diff --git a/workflow-templates/cdk-deploy.properties.json b/workflow-templates/cdk-deploy.properties.json new file mode 100644 index 0000000..26a9dc4 --- /dev/null +++ b/workflow-templates/cdk-deploy.properties.json @@ -0,0 +1,7 @@ +{ + "name": "Sea Haven — Deploy (CDK)", + "description": "Deploys a CDK stack to AWS (account 328440206208, us-east-1) via OIDC on push to main, using the org reusable cd-cdk workflow.", + "iconName": "octicon-rocket", + "categories": ["Deployment", "TypeScript", "Python"], + "filePatterns": ["cdk\\.json$"] +} diff --git a/workflow-templates/cdk-deploy.yml b/workflow-templates/cdk-deploy.yml new file mode 100644 index 0000000..e092d91 --- /dev/null +++ b/workflow-templates/cdk-deploy.yml @@ -0,0 +1,10 @@ +name: Deploy (CDK) +on: + push: + branches: [main] + +jobs: + deploy: + uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@main + secrets: + deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }} diff --git a/workflow-templates/ci-node.properties.json b/workflow-templates/ci-node.properties.json new file mode 100644 index 0000000..e8c6d62 --- /dev/null +++ b/workflow-templates/ci-node.properties.json @@ -0,0 +1,7 @@ +{ + "name": "Sea Haven — CI (Node / TypeScript / CDK)", + "description": "Runs npm ci, tsc --noEmit, optional ESLint/Jest, and cdk synth via the org reusable workflow.", + "iconName": "octicon-checklist", + "categories": ["TypeScript", "JavaScript", "Continuous integration"], + "filePatterns": ["package\\.json$", "tsconfig\\.json$", "cdk\\.json$"] +} diff --git a/workflow-templates/ci-node.yml b/workflow-templates/ci-node.yml new file mode 100644 index 0000000..eef89ac --- /dev/null +++ b/workflow-templates/ci-node.yml @@ -0,0 +1,8 @@ +name: CI (Node / TypeScript) +on: + pull_request: + branches: [main] + +jobs: + ci: + uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@main diff --git a/workflow-templates/ci-python.properties.json b/workflow-templates/ci-python.properties.json new file mode 100644 index 0000000..b6a8d57 --- /dev/null +++ b/workflow-templates/ci-python.properties.json @@ -0,0 +1,7 @@ +{ + "name": "Sea Haven — CI (Python / SAM)", + "description": "Runs ruff check, ruff format --check, pytest, and sam validate --lint via the org reusable workflow.", + "iconName": "octicon-checklist", + "categories": ["Python", "Continuous integration"], + "filePatterns": ["requirements.*\\.txt$", "template\\.ya?ml$", "pyproject\\.toml$"] +} diff --git a/workflow-templates/ci-python.yml b/workflow-templates/ci-python.yml new file mode 100644 index 0000000..67c697d --- /dev/null +++ b/workflow-templates/ci-python.yml @@ -0,0 +1,10 @@ +name: CI (Python / SAM) +on: + pull_request: + branches: [main] + +jobs: + ci: + uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-sam.yaml@main + with: + run-tests: true diff --git a/workflow-templates/dependency-review.properties.json b/workflow-templates/dependency-review.properties.json new file mode 100644 index 0000000..d5d4633 --- /dev/null +++ b/workflow-templates/dependency-review.properties.json @@ -0,0 +1,7 @@ +{ + "name": "Sea Haven — Dependency Review", + "description": "Scans PRs for vulnerable or newly-introduced dependencies, failing on high severity. Requires Dependency Graph (GHAS on private repos).", + "iconName": "octicon-shield-check", + "categories": ["Security", "Dependency management"], + "filePatterns": ["package\\.json$", "requirements.