Merge branch 'main' into chore/remove-retired-review-tooling

This commit is contained in:
Adam Moussa 2026-07-28 12:45:27 -04:00 • committed by GitHub
commit 8d8d832757
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
15 changed files with 133 additions and 0 deletions

View file

@ -20,6 +20,9 @@ on:
type: boolean type: boolean
default: true default: true
permissions:
contents: read
jobs: jobs:
ci: ci:
runs-on: ubuntu-latest runs-on: ubuntu-latest

View file

@ -44,6 +44,9 @@ on:
type: boolean type: boolean
default: true default: true
permissions:
contents: read
jobs: jobs:
ci: ci:
runs-on: ubuntu-latest runs-on: ubuntu-latest

View file

@ -56,6 +56,9 @@ on:
type: string type: string
default: "template.yaml" default: "template.yaml"
permissions:
contents: read
jobs: jobs:
ci: ci:
runs-on: ubuntu-latest runs-on: ubuntu-latest

View file

@ -6,5 +6,9 @@ on:
jobs: jobs:
deploy: deploy:
uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@555d07c3a240689a81668026787eba089df4c975 # main uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@555d07c3a240689a81668026787eba089df4c975 # main
with:
# Matches local dev (Node 24 / npm 11, lockfileVersion 3). This is also the
# reusable workflow's default — passed explicitly to pin against drift.
node-version: "24"
secrets: secrets:
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }} deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}

View file

@ -0,0 +1,7 @@
{
"name": "Sea Haven — CI (.NET)",
"description": "Runs dotnet restore, build (Release), and dotnet test for a solution or project via the org reusable workflow.",
"iconName": "octicon-checklist",
"categories": ["C#", "Continuous integration"],
"filePatterns": ["\\.csproj$", "\\.sln$"]
}

View file

@ -0,0 +1,14 @@
name: CI (.NET)
on:
pull_request:
branches: [main]
jobs:
ci:
# Job id MUST stay `ci`: the reusable's job is also `ci`, so the check
# context resolves to the required `ci / ci`.
#
# Every input is optional. Common overrides: `solution` (defaults to *.sln
# in the working directory), `working-directory`, and `dotnet-version`
# (defaults to 8.0.x). This reusable has no `node-version` input.
uses: Sea-Haven-Industries/.github/.github/workflows/ci-dotnet.yaml@555d07c3a240689a81668026787eba089df4c975 # main

View file

@ -6,3 +6,7 @@ on:
jobs: jobs:
ci: ci:
uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@555d07c3a240689a81668026787eba089df4c975 # main uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@555d07c3a240689a81668026787eba089df4c975 # main
with:
# Matches local dev (Node 24 / npm 11, lockfileVersion 3). This is also the
# reusable workflow's default — passed explicitly to pin against drift.
node-version: "24"

View file

@ -0,0 +1,7 @@
{
"name": "Sea Haven — CI (Python / app)",
"description": "Runs ruff check, ruff format --check, a pytest collect-only import check, and an optional subproject suite via the org reusable workflow. For Python repos that do not deploy via SAM or CDK.",
"iconName": "octicon-checklist",
"categories": ["Python", "Continuous integration"],
"filePatterns": ["requirements.*\\.txt$", "pyproject\\.toml$"]
}

View file

@ -0,0 +1,14 @@
name: CI (Python / app)
on:
pull_request:
branches: [main]
jobs:
ci:
# Job id MUST stay `ci`: the reusable's aggregator job is also `ci`, so the
# check context resolves to the required `ci / ci`.
#
# Every input is optional. Common overrides: `source-dirs` (ruff targets),
# `requirements` (non-default requirements file), `subproject-dir` (a
# self-contained suite that must run in its own working directory).
uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-app.yaml@555d07c3a240689a81668026787eba089df4c975 # main

