Commit graph

114 commits

Author SHA1 Message Date
Adam Moussa
0df5ee3955
Merge pull request #97 from Sea-Haven-Industries/fix/remove-slack-bot-role-step2
fix(iam): drop the decommissioned slack-bot deploy role from the stack (step 2/2)
2026-07-27 18:06:43 -04:00
e009d3c65f
fix(iam): drop the decommissioned slack-bot deploy role from the stack (step 2/2)
Removes the SeahavenSlackBotDeployRole resource block. Step 1 recorded
DeletionPolicy/UpdateReplacePolicy Retain in the deployed template, so
CloudFormation stops managing the resource without issuing DeleteRole
against a role that no longer exists -- confirmed from the change set,
which reports PolicyAction: Retain on a single Remove entry.

seahaven-slack-bot was decommissioned in favour of sh-mcp and the role
was deleted directly in IAM on 2026-07-23. The stack is now consistent
with reality again, and stack updates no longer fail on it.
2026-07-27 18:04:47 -04:00
Adam Moussa
2ec783052a
Merge pull request #96 from Sea-Haven-Industries/fix/remove-decommissioned-slack-bot-role
fix(iam): stop the decommissioned slack-bot role breaking every stack update (step 1/2)
2026-07-27 18:02:55 -04:00
2f232b6efd
fix(iam): stop the decommissioned slack-bot role breaking every stack update
seahaven-slack-bot was retired in favour of sh-mcp and its deploy role was
deleted directly in IAM on 2026-07-23, leaving the stack holding a
resource that no longer exists. The Outputs section resolved
!GetAtt SeahavenSlackBotDeployRole.Arn as a LIVE IAM read at the end of
every update, so the role's absence failed the whole thing:

  Unable to retrieve Arn attribute for AWS::IAM::Role, with error message
  The role with name githubdeploy-seahaven-slack-bot cannot be found. (404)

This is latent and invisible: the resource definition is unchanged, so it
produces no change-set entry, and change sets do not preview Outputs
resolution. A clean change set was not evidence the update would succeed.
It surfaced when the Phase A boundary-Deny change failed on it.

Step 1 of two. Removes the Output so updates stop resolving the ghost, and
records DeletionPolicy/UpdateReplacePolicy Retain so that step 2 can drop
the resource without CloudFormation issuing DeleteRole against a role that
is not there. Verified from the change set that this step touches only
DeletionPolicy and UpdateReplacePolicy -- metadata, requiresRecreation
Never -- so no IAM call is made against the missing role.

Nothing imported the Output: it had no ExportName, and no stack imports
any export from this stack.

Step 2 deletes the resource block itself.
2026-07-27 18:00:38 -04:00
Adam Moussa
b7d7be2727
Merge pull request #94 from Sea-Haven-Industries/cd/add-dotnet-eb
Some checks are pending
ci / ci / ci (push) Waiting to run
ci(cd-dotnet-eb): add reusable CD workflow for .NET on Elastic Beanstalk
2026-07-27 17:28:56 -04:00
8c3487b6bc
ci(cd-dotnet-eb): add reusable CD workflow for .NET on Elastic Beanstalk
Publishes a .NET project, packages the output as a bundle, uploads it,
creates an Elastic Beanstalk application version, and updates an
existing environment using OIDC credentials. It deploys to an
environment; it never creates one.

Two deliberate departures from the existing cd-* reusables:

- A concurrency group keyed on application+environment, with
  cancel-in-progress false, so two pushes cannot deploy over each other
  and an in-flight deploy is never aborted midway. The existing cd-*
  workflows have no concurrency group at all.
- No input or secret is interpolated into a run: body; everything goes
  through env-var indirection. The repo's actionlint runs with
  shellcheck disabled, so this is a hand-maintained property.

The post-deploy check polls rather than using the CLI waiter
"elasticbeanstalk wait environment-updated": that waiter is hardcoded to
20 attempts x 20s and the CLI cannot extend it, so a slower rolling
deploy would fail the job while the deployment was still healthy. The
timeout is an input instead. The check asserts status, health and the
running version label -- Elastic Beanstalk reports a rolled-back deploy
as a healthy Ready environment running the previous version, so without
the version assertion the job would go green over a failed deploy.

