renovate[bot]
08d8ca31a9
chore(deps): update sea-haven-industries/.github action to v1.0.11 ( #143 )
...
ci / ci / ci (push) Has been cancelled
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-09-16 16:46:00 +00:00
renovate[bot]
9b7b464d5c
chore(deps): update sea-haven-industries/.github action to v1.0.10 ( #140 )
...
ci / ci / ci (push) Has been cancelled
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-08-31 15:48:50 +00:00
renovate[bot]
e5b0cf714d
chore(deps): update github actions ( #134 )
ci / ci / ci (push) Waiting to run
Release on reusable change / version (push) Has been cancelled
Release on reusable change / release (push) Has been cancelled
2026-08-24 21:18:32 +00:00
Adam Moussa
9c1ecf9428
ci: add deterministic PR policy and align org templates (PLAT-62) ( #115 )
...
ci / ci / ci (push) Waiting to run
Release on reusable change / version (push) Waiting to run
Release on reusable change / release (push) Blocked by required conditions
* docs: align organization templates with Cursor conventions
Refs: PLAT-62
* ci: add deterministic PR policy gate
Refs: PLAT-62
* fix(ci): grandfather unchanged workflow policy debt
Refs: PLAT-62
* fix(ci): address PR policy security review
Refs: PLAT-62
* fix(ci): scan copied workflow files
Refs: PLAT-62
* fix(ci): close remaining workflow policy bypasses
Refs: PLAT-62
* fix(policy): reject uses block scalar action refs
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
* fix(policy): preserve line-specific violation fingerprints
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
---------
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
2026-08-03 20:30:32 -04:00
69b28c6f3a
ci: pin workflow-template refs to commit SHA
...
Per the updated handbook convention (engineering-handbook PR #18 ),
reusable-workflow references use full commit SHA pins with a '# main'
comment instead of the mutable @main branch ref. Templates now ship
pinned so new repos start convention-compliant; Dependabot advances
the pin after instantiation. Commented usage examples in ci-static and
ci-typescript-frontend use the <full-commit-sha> placeholder form.
2026-07-27 15:38:18 -04:00
Adam Moussa
7b34404e40
fix/dependency-review-permissions ( #86 )
...
ci / ci / ci (push) Waiting to run
* fix: drop `pull-requests: write` and 'comment-summary-in-pr: on-failure'
* fix: update dependency-review.yml template to match callable permissions
2026-07-23 11:54:59 -04:00
Adam Moussa
fc75158c94
docs: refresh .github README and workflow-templates (INFRA-142) ( #73 )
...
- README: mark compliance-audit.yaml deprecated (2026-06-10), document all
12 reusable workflows (was 6), add workflow-templates and action-pinning
policy sections
- dependency-review.yml template: convert to thin caller of
callable-dependency-review.yaml (was inlining dependency-review-action@v4,
drifted from callable @v5)
- callable-dependency-review.yaml: preserve comment-summary-in-pr on-failure
and grant pull-requests: write
- add labeler.yml + labeler.properties.json starter template
2026-07-08 16:21:37 -04:00
3a258918e2
chore(ci): bump actions/checkout v6 -> v7 across reusable workflows
...
actions/checkout v7.0.0 (2026-06-18) is internally an ESM rebuild plus
one behavioral change: it blocks checking out a fork PR head ref under
pull_request_target / workflow_run (PR #2454 ). No Sea Haven workflow uses
those triggers, so there is no reachable behavior change. The Node 24
runtime requirement already landed at v6, so v6 -> v7 carries no new
runner requirement. All runners here are GitHub-hosted (ubuntu, macos).
Covers all 16 checkout pins across 12 reusable/standalone workflows plus
the dependency-review workflow-template scaffold. Consumers on @main pick
this up automatically on merge.
2026-06-25 11:43:10 -04:00
Adam Moussa
7f84f9cfde
INFRA-58 INFRA-59: org starter workflows + issue templates ( #43 )
...
* INFRA-59: add org issue templates (bug, feature, infra-change) + config
Adds .github/ISSUE_TEMPLATE/ with bug_report.md, feature_request.md,
infra-change.md (change-control: impact, rollback plan, affected stacks),
and config.yml disabling blank issues + routing ops to INFRA Jira.
* INFRA-58: add org starter workflows wrapping reusable workflows
Adds workflow-templates/ with starters + .properties.json for:
ci-node, ci-python, cdk-deploy, sam-deploy, dependency-review, labeler,
triage. CI/CD starters call the org reusable workflows in
.github/.github/workflows/ at @main with their required inputs/secrets.
2026-06-05 17:26:16 -04:00