diff --git a/.github/ISSUE_TEMPLATE/config.yml b/.github/ISSUE_TEMPLATE/config.yml index 692c38d..7e183d1 100644 --- a/.github/ISSUE_TEMPLATE/config.yml +++ b/.github/ISSUE_TEMPLATE/config.yml @@ -1,5 +1,5 @@ blank_issues_enabled: false contact_links: - - name: Internal IT support - url: https://seahaven.atlassian.net/jira/software/projects/INFRA - about: For operational issues, file an INFRA Jira ticket instead. + - name: Jira — DEV / PLAT / SEC + url: https://seahaven.atlassian.net/jira + about: File all org work in Jira (DEV, PLAT, or SEC). INFRA is a closed archive. GitHub Issues are active only on shoc-backend, shoc-frontend-new, and open-swe. diff --git a/.github/ISSUE_TEMPLATE/feature_request.md b/.github/ISSUE_TEMPLATE/feature_request.md index 6444918..c83f223 100644 --- a/.github/ISSUE_TEMPLATE/feature_request.md +++ b/.github/ISSUE_TEMPLATE/feature_request.md @@ -15,7 +15,6 @@ assignees: amoussa1229 ## AWS / integration impact - New or changed AWS resources (Lambda, DynamoDB, S3, API Gateway): - Slack app(s) involved: -- Confluence Architecture Map update needed: yes / no ## Alternatives considered diff --git a/.github/ISSUE_TEMPLATE/infra-change.md b/.github/ISSUE_TEMPLATE/infra-change.md index 74141a3..90d0bf3 100644 --- a/.github/ISSUE_TEMPLATE/infra-change.md +++ b/.github/ISSUE_TEMPLATE/infra-change.md @@ -21,6 +21,4 @@ assignees: amoussa1229 ## Documentation -- [ ] Confluence Architecture Map (id 1540098) update queued - [ ] README updated in same PR -- [ ] Project memory entry queued diff --git a/.github/PULL_REQUEST_TEMPLATE.md b/.github/PULL_REQUEST_TEMPLATE.md index bf5c9df..4a8f12b 100644 --- a/.github/PULL_REQUEST_TEMPLATE.md +++ b/.github/PULL_REQUEST_TEMPLATE.md @@ -1,8 +1,14 @@ ## Summary @@ -15,13 +21,4 @@ PR conventions — see engineering-handbook/pull-requests.md ## Notes - - -## Sea Haven checklist -- [ ] CDK diff / SAM changeset reviewed (if infra change) -- [ ] Secrets added to Parameter Store / Secrets Manager (not hardcoded) -- [ ] DynamoDB PITR verified on new tables -- [ ] Slack notification tested in staging -- [ ] Confluence Architecture Map updated -- [ ] Memory update queued (if new repo/stack) -- [ ] Cross-review requested (if IAM or Lambda handler signature change) + diff --git a/.github/workflows/cd-dotnet-eb.yaml b/.github/workflows/cd-dotnet-eb.yaml index 35a8435..3e9d70c 100644 --- a/.github/workflows/cd-dotnet-eb.yaml +++ b/.github/workflows/cd-dotnet-eb.yaml @@ -4,7 +4,7 @@ name: CD — .NET Elastic Beanstalk # # jobs: # deploy: -# uses: Sea-Haven-Industries/.github/.github/workflows/cd-dotnet-eb.yaml@ # main +# uses: Sea-Haven-Industries/.github/.github/workflows/cd-dotnet-eb.yaml@ # v1.0.4 # with: # project: "Api.Example/Api.Example.csproj" # eb-application: "example-api" diff --git a/.github/workflows/ci-mobile-ios.yaml b/.github/workflows/ci-mobile-ios.yaml index f29874f..8c31458 100644 --- a/.github/workflows/ci-mobile-ios.yaml +++ b/.github/workflows/ci-mobile-ios.yaml @@ -35,7 +35,7 @@ name: CI — Mobile iOS # Caller example: # jobs: # ci: -# uses: Sea-Haven-Industries/.github/.github/workflows/ci-mobile-ios.yaml@ # main +# uses: Sea-Haven-Industries/.github/.github/workflows/ci-mobile-ios.yaml@ # v1.0.4 # with: # working-directory: mobile # cache-dependency-path: mobile/package-lock.json diff --git a/.github/workflows/ci-static.yaml b/.github/workflows/ci-static.yaml index b03d5db..e203970 100644 --- a/.github/workflows/ci-static.yaml +++ b/.github/workflows/ci-static.yaml @@ -15,7 +15,7 @@ name: CI — Static Site # Caller example (build mode): # jobs: # ci: -# uses: Sea-Haven-Industries/.github/.github/workflows/ci-static.yaml@ # main +# uses: Sea-Haven-Industries/.github/.github/workflows/ci-static.yaml@ # v1.0.4 # with: # build-command: "npx @11ty/eleventy" # check-dir: "_site" diff --git a/.github/workflows/ci-typescript-frontend.yaml b/.github/workflows/ci-typescript-frontend.yaml index 18f81bf..fa72813 100644 --- a/.github/workflows/ci-typescript-frontend.yaml +++ b/.github/workflows/ci-typescript-frontend.yaml @@ -13,7 +13,7 @@ name: CI — TypeScript Frontend # Caller example: # jobs: # ci: -# uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-frontend.yaml@ # main +# uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-frontend.yaml@ # v1.0.4 # with: # node-version: "24" diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml index 43c72d0..e1eba01 100644 --- a/.github/workflows/release.yaml +++ b/.github/workflows/release.yaml @@ -32,7 +32,7 @@ name: Release — Tag and GitHub Release # Caller example: # jobs: # release: -# uses: Sea-Haven-Industries/.github/.github/workflows/release.yaml@ # main +# uses: Sea-Haven-Industries/.github/.github/workflows/release.yaml@ # v1.0.4 # with: # version: ${{ inputs.version }} # diff --git a/README.md b/README.md index 26ad712..ea77995 100644 --- a/README.md +++ b/README.md @@ -2,6 +2,28 @@ Organization-level GitHub configuration for Sea Haven Industries. +## Git and PR conventions + +### Branch naming + +`feature/`, `fix/`, `hotfix/`, `chore/`, `docs/`, `refactor/`, `release/` + kebab-case description. Branch names do not contain Jira keys. + +### Commit format + +`type(scope): description` — lowercase, imperative, no trailing period, header ≤ 72 chars. Types: `feat`, `fix`, `docs`, `style`, `refactor`, `perf`, `test`, `build`, `ci`, `chore`, `revert`, `release`. Breaking change: `feat!:` + `BREAKING CHANGE:` footer. + +### PR title + +`type(scope): description (DEV-123)` — the Jira key is required at the end in parentheses. Active projects: **DEV** (product), **PLAT** (platform), **SEC** (security). INFRA is a closed archive. Jira-exempt only: Dependabot PRs and permission-controlled emergency reverts. + +### PR body + +Exactly four headings in order: `## Summary`, `## Validation`, `## Tests`, `## Notes`. Use `None.` under Notes if empty. + +### Deploy path + +The two sanctioned deploy paths are merge to `main` triggering the pipeline and `workflow_dispatch` on that same pipeline. No manual workstation deploys to production. + ## What's in here ### Reusable Workflows @@ -54,8 +76,8 @@ All workflow refs across the org are pinned to full commit SHAs: uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-sam.yaml@ # v1.0.3 ``` - Branch refs are mutable: a bad commit on this repo would flow instantly into every consumer's CI and deploy path, while a SHA pin turns the same change into a reviewable Dependabot PR. Two prerequisites keep pins advancing instead of freezing: every consumer repo's `dependabot.yml` must include the `github-actions` ecosystem (weekly), and Dependabot must be granted access to this repo at the org level (Org Settings → Advanced Security → Global settings → "Grant Dependabot access to repositories"); without the grant, update jobs fail with `git_dependencies_not_reachable` and pins freeze silently. `release-on-merge.yaml` tags this repo on every reusable-workflow change so Dependabot has releases to diff against. When adding a caller by hand, pin to the current tip of `main` (`gh api /repos/Sea-Haven-Industries/.github/commits/main --jq .sha`) and let Dependabot advance it from there. -- **Third-party and first-party actions** (`actions/checkout`, `actions/setup-python`, `actions/labeler`, …) are likewise **SHA-pinned** with a trailing version comment (e.g. `actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1`); Dependabot