*\\.txt$", "pyproject\\.toml$"] +} diff --git a/workflow-templates/dependency-review.yml b/workflow-templates/dependency-review.yml new file mode 100644 index 0000000..31ba4a0 --- /dev/null +++ b/workflow-templates/dependency-review.yml @@ -0,0 +1,20 @@ +name: Dependency Review +on: + pull_request: + branches: [main] + +permissions: + contents: read + pull-requests: write + +jobs: + dependency-review: + runs-on: ubuntu-latest + steps: + - name: Checkout + uses: actions/checkout@v6 + - name: Dependency Review + uses: actions/dependency-review-action@v4 + with: + fail-on-severity: high + comment-summary-in-pr: on-failure diff --git a/workflow-templates/labeler.properties.json b/workflow-templates/labeler.properties.json new file mode 100644 index 0000000..06e8b23 --- /dev/null +++ b/workflow-templates/labeler.properties.json @@ -0,0 +1,7 @@ +{ + "name": "Sea Haven — PR Labeler", + "description": "Auto-labels PRs by changed paths (infra / lambda / ci / docs). Requires a .github/labeler.yml config.", + "iconName": "octicon-tag", + "categories": ["Automation", "Pull requests"], + "filePatterns": [".github/labeler\\.ya?ml$"] +} diff --git a/workflow-templates/labeler.yml b/workflow-templates/labeler.yml new file mode 100644 index 0000000..dbe6db3 --- /dev/null +++ b/workflow-templates/labeler.yml @@ -0,0 +1,20 @@ +name: Labeler +on: [pull_request_target] + +permissions: + contents: read + pull-requests: write + +jobs: + label: + runs-on: ubuntu-latest + steps: + # Requires .github/labeler.yml in this repo, e.g.: + # infra: [ 'cdk/**', 'template.yaml', 'oidc-deploy-roles.yaml' ] + # lambda: [ 'lambdas/**', 'src/**', 'functions/**' ] + # ci: [ '.github/workflows/**' ] + # docs: [ '**/*.md' ] + - uses: actions/labeler@v5 + with: + repo-token: ${{ secrets.GITHUB_TOKEN }} + sync-labels: true diff --git a/workflow-templates/sam-deploy.properties.json b/workflow-templates/sam-deploy.properties.json new file mode 100644 index 0000000..4506ac2 --- /dev/null +++ b/workflow-templates/sam-deploy.properties.json @@ -0,0 +1,7 @@ +{ + "name": "Sea Haven — Deploy (SAM)", + "description": "Deploys a SAM stack to AWS (account 328440206208, us-east-1) via OIDC on push to main, using the org reusable cd-sam workflow. Set stack-name and cfn-role-arn before enabling.", + "iconName": "octicon-rocket", + "categories": ["Deployment", "Python"], + "filePatterns": ["template\\.ya?ml$", "samconfig\\.toml$"] +} diff --git a/workflow-templates/sam-deploy.yml b/workflow-templates/sam-deploy.yml new file mode 100644 index 0000000..f24cc70 --- /dev/null +++ b/workflow-templates/sam-deploy.yml @@ -0,0 +1,15 @@ +name: Deploy (SAM) +on: + push: + branches: [main] + +jobs: + deploy: + uses: Sea-Haven-Industries/.github/.github/workflows/cd-sam.yaml@main + with: + # Required: the CloudFormation stack name (kebab-case, matches repo name). + stack-name: $default-branch + # Required: the CloudFormation execution role ARN for this stack. + cfn-role-arn: arn:aws:iam::328440206208:role/REPLACE-ME-cfn-exec-role + secrets: + deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }} diff --git a/workflow-templates/triage.properties.json b/workflow-templates/triage.properties.json new file mode 100644 index 0000000..fa96f51 --- /dev/null +++ b/workflow-templates/triage.properties.json @@ -0,0 +1,7 @@ +{ + "name": "Sea Haven — Issue Triage", + "description": "Labels newly opened/reopened issues with needs-triage for weekly review.", + "iconName": "octicon-inbox", + "categories": ["Automation", "Issues"], + "filePatterns": [] +} diff --git a/workflow-templates/triage.yml b/workflow-templates/triage.yml new file mode 100644 index 0000000..d7a96a9 --- /dev/null +++ b/workflow-templates/triage.yml @@ -0,0 +1,22 @@ +name: Triage +on: + issues: + types: [opened, reopened] + +permissions: + issues: write + +jobs: + triage: + runs-on: ubuntu-latest + steps: + - name: Add needs-triage label + uses: actions/github-script@v7 + with: + script: | + await github.rest.issues.addLabels({ + owner: context.repo.owner, + repo: context.repo.repo, + issue_number: context.issue.number, + labels: ['needs-triage'] + });