docs: refresh .github README and workflow-templates (INFRA-142) (#73)

- README: mark compliance-audit.yaml deprecated (2026-06-10), document all
  12 reusable workflows (was 6), add workflow-templates and action-pinning
  policy sections
- dependency-review.yml template: convert to thin caller of
  callable-dependency-review.yaml (was inlining dependency-review-action@v4,
  drifted from callable @v5)
- callable-dependency-review.yaml: preserve comment-summary-in-pr on-failure
  and grant pull-requests: write
- add labeler.yml + labeler.properties.json starter template
This commit is contained in:
Adam Moussa 2026-07-08 16:21:37 -04:00 • committed by GitHub
parent 4eff8bbc6d
commit fc75158c94
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
5 changed files with 53 additions and 10 deletions

View file

@ -3,6 +3,7 @@ on:
workflow_call:
permissions:
contents: read
pull-requests: write
jobs:
dependency-review:
runs-on: ubuntu-latest
@ -11,3 +12,4 @@ jobs:
- uses: actions/dependency-review-action@v5
with:
fail-on-severity: high
comment-summary-in-pr: on-failure

View file

@ -16,7 +16,33 @@ Organization-level GitHub configuration for Sea Haven Industries.
**`.github/workflows/cd-cdk.yaml`** — Reusable CD workflow for CDK repos (TypeScript and Python). Runs `cdk deploy --all` with OIDC credentials. Supports optional Python setup for Python CDK repos and QEMU emulation for cross-platform Docker builds.
**`.github/workflows/compliance-audit.yaml`** — Scheduled weekly audit (Mondays 10am ET) that checks all org repos for compliance with Sea Haven conventions. Creates GitHub issues on repos with violations. Can also be triggered manually via `workflow_dispatch`. Uses the `claude-code-ci` GitHub App + `ANTHROPIC_API_KEY` (see Setup).
**`.github/workflows/ci-python-app.yaml`** — Reusable CI for non-SAM Python apps (ruff check + format, optional pytest; no SAM validate).
**`.github/workflows/ci-dotnet.yaml`** — Reusable CI for .NET solutions (`dotnet build`, optional `dotnet test`; SDK version and solution path as inputs).
**`.github/workflows/ci-static.yaml`** — Reusable CI for static sites (e.g. Eleventy builds for seahaven-site).
**`.github/workflows/cd-mobile-ios.yaml`** — Reusable CD for iOS apps via Fastlane to TestFlight (Node + Ruby setup inputs).
**`.github/workflows/callable-labeler.yaml`** — Org-wide PR auto-labeler. Label rules live inline here (single source of truth) — consumer repos need only a thin caller with `contents: read`, `pull-requests: write`, and `issues: write`; no per-repo labeler.yml.
**`.github/workflows/callable-dependency-review.yaml`** — Dependency review on PRs, failing on high severity. Requires Dependency Graph.
**`.github/workflows/ci.yaml`** — Self-CI for this repo: actionlint (checksum-verified install) over all workflow files, emitting the required `ci / ci` status context.
**`.github/workflows/compliance-audit.yaml`** — **DEPRECATED (2026-06-10).** The weekly scheduled org-wide audit has been retired: the schedule was removed and the workflow is disabled in the Actions tab (manual `workflow_dispatch` only, kept for historical reference). Repo compliance is now handled by the Claude Code App on pull requests and the engineering handbook directly. Safe to delete in a future cleanup.
### Workflow templates (`workflow-templates/`)
Starter workflows offered on the org's **Actions → New workflow** page: `ci-python`, `ci-node`, `cdk-deploy`, `sam-deploy`, `dependency-review`, `labeler`, `triage`. Each is a thin caller of the corresponding reusable workflow above (`triage` is standalone). Every template has a paired `properties.json` (name, description, icon, `filePatterns` for auto-suggestion). Replace any `REPLACE-ME` placeholders before enabling.
### Action pinning policy
Third-party action refs across the org follow a tiered policy:
- **High-trust / high-blast-radius third-party actions are SHA-pinned** with a trailing version comment (e.g. `actions/labeler` in `callable-labeler.yaml`), and binary installs are checksum-verified (actionlint in `ci.yaml`). Dependabot keeps the SHA current via its trailing-comment mechanism.
- **Common first-party actions** (`actions/checkout`, `actions/dependency-review-action`, `actions/github-script`) are pinned to a **major tag** (`@v7`, `@v5`, …) and kept current by Dependabot version updates gated by CI.
- **Org reusable workflows** are referenced at **`@main`** (`uses: Sea-Haven-Industries/.github/.github/workflows/…@main`). This is deliberate: caller and callable share one trust domain, and pinning callers to a SHA would freeze every consumer against central fixes. Templates in `workflow-templates/` follow the same `@main` convention.
### PR Reviews

View file

@ -9,12 +9,4 @@ permissions:
jobs:
dependency-review:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v7
- name: Dependency Review
uses: actions/dependency-review-action@v4
with:
fail-on-severity: high
comment-summary-in-pr: on-failure
uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@main

View file

@ -0,0 +1,7 @@
{
"name": "Sea Haven — PR Labeler",
"description": "Auto-labels PRs (infra/app/ci/docs/dependencies/tests) via the org callable labeler. Label rules live centrally in Sea-Haven-Industries/.github — no per-repo labeler.yml needed.",
"iconName": "octicon-tag",
"categories": ["Automation"],
"filePatterns": []
}

View file

@ -0,0 +1,16 @@
name: labeler
on:
pull_request:
# All three permission grants are load-bearing: reusable-workflow permissions can
# only be downgraded from the caller, so omitting one (e.g. issues:write) either
# fails to create labels or triggers a silent startup_failure. `pull_request`
# (NOT pull_request_target) is correct — the org takes no fork PRs.
permissions:
contents: read
pull-requests: write
issues: write
jobs:
label:
uses: Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml@main