Commit graph

176 commits

Author SHA1 Message Date
renovate[bot]
122292e109
chore(deps): update github actions 2026-08-24 21:05:53 +00:00
Adam Moussa
cc75356ed1
fix(ci): drop two-step mergify merge conditions (#133) 2026-08-24 16:47:44 -04:00
Adam Moussa
91ff9ed08e
fix(ci): gate mergify on github-review-decision instead of approval count (#132)
Some checks are pending
ci / ci / ci (push) Waiting to run
2026-08-24 15:42:59 -04:00
Adam Moussa
db5e1b4b19
chore(ci): remove pr-policy starter template (#131)
Some checks are pending
ci / ci / ci (push) Waiting to run
2026-08-24 15:11:41 -04:00
Adam Moussa
dc56defea2
fix(ci): allow dependabot and renovate in mergify queue (#130)
Some checks are pending
ci / ci / ci (push) Waiting to run
2026-08-24 14:13:41 -04:00
Adam Moussa
deff75a3bb
fix: update merge queue configuration (#129)
Signed-off-by: Adam Moussa <null>
2026-08-24 14:09:28 -04:00
mergify[bot]
08e8520c1f
Merge pull request #128 from Sea-Haven-Industries/chore/switch-to-mergify
chore(ci): switch auto-merge from seahaven-bot to Mergify (PLAT-108)
2026-08-24 17:50:58 +00:00
9fb1bb5549
fix(ci): use github-review-decision instead of illegal CODEOWNERS condition 2026-08-24 13:26:42 -04:00
a04036962c
fix(ci): require review and ci before mergify auto-queue 2026-08-24 13:17:14 -04:00
dce935ce31
chore(ci): switch auto-merge from seahaven-bot to Mergify 2026-08-24 13:06:47 -04:00
Adam Moussa
f2f2d4066c
ci: enable squash auto-merge on ready PRs (PLAT-108) (#126)
Some checks failed
ci / ci / ci (push) Has been cancelled
* ci: enable squash auto-merge on ready PRs

* fix: add auto-merge.yaml as a release exclusion

* fix(ci): serialize auto-merge enable and ignore already-enabled
2026-08-21 23:34:16 +00:00
Adam Moussa
8ec1f627fe
ci: add merge_group and drop policy caller (PLAT-108) (#125)
Some checks are pending
ci / ci / ci (push) Waiting to run
* ci: add merge_group trigger for required ci / ci

* ci: drop this repo's PR policy caller
2026-08-21 17:41:23 -04:00
Adam Moussa
af0f002e14
ci: expand labeler globs and skip dependabot pr policy (PLAT-107) (#124)
Some checks failed
ci / ci / ci (push) Waiting to run
Release on reusable change / version (push) Has been cancelled
Release on reusable change / release (push) Has been cancelled
* ci: expand labeler globs and skip dependabot pr policy

.NET product paths never matched app, so backend PRs stayed unlabeled. Dependabot PRs still ran commit-subject and pin checks on generated titles. Skip those PRs in the reusable policy job.

* fix(labeler): match nested elastic beanstalk config paths

Root-only .ebextensions and .platform globs miss api/.ebextensions in monorepos. Mirror the Dockerfile nested form.
2026-08-21 12:42:28 -04:00
Adam Moussa
59c7b1f9a3
chore(iam): remove mgmt meal-order weekly-menu OIDC role (#123)
Some checks are pending
ci / ci / ci (push) Waiting to run
Weekly-menu publish now assumes the prod HCP role; drop the orphaned
mgmt github-meal-order-manager-weekly-menu role from this stack.
2026-08-20 13:21:59 -04:00
dependabot[bot]
d37ca73ffa
chore(deps): bump callable-pr-policy.yaml (#122)
Some checks failed
ci / ci / ci (push) Has been cancelled
Bumps the minor-and-patch group with 1 update: [Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml](https://github.com/sea-haven-industries/.github).

Updates `Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml` from 1.0.6 to 1.0.7
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](7ac3528750...e5691d8a7f)

---
updated-dependencies:
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml
  dependency-version: 1.0.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-17 19:11:53 +00:00
Adam Moussa
e5691d8a7f
fix(policy): accept AP Jira keys in PR titles (#121)
Some checks failed
ci / ci / ci (push) Has been cancelled
Release on reusable change / version (push) Has been cancelled
Release on reusable change / release (push) Has been cancelled
2026-08-10 20:55:27 +00:00
dependabot[bot]
123366c3f1
chore(deps): bump callable-pr-policy.yaml (#120)
Some checks are pending
ci / ci / ci (push) Waiting to run
Bumps the minor-and-patch group with 1 update: [Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml](https://github.com/sea-haven-industries/.github).

