mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-09-30 05:53:12 +00:00
docs: fix README review drift + add community-health files (#48)
INFRA-69: README documented the deleted claude-code-review.yaml workflow and its rollout as the live PR-review setup. PR reviews are handled by the official Claude Code App (since 2026-05-13); corrected the workflow list, added a PR Reviews note, marked the legacy rollout script, and replaced the obsolete rollout step. Preserved the claude-code-ci App + secrets (compliance-audit still uses them). INFRA-68: add SECURITY.md (private vuln reporting via GitHub advisory / email) and SUPPORT.md (Jira INFRA, handbook, security pointer).
This commit is contained in:
parent
b4d9c32a9c
commit
e9263123c7
3 changed files with 34 additions and 9 deletions
16
README.md
16
README.md
|
|
@ -14,13 +14,15 @@ Organization-level GitHub configuration for Sea Haven Industries.
|
|||
|
||||
**`.github/workflows/cd-cdk.yaml`** — Reusable CD workflow for CDK repos (TypeScript and Python). Runs `cdk deploy --all` with OIDC credentials. Supports optional Python setup for Python CDK repos and QEMU emulation for cross-platform Docker builds.
|
||||
|
||||
**`.github/workflows/claude-code-review.yaml`** — Reusable PR review workflow powered by Claude Code. Individual repos call this via a thin wrapper workflow. Reviews for code correctness, security issues, and Sea Haven conventions (kebab-case, secrets placement, Lambda defaults).
|
||||
**`.github/workflows/compliance-audit.yaml`** — Scheduled weekly audit (Mondays 10am ET) that checks all org repos for compliance with Sea Haven conventions. Creates GitHub issues on repos with violations. Can also be triggered manually via `workflow_dispatch`. Uses the `claude-code-ci` GitHub App + `ANTHROPIC_API_KEY` (see Setup).
|
||||
|
||||
**`.github/workflows/compliance-audit.yaml`** — Scheduled weekly audit (Mondays 10am ET) that checks all org repos for compliance with Sea Haven conventions. Creates GitHub issues on repos with violations. Can also be triggered manually via `workflow_dispatch`.
|
||||
### PR Reviews
|
||||
|
||||
PR reviews are handled by the **official Claude Code GitHub App** (installed org-wide, enabled as a required check in the org ruleset) — there is **no review workflow in this repo**. The earlier custom `claude-code-review.yaml` reusable workflow and its per-repo wrapper were retired on 2026-05-13 when the App took over.
|
||||
|
||||
### Scripts
|
||||
|
||||
**`scripts/rollout-review-workflow.sh`** — One-time script to push the thin PR review wrapper workflow to all org repos via the GitHub API. Creates a branch and PR on each repo.
|
||||
**`scripts/rollout-review-workflow.sh`** — **Legacy / superseded.** One-time script that pushed the old PR-review wrapper workflow to all org repos. Obsolete since reviews moved to the official Claude Code App (2026-05-13); retained only for historical reference.
|
||||
|
||||
### AWS deploy roles & IAM (`oidc-deploy-roles.yaml`)
|
||||
|
||||
|
|
@ -254,10 +256,6 @@ Enable optional steps as repos adopt them:
|
|||
| `run-cdk-synth` | `true` | Repo is CDK-based |
|
||||
| `run-sam-validate` | `true` (Python) / `false` (TS) | Repo has a SAM template |
|
||||
|
||||
### 6. Roll out PR reviews to repos
|
||||
### 6. PR reviews
|
||||
|
||||
```bash
|
||||
./scripts/rollout-review-workflow.sh
|
||||
```
|
||||
|
||||
This creates a PR on each repo adding the thin wrapper workflow. Review and merge them, then delete the `add-claude-review` branches.
|
||||
PR reviews run via the **official Claude Code GitHub App** — install it on the org and enable it as a required check in the ruleset. No per-repo workflow or rollout is needed; the legacy `rollout-review-workflow.sh` is retained only for historical reference.
|
||||
|
|
|
|||
17
SECURITY.md
Normal file
17
SECURITY.md
Normal file
|
|
@ -0,0 +1,17 @@
|
|||
# Security Policy
|
||||
|
||||
Sea-Haven-Industries repositories are private and for internal Sea Haven use.
|
||||
|
||||
## Reporting a vulnerability
|
||||
|
||||
If you discover a security vulnerability in any Sea-Haven-Industries repository:
|
||||
|
||||
- **Do not** open a public issue or describe the vulnerability in a pull request.
|
||||
- Open a private **GitHub Security Advisory** on the affected repository (**Security → Advisories → Report a vulnerability**), **or**
|
||||
- Email **adam@seahavenind.com** with the details.
|
||||
|
||||
Please include the affected repository and component, reproduction steps, and the potential impact. We aim to acknowledge reports within 2 business days.
|
||||
|
||||
## Supported versions
|
||||
|
||||
These repositories back internal services that are deployed continuously from `main`. Only the currently deployed revision is supported — there are no tagged releases to patch retroactively. Fixes are rolled forward through the normal CI/CD pipeline.
|
||||
10
SUPPORT.md
Normal file
10
SUPPORT.md
Normal file
|
|
@ -0,0 +1,10 @@
|
|||
# Support
|
||||
|
||||
Sea-Haven-Industries repositories are private and intended for internal Sea Haven use; external support is not provided.
|
||||
|
||||
## Where to go
|
||||
|
||||
- **Bugs, feature requests, infrastructure work** — file a ticket in Jira (**INFRA** project) or open an issue on the relevant repository.
|
||||
- **Operational or urgent issues** — contact Adam Moussa (adam@seahavenind.com).
|
||||
- **Engineering conventions and standards** — see the [engineering-handbook](https://github.com/Sea-Haven-Industries/engineering-handbook).
|
||||
- **Security vulnerabilities** — follow [SECURITY.md](SECURITY.md) (do not open a public issue).
|
||||
Loading…
Add table
Reference in a new issue