diff --git a/.github/workflows/callable-dependency-review.yaml b/.github/workflows/callable-dependency-review.yaml index e186044..3845e0b 100644 --- a/.github/workflows/callable-dependency-review.yaml +++ b/.github/workflows/callable-dependency-review.yaml @@ -3,6 +3,7 @@ on: workflow_call: permissions: contents: read + pull-requests: write jobs: dependency-review: runs-on: ubuntu-latest @@ -11,3 +12,4 @@ jobs: - uses: actions/dependency-review-action@v5 with: fail-on-severity: high + comment-summary-in-pr: on-failure diff --git a/README.md b/README.md index 096beb9..56c0367 100644 --- a/README.md +++ b/README.md @@ -16,7 +16,33 @@ Organization-level GitHub configuration for Sea Haven Industries. **`.github/workflows/cd-cdk.yaml`** — Reusable CD workflow for CDK repos (TypeScript and Python). Runs `cdk deploy --all` with OIDC credentials. Supports optional Python setup for Python CDK repos and QEMU emulation for cross-platform Docker builds. -**`.github/workflows/compliance-audit.yaml`** — Scheduled weekly audit (Mondays 10am ET) that checks all org repos for compliance with Sea Haven conventions. Creates GitHub issues on repos with violations. Can also be triggered manually via `workflow_dispatch`. Uses the `claude-code-ci` GitHub App + `ANTHROPIC_API_KEY` (see Setup). +**`.github/workflows/ci-python-app.yaml`** — Reusable CI for non-SAM Python apps (ruff check + format, optional pytest; no SAM validate). + +**`.github/workflows/ci-dotnet.yaml`** — Reusable CI for .NET solutions (`dotnet build`, optional `dotnet test`; SDK version and solution path as inputs). + +**`.github/workflows/ci-static.yaml`** — Reusable CI for static sites (e.g. Eleventy builds for seahaven-site). + +**`.github/workflows/cd-mobile-ios.yaml`** — Reusable CD for iOS apps via Fastlane to TestFlight (Node + Ruby setup inputs). + +**`.github/workflows/callable-labeler.yaml`** — Org-wide PR auto-labeler. Label rules live inline here (single source of truth) — consumer repos need only a thin caller with `contents: read`, `pull-requests: write`, and `issues: write`; no per-repo labeler.yml. + +**`.github/workflows/callable-dependency-review.yaml`** — Dependency review on PRs, failing on high severity. Requires Dependency Graph. + +**`.github/workflows/ci.yaml`** — Self-CI for this repo: actionlint (checksum-verified install) over all workflow files, emitting the required `ci / ci` status context. + +**`.github/workflows/compliance-audit.yaml`** — **DEPRECATED (2026-06-10).** The weekly scheduled org-wide audit has been retired: the schedule was removed and the workflow is disabled in the Actions tab (manual `workflow_dispatch` only, kept for historical reference). Repo compliance is now handled by the Claude Code App on pull requests and the engineering handbook directly. Safe to delete in a future cleanup. + +### Workflow templates (`workflow-templates/`) + +Starter workflows offered on the org's **Actions → New workflow** page: `ci-python`, `ci-node`, `cdk-deploy`, `sam-deploy`, `dependency-review`, `labeler`, `triage`. Each is a thin caller of the corresponding reusable workflow above (`triage` is standalone). Every template has a paired `properties.json` (name, description, icon, `filePatterns` for auto-suggestion). Replace any `REPLACE-ME` placeholders before enabling. + +### Action pinning policy + +Third-party action refs across the org follow a tiered policy: + +- **High-trust / high-blast-radius third-party actions are SHA-pinned** with a trailing version comment (e.g. `actions/labeler` in `callable-labeler.yaml`), and binary installs are checksum-verified (actionlint in `ci.yaml`). Dependabot keeps the SHA current via its trailing-comment mechanism. +- **Common first-party actions** (`actions/checkout`, `actions/dependency-review-action`, `actions/github-script`) are pinned to a **major tag** (`@v7`, `@v5`, …) and kept current by Dependabot version updates gated by CI. +- **Org reusable workflows** are referenced at **`@main`** (`uses: Sea-Haven-Industries/.github/.github/workflows/…@main`). This is deliberate: caller and callable share one trust domain, and pinning callers to a SHA would freeze every consumer against central fixes. Templates in `workflow-templates/` follow the same `@main` convention. ### PR Reviews diff --git a/workflow-templates/dependency-review.yml b/workflow-templates/dependency-review.yml index 059ea47..40aaa32 100644 --- a/workflow-templates/dependency-review.yml +++ b/workflow-templates/dependency-review.yml @@ -9,12 +9,4 @@ permissions: jobs: dependency-review: - runs-on: ubuntu-latest - steps: - - name: Checkout - uses: actions/checkout@v7 - - name: Dependency Review - uses: actions/dependency-review-action@v4 - with: - fail-on-severity: high - comment-summary-in-pr: on-failure + uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@main diff --git a/workflow-templates/labeler.properties.json b/workflow-templates/labeler.properties.json new file mode 100644 index 0000000..adf31b7 --- /dev/null +++ b/workflow-templates/labeler.properties.json @@ -0,0 +1,7 @@ +{ + "name": "Sea Haven — PR Labeler", + "description": "Auto-labels PRs (infra/app/ci/docs/dependencies/tests) via the org callable labeler. Label rules live centrally in Sea-Haven-Industries/.github — no per-repo labeler.yml needed.", + "iconName": "octicon-tag", + "categories": ["Automation"], + "filePatterns": [] +} diff --git a/workflow-templates/labeler.yml b/workflow-templates/labeler.yml new file mode 100644 index 0000000..5914610 --- /dev/null +++ b/workflow-templates/labeler.yml @@ -0,0 +1,16 @@ +name: labeler +on: + pull_request: + +# All three permission grants are load-bearing: reusable-workflow permissions can +# only be downgraded from the caller, so omitting one (e.g. issues:write) either +# fails to create labels or triggers a silent startup_failure. `pull_request` +# (NOT pull_request_target) is correct — the org takes no fork PRs. +permissions: + contents: read + pull-requests: write + issues: write + +jobs: + label: + uses: Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml@main