Replaces the malformed cd-dotnet-eb.yaml.yml stub (doubled extension,
empty on:/jobs:). Adds the matching starter template and README entries.
2026-07-27 17:25:23 -04:00
Adam Moussa
a39585b60d
Merge pull request #93 from Sea-Haven-Industries/ci/sam-deploy-template-role-placeholder
Some checks are pending
ci / ci / ci (push) Waiting to run
ci(templates): replace hardcoded management-account role ARN with placeholder
2026-07-27 16:34:52 -04:00
5a5ab684f6
ci(templates): replace hardcoded management-account role ARN with placeholder
The sam-deploy starter template pointed every new repo's cfn-role-arn at
the management account's execution role, silently landing new workloads
in an account frozen for workloads. The ARN is now a REPLACE-ME
placeholder with guidance to use the github-cfn-execution-role in the
repo's target account.
2026-07-27 16:03:25 -04:00
Adam Moussa
786dcfe8d9
Merge pull request #92 from Sea-Haven-Industries/ci/sha-pin-workflow-refs
ci: pin workflow-template refs to commit SHA
2026-07-27 15:39:54 -04:00
69b28c6f3a
ci: pin workflow-template refs to commit SHA
Per the updated handbook convention (engineering-handbook PR #18),
reusable-workflow references use full commit SHA pins with a '# main'
comment instead of the mutable @main branch ref. Templates now ship
pinned so new repos start convention-compliant; Dependabot advances
the pin after instantiation. Commented usage examples in ci-static and
ci-typescript-frontend use the <full-commit-sha> placeholder form.
2026-07-27 15:38:18 -04:00
dependabot[bot]
555d07c3a2
Bump actions/labeler from 6.2.0 to 7.0.0 (#91)
Some checks are pending
ci / ci / ci (push) Waiting to run
Bumps [actions/labeler](https://github.com/actions/labeler) from 6.2.0 to 7.0.0.
- [Release notes](https://github.com/actions/labeler/releases)
- [Commits](b8dd2d9be0...bf12e9b00b)

---
updated-dependencies:
- dependency-name: actions/labeler
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-27 14:08:27 -04:00
dependabot[bot]
265889fb69
Bump the minor-and-patch group with 3 updates (#90)
Bumps the minor-and-patch group with 3 updates: [aws-actions/configure-aws-credentials](https://github.com/aws-actions/configure-aws-credentials), [ruby/setup-ruby](https://github.com/ruby/setup-ruby) and [anthropics/claude-code-action](https://github.com/anthropics/claude-code-action).


Updates `aws-actions/configure-aws-credentials` from 6.2.2 to 6.2.3
- [Release notes](https://github.com/aws-actions/configure-aws-credentials/releases)
- [Changelog](https://github.com/aws-actions/configure-aws-credentials/blob/main/CHANGELOG.md)
- [Commits](517a711dbc...e6de054238)

Updates `ruby/setup-ruby` from 1.319.0 to 1.321.0
- [Release notes](https://github.com/ruby/setup-ruby/releases)
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb)
- [Commits](003a5c4d8d...95ef2b042f)

Updates `anthropics/claude-code-action` from 1.0.178 to 1.0.183
- [Release notes](https://github.com/anthropics/claude-code-action/releases)
- [Commits](af0559ee4f...be7b93b190)

---
updated-dependencies:
- dependency-name: aws-actions/configure-aws-credentials
  dependency-version: 6.2.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: ruby/setup-ruby
  dependency-version: 1.321.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: anthropics/claude-code-action
  dependency-version: 1.0.183
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-27 13:53:57 -04:00
Adam Moussa
07ce007bad
ci(dependency-review): add optional allow-ghsas pass-through input (#89)
Callers with an adjudicated accepted-risk advisory (suppressed with
justification in their repo-local .security-review/suppressions.json)
had no way to keep the dependency-review check green when a lockfile
diff touches a package still inside the vulnerable range. Passes the
input straight to actions/dependency-review-action. Default '' is
byte-identical to an unset action input, so existing callers are
unaffected.

First consumer: seahaven-site, allowing GHSA-mh99-v99m-4gvg
(brace-expansion, no in-range fix until @11ty/recursive-copy bumps
minimatch).
2026-07-27 13:35:47 -04:00
seahaven-openswe[bot]
f71002a9ed
fix: pin ruff to 0.15.22 in ci-python-sam and ci-python-app workflows (#88)
Some checks failed
ci / ci / ci (push) Has been cancelled
Unpinned pip install ruff let ruff 0.16.0 pick up expanded
default lint rules, breaking every caller repo without its
own ruff config. Pinning prevents implicit rule-set changes
on new ruff releases.

