mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-09-30 04:43:12 +00:00
Add dependency-review workflow and Sea Haven PR checklist (#36)
Add a reusable callable-dependency-review workflow that runs actions/dependency-review-action with fail-on-severity: high, and append a Sea Haven checklist to the PR template covering infra, secrets, PITR, Slack, Confluence, memory, and cross-review.
This commit is contained in:
parent
204958e8d9
commit
3f4bf4f54d
2 changed files with 23 additions and 0 deletions
9
.github/PULL_REQUEST_TEMPLATE.md
vendored
9
.github/PULL_REQUEST_TEMPLATE.md
vendored
|
|
@ -16,3 +16,12 @@ PR conventions — see engineering-handbook/pull-requests.md
|
|||
|
||||
## Notes
|
||||
<!-- Anything reviewers should know: migration steps, deploy order, follow-ups, breaking changes. Delete this section if empty. -->
|
||||
|
||||
## Sea Haven checklist
|
||||
- [ ] CDK diff / SAM changeset reviewed (if infra change)
|
||||
- [ ] Secrets added to Parameter Store / Secrets Manager (not hardcoded)
|
||||
- [ ] DynamoDB PITR verified on new tables
|
||||
- [ ] Slack notification tested in staging
|
||||
- [ ] Confluence Architecture Map updated
|
||||
- [ ] Memory update queued (if new repo/stack)
|
||||
- [ ] Cross-review requested (if IAM or Lambda handler signature change)
|
||||
|
|
|
|||
14
.github/workflows/callable-dependency-review.yaml
vendored
Normal file
14
.github/workflows/callable-dependency-review.yaml
vendored
Normal file
|
|
@ -0,0 +1,14 @@
|
|||
name: Dependency Review
|
||||
on:
|
||||
workflow_call:
|
||||
permissions:
|
||||
contents: read
|
||||
pull-requests: write
|
||||
jobs:
|
||||
dependency-review:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
- uses: actions/dependency-review-action@v4
|
||||
with:
|
||||
fail-on-severity: high
|
||||
Loading…
Add table
Reference in a new issue