keeps the SHA and comment current. + Branch refs are mutable: a bad commit on this repo would flow instantly into every consumer's CI and deploy path, while a SHA pin turns the same change into a reviewable Dependabot PR. Two prerequisites keep pins advancing instead of freezing: every consumer repo's `dependabot.yml` must include the `github-actions` ecosystem (weekly), and Dependabot must be granted access to this repo at the org level (Org Settings → Advanced Security → Global settings → "Grant Dependabot access to repositories"); without the grant, update jobs fail with `git_dependencies_not_reachable` and pins freeze silently. `release-on-merge.yaml` tags this repo on every reusable-workflow change so Dependabot has releases to diff against. When adding a caller by hand, pin to the latest release commit (`gh api /repos/Sea-Haven-Industries/.github/commits/vX.Y.Z --jq .sha`), annotate it with `# vX.Y.Z`, and let Dependabot advance it from there. +- **Third-party and first-party actions** (`actions/checkout`, `actions/setup-python`, `actions/labeler`, …) — a subset are already SHA-pinned (e.g. `actions/labeler`, `aws-actions/*`, `docker/setup-qemu-action`, `ruby/setup-ruby`); the remainder (`actions/checkout`, `actions/setup-node`, `actions/setup-python`, `actions/setup-dotnet`, `actions/dependency-review-action`) currently use floating major-version tags. Full SHA pinning for this group is deferred (PLAT backlog); Dependabot will keep SHA and comment current once pins are set. - **Binary installs are checksum-verified** (actionlint in `ci.yaml`). ### AWS deploy roles & IAM (`oidc-deploy-roles.yaml`) @@ -110,7 +132,7 @@ A function's effective permissions are the **intersection** of its own role poli 2. Redeploy the SAM stacks so their roles pick it up (while the exec role still permits it). 3. *Then* tighten the exec role. -Wrong order breaks every SAM deploy. (History: INFRA-103 established the boundary, INFRA-97 scoped the role.) CDK repos are unaffected — they deploy via `cdk-hnb659fds-*` roles, not this execution role. +Wrong order breaks every SAM deploy. CDK repos are unaffected — they deploy via `cdk-hnb659fds-*` roles, not this execution role. This ordering rule is about changing the **boundary** or the conditions that gate it. It does not apply to changes that only add permissions to the exec role. @@ -149,7 +171,7 @@ on: jobs: ci: - uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-sam.yaml@ # + uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-sam.yaml@81cf168170f356d1423d7736f7ce93fd6611ad53 # v1.0.4 ``` **TypeScript CDK repo** (e.g., seahaven-door-unlock-api, seahaven-slack-bot): @@ -162,7 +184,7 @@ on: jobs: ci: - uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@ # + uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@81cf168170f356d1423d7736f7ce93fd6611ad53 # v1.0.4 ``` **Node.js SAM repo** (e.g., payments-dashboard): @@ -175,7 +197,7 @@ on: jobs: ci: - uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@ # + uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@81cf168170f356d1423d7736f7ce93fd6611ad53 # v1.0.4 with: run-typecheck: false run-cdk-synth: false @@ -192,12 +214,12 @@ on: jobs: python: - uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-sam.yaml@ # + uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-sam.yaml@81cf168170f356d1423d7736f7ce93fd6611ad53 # v1.0.4 with: source-dirs: "src" run-sam-validate: false typescript: - uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@ # + uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@81cf168170f356d1423d7736f7ce93fd6611ad53 # v1.0.4 ``` ### 3. Add CD to a repo @@ -214,7 +236,7 @@ on: jobs: deploy: - uses: Sea-Haven-Industries/.github/.github/workflows/cd-sam.yaml@ # + uses: Sea-Haven-Industries/.github/.github/workflows/cd-sam.yaml@81cf168170f356d1423d7736f7ce93fd6611ad53 # v1.0.4 with: stack-name: afterhours-shift-manager cfn-role-arn: arn:aws:iam::328440206208:role/github-cfn-execution-role @@ -234,7 +256,7 @@ on: jobs: deploy: - uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@ # + uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@81cf168170f356d1423d7736f7ce93fd6611ad53 # v1.0.4 secrets: deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }} ``` @@ -249,7 +271,7 @@ on: jobs: deploy: - uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@ # + uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@81cf168170f356d1423d7736f7ce93fd6611ad53 # v1.0.4 with: python-version: "3.12" cdk-dir: cdk @@ -267,7 +289,7 @@ on: jobs: deploy: - uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@ # + uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@81cf168170f356d1423d7736f7ce93fd6611ad53 # v1.0.4 with: enable-qemu: true secrets: @@ -284,7 +306,7 @@ on: jobs: deploy: - uses: Sea-Haven-Industries/.github/.github/workflows/cd-dotnet-eb.yaml@ # + uses: Sea-Haven-Industries/.github/.github/workflows/cd-dotnet-eb.yaml@81cf168170f356d1423d7736f7ce93fd6611ad53 # v1.0.4 with: project: Api.SeaHavenIndustries/Api.SeaHavenIndustries.csproj eb-application: shoc-backend diff --git a/SUPPORT.md b/SUPPORT.md index 6854763..2a136b6 100644 --- a/SUPPORT.md +++ b/SUPPORT.md @@ -4,7 +4,8 @@ Sea-Haven-Industries repositories are private and intended for internal Sea Have ## Where to go -- **Bugs, feature requests, infrastructure work** — file a ticket in Jira (**INFRA** project) or open an issue on the relevant repository. +- **Bugs and feature requests** — file a ticket in Jira (**DEV**, **PLAT**, or **SEC** depending on scope). GitHub Issues are active only on shoc-backend, shoc-frontend-new, and open-swe (contractor/fork intake). +- **Infrastructure and platform work** — use the **PLAT** project. Security issues go in **SEC**. - **Operational or urgent issues** — contact Adam Moussa (adam@seahavenind.com). - **Engineering conventions and standards** — see the [engineering-handbook](https://github.com/Sea-Haven-Industries/engineering-handbook). - **Security vulnerabilities** — follow [SECURITY.md](SECURITY.md) (do not open a public issue). diff --git a/workflow-templates/cdk-deploy.yml b/workflow-templates/cdk-deploy.yml index fb65cd3..0afa2ba 100644 --- a/workflow-templates/cdk-deploy.yml +++ b/workflow-templates/cdk-deploy.yml @@ -5,7 +5,7 @@ on: jobs: deploy: - uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@555d07c3a240689a81668026787eba089df4c975 # main + uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@81cf168170f356d1423d7736f7ce93fd6611ad53 # v1.0.4 with: # Matches local dev (Node 24 / npm 11, lockfileVersion 3). This is also the # reusable workflow's default — passed explicitly to pin against drift. diff --git a/workflow-templates/ci-dotnet.yml b/workflow-templates/ci-dotnet.yml index 29aace2..0f0be14 100644 --- a/workflow-templates/ci-dotnet.yml +++ b/workflow-templates/ci-dotnet.yml @@ -11,4 +11,4 @@ jobs: # Every input is optional. Common overrides: `solution` (defaults to *.sln # in the working directory), `working-directory`, and `dotnet-version` # (defaults to 8.0.x). This reusable has no `node-version` input. - uses: Sea-Haven-Industries/.github/.github/workflows/ci-dotnet.yaml@555d07c3a240689a81668026787eba089df4c975 # main + uses: Sea-Haven-Industries/.github/.github/workflows/ci-dotnet.yaml@81cf168170f356d1423d7736f7ce93fd6611ad53 # v1.0.4 diff --git a/workflow-templates/ci-mobile-ios.yml