Refs: #87

Co-authored-by: amoussa1229 <166072409+amoussa1229@users.noreply.github.com>
2026-07-23 15:51:07 -04:00
Adam Moussa
7b34404e40
fix/dependency-review-permissions (#86)
Some checks are pending
ci / ci / ci (push) Waiting to run
* fix: drop `pull-requests: write` and 'comment-summary-in-pr: on-failure'

* fix: update dependency-review.yml template to match callable permissions
2026-07-23 11:54:59 -04:00
Adam Moussa
d61d921e9a
fix(iam): grant deploy roles s3 encryption-config actions (#84)
Some checks are pending
ci / ci / ci (push) Waiting to run
payments-dashboard's BoaRawBucket (first bucket in the org with an
explicit BucketEncryption block) failed CREATE: the CFN execution
role lacked s3:PutEncryptionConfiguration. Adds the Get/Put pair to
the shared s3-management statement (bucket-level, existing * scope).

Escalation review: the role holds no kms:* actions anywhere, so the
PutEncryptionConfiguration + PutBucketPolicy combination cannot pivot
to a role-controlled KMS key; SCPs permit the action (the original
denial was identity-policy). GPT-4.1 cross-family review: FIX-level
only, dispositioned above. Stack deployed before merge per README.

Refs: payments-dashboard#76
2026-07-22 16:17:38 -04:00
Adam Moussa
a960fd8fd7
ci: batch Dependabot setup-action major bumps (#80, #81, #82) (#83)
Some checks are pending
ci / ci / ci (push) Waiting to run
* Bump actions/setup-dotnet from 5 to 6

Bumps [actions/setup-dotnet](https://github.com/actions/setup-dotnet) from 5 to 6.
- [Release notes](https://github.com/actions/setup-dotnet/releases)
- [Commits](https://github.com/actions/setup-dotnet/compare/v5...v6)

---
updated-dependencies:
- dependency-name: actions/setup-dotnet
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>

* Bump actions/setup-python from 6 to 7

Bumps [actions/setup-python](https://github.com/actions/setup-python) from 6 to 7.
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](https://github.com/actions/setup-python/compare/v6...v7)

---
updated-dependencies:
- dependency-name: actions/setup-python
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>

* Bump actions/setup-node from 6 to 7

Bumps [actions/setup-node](https://github.com/actions/setup-node) from 6 to 7.
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](https://github.com/actions/setup-node/compare/v6...v7)

---
updated-dependencies:
- dependency-name: actions/setup-node
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-22 12:34:38 -04:00
dependabot[bot]
1bb634d78d
Bump the minor-and-patch group with 2 updates (#79)
Some checks are pending
ci / ci / ci (push) Waiting to run
Bumps the minor-and-patch group with 2 updates: [ruby/setup-ruby](https://github.com/ruby/setup-ruby) and [anthropics/claude-code-action](https://github.com/anthropics/claude-code-action).


Updates `ruby/setup-ruby` from 1.316.0 to 1.319.0
- [Release notes](https://github.com/ruby/setup-ruby/releases)
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb)
- [Commits](d45b1a4e94...003a5c4d8d)

Updates `anthropics/claude-code-action` from 1.0.171 to 1.0.178
- [Release notes](https://github.com/anthropics/claude-code-action/releases)
- [Commits](e90deca476...af0559ee4f)

---
updated-dependencies:
- dependency-name: ruby/setup-ruby
  dependency-version: 1.319.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: anthropics/claude-code-action
  dependency-version: 1.0.178
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-21 15:33:24 -04:00
Adam Moussa
18b37b7eab
Remove rename-transition sub from account-baseline deploy role (#78)
Some checks failed
ci / ci / ci (push) Has been cancelled
Post-rename deploy verified green from seahaven-org-baseline (run
29355616637, both account jobs). The freed repo name must not stay
trusted (namespace-reuse window, security review IAC-02).
2026-07-14 13:55:56 -04:00
Adam Moussa
3cde673b9d
cd-cdk stacks input + org-baseline rename trust pair (#77)
* Add stacks input to cd-cdk for multi-account apps

cdk deploy was hardcoded to --all, which breaks when one CDK app defines
stacks for two AWS accounts: whichever role the job assumed fails on the
other account's stacks. Callers can now pass per-job stack selectors;
default stays --all so existing callers are unaffected.

