CODEOWNERS cannot require approval from two distinct teams on the same
files (multiple owners on a line is any-one/OR; separate lines are
last-match-wins). shoc-backend and shoc-frontend-new need every PR to be
approved by BOTH the external dev team and the internal-dev senior group,
so a custom gate is the only way to express that AND.
callable-required-review.yaml passes only when every team named in
all-of-teams has at least one approving review. Team membership is an org
read the default GITHUB_TOKEN cannot do, so the caller supplies a GitHub
App token (Members: read + Pull requests: read); no write scopes are
needed because the job's own pass/fail is the required status check. It
re-evaluates on pull_request and pull_request_review, and ignores author
self-reviews and non-decisive COMMENTED reviews.
Actions are SHA-pinned (Dependabot github-actions ecosystem already
covers this repo). The all-of-teams input is read via env, never
interpolated into the script body, to avoid Actions script injection.
INFRA-69: README documented the deleted claude-code-review.yaml workflow and
its rollout as the live PR-review setup. PR reviews are handled by the official
Claude Code App (since 2026-05-13); corrected the workflow list, added a PR
Reviews note, marked the legacy rollout script, and replaced the obsolete
rollout step. Preserved the claude-code-ci App + secrets (compliance-audit
still uses them).
INFRA-68: add SECURITY.md (private vuln reporting via GