diff --git a/README.md b/README.md index 9d754d0..13331c8 100644 --- a/README.md +++ b/README.md @@ -14,13 +14,15 @@ Organization-level GitHub configuration for Sea Haven Industries. **`.github/workflows/cd-cdk.yaml`** — Reusable CD workflow for CDK repos (TypeScript and Python). Runs `cdk deploy --all` with OIDC credentials. Supports optional Python setup for Python CDK repos and QEMU emulation for cross-platform Docker builds. -**`.github/workflows/claude-code-review.yaml`** — Reusable PR review workflow powered by Claude Code. Individual repos call this via a thin wrapper workflow. Reviews for code correctness, security issues, and Sea Haven conventions (kebab-case, secrets placement, Lambda defaults). +**`.github/workflows/compliance-audit.yaml`** — Scheduled weekly audit (Mondays 10am ET) that checks all org repos for compliance with Sea Haven conventions. Creates GitHub issues on repos with violations. Can also be triggered manually via `workflow_dispatch`. Uses the `claude-code-ci` GitHub App + `ANTHROPIC_API_KEY` (see Setup). -**`.github/workflows/compliance-audit.yaml`** — Scheduled weekly audit (Mondays 10am ET) that checks all org repos for compliance with Sea Haven conventions. Creates GitHub issues on repos with violations. Can also be triggered manually via `workflow_dispatch`. +### PR Reviews + +PR reviews are handled by the **official Claude Code GitHub App** (installed org-wide, enabled as a required check in the org ruleset) — there is **no review workflow in this repo**. The earlier custom `claude-code-review.yaml` reusable workflow and its per-repo wrapper were retired on 2026-05-13 when the App took over. ### Scripts -**`scripts/rollout-review-workflow.sh`** — One-time script to push the thin PR review wrapper workflow to all org repos via the GitHub API. Creates a branch and PR on each repo. +**`scripts/rollout-review-workflow.sh`** — **Legacy / superseded.** One-time script that pushed the old PR-review wrapper workflow to all org repos. Obsolete since reviews moved to the official Claude Code App (2026-05-13); retained only for historical reference. ### AWS deploy roles & IAM (`oidc-deploy-roles.yaml`) @@ -254,10 +256,6 @@ Enable optional steps as repos adopt them: | `run-cdk-synth` | `true` | Repo is CDK-based | | `run-sam-validate` | `true` (Python) / `false` (TS) | Repo has a SAM template | -### 6. Roll out PR reviews to repos +### 6. PR reviews -```bash -./scripts/rollout-review-workflow.sh -``` - -This creates a PR on each repo adding the thin wrapper workflow. Review and merge them, then delete the `add-claude-review` branches. +PR reviews run via the **official Claude Code GitHub App** — install it on the org and enable it as a required check in the ruleset. No per-repo workflow or rollout is needed; the legacy `rollout-review-workflow.sh` is retained only for historical reference. diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..ffbba95 --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,17 @@ +# Security Policy + +Sea-Haven-Industries repositories are private and for internal Sea Haven use. + +## Reporting a vulnerability + +If you discover a security vulnerability in any Sea-Haven-Industries repository: + +- **Do not** open a public issue or describe the vulnerability in a pull request. +- Open a private **GitHub Security Advisory** on the affected repository (**Security → Advisories → Report a vulnerability**), **or** +- Email **adam@seahavenind.com** with the details. + +Please include the affected repository and component, reproduction steps, and the potential impact. We aim to acknowledge reports within 2 business days. + +## Supported versions + +These repositories back internal services that are deployed continuously from `main`. Only the currently deployed revision is supported — there are no tagged releases to patch retroactively. Fixes are rolled forward through the normal CI/CD pipeline. diff --git a/SUPPORT.md b/SUPPORT.md new file mode 100644 index 0000000..6854763 --- /dev/null +++ b/SUPPORT.md @@ -0,0 +1,10 @@ +# Support + +Sea-Haven-Industries repositories are private and intended for internal Sea Haven use; external support is not provided. + +## Where to go + +- **Bugs, feature requests, infrastructure work** — file a ticket in Jira (**INFRA** project) or open an issue on the relevant repository. +- **Operational or urgent issues** — contact Adam Moussa (adam@seahavenind.com). +- **Engineering conventions and standards** — see the [engineering-handbook](https://github.com/Sea-Haven-Industries/engineering-handbook). +- **Security vulnerabilities** — follow [SECURITY.md](SECURITY.md) (do not open a public issue).