* Trust seahaven-org-baseline sub on account-baseline deploy role

Transition pair for the repo rename: OIDC sub claims carry the repo full
name, so the renamed repo cannot assume the role until its sub is
trusted. Old sub is removed after a post-rename deploy verifies green.

* Pass stacks selector via env var, not expression interpolation

Defense-in-depth from the security review: expression interpolation
into run: is pre-shell text substitution, so metacharacters in the
input would execute as script. Env-var expansion never re-parses shell
syntax; word-splitting for multiple selectors is preserved.
2026-07-14 13:47:56 -04:00
dependabot[bot]
4505931ad8
Bump the minor-and-patch group with 3 updates (#75)
Some checks are pending
ci / ci / ci (push) Waiting to run
Bumps the minor-and-patch group with 3 updates: [actions/labeler](https://github.com/actions/labeler), [aws-actions/configure-aws-credentials](https://github.com/aws-actions/configure-aws-credentials) and [anthropics/claude-code-action](https://github.com/anthropics/claude-code-action).


Updates `actions/labeler` from 6.1.0 to 6.2.0
- [Release notes](https://github.com/actions/labeler/releases)
- [Commits](f27b608878...b8dd2d9be0)

Updates `aws-actions/configure-aws-credentials` from 6.2.1 to 6.2.2
- [Release notes](https://github.com/aws-actions/configure-aws-credentials/releases)
- [Changelog](https://github.com/aws-actions/configure-aws-credentials/blob/main/CHANGELOG.md)
- [Commits](254c19bd24...517a711dbc)

Updates `anthropics/claude-code-action` from 1.0.165 to 1.0.171
- [Release notes](https://github.com/anthropics/claude-code-action/releases)
- [Commits](558b1d6cab...e90deca476)

---
updated-dependencies:
- dependency-name: actions/labeler
  dependency-version: 6.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: aws-actions/configure-aws-credentials
  dependency-version: 6.2.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: anthropics/claude-code-action
  dependency-version: 1.0.171
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-13 14:48:15 -04:00
Adam Moussa
9fa0a71564
ci: add concurrency to ci-python-app + fix sam-deploy template (INFRA-136) (#74)
Some checks failed
ci / ci / ci (push) Has been cancelled
Add job-level concurrency (cancel-in-progress) to all four ci-python-app
jobs, matching the ci-python-sam idiom. Per-job group keys include
github.job so the parallel jobs in a single run do not share a group.

Replace sam-deploy starter-template stack-name: $default-branch (which
GitHub substitutes to the literal branch name main) with a
REPLACE-ME-stack-name placeholder, and point cfn-role-arn at the real
shared github-cfn-execution-role.
2026-07-08 16:32:40 -04:00
Adam Moussa
fc75158c94
docs: refresh .github README and workflow-templates (INFRA-142) (#73)
- README: mark compliance-audit.yaml deprecated (2026-06-10), document all
  12 reusable workflows (was 6), add workflow-templates and action-pinning
  policy sections
- dependency-review.yml template: convert to thin caller of
  callable-dependency-review.yaml (was inlining dependency-review-action@v4,
  drifted from callable @v5)
- callable-dependency-review.yaml: preserve comment-summary-in-pr on-failure
  and grant pull-requests: write
- add labeler.yml + labeler.properties.json starter template
2026-07-08 16:21:37 -04:00
Adam Moussa
4eff8bbc6d
chore(ci): SHA-pin mutable-tag third-party actions (INFRA-118) (#72)
Some checks failed
ci / ci / ci (push) Has been cancelled
2026-07-06 18:26:29 -04:00
dependabot[bot]
fd60e4c904
Bump the minor-and-patch group with 2 updates (#71)
Some checks are pending
ci / ci / ci (push) Waiting to run
Bumps the minor-and-patch group with 2 updates: [ruby/setup-ruby](https://github.com/ruby/setup-ruby) and [anthropics/claude-code-action](https://github.com/anthropics/claude-code-action).


