Add dependency-review workflow and Sea Haven PR checklist (#36)

Add a reusable callable-dependency-review workflow that runs
actions/dependency-review-action with fail-on-severity: high, and
append a Sea Haven checklist to the PR template covering infra,
secrets, PITR, Slack, Confluence, memory, and cross-review.
This commit is contained in:
Adam Moussa 2026-06-05 12:11:36 -04:00 • committed by GitHub
parent 204958e8d9
commit 3f4bf4f54d
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
2 changed files with 23 additions and 0 deletions

View file

@ -16,3 +16,12 @@ PR conventions — see engineering-handbook/pull-requests.md
## Notes
<!-- Anything reviewers should know: migration steps, deploy order, follow-ups, breaking changes. Delete this section if empty. -->
## Sea Haven checklist
- [ ] CDK diff / SAM changeset reviewed (if infra change)
- [ ] Secrets added to Parameter Store / Secrets Manager (not hardcoded)
- [ ] DynamoDB PITR verified on new tables
- [ ] Slack notification tested in staging
- [ ] Confluence Architecture Map updated
- [ ] Memory update queued (if new repo/stack)
- [ ] Cross-review requested (if IAM or Lambda handler signature change)

View file

@ -0,0 +1,14 @@
name: Dependency Review
on:
workflow_call:
permissions:
contents: read
pull-requests: write
jobs:
dependency-review:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v6
- uses: actions/dependency-review-action@v4
with:
fail-on-severity: high