mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-09-30 05:53:12 +00:00
ci: add released PR policy self-caller
Refs: PLAT-62
This commit is contained in:
parent
9c1ecf9428
commit
bad3b46cfa
5 changed files with 56 additions and 5 deletions
22
.github/workflows/policy.yaml
vendored
Normal file
22
.github/workflows/policy.yaml
vendored
Normal file
|
|
@ -0,0 +1,22 @@
|
|||
name: PR Policy
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
types: [opened, reopened, synchronize, edited, labeled, unlabeled, ready_for_review]
|
||||
|
||||
concurrency:
|
||||
group: "policy-${{ github.event.pull_request.number }}"
|
||||
cancel-in-progress: true
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
issues: read
|
||||
pull-requests: read
|
||||
|
||||
jobs:
|
||||
policy:
|
||||
uses: Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml@9c1ecf942894b19aba5c71b85b41906c6c83b749 # v1.0.5
|
||||
secrets:
|
||||
JIRA_CLOUD_ID: ${{ secrets.JIRA_CLOUD_ID }}
|
||||
JIRA_SERVICE_ACCOUNT_EMAIL: ${{ secrets.JIRA_SERVICE_ACCOUNT_EMAIL }}
|
||||
JIRA_API_TOKEN: ${{ secrets.JIRA_API_TOKEN }}
|
||||
1
.github/workflows/release-on-merge.yaml
vendored
1
.github/workflows/release-on-merge.yaml
vendored
|
|
@ -30,6 +30,7 @@ on:
|
|||
- ".github/workflows/**"
|
||||
- "!.github/workflows/ci.yaml"
|
||||
- "!.github/workflows/labeler.yaml"
|
||||
- "!.github/workflows/policy.yaml"
|
||||
- "!.github/workflows/release-on-merge.yaml"
|
||||
workflow_dispatch:
|
||||
inputs:
|
||||
|
|
|
|||
10
README.md
10
README.md
|
|
@ -64,7 +64,7 @@ The supply-chain check operates in **diff mode**: for modified or renamed workfl
|
|||
|
||||
**`.github/workflows/release-on-merge.yaml`** — Repo automation (not callable): cuts a tag and GitHub Release for **this** repo whenever a merge to `main` changes a reusable workflow, so Dependabot has a release to advance consumer SHA pins to (see the pinning policy below).
|
||||
|
||||
**`.github/workflows/policy.yaml`** — Intentionally absent from this PR. The self-caller must pin `Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml` to a released 40-char SHA with a matching `# vX.Y.Z` comment; a mutable local `./` path reference is rejected by the supply-chain gate on modified workflow files. The follow-up PR can be opened once this PR merges and `release-on-merge.yaml` cuts the first release containing `callable-pr-policy.yaml`, then using `gh api /repos/Sea-Haven-Industries/.github/commits/vX.Y.Z --jq .sha` to obtain the pin.
|
||||
**`.github/workflows/policy.yaml`** — This repo's own thin caller of `callable-pr-policy.yaml`, so the PR policy gate runs on `.github`'s own PRs. Pinned to the remote SHA at v1.0.5; a local `./` path reference is rejected by the supply-chain gate. The Jira org secrets (`JIRA_CLOUD_ID`, `JIRA_SERVICE_ACCOUNT_EMAIL`, `JIRA_API_TOKEN`) must be granted to this repo before human PR checks can pass (Dependabot and supply-chain checks still run without them).
|
||||
|
||||
**`.github/workflows/labeler.yaml`** — This repo's own thin caller of `callable-labeler.yaml`, so the labeler runs on `.github`'s own PRs.
|
||||
|
||||
|
|
@ -72,9 +72,9 @@ The supply-chain check operates in **diff mode**: for modified or renamed workfl
|
|||
|
||||
### Workflow templates (`workflow-templates/`)
|
||||
|
||||
Starter workflows offered on the org's **Actions → New workflow** page: `cdk-deploy`, `ci-dotnet`, `ci-mobile-ios`, `ci-node`, `ci-python`, `ci-python-app`, `ci-static`, `ci-typescript-frontend`, `dependency-review`, `dotnet-eb-deploy`, `labeler`, `mobile-ios-deploy`, `release`, `sam-deploy`, `triage`. Each is a thin caller of the corresponding reusable workflow above (`triage` is standalone). Every template has a paired `properties.json` (name, description, icon, `filePatterns` for auto-suggestion). Replace any `REPLACE-ME` placeholders before enabling. Templates are not scanned by Dependabot, so refresh their pinned SHAs opportunistically when editing one.
