From 3f4bf4f54d7b240d88e65f20bd3c44d43786ff00 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Fri, 5 Jun 2026 12:11:36 -0400 Subject: [PATCH 1/4] Add dependency-review workflow and Sea Haven PR checklist (#36) Add a reusable callable-dependency-review workflow that runs actions/dependency-review-action with fail-on-severity: high, and append a Sea Haven checklist to the PR template covering infra, secrets, PITR, Slack, Confluence, memory, and cross-review. --- .github/PULL_REQUEST_TEMPLATE.md | 9 +++++++++ .github/workflows/callable-dependency-review.yaml | 14 ++++++++++++++ 2 files changed, 23 insertions(+) create mode 100644 .github/workflows/callable-dependency-review.yaml diff --git a/.github/PULL_REQUEST_TEMPLATE.md b/.github/PULL_REQUEST_TEMPLATE.md index 9cab3a8..bf5c9df 100644 --- a/.github/PULL_REQUEST_TEMPLATE.md +++ b/.github/PULL_REQUEST_TEMPLATE.md @@ -16,3 +16,12 @@ PR conventions — see engineering-handbook/pull-requests.md ## Notes + +## Sea Haven checklist +- [ ] CDK diff / SAM changeset reviewed (if infra change) +- [ ] Secrets added to Parameter Store / Secrets Manager (not hardcoded) +- [ ] DynamoDB PITR verified on new tables +- [ ] Slack notification tested in staging +- [ ] Confluence Architecture Map updated +- [ ] Memory update queued (if new repo/stack) +- [ ] Cross-review requested (if IAM or Lambda handler signature change) diff --git a/.github/workflows/callable-dependency-review.yaml b/.github/workflows/callable-dependency-review.yaml new file mode 100644 index 0000000..646225b --- /dev/null +++ b/.github/workflows/callable-dependency-review.yaml @@ -0,0 +1,14 @@ +name: Dependency Review +on: + workflow_call: +permissions: + contents: read + pull-requests: write +jobs: + dependency-review: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v6 + - uses: actions/dependency-review-action@v4 + with: + fail-on-severity: high From 81189e6476245be27b272fdf9b0a057ff4d1aea2 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Fri, 5 Jun 2026 12:11:40 -0400 Subject: [PATCH 2/4] Add org-wide default CODEOWNERS (#37) Set @amoussa1229 as the default owner for all paths so the new required code-owner review rule on the org main-branch ruleset has a reviewer to resolve against. The .github repo CODEOWNERS acts as the org-wide fallback for repos without their own file. --- .github/CODEOWNERS | 1 + 1 file changed, 1 insertion(+) create mode 100644 .github/CODEOWNERS diff --git a/.github/CODEOWNERS b/.github/CODEOWNERS new file mode 100644 index 0000000..cf586fc --- /dev/null +++ b/.github/CODEOWNERS @@ -0,0 +1 @@ +* @amoussa1229 From 73b98a66ac4c5f6444ea394fd8ec7a04bd1e540c Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Fri, 5 Jun 2026 12:11:44 -0400 Subject: [PATCH 3/4] chore(ci): bump actions/checkout to v6 (#34) Bump all actions/checkout references to @v6 (org target). v4 runs on a node runtime version that is being deprecated; v6 is the verified org standard alongside configure-aws-credentials@v6. Ref: engineering-handbook cicd.md (workflow standardization). --- .github/workflows/cd-cdk.yaml | 2 +- .github/workflows/cd-mobile-ios.yaml | 2 +- .github/workflows/cd-sam.yaml | 2 +- .github/workflows/ci-dotnet.yaml | 2 +- .github/workflows/ci-python-sam.yaml | 2 +- .github/workflows/ci-typescript-cdk.yaml | 2 +- .github/workflows/compliance-audit.yaml | 4 ++-- 7 files changed, 8 insertions(+), 8 deletions(-) diff --git a/.github/workflows/cd-cdk.yaml b/.github/workflows/cd-cdk.yaml index 5ed6726..0463b28 100644 --- a/.github/workflows/cd-cdk.yaml +++ b/.github/workflows/cd-cdk.yaml @@ -53,7 +53,7 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 30 steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v6 - uses: docker/setup-qemu-action@v3 if: ${{ inputs.enable-qemu }} diff --git a/.github/workflows/cd-mobile-ios.yaml b/.github/workflows/cd-mobile-ios.yaml index 40036b7..239dd7b 100644 --- a/.github/workflows/cd-mobile-ios.yaml +++ b/.github/workflows/cd-mobile-ios.yaml @@ -60,7 +60,7 @@ jobs: run: working-directory: ${{ inputs.working-directory }} steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v6 - uses: aws-actions/configure-aws-credentials@v4 with: diff --git a/.github/workflows/cd-sam.yaml b/.github/workflows/cd-sam.yaml index 0d8f69f..98d4ac0 100644 --- a/.github/workflows/cd-sam.yaml +++ b/.github/workflows/cd-sam.yaml @@ -40,7 +40,7 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 15 steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v6 - uses: actions/setup-python@v5 with: diff --git a/.github/workflows/ci-dotnet.yaml b/.github/workflows/ci-dotnet.yaml index e12a927..ce88647 100644 --- a/.github/workflows/ci-dotnet.yaml +++ b/.github/workflows/ci-dotnet.yaml @@ -28,7 +28,7 @@ jobs: run: working-directory: ${{ inputs.working-directory }} steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v6 - uses: actions/setup-dotnet@v5 with: diff --git a/.github/workflows/ci-python-sam.yaml b/.github/workflows/ci-python-sam.yaml index a66dc25..85c6cfb 100644 --- a/.github/workflows/ci-python-sam.yaml +++ b/.github/workflows/ci-python-sam.yaml @@ -49,7 +49,7 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 10 steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v6 - uses: actions/setup-python@v5 with: diff --git a/.github/workflows/ci-typescript-cdk.yaml b/.github/workflows/ci-typescript-cdk.yaml index 9d2d6e0..ac7e9a7 100644 --- a/.github/workflows/ci-typescript-cdk.yaml +++ b/.github/workflows/ci-typescript-cdk.yaml @@ -61,7 +61,7 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 30 steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v6 - uses: docker/setup-qemu-action@v3 if: ${{ inputs.enable-qemu }} diff --git a/.github/workflows/compliance-audit.yaml b/.github/workflows/compliance-audit.yaml index dff1e85..2d89c71 100644 --- a/.github/workflows/compliance-audit.yaml +++ b/.github/workflows/compliance-audit.yaml @@ -57,13 +57,13 @@ jobs: repositories: ${{ matrix.repo }},engineering-handbook - name: Checkout repo - uses: actions/checkout@v4 + uses: actions/checkout@v6 with: repository: Sea-Haven-Industries/${{ matrix.repo }} token: ${{ steps.app-token.outputs.token }} - name: Checkout engineering handbook - uses: actions/checkout@v4 + uses: actions/checkout@v6 with: repository: Sea-Haven-Industries/engineering-handbook token: ${{ steps.app-token.outputs.token }} From 7aab740e596dca9c7624e3f659850e32e5e532d3 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Fri, 5 Jun 2026 12:12:30 -0400 Subject: [PATCH 4/4] chore(ci): bump configure-aws-credentials to v6 (#35) Bump all aws-actions/configure-aws-credentials references to @v6 (org target) across the reusable CD workflows. v6 is the verified org standard alongside actions/checkout@v6. Ref: engineering-handbook cicd.md (workflow standardization). --- .github/workflows/cd-cdk.yaml | 2 +- .github/workflows/cd-mobile-ios.yaml | 2 +- .github/workflows/cd-sam.yaml | 2 +- 3 files changed, 3 insertions(+), 3 deletions(-) diff --git a/.github/workflows/cd-cdk.yaml b/.github/workflows/cd-cdk.yaml index 0463b28..8bdce3c 100644 --- a/.github/workflows/cd-cdk.yaml +++ b/.github/workflows/cd-cdk.yaml @@ -90,7 +90,7 @@ jobs: pip install -r "$req" done - - uses: aws-actions/configure-aws-credentials@v4 + - uses: aws-actions/configure-aws-credentials@v6 with: role-to-assume: ${{ secrets.deploy-role-arn }} aws-region: ${{ inputs.region }} diff --git a/.github/workflows/cd-mobile-ios.yaml b/.github/workflows/cd-mobile-ios.yaml index 239dd7b..c20896f 100644 --- a/.github/workflows/cd-mobile-ios.yaml +++ b/.github/workflows/cd-mobile-ios.yaml @@ -62,7 +62,7 @@ jobs: steps: - uses: actions/checkout@v6 - - uses: aws-actions/configure-aws-credentials@v4 + - uses: aws-actions/configure-aws-credentials@v6 with: role-to-assume: ${{ secrets.deploy-role-arn }} aws-region: ${{ inputs.region }} diff --git a/.github/workflows/cd-sam.yaml b/.github/workflows/cd-sam.yaml index 98d4ac0..4be533d 100644 --- a/.github/workflows/cd-sam.yaml +++ b/.github/workflows/cd-sam.yaml @@ -48,7 +48,7 @@ jobs: - uses: aws-actions/setup-sam@v2 - - uses: aws-actions/configure-aws-credentials@v4 + - uses: aws-actions/configure-aws-credentials@v6 with: role-to-assume: ${{ secrets.deploy-role-arn }} aws-region: ${{ inputs.region }}