View file

@ -0,0 +1,7 @@
{
"name": "Sea Haven — CI (Static Site)",
"description": "Validates static HTML/CSS/JS sites (S3 + CloudFront repos): htmlhint, JSON-LD parsing, sitemap.xml well-formedness, and internal link resolution via the org reusable workflow.",
"iconName": "octicon-checklist",
"categories": ["HTML", "Continuous integration"],
"filePatterns": ["index\\.html$"]
}

View file

@ -0,0 +1,18 @@
name: CI (Static Site)
on:
pull_request:
branches: [main]
jobs:
ci:
# Job id MUST stay `ci`: the reusable's job is also `ci`, so the check
# context resolves to the required `ci / ci`.
uses: Sea-Haven-Industries/.github/.github/workflows/ci-static.yaml@555d07c3a240689a81668026787eba089df4c975 # main
with:
# Pinned explicitly (handbook): local dev is Node 24 / npm 11, which
# generates lockfileVersion 3. Being explicit avoids lockfile drift.
node-version: "24"
# Defaults to source mode — the checks run against the repo root. For a
# templated site (Eleventy, Astro), add `build-command` plus `check-dir`
# so the checks validate the BUILT output that actually ships; otherwise
# they pass vacuously against source templates that contain no HTML.

View file

@ -0,0 +1,7 @@
{
"name": "Sea Haven — CI (TypeScript / frontend)",
"description": "Runs the Sea Haven standards gate, format:check, lint, build, unit tests, and a Playwright browser smoke for bundled Vite/React/Vue apps via the org reusable workflow.",
"iconName": "octicon-checklist",
"categories": ["TypeScript", "JavaScript", "Continuous integration"],
"filePatterns": ["package\\.json$", "vite\\.config\\.[jt]s$", "playwright\\.config\\.[jt]s$"]
}

View file

@ -0,0 +1,14 @@
name: CI (TypeScript / frontend)
on:
pull_request:
branches: [main]
jobs:
ci:
# Job id MUST stay `ci`: the reusable's job is also `ci`, so the check
# context resolves to the required `ci / ci`.
uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-frontend.yaml@555d07c3a240689a81668026787eba089df4c975 # main
with:
# Pinned explicitly (handbook): local dev is Node 24 / npm 11, which
# generates lockfileVersion 3. Being explicit avoids lockfile drift.
node-version: "24"

View file

@ -0,0 +1,7 @@
{
"name": "Sea Haven — Deploy (iOS / TestFlight)",
"description": "Builds the iOS app with Fastlane and uploads it to TestFlight on push to main, using the org reusable cd-mobile-ios workflow. Requires the AWS_DEPLOY_ROLE_ARN, MATCH_PASSWORD, ASC_KEY_ID, ASC_ISSUER_ID and ASC_KEY_CONTENT repo secrets.",
"iconName": "octicon-rocket",
"categories": ["Deployment", "Mobile", "JavaScript"],
"filePatterns": ["Gemfile$", "app\\.json$", "metro\\.config\\.[cm]?js$"]
}

View file

@ -0,0 +1,21 @@
name: Deploy (iOS / TestFlight)
on:
push:
branches: [main]
jobs:
deploy:
uses: Sea-Haven-Industries/.github/.github/workflows/cd-mobile-ios.yaml@555d07c3a240689a81668026787eba089df4c975 # main
with:
# Pinned explicitly (handbook): local dev is Node 24 / npm 11, which
# generates lockfileVersion 3. Being explicit avoids lockfile drift.
node-version: "24"
secrets:
# All five are required. deploy-role-arn is the repo's OIDC role, used
# here to read the fastlane match certificate store from S3; the four
# asc-*/match-* values come from App Store Connect and the match repo.
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}
match-password: ${{ secrets.MATCH_PASSWORD }}
asc-key-id: ${{ secrets.ASC_KEY_ID }}
asc-issuer-id: ${{ secrets.ASC_ISSUER_ID }}
asc-key-content: ${{ secrets.ASC_KEY_CONTENT }}