|
||||
Starter workflows offered on the org's **Actions → New workflow** page: `cdk-deploy`, `ci-dotnet`, `ci-mobile-ios`, `ci-node`, `ci-python`, `ci-python-app`, `ci-static`, `ci-typescript-frontend`, `dependency-review`, `dotnet-eb-deploy`, `labeler`, `mobile-ios-deploy`, `pr-policy`, `release`, `sam-deploy`, `triage`. Each is a thin caller of the corresponding reusable workflow above (`triage` is standalone). Every template has a paired `properties.json` (name, description, icon, `filePatterns` for auto-suggestion). Replace any `REPLACE-ME` placeholders before enabling. Templates are not scanned by Dependabot, so refresh their pinned SHAs opportunistically when editing one.
|
||||
|
||||
A `pr-policy` starter template can be added to `workflow-templates/` only after the PR that introduces `callable-pr-policy.yaml` merges and `release-on-merge.yaml` cuts the first release containing it. Until then, consumer repos must add the caller workflow manually (see §3).
|
||||
A `pr-policy` starter template is available in `workflow-templates/`. Before the template produces passing human PR checks, the three Jira org secrets must be granted to the consumer repo (see §1).
|
||||
|
||||
### Ref pinning policy
|
||||
|
||||
|
|
@ -261,14 +261,14 @@ permissions:
|
|||
|
||||
jobs:
|
||||
policy:
|
||||
uses: Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml@<full-commit-sha> # vX.Y.Z
|
||||
uses: Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml@9c1ecf942894b19aba5c71b85b41906c6c83b749 # v1.0.5
|
||||
secrets:
|
||||
JIRA_CLOUD_ID: ${{ secrets.JIRA_CLOUD_ID }}
|
||||
JIRA_SERVICE_ACCOUNT_EMAIL: ${{ secrets.JIRA_SERVICE_ACCOUNT_EMAIL }}
|
||||
JIRA_API_TOKEN: ${{ secrets.JIRA_API_TOKEN }}
|
||||
```
|
||||
|
||||
Replace `<full-commit-sha>` with the SHA of the release that contains `callable-pr-policy.yaml`:
|
||||
Replace `<full-commit-sha>` with the SHA of the release that contains `callable-pr-policy.yaml`. The current pinned SHA is `9c1ecf942894b19aba5c71b85b41906c6c83b749` (v1.0.5). To resolve the SHA for a future release:
|
||||
|
||||
```bash
|
||||
gh api /repos/Sea-Haven-Industries/.github/commits/vX.Y.Z --jq .sha
|
||||
|
|
|
|||
7
workflow-templates/pr-policy.properties.json
Normal file
7
workflow-templates/pr-policy.properties.json
Normal file
|
|
@ -0,0 +1,7 @@
|
|||
{
|
||||
"name": "Sea Haven — PR Policy",
|
||||
"description": "Validates PR title convention (type/scope/Jira key), branch naming, four-section body, commit subjects, AI attribution footers, and workflow supply-chain pins via the org callable policy workflow. Requires JIRA_CLOUD_ID, JIRA_SERVICE_ACCOUNT_EMAIL, and JIRA_API_TOKEN org secrets granted to the repo.",
|
||||
"iconName": "octicon-checklist",
|
||||
"categories": ["Automation", "Utilities"],
|
||||
"filePatterns": []
|
||||
}
|
||||
21
workflow-templates/pr-policy.yml
Normal file
21
workflow-templates/pr-policy.yml
Normal file
|
|
@ -0,0 +1,21 @@
|
|||
name: PR Policy
|
||||
on:
|
||||
pull_request:
|
||||
types: [opened, reopened, synchronize, edited, labeled, unlabeled, ready_for_review]
|
||||
|
||||
concurrency:
|
||||
group: "policy-${{ github.event.pull_request.number }}"
|
||||
cancel-in-progress: true
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
issues: read
|
||||
pull-requests: read
|
||||
|
||||
jobs:
|
||||
policy:
|
||||
uses: Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml@9c1ecf942894b19aba5c71b85b41906c6c83b749 # v1.0.5
|
||||
secrets:
|
||||
JIRA_CLOUD_ID: ${{ secrets.JIRA_CLOUD_ID }}
|
||||
JIRA_SERVICE_ACCOUNT_EMAIL: ${{ secrets.JIRA_SERVICE_ACCOUNT_EMAIL }}
|
||||
JIRA_API_TOKEN: ${{ secrets.JIRA_API_TOKEN }}
|
||||
Loading…
Add table
Reference in a new issue