From c792dceb8b8c54832bf1e7ca402062edd61b3723 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Fri, 21 Aug 2026 17:23:12 -0400 Subject: [PATCH] ci: drop this repo's PR policy caller --- .github/workflows/policy.yaml | 22 ---------------------- README.md | 2 -- 2 files changed, 24 deletions(-) delete mode 100644 .github/workflows/policy.yaml diff --git a/.github/workflows/policy.yaml b/.github/workflows/policy.yaml deleted file mode 100644 index c65c4f6..0000000 --- a/.github/workflows/policy.yaml +++ /dev/null @@ -1,22 +0,0 @@ -name: PR Policy - -on: - pull_request: - types: [opened, reopened, synchronize, edited, labeled, unlabeled, ready_for_review] - -concurrency: - group: "policy-${{ github.event.pull_request.number }}" - cancel-in-progress: true - -permissions: - contents: read - issues: read - pull-requests: read - -jobs: - policy: - uses: Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml@e5691d8a7f96ac4d5a841a82975ff0a4354d53ac # v1.0.7 - secrets: - JIRA_CLOUD_ID: ${{ secrets.JIRA_CLOUD_ID }} - JIRA_SERVICE_ACCOUNT_EMAIL: ${{ secrets.JIRA_SERVICE_ACCOUNT_EMAIL }} - JIRA_API_TOKEN: ${{ secrets.JIRA_API_TOKEN }} diff --git a/README.md b/README.md index 4c9e4e3..76881d5 100644 --- a/README.md +++ b/README.md @@ -64,8 +64,6 @@ The supply-chain check operates in **diff mode**: for modified or renamed workfl **`.github/workflows/release-on-merge.yaml`** — Repo automation (not callable): cuts a tag and GitHub Release for **this** repo whenever a merge to `main` changes a reusable workflow, so Dependabot has a release to advance consumer SHA pins to (see the pinning policy below). -**`.github/workflows/policy.yaml`** — This repo's own thin caller of `callable-pr-policy.yaml`, so the PR policy gate runs on `.github`'s own PRs. Pinned to the remote SHA at v1.0.5; a local `./` path reference is rejected by the supply-chain gate. The Jira org secrets (`JIRA_CLOUD_ID`, `JIRA_SERVICE_ACCOUNT_EMAIL`, `JIRA_API_TOKEN`) must be granted to this repo before human PRs that include a Jira key can pass the existence check. Dependabot-authored PRs skip the gate. - **`.github/workflows/labeler.yaml`** — This repo's own thin caller of `callable-labeler.yaml`, so the labeler runs on `.github`'s own PRs. **`.github/workflows/ci.yaml`** — Self-CI for this repo: actionlint (checksum-verified install) over all workflow files, emitting the required `ci / ci` status context. Its shellcheck integration is enabled, so `run:` bodies are shell-linted too; the two deploy steps that rely on intentional word-splitting (`sam deploy … $PARAMS`, `cdk deploy $STACKS`) carry a per-line, commented `# shellcheck disable=SC2086` rather than being quoted or globally exempted.