Updates `Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml` from 1.0.5 to 1.0.6
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](9c1ecf9428...7ac3528750)

---
updated-dependencies:
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml
  dependency-version: 1.0.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-10 17:55:10 +00:00
Adam Moussa
9a2efffce3
fix(iam): grant weekly-menu role SSM deploy params (#119)
Some checks are pending
ci / ci / ci (push) Waiting to run
2026-08-10 11:39:40 -04:00
Adam Moussa
9f2adabbea
chore(iam): remove procurement-ingest OIDC deploy role (PLAT-88) (#118)
Some checks failed
ci / ci / ci (push) Has been cancelled
* chore(iam): remove procurement-ingest OIDC deploy role

* chore(iam): drop procurement-ingest OIDC role output
2026-08-07 12:42:07 -04:00
Adam Moussa
7ac3528750
fix(policy): allow sync merges and longer PR titles (#117)
Some checks failed
ci / ci / ci (push) Has been cancelled
Release on reusable change / version (push) Has been cancelled
Release on reusable change / release (push) Has been cancelled
Refs: PLAT-62
2026-08-04 14:41:48 -04:00
Adam Moussa
12e70a2279
ci: add released PR policy self-caller (#116)
Some checks are pending
ci / ci / ci (push) Waiting to run
Refs: PLAT-62
2026-08-04 11:16:48 -04:00
Adam Moussa
9c1ecf9428
ci: add deterministic PR policy and align org templates (PLAT-62) (#115)
Some checks are pending
ci / ci / ci (push) Waiting to run
Release on reusable change / version (push) Waiting to run
Release on reusable change / release (push) Blocked by required conditions
* docs: align organization templates with Cursor conventions

Refs: PLAT-62

* ci: add deterministic PR policy gate

Refs: PLAT-62

* fix(ci): grandfather unchanged workflow policy debt

Refs: PLAT-62

* fix(ci): address PR policy security review

Refs: PLAT-62

* fix(ci): scan copied workflow files

Refs: PLAT-62

* fix(ci): close remaining workflow policy bypasses

Refs: PLAT-62

* fix(policy): reject uses block scalar action refs

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

* fix(policy): preserve line-specific violation fingerprints

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
2026-08-03 20:30:32 -04:00
Adam Moussa
b94062bd86
fix(iam): grant weekly-menu role execute-api invoke (#114)
Some checks are pending
ci / ci / ci (push) Waiting to run
Release on reusable change / version (push) Waiting to run
Release on reusable change / release (push) Blocked by required conditions
2026-08-03 15:32:35 -04:00
Adam Moussa
81cf168170
fix(deploy): recover SAM stacks after update rollback 2026-08-03 14:38:39 -04:00
Adam Moussa
9a7171a855
Merge pull request #112 from Sea-Haven-Industries/docs/readme-pinning-and-catalog
Some checks failed
ci / ci / ci (push) Has been cancelled
docs: align README pinning policy with SHA-pin convention and complete the catalog
2026-07-29 13:02:55 -04:00
ca5dae6aff
docs: align README pinning policy with SHA-pin convention and complete the catalog 2026-07-29 13:00:53 -04:00
Adam Moussa
18e207a799
Merge pull request #111 from Sea-Haven-Industries/feat/weekly-menu-scoped-role
Some checks failed
ci / ci / ci (push) Waiting to run
Release on reusable change / version (push) Has been cancelled
Release on reusable change / release (push) Has been cancelled
feat(iam): add scoped OIDC role for the meal-order-manager weekly-menu job
2026-07-28 19:24:29 -04:00
c2c1b80b60
feat(iam): add scoped OIDC role for the meal-order-manager weekly-menu job 2026-07-28 19:16:05 -04:00
Adam Moussa
3f74677422
Merge pull request #110 from Sea-Haven-Industries/fix/ci-ts-cdk-npm-test
fix(ci): run npm test instead of hardcoded npx jest in ci-typescript-cdk
2026-07-28 18:46:15 -04:00
Adam Moussa
93a370bfa8 fix(ci): run npm test instead of hardcoded npx jest in ci-typescript-cdk 2026-07-28 18:44:30 -04:00
Adam Moussa
3620c84cbb
Merge pull request #109 from Sea-Haven-Industries/fix/audit-github-script
Some checks are pending
ci / ci / ci (push) Waiting to run
ci(templates): pin github-script to v9.0.0 in the triage starter
2026-07-28 18:40:58 -04:00
Adam Moussa
e2c43bd4ee ci(templates): pin github-script to v9.0.0 in the triage starter 2026-07-28 18:37:45 -04:00
Adam Moussa
0170a57c0d
Merge pull request #108 from Sea-Haven-Industries/fix/reusable-concurrency-job-key
Some checks are pending
ci / ci / ci (push) Waiting to run
Release on reusable change / version (push) Waiting to run
Release on reusable change / release (push) Blocked by required conditions
fix(ci): key multi-job reusable concurrency on a literal job id
2026-07-28 17:26:19 -04:00
a394b54f82
fix(ci): key multi-job reusable concurrency on a literal job id
ci-python-app.yaml and ci-mobile-ios.yaml built their concurrency group
from ${{ github.job }}. In a called workflow that expression evaluates to
the caller's job id, not the job's own id, so every job in the reusable
resolved to the same group. With cancel-in-progress: true they cancelled
each other.

