mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-09-30 15:13:12 +00:00
docs: refresh .github README and workflow-templates (INFRA-142) (#73)
- README: mark compliance-audit.yaml deprecated (2026-06-10), document all 12 reusable workflows (was 6), add workflow-templates and action-pinning policy sections - dependency-review.yml template: convert to thin caller of callable-dependency-review.yaml (was inlining dependency-review-action@v4, drifted from callable @v5) - callable-dependency-review.yaml: preserve comment-summary-in-pr on-failure and grant pull-requests: write - add labeler.yml + labeler.properties.json starter template
This commit is contained in:
parent
4eff8bbc6d
commit
fc75158c94
5 changed files with 53 additions and 10 deletions
|
|
@ -3,6 +3,7 @@ on:
|
|||
workflow_call:
|
||||
permissions:
|
||||
contents: read
|
||||
pull-requests: write
|
||||
jobs:
|
||||
dependency-review:
|
||||
runs-on: ubuntu-latest
|
||||
|
|
@ -11,3 +12,4 @@ jobs:
|
|||
- uses: actions/dependency-review-action@v5
|
||||
with:
|
||||
fail-on-severity: high
|
||||
comment-summary-in-pr: on-failure
|
||||
|
|
|
|||
28
README.md
28
README.md
|
|
@ -16,7 +16,33 @@ Organization-level GitHub configuration for Sea Haven Industries.
|
|||
|
||||
**`.github/workflows/cd-cdk.yaml`** — Reusable CD workflow for CDK repos (TypeScript and Python). Runs `cdk deploy --all` with OIDC credentials. Supports optional Python setup for Python CDK repos and QEMU emulation for cross-platform Docker builds.
|
||||
|
||||
**`.github/workflows/compliance-audit.yaml`** — Scheduled weekly audit (Mondays 10am ET) that checks all org repos for compliance with Sea Haven conventions. Creates GitHub issues on repos with violations. Can also be triggered manually via `workflow_dispatch`. Uses the `claude-code-ci` GitHub App + `ANTHROPIC_API_KEY` (see Setup).
|
||||
**`.github/workflows/ci-python-app.yaml`** — Reusable CI for non-SAM Python apps (ruff check + format, optional pytest; no SAM validate).
|
||||
|
||||
**`.github/workflows/ci-dotnet.yaml`** — Reusable CI for .NET solutions (`dotnet build`, optional `dotnet test`; SDK version and solution path as inputs).
|
||||
|
||||
**`.github/workflows/ci-static.yaml`** — Reusable CI for static sites (e.g. Eleventy builds for seahaven-site).
|
||||
|
||||
**`.github/workflows/cd-mobile-ios.yaml`** — Reusable CD for iOS apps via Fastlane to TestFlight (Node + Ruby setup inputs).
|
||||
|
||||
**`.github/workflows/callable-labeler.yaml`** — Org-wide PR auto-labeler. Label rules live inline here (single source of truth) — consumer repos need only a thin caller with `contents: read`, `pull-requests: write`, and `issues: write`; no per-repo labeler.yml.
|
||||
|
||||
**`.github/workflows/callable-dependency-review.yaml`** — Dependency review on PRs, failing on high severity. Requires Dependency Graph.
|
||||
|
||||
**`.github/workflows/ci.yaml`** — Self-CI for this repo: actionlint (checksum-verified install) over all workflow files, emitting the required `ci / ci` status context.
|
||||
|
||||
**`.github/workflows/compliance-audit.yaml`** — **DEPRECATED (2026-06-10).** The weekly scheduled org-wide audit has been retired: the schedule was removed and the workflow is disabled in the Actions tab (manual `workflow_dispatch` only, kept for historical reference). Repo compliance is now handled by the Claude Code App on pull requests and the engineering handbook directly. Safe to delete in a future cleanup.
|
||||
|
||||
### Workflow templates (`workflow-templates/`)
|
||||
|
||||
Starter workflows offered on the org's **Actions → New workflow** page: `ci-python`, `ci-node`, `cdk-deploy`, `sam-deploy`, `dependency-review`, `labeler`, `triage`. Each is a thin caller of the corresponding reusable workflow above (`triage` is standalone). Every template has a paired `properties.json` (name, description, icon, `filePatterns` for auto-suggestion). Replace any `REPLACE-ME` placeholders before enabling.
|
||||
|
||||
### Action pinning policy
|
||||
|
||||
Third-party action refs across the org follow a tiered policy:
|
||||
|
||||
- **High-trust / high-blast-radius third-party actions are SHA-pinned** with a trailing version comment (e.g. `actions/labeler` in `callable-labeler.yaml`), and binary installs are checksum-verified (actionlint in `ci.yaml`). Dependabot keeps the SHA current via its trailing-comment mechanism.
|
||||
- **Common first-party actions** (`actions/checkout`, `actions/dependency-review-action`, `actions/github-script`) are pinned to a **major tag** (`@v7`, `@v5`, …) and kept current by Dependabot version updates gated by CI.
|
||||
- **Org reusable workflows** are referenced at **`@main`** (`uses: Sea-Haven-Industries/.github/.github/workflows/…@main`). This is deliberate: caller and callable share one trust domain, and pinning callers to a SHA would freeze every consumer against central fixes. Templates in `workflow-templates/` follow the same `@main` convention.
|
||||
|
||||
### PR Reviews
|
||||
|
||||
|
|
|
|||
|
|
@ -9,12 +9,4 @@ permissions:
|
|||
|
||||
jobs:
|
||||
dependency-review:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v7
|
||||
- name: Dependency Review
|
||||
uses: actions/dependency-review-action@v4
|
||||
with:
|
||||
fail-on-severity: high
|
||||
comment-summary-in-pr: on-failure
|
||||
uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@main
|
||||
|
|
|
|||
7
workflow-templates/labeler.properties.json
Normal file
7
workflow-templates/labeler.properties.json
Normal file
|
|
@ -0,0 +1,7 @@
|
|||
{
|
||||
"name": "Sea Haven — PR Labeler",
|
||||
"description": "Auto-labels PRs (infra/app/ci/docs/dependencies/tests) via the org callable labeler. Label rules live centrally in Sea-Haven-Industries/.github — no per-repo labeler.yml needed.",
|
||||
"iconName": "octicon-tag",
|
||||
"categories": ["Automation"],
|
||||
"filePatterns": []
|
||||
}
|
||||
16
workflow-templates/labeler.yml
Normal file
16
workflow-templates/labeler.yml
Normal file
|
|
@ -0,0 +1,16 @@
|
|||
name: labeler
|
||||
on:
|
||||
pull_request:
|
||||
|
||||
# All three permission grants are load-bearing: reusable-workflow permissions can
|
||||
# only be downgraded from the caller, so omitting one (e.g. issues:write) either
|
||||
# fails to create labels or triggers a silent startup_failure. `pull_request`
|
||||
# (NOT pull_request_target) is correct — the org takes no fork PRs.
|
||||
permissions:
|
||||
contents: read
|
||||
pull-requests: write
|
||||
issues: write
|
||||
|
||||
jobs:
|
||||
label:
|
||||
uses: Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml@main
|
||||
Loading…
Add table
Reference in a new issue