Updates `ruby/setup-ruby` from 1.314.0 to 1.316.0
- [Release notes](https://github.com/ruby/setup-ruby/releases)
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb)
- [Commits](9eb537ca03...d45b1a4e94)

Updates `anthropics/claude-code-action` from 1.0.159 to 1.0.165
- [Release notes](https://github.com/anthropics/claude-code-action/releases)
- [Commits](a92e7c70a4...558b1d6cab)

---
updated-dependencies:
- dependency-name: ruby/setup-ruby
  dependency-version: 1.316.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: anthropics/claude-code-action
  dependency-version: 1.0.165
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-06 17:31:55 -04:00
dependabot[bot]
e732e119e3
Bump anthropics/claude-code-action in the minor-and-patch group (#69)
Some checks failed
ci / ci / ci (push) Has been cancelled
Bumps the minor-and-patch group with 1 update: [anthropics/claude-code-action](https://github.com/anthropics/claude-code-action).


Updates `anthropics/claude-code-action` from 1.0.153 to 1.0.159
- [Release notes](https://github.com/anthropics/claude-code-action/releases)
- [Commits](2fee155104...a92e7c70a4)

---
updated-dependencies:
- dependency-name: anthropics/claude-code-action
  dependency-version: 1.0.159
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-30 19:46:13 -04:00
Adam Moussa
49110fa9b6
Merge pull request #68 from Sea-Haven-Industries/chore/checkout-v7
Some checks failed
ci / ci / ci (push) Has been cancelled
chore(ci): bump actions/checkout v6 → v7 across reusable workflows
2026-06-25 11:50:43 -04:00
3a258918e2 chore(ci): bump actions/checkout v6 -> v7 across reusable workflows
actions/checkout v7.0.0 (2026-06-18) is internally an ESM rebuild plus
one behavioral change: it blocks checking out a fork PR head ref under
pull_request_target / workflow_run (PR #2454). No Sea Haven workflow uses
those triggers, so there is no reachable behavior change. The Node 24
runtime requirement already landed at v6, so v6 -> v7 carries no new
runner requirement. All runners here are GitHub-hosted (ubuntu, macos).

Covers all 16 checkout pins across 12 reusable/standalone workflows plus
the dependency-review workflow-template scaffold. Consumers on @main pick
this up automatically on merge.
2026-06-25 11:43:10 -04:00
Adam Moussa
09fa684b37
Merge pull request #67 from Sea-Haven-Industries/infra/ci-typescript-frontend-reusable
Some checks are pending
ci / ci / ci (push) Waiting to run
Add reusable CI workflow for TypeScript front-end apps
2026-06-24 16:45:50 -04:00
2e356920c7 Add reusable CI workflow for TypeScript front-end apps
Adds ci-typescript-frontend.yaml, a workflow_call reusable CI for bundled
TypeScript SPAs (Vite / React / Vue with vitest + Playwright). Existing
reusable CIs do not fit this shape: ci-static is for plain HTML sites and
ci-typescript-cdk targets CDK infra repos.

The workflow runs as a single `ci` job so callers emit the `ci / ci` status
context the org branch-protection rulesets require. Steps: a Sea Haven
standards gate (required npm scripts present, plus a changed-line guard for
AI-tool footers, hook bypasses, and hardcoded secrets), then format:check,
lint, build, unit tests, and an optional Playwright browser smoke. Every step
past the standards gate is individually toggleable, and string inputs are
passed through env to avoid expression injection.

Documents the workflow in the README reusable-workflows list.
2026-06-24 16:42:54 -04:00
dependabot[bot]
945f0b6021
Bump the minor-and-patch group with 2 updates (#65)
Some checks are pending
ci / ci / ci (push) Waiting to run
Bumps the minor-and-patch group with 2 updates: [ruby/setup-ruby](https://github.com/ruby/setup-ruby) and [anthropics/claude-code-action](https://github.com/anthropics/claude-code-action).


Updates `ruby/setup-ruby` from 1.313.0 to 1.314.0
- [Release notes](https://github.com/ruby/setup-ruby/releases)
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb)
- [Commits](89f90524b8...9eb537ca03)

Updates `anthropics/claude-code-action` from 1.0.149 to 1.0.153
- [Release notes](https://github.com/anthropics/claude-code-action/releases)
- [Commits](4d7e1f0cd8...2fee155104)

---
updated-dependencies:
- dependency-name: ruby/setup-ruby
  dependency-version: 1.314.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: anthropics/claude-code-action
  dependency-version: 1.0.153
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-24 15:55:42 -04:00
Adam Moussa
6714382a29
Merge pull request #63 from Sea-Haven-Industries/fix/labeler-monorepo-paths
Some checks failed
ci / ci / ci (push) Has been cancelled
fix(labeler): cover monorepo layouts + harden the reusable labeler
2026-06-18 13:43:39 -04:00
d31893d318 fix(labeler): cover monorepo layouts and harden the reusable workflow
The central label rules assumed a root-level project layout
(lib/**, bin/**, cdk/**, src/**), so monorepos that nest components
under top-level dirs (infra/, web/, mobile/, shared/) matched nothing
for those areas. PRs touching only infra/lib/** or web/** ran the
labeler green but received no label.