Observed in pr-reviewer after repinning it off a ref that predates the
concurrency blocks: one run, ci / lint cancelled 1s after start by a
sibling, ci / subproject-tests succeeded, and the aggregator failed on the
cancelled dependency.

Replaces the expression with the job id written out literally in all 7
groups, and records the reason at the first block in each file.
2026-07-28 17:22:51 -04:00
Adam Moussa
880ba803d2
Merge pull request #107 from Sea-Haven-Industries/docs/release-reusable-caller-note
docs(release): point the reusable at this repo's own caller
2026-07-28 17:15:11 -04:00
7c0c6ab984
docs(release): point the reusable at this repo's own caller
release.yaml documented a generic caller example but not the caller that
actually exists in this repo. Notes that release-on-merge.yaml computes the
version, calls this workflow by local path, and is the only caller that does
so without a version comment.
2026-07-28 17:13:44 -04:00
Adam Moussa
2fbfb2e7cf
Merge pull request #106 from Sea-Haven-Industries/feat/release-on-reusable-change
feat(release): cut a tag and release when a reusable workflow changes
2026-07-28 17:05:28 -04:00
34977d2457
feat(release): cut a tag and release when a reusable workflow changes
Callers pin `uses:` to a commit SHA of this repo. Dependabot's
github-actions updater finds a newer SHA for a pinned ref by reading the
target repo's tags and releases; this repo has 0 tags and 0 releases, so
there is nothing for it to resolve and it reports no update. The fleet's
pins have not moved as a result.

Adds a caller for the release reusable, triggered on push to main and
filtered to paths under .github/workflows/ excluding the three files no
caller consumes (ci.yaml, labeler.yaml, and this file).

Version is a patch bump from the highest existing vMAJOR.MINOR.PATCH tag,
1.0.0 when none exist. workflow_dispatch takes an explicit version for
minor and major bumps.

Runs are serialised with cancel-in-progress false: two merges landing
together would otherwise read the same highest tag, compute the same next
version, and the second would hit the reusable's existing-tag guard and
no-op, leaving that change unreleased.
2026-07-28 17:01:44 -04:00
Adam Moussa
0fd7ecf2a5
Merge pull request #105 from Sea-Haven-Industries/feat/release-workflow-and-ios-ci
feat(workflows): add release and iOS CI reusable workflows, pass node-version on ci-python template
2026-07-28 16:50:06 -04:00
ead0b6cf6c
feat(workflow-templates): add release and ci-mobile-ios templates, pass node-version on ci-python
release.yml / release.properties.json and ci-mobile-ios.yml /
ci-mobile-ios.properties.json are new caller templates for the two reusable
workflows added in 9389e51. Both pin the reusable to 9389e51, the commit that
introduces the workflow files.

release.yml triggers on workflow_dispatch with a required `version` input and
declares `permissions: contents: write`, which the reusable needs to push the
tag and publish the Release. ci-mobile-ios.yml triggers on pull_request and
keys its job `ci` so the check context resolves to `ci / ci`.

ci-python.yml now passes `node-version: "24"`. Its target,
ci-python-sam.yaml, declares that input at line 34 with default "24"; the
ci-static, ci-typescript-frontend, ci-node, cdk-deploy and mobile-ios-deploy
templates already pass the same value.

