docs: fix README review drift + add community-health files (#48)

INFRA-69: README documented the deleted claude-code-review.yaml workflow and
its rollout as the live PR-review setup. PR reviews are handled by the official
Claude Code App (since 2026-05-13); corrected the workflow list, added a PR
Reviews note, marked the legacy rollout script, and replaced the obsolete
rollout step. Preserved the claude-code-ci App + secrets (compliance-audit
still uses them).

INFRA-68: add SECURITY.md (private vuln reporting via GitHub advisory / email)
and SUPPORT.md (Jira INFRA, handbook, security pointer).
This commit is contained in:
Adam Moussa 2026-06-10 15:35:31 -04:00 • committed by GitHub
parent b4d9c32a9c
commit e9263123c7
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
3 changed files with 34 additions and 9 deletions

View file

@ -14,13 +14,15 @@ Organization-level GitHub configuration for Sea Haven Industries.
**`.github/workflows/cd-cdk.yaml`** — Reusable CD workflow for CDK repos (TypeScript and Python). Runs `cdk deploy --all` with OIDC credentials. Supports optional Python setup for Python CDK repos and QEMU emulation for cross-platform Docker builds.
**`.github/workflows/claude-code-review.yaml`** — Reusable PR review workflow powered by Claude Code. Individual repos call this via a thin wrapper workflow. Reviews for code correctness, security issues, and Sea Haven conventions (kebab-case, secrets placement, Lambda defaults).
**`.github/workflows/compliance-audit.yaml`** — Scheduled weekly audit (Mondays 10am ET) that checks all org repos for compliance with Sea Haven conventions. Creates GitHub issues on repos with violations. Can also be triggered manually via `workflow_dispatch`. Uses the `claude-code-ci` GitHub App + `ANTHROPIC_API_KEY` (see Setup).
**`.github/workflows/compliance-audit.yaml`** — Scheduled weekly audit (Mondays 10am ET) that checks all org repos for compliance with Sea Haven conventions. Creates GitHub issues on repos with violations. Can also be triggered manually via `workflow_dispatch`.
### PR Reviews
PR reviews are handled by the **official Claude Code GitHub App** (installed org-wide, enabled as a required check in the org ruleset) — there is **no review workflow in this repo**. The earlier custom `claude-code-review.yaml` reusable workflow and its per-repo wrapper were retired on 2026-05-13 when the App took over.
### Scripts
**`scripts/rollout-review-workflow.sh`** — One-time script to push the thin PR review wrapper workflow to all org repos via the GitHub API. Creates a branch and PR on each repo.
**`scripts/rollout-review-workflow.sh`** — **Legacy / superseded.** One-time script that pushed the old PR-review wrapper workflow to all org repos. Obsolete since reviews moved to the official Claude Code App (2026-05-13); retained only for historical reference.
### AWS deploy roles & IAM (`oidc-deploy-roles.yaml`)
@ -254,10 +256,6 @@ Enable optional steps as repos adopt them:
| `run-cdk-synth` | `true` | Repo is CDK-based |
| `run-sam-validate` | `true` (Python) / `false` (TS) | Repo has a SAM template |
### 6. Roll out PR reviews to repos
### 6. PR reviews
```bash
./scripts/rollout-review-workflow.sh
```
This creates a PR on each repo adding the thin wrapper workflow. Review and merge them, then delete the `add-claude-review` branches.
PR reviews run via the **official Claude Code GitHub App** — install it on the org and enable it as a required check in the ruleset. No per-repo workflow or rollout is needed; the legacy `rollout-review-workflow.sh` is retained only for historical reference.

17
SECURITY.md Normal file
View file

@ -0,0 +1,17 @@
# Security Policy
Sea-Haven-Industries repositories are private and for internal Sea Haven use.
## Reporting a vulnerability
If you discover a security vulnerability in any Sea-Haven-Industries repository:
- **Do not** open a public issue or describe the vulnerability in a pull request.
- Open a private **GitHub Security Advisory** on the affected repository (**Security → Advisories → Report a vulnerability**), **or**
- Email **adam@seahavenind.com** with the details.
Please include the affected repository and component, reproduction steps, and the potential impact. We aim to acknowledge reports within 2 business days.
## Supported versions
These repositories back internal services that are deployed continuously from `main`. Only the currently deployed revision is supported — there are no tagged releases to patch retroactively. Fixes are rolled forward through the normal CI/CD pipeline.

10
SUPPORT.md Normal file
View file

@ -0,0 +1,10 @@
# Support
Sea-Haven-Industries repositories are private and intended for internal Sea Haven use; external support is not provided.
## Where to go
- **Bugs, feature requests, infrastructure work** — file a ticket in Jira (**INFRA** project) or open an issue on the relevant repository.
- **Operational or urgent issues** — contact Adam Moussa (adam@seahavenind.com).
- **Engineering conventions and standards** — see the [engineering-handbook](https://github.com/Sea-Haven-Industries/engineering-handbook).
- **Security vulnerabilities** — follow [SECURITY.md](SECURITY.md) (do not open a public issue).