Label coverage:
- infra: + 'infra/**' (covers infra/lib, infra/bin, infra/cdk.json)
- app:   + 'web/**', 'mobile/**', 'shared/**'
Additions are appended to the existing root paths, so single-project
repos are unaffected; deliberately avoided blanket '**/lib/**' globs
that would mislabel web/src/lib/** as infra.

Hardening rolled in while here:
- Pin actions/labeler to a commit SHA (was the floating @v6 tag)
- Add a per-PR concurrency group with a run_id fallback for non-PR
  callers, so rapid pushes cancel superseded label runs
- Broaden 'ci' (.github/actions/**), 'dependencies'
  (Directory.Packages.props, yarn.lock, pnpm-lock.yaml, Podfile/.lock)
  and 'tests' (JS/TS .test/.spec, pytest test_*.py/conftest,
  .NET *Tests.cs, Java *Test.java, Go, Ruby) globs

Caller repos must already have any label a rule can emit; actions/labeler
does not create missing labels. The org 'infra' label was backfilled
across repos separately.
2026-06-18 13:40:18 -04:00
Adam Moussa
347558820d
Merge pull request #62 from Sea-Haven-Industries/feature/ci-python-app-reusable
Some checks are pending
ci / ci / ci (push) Waiting to run
Add ci-python-app reusable workflow
2026-06-17 17:28:00 -04:00
c36b737af7 Add ci-python-app reusable workflow
Reusable CI for plain Python apps / locally-run tooling that don't deploy via
SAM or CDK. Beyond ruff lint/format + the conventions audit, it adds a
collect-only import check for a root suite whose live run needs secrets, and an
isolated full pytest run for a self-contained subproject dir (whose tests/
package would collide with the root tests/ under one rootdir).

Emits the org-required `ci / ci` via an aggregator job keyed `ci` that gates on
every other job. actionlint-clean.
2026-06-17 17:26:16 -04:00
Adam Moussa
0442339fff
Merge pull request #60 from Sea-Haven-Industries/dependabot/github_actions/actions/setup-python-6
Some checks are pending
ci / ci / ci (push) Waiting to run
Bump actions/setup-python from 5 to 6
2026-06-16 16:00:20 -04:00
Adam Moussa
c2735defa0
Merge branch 'main' into dependabot/github_actions/actions/setup-python-6 2026-06-16 15:59:54 -04:00
Adam Moussa
cfa7512e97
Merge pull request #58 from Sea-Haven-Industries/dependabot/github_actions/minor-and-patch-02ee58b77d
Bump the minor-and-patch group across 1 directory with 2 updates
2026-06-16 15:59:08 -04:00
Adam Moussa
2ae95530c0
Merge branch 'main' into dependabot/github_actions/minor-and-patch-02ee58b77d 2026-06-16 15:58:37 -04:00
Adam Moussa
23bddc337d
Merge pull request #59 from Sea-Haven-Industries/dependabot/github_actions/aws-actions/setup-sam-3
Bump aws-actions/setup-sam from 2 to 3
2026-06-16 15:58:08 -04:00
dependabot[bot]
6333d5cc34
Bump aws-actions/setup-sam from 2 to 3
Bumps [aws-actions/setup-sam](https://github.com/aws-actions/setup-sam) from 2 to 3.
- [Release notes](https://github.com/aws-actions/setup-sam/releases)
- [Commits](https://github.com/aws-actions/setup-sam/compare/v2...v3)

---
updated-dependencies:
- dependency-name: aws-actions/setup-sam
  dependency-version: '3'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-16 19:57:39 +00:00
dependabot[bot]
828187d5bd
Bump the minor-and-patch group across 1 directory with 2 updates
Bumps the minor-and-patch group with 2 updates in the / directory: [ruby/setup-ruby](https://github.com/ruby/setup-ruby) and [anthropics/claude-code-action](https://github.com/anthropics/claude-code-action).


