Commit graph

2 commits

Author SHA1 Message Date
Adam Moussa
9c1ecf9428
ci: add deterministic PR policy and align org templates (PLAT-62) (#115)
Some checks are pending
ci / ci / ci (push) Waiting to run
Release on reusable change / version (push) Waiting to run
Release on reusable change / release (push) Blocked by required conditions
* docs: align organization templates with Cursor conventions

Refs: PLAT-62

* ci: add deterministic PR policy gate

Refs: PLAT-62

* fix(ci): grandfather unchanged workflow policy debt

Refs: PLAT-62

* fix(ci): address PR policy security review

Refs: PLAT-62

* fix(ci): scan copied workflow files

Refs: PLAT-62

* fix(ci): close remaining workflow policy bypasses

Refs: PLAT-62

* fix(policy): reject uses block scalar action refs

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

* fix(policy): preserve line-specific violation fingerprints

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
2026-08-03 20:30:32 -04:00
Adam Moussa
e9263123c7
docs: fix README review drift + add community-health files (#48)
INFRA-69: README documented the deleted claude-code-review.yaml workflow and
its rollout as the live PR-review setup. PR reviews are handled by the official
Claude Code App (since 2026-05-13); corrected the workflow list, added a PR
Reviews note, marked the legacy rollout script, and replaced the obsolete
rollout step. Preserved the claude-code-ci App + secrets (compliance-audit
still uses them).

INFRA-68: add SECURITY.md (private vuln reporting via GitHub advisory / email)
and SUPPORT.md (Jira INFRA, handbook, security pointer).
2026-06-10 15:35:31 -04:00