b/workflow-templates/ci-mobile-ios.yml index 01c348c..b4ca371 100644 --- a/workflow-templates/ci-mobile-ios.yml +++ b/workflow-templates/ci-mobile-ios.yml @@ -7,7 +7,7 @@ jobs: ci: # Job id MUST stay `ci`: the reusable's aggregator job is also `ci`, so the # check context resolves to the required `ci / ci`. - uses: Sea-Haven-Industries/.github/.github/workflows/ci-mobile-ios.yaml@9389e51c10c506caa55f204527452a9e29b0e438 # main + uses: Sea-Haven-Industries/.github/.github/workflows/ci-mobile-ios.yaml@81cf168170f356d1423d7736f7ce93fd6611ad53 # v1.0.4 with: # Matches local dev (Node 24 / npm 11, lockfileVersion 3). This is also # the reusable workflow's default — passed explicitly to pin against drift. diff --git a/workflow-templates/ci-node.yml b/workflow-templates/ci-node.yml index c82818a..3e8e1fb 100644 --- a/workflow-templates/ci-node.yml +++ b/workflow-templates/ci-node.yml @@ -5,7 +5,7 @@ on: jobs: ci: - uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@555d07c3a240689a81668026787eba089df4c975 # main + uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@81cf168170f356d1423d7736f7ce93fd6611ad53 # v1.0.4 with: # Matches local dev (Node 24 / npm 11, lockfileVersion 3). This is also the # reusable workflow's default — passed explicitly to pin against drift. diff --git a/workflow-templates/ci-python-app.yml b/workflow-templates/ci-python-app.yml index 9e23b13..363785b 100644 --- a/workflow-templates/ci-python-app.yml +++ b/workflow-templates/ci-python-app.yml @@ -11,4 +11,4 @@ jobs: # Every input is optional. Common overrides: `source-dirs` (ruff targets), # `requirements` (non-default requirements file), `subproject-dir` (a # self-contained suite that must run in its own working directory). - uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-app.yaml@555d07c3a240689a81668026787eba089df4c975 # main + uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-app.yaml@81cf168170f356d1423d7736f7ce93fd6611ad53 # v1.0.4 diff --git a/workflow-templates/ci-python.yml b/workflow-templates/ci-python.yml index a12000f..a3f09b2 100644 --- a/workflow-templates/ci-python.yml +++ b/workflow-templates/ci-python.yml @@ -5,7 +5,7 @@ on: jobs: ci: - uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-sam.yaml@555d07c3a240689a81668026787eba089df4c975 # main + uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-sam.yaml@81cf168170f356d1423d7736f7ce93fd6611ad53 # v1.0.4 with: run-tests: true # ci-python-sam.yaml declares a `node-version` input (default "24") that diff --git a/workflow-templates/ci-static.yml b/workflow-templates/ci-static.yml index b7a1705..78127ea 100644 --- a/workflow-templates/ci-static.yml +++ b/workflow-templates/ci-static.yml @@ -7,7 +7,7 @@ jobs: ci: # Job id MUST stay `ci`: the reusable's job is also `ci`, so the check # context resolves to the required `ci / ci`. - uses: Sea-Haven-Industries/.github/.github/workflows/ci-static.yaml@555d07c3a240689a81668026787eba089df4c975 # main + uses: Sea-Haven-Industries/.github/.github/workflows/ci-static.yaml@81cf168170f356d1423d7736f7ce93fd6611ad53 # v1.0.4 with: # Pinned explicitly (handbook): local dev is Node 24 / npm 11, which # generates lockfileVersion 3. Being explicit avoids lockfile drift. diff --git a/workflow-templates/ci-typescript-frontend.yml b/workflow-templates/ci-typescript-frontend.yml index 3b75187..14d5649 100644 --- a/workflow-templates/ci-typescript-frontend.yml +++ b/workflow-templates/ci-typescript-frontend.yml @@ -7,7 +7,7 @@ jobs: ci: # Job id MUST stay `ci`: the reusable's job is also `ci`, so the check # context resolves to the required `ci / ci`. - uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-frontend.yaml@555d07c3a240689a81668026787eba089df4c975 # main + uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-frontend.yaml@81cf168170f356d1423d7736f7ce93fd6611ad53 # v1.0.4 with: # Pinned explicitly (handbook): local dev is Node 24 / npm 11, which # generates lockfileVersion 3. Being explicit avoids lockfile drift. diff --git a/workflow-templates/dependency-review.yml b/workflow-templates/dependency-review.yml index 36c0f4e..8c06587 100644 --- a/workflow-templates/dependency-review.yml +++ b/workflow-templates/dependency-review.yml @@ -8,4 +8,4 @@ permissions: jobs: dependency-review: - uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@555d07c3a240689a81668026787eba089df4c975 # main + uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@81cf168170f356d1423d7736f7ce93fd6611ad53 # v1.0.4 diff --git a/workflow-templates/dotnet-eb-deploy.yml b/workflow-templates/dotnet-eb-deploy.yml index 1316bcc..b2db872 100644 --- a/workflow-templates/dotnet-eb-deploy.yml +++ b/workflow-templates/dotnet-eb-deploy.yml @@ -5,7 +5,7 @@ on: jobs: deploy: - uses: Sea-Haven-Industries/.github/.github/workflows/cd-dotnet-eb.yaml@555d07c3a240689a81668026787eba089df4c975 # main + uses: Sea-Haven-Industries/.github/.github/workflows/cd-dotnet-eb.yaml@81cf168170f356d1423d7736f7ce93fd6611ad53 # v1.0.4 with: # Required: the project to publish, relative to the repo root. project: REPLACE-ME-project-csproj diff --git a/workflow-templates/labeler.yml b/workflow-templates/labeler.yml index d07b5b8..217f89b 100644 --- a/workflow-templates/labeler.yml +++ b/workflow-templates/labeler.yml @@ -13,4 +13,4 @@ permissions: jobs: label: - uses: Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml@555d07c3a240689a81668026787eba089df4c975 # main + uses: Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml@81cf168170f356d1423d7736f7ce93fd6611ad53 # v1.0.4 diff --git a/workflow-templates/mobile-ios-deploy.yml b/workflow-templates/mobile-ios-deploy.yml index ece8fd5..95759f4 100644 --- a/workflow-templates/mobile-ios-deploy.yml +++ b/workflow-templates/mobile-ios-deploy.yml @@ -5,7 +5,7 @@ on: jobs: deploy: - uses: Sea-Haven-Industries/.github/.github/workflows/cd-mobile-ios.yaml@555d07c3a240689a81668026787eba089df4c975 # main + uses: Sea-Haven-Industries/.github/.github/workflows/cd-mobile-ios.yaml@81cf168170f356d1423d7736f7ce93fd6611ad53 # v1.0.4 with: # Pinned explicitly (handbook): local dev is Node 24 / npm 11, which # generates lockfileVersion 3. Being explicit avoids lockfile drift. diff --git a/workflow-templates/release.yml b/workflow-templates/release.yml index 1dab305..b0c52ee 100644 --- a/workflow-templates/release.yml +++ b/workflow-templates/release.yml @@ -13,7 +13,7 @@ permissions: jobs: release: - uses: Sea-Haven-Industries/.github/.github/workflows/release.yaml@9389e51c10c506caa55f204527452a9e29b0e438 # main + uses: Sea-Haven-Industries/.github/.github/workflows/release.yaml@81cf168170f356d1423d7736f7ce93fd6611ad53 # v1.0.4 with: version: ${{ inputs.version }} # Tags in this org are v-prefixed MAJOR.MINOR.PATCH; "v" is the default diff --git a/workflow-templates/sam-deploy.yml b/workflow-templates/sam-deploy.yml index f2835a2..54a8deb 100644 --- a/workflow-templates/sam-deploy.yml +++ b/workflow-templates/sam-deploy.yml @@ -5,7 +5,7 @@ on: jobs: deploy: - uses: Sea-Haven-Industries/.github/.github/workflows/cd-sam.yaml@555d07c3a240689a81668026787eba089df4c975 # main + uses: Sea-Haven-Industries/.github/.github/workflows/cd-sam.yaml@81cf168170f356d1423d7736f7ce93fd6611ad53 # v1.0.4 with: # Required: the CloudFormation stack name (kebab-case, matches repo name). # NOTE: this is a literal placeholder on purpose — starter-workflow variables