Updates `ruby/setup-ruby` from 1.312.0 to 1.313.0
- [Release notes](https://github.com/ruby/setup-ruby/releases)
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb)
- [Commits](12fd324f1d...89f90524b8)

Updates `anthropics/claude-code-action` from 1.0.144 to 1.0.149
- [Release notes](https://github.com/anthropics/claude-code-action/releases)
- [Commits](0f97b95b65...4d7e1f0cd8)

---
updated-dependencies:
- dependency-name: anthropics/claude-code-action
  dependency-version: 1.0.148
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: ruby/setup-ruby
  dependency-version: 1.313.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-16 19:55:52 +00:00
Adam Moussa
9bdf7a4063
Merge pull request #61 from Sea-Haven-Industries/ci-actionlint-gate
Wire .github to consume its own reusables: self-CI ci/ci gate + PR labeler
2026-06-16 15:52:35 -04:00
9353a212c3 Run the org PR labeler on .github's own PRs
Add a thin caller so the .github repo invokes its own reusable
callable-labeler.yaml on pull_request, like every consumer repo does. Without a
caller the workflow_call-only labeler never runs on .github's own PRs (this is
why #61 wasn't auto-labeled). Grants the three permissions the reusable requires
(contents:read, pull-requests:write, issues:write).
2026-06-16 15:51:10 -04:00
Adam Moussa
5937ab73e6
Merge branch 'main' into ci-actionlint-gate 2026-06-16 15:46:45 -04:00
2f25ac3535 Add self-CI actionlint gate to satisfy ci/ci ruleset
The org ruleset requires the 'ci / ci' status check on every repo, but this
.github repo only houses reusable (workflow_call) workflows and emitted no such
check — so every PR sat 'Expected — Waiting for status to be reported' and was
unmergeable, including the open Dependabot bumps (#58, #59, #60).

Add a workflow that runs actionlint (pinned, checksum-verified) over the
workflow files. The ruleset matches the required check against the JOB's
check-run name, so the job is named literally 'ci / ci' to emit that exact
context (a job named 'ci' emits context 'ci', which the UI only cosmetically
shows as 'ci / ci'). shellcheck integration is disabled for now; 4 pre-existing
run-step findings are left for a separate cleanup.

Pre-existing checkov IAM findings in oidc-deploy-roles.yaml are accepted-risk
and suppressed via machine-level security-review config, intentionally NOT
committed to this repo.
2026-06-16 15:35:09 -04:00
dependabot[bot]
568a0aacad
Bump actions/setup-python from 5 to 6
Bumps [actions/setup-python](https://github.com/actions/setup-python) from 5 to 6.
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](https://github.com/actions/setup-python/compare/v5...v6)

---
updated-dependencies:
- dependency-name: actions/setup-python
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-15 17:48:51 +00:00
Adam Moussa
e4e4b42ce6
Merge pull request #57 from Sea-Haven-Industries/feature/ci-static-build-support
ci-static: add build mode for templated static sites
2026-06-12 16:40:04 -04:00
e43a9cb447 ci-static: add build mode for templated static sites
Add check-dir + build-command inputs. When build-command is set, run
npm ci + the build, then validate the built output in check-dir (e.g.
_site) instead of repo source. Without this, a site that templates its
HTML (Eleventy etc.) has no source HTML and the checks pass vacuously.

Backward-compatible: defaults (check-dir='.', build-command='') preserve
source-mode behavior for existing callers. build-command is passed via
env to avoid expression injection into the run script.
2026-06-12 16:29:19 -04:00
Adam Moussa
dea18763ee
Add ci-static reusable workflow and content label rule (#56)
- ci-static.yaml: reusable CI for static HTML/CSS/JS sites (S3+CloudFront
  repos with no build framework). Job 'ci' emits the 'ci / ci' status
  context required by the org main-branch ruleset, which static sites
  previously could not satisfy (only ci-dotnet/python-sam/typescript-cdk
  existed). Checks: htmlhint, JSON-LD validity, sitemap well-formedness,
  internal-link/asset resolution, README/.gitignore conventions.
- callable-labeler.yaml: add a 'content' rule (html/css/assets/sitemap/
  robots) so static-site PRs get labeled instead of matching nothing.
2026-06-12 16:05:18 -04:00