_CLOUD_ID: ${{ secrets.JIRA_CLOUD_ID }} + JIRA_SERVICE_ACCOUNT_EMAIL: ${{ secrets.JIRA_SERVICE_ACCOUNT_EMAIL }} + JIRA_API_TOKEN: ${{ secrets.JIRA_API_TOKEN }} diff --git a/.github/workflows/release-on-merge.yaml b/.github/workflows/release-on-merge.yaml index 7460afe..4cd7292 100644 --- a/.github/workflows/release-on-merge.yaml +++ b/.github/workflows/release-on-merge.yaml @@ -30,6 +30,7 @@ on: - ".github/workflows/**" - "!.github/workflows/ci.yaml" - "!.github/workflows/labeler.yaml" + - "!.github/workflows/policy.yaml" - "!.github/workflows/release-on-merge.yaml" workflow_dispatch: inputs: diff --git a/README.md b/README.md index 320972d..5fc4ece 100644 --- a/README.md +++ b/README.md @@ -64,7 +64,7 @@ The supply-chain check operates in **diff mode**: for modified or renamed workfl **`.github/workflows/release-on-merge.yaml`** — Repo automation (not callable): cuts a tag and GitHub Release for **this** repo whenever a merge to `main` changes a reusable workflow, so Dependabot has a release to advance consumer SHA pins to (see the pinning policy below). -**`.github/workflows/policy.yaml`** — Intentionally absent from this PR. The self-caller must pin `Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml` to a released 40-char SHA with a matching `# vX.Y.Z` comment; a mutable local `./` path reference is rejected by the supply-chain gate on modified workflow files. The follow-up PR can be opened once this PR merges and `release-on-merge.yaml` cuts the first release containing `callable-pr-policy.yaml`, then using `gh api /repos/Sea-Haven-Industries/.github/commits/vX.Y.Z --jq .sha` to obtain the pin. +**`.github/workflows/policy.yaml`** — This repo's own thin caller of `callable-pr-policy.yaml`, so the PR policy gate runs on `.github`'s own PRs. Pinned to the remote SHA at v1.0.5; a local `./` path reference is rejected by the supply-chain gate. The Jira org secrets (`JIRA_CLOUD_ID`, `JIRA_SERVICE_ACCOUNT_EMAIL`, `JIRA_API_TOKEN`) must be granted to this repo before human PR checks can pass (Dependabot and supply-chain checks still run without them). **`.github/workflows/labeler.yaml`** — This repo's own thin caller of `callable-labeler.yaml`, so the labeler runs on `.github`'s own PRs. @@ -72,9 +72,9 @@ The supply-chain check operates in **diff mode**: for modified or renamed workfl ### Workflow templates (`workflow-templates/`) -Starter workflows offered on the org's **Actions → New workflow** page: `cdk-deploy`, `ci-dotnet`, `ci-mobile-ios`, `ci-node`, `ci-python`, `ci-python-app`, `ci-static`, `ci-typescript-frontend`, `dependency-review`, `dotnet-eb-deploy`, `labeler`, `mobile-ios-deploy`, `release`, `sam-deploy`, `triage`. Each is a thin caller of the corresponding reusable workflow above (`triage` is standalone). Every template has a paired `properties.json` (name, description, icon, `filePatterns` for auto-suggestion). Replace any `REPLACE-ME` placeholders before enabling. Templates are not scanned by Dependabot, so refresh their pinned SHAs opportunistically when editing one. +Starter workflows offered on the org's **Actions → New workflow** page: `cdk-deploy`, `ci-dotnet`, `ci-mobile-ios`, `ci-node`, `ci-python`, `ci-python-app`, `ci-static`, `ci-typescript-frontend`, `dependency-review`, `dotnet-eb-deploy`, `labeler`, `mobile-ios-deploy`, `pr-policy`, `release`, `sam-deploy`, `triage`. Each is a thin caller of the corresponding reusable workflow above (`triage` is standalone). Every template has a paired `properties.json` (name, description, icon, `filePatterns` for auto-suggestion). Replace any `REPLACE-ME` placeholders before enabling. Templates are not scanned by Dependabot, so refresh their pinned SHAs opportunistically when editing one. -A `pr-policy` starter template can be added to `workflow-templates/` only after the PR that introduces `callable-pr-policy.yaml` merges and `release-on-merge.yaml` cuts the first release containing it. Until then, consumer repos must add the caller workflow manually (see §3). +A `pr-policy` starter template is available in `workflow-templates/`. Before the template produces passing human PR checks, the three Jira org secrets must be granted to the consumer repo (see §1). ### Ref pinning policy @@ -261,14 +261,14 @@ permissions: jobs: policy: - uses: Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml@ # vX.Y.Z + uses: Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml@9c1ecf942894b19aba5c71b85b41906c6c83b749 # v1.0.5 secrets: JIRA_CLOUD_ID: ${{ secrets.JIRA_CLOUD_ID }} JIRA_SERVICE_ACCOUNT_EMAIL: ${{ secrets.JIRA_SERVICE_ACCOUNT_EMAIL }} JIRA_API_TOKEN: ${{ secrets.JIRA_API_TOKEN }} ``` -Replace `` with the SHA of the release that contains `callable-pr-policy.yaml`: +Replace `` with the SHA of the release that contains `callable-pr-policy.yaml`. The current pinned SHA is `9c1ecf942894b19aba5c71b85b41906c6c83b749` (v1.0.5). To resolve the SHA for a future release: ```bash gh api /repos/Sea-Haven-Industries/.github/commits/vX.Y.Z --jq .sha diff --git a/workflow-templates/pr-policy.properties.json b/workflow-templates/pr-policy.properties.json new file mode 100644 index 0000000..0ec0b1b --- /dev/null +++ b/workflow-templates/pr-policy.properties.json @@ -0,0 +1,7 @@ +{ + "name": "Sea Haven — PR Policy", + "description": "Validates PR title convention (type/scope/Jira key), branch naming, four-section body, commit subjects, AI attribution footers, and workflow supply-chain pins via the org callable policy workflow. Requires JIRA_CLOUD_ID, JIRA_SERVICE_ACCOUNT_EMAIL, and JIRA_API_TOKEN org secrets granted to the repo.", + "iconName": "octicon-checklist", + "categories": ["Automation", "Utilities"], + "filePatterns": [] +} diff --git a/workflow-templates/pr-policy.yml b/workflow-templates/pr-policy.yml new file mode 100644 index 0000000..72876e5 --- /dev/null +++ b/workflow-templates/pr-policy.yml @@ -0,0 +1,21 @@ +name: PR Policy +on: + pull_request: + types: [opened, reopened, synchronize, edited, labeled, unlabeled, ready_for_review] + +concurrency: + group: "policy-${{ github.event.pull_request.number }}" + cancel-in-progress: true + +permissions: + contents: read + issues: read + pull-requests: read + +jobs: + policy: + uses: Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml@9c1ecf942894b19aba5c71b85b41906c6c83b749 # v1.0.5 + secrets: + JIRA_CLOUD_ID: ${{ secrets.JIRA_CLOUD_ID }} + JIRA_SERVICE_ACCOUNT_EMAIL: ${{ secrets.JIRA_SERVICE_ACCOUNT_EMAIL }} + JIRA_API_TOKEN: ${{ secrets.JIRA_API_TOKEN }}