Both new .properties.json files carry the same five keys as the thirteen
existing ones: categories, description, filePatterns, iconName, name.
2026-07-28 15:57:17 -04:00
9389e51c10
feat(workflows): add release and ci-mobile-ios reusable workflows
release.yaml is workflow_call-only. It normalises and validates a `version`
input against MAJOR.MINOR.PATCH, skips every mutating step when the tag or a
Release for it already exists, creates an annotated tag with `git tag -a` and
publishes a GitHub Release with `gh release create --verify-tag`. Top-level
permissions grant `contents: write` only; no id-token is requested. The
previous-tag lookup and `--generate-notes` both work in a repo with no tags.

ci-mobile-ios.yaml is workflow_call-only and pairs with cd-mobile-ios.yaml,
reusing its node-version, ruby-version, working-directory,
cache-dependency-path and fastlane-lane input names. Job `js` runs npm ci,
typecheck, optional lint and optional tests on ubuntu-latest. Job `ios-build`
runs pod install and `xcodebuild build` on macos-26 with
CODE_SIGNING_ALLOWED=NO, CODE_SIGNING_REQUIRED=NO and CODE_SIGN_IDENTITY="";
it declares no secrets and performs no upload. Job `ci` aggregates both via
`needs` so a caller job keyed `ci` reports `ci / ci`. All three jobs carry
job-level concurrency with cancel-in-progress: true. Top-level permissions are
`contents: read`.

The Fastlane branch carries a per-line `# shellcheck disable=SC2086` because
fastlane requires the platform and lane as two argv entries.
2026-07-28 15:55:43 -04:00
Adam Moussa
7a8243248b
Merge pull request #103 from Sea-Haven-Industries/chore/cd-concurrency-groups
Some checks are pending
ci / ci / ci (push) Waiting to run
ci: add job-level concurrency to the cd-cdk, cd-sam and iOS deploys
2026-07-28 12:59:32 -04:00
Adam Moussa
eed8c97e79
Merge branch 'main' into chore/cd-concurrency-groups 2026-07-28 12:55:57 -04:00
Adam Moussa
bcaeaf7759
Merge pull request #104 from Sea-Haven-Industries/ci/enable-actionlint-shellcheck
Some checks are pending
ci / ci / ci (push) Waiting to run
ci: enable actionlint's shellcheck integration in self-CI
2026-07-28 12:55:26 -04:00
Adam Moussa
c286a98514
Merge branch 'main' into ci/enable-actionlint-shellcheck 2026-07-28 12:54:23 -04:00
Adam Moussa
62254a7837
Merge pull request #102 from Sea-Haven-Industries/fix/workflow-expression-injection
fix(ci): pass deploy inputs via env, not shell interpolation
2026-07-28 12:53:28 -04:00
Adam Moussa
3de50b94a0
Merge branch 'main' into fix/workflow-expression-injection 2026-07-28 12:51:58 -04:00
Adam Moussa
149ac1c79a
Merge pull request #101 from Sea-Haven-Industries/chore/remove-retired-review-tooling
chore: remove retired pr-review and compliance-audit tooling
2026-07-28 12:47:24 -04:00
5889d52333
ci: enable actionlint's shellcheck integration in self-CI
The self-CI gate ran `./actionlint -shellcheck=`, and the empty value
silently disabled the shell-linting half of the check — so every `run:`
body in the reusable workflows this repo publishes was unlinted, on the
exact path that deploys to AWS.

Measured against the pinned actionlint 1.7.12 and the shellcheck the
ubuntu-latest runner ships (0.9.0-1), the real backlog was 5 findings,
not the 4 the old comment claimed. Three were genuine and are fixed in
the shell:

- cd-cdk.yaml "Publish .NET project" (SC2046): the project path was
  interpolated inline and `$(dirname ...)` was unquoted, so a path
  containing whitespace split into several arguments. Now passed via
  env indirection and quoted, which also removes the last inline
  expression interpolation from that step.
- cd-cdk.yaml / ci-python-sam.yaml "Install Python dependencies"
  (SC2044 x2): `for req in $(find ...)` word-split and globbed every
  path found. Replaced with a NUL-delimited `while read` loop.

Two are deliberate and are suppressed per-line, with the reasoning in a
comment directly above:

- cd-sam.yaml `sam deploy ... $PARAMS` and cd-cdk.yaml
  `cdk deploy $STACKS` (SC2086 x2) rely on word-splitting so multiple
  parameter overrides / stack selectors reach the CLI as separate argv
  entries. Quoting them would collapse each into a single argument and
  break every parameterised or multi-stack deploy, so they keep the
  unquoted expansion and carry a scoped `# shellcheck disable=SC2086`.

The gate now runs plain `./actionlint` (shellcheck defaults to the
binary on PATH) and prints `shellcheck --version` first, so the check
fails loudly if a future runner image drops it instead of quietly
linting less.
2026-07-28 12:46:17 -04:00
Adam Moussa
8d8d832757
Merge branch 'main' into chore/remove-retired-review-tooling 2026-07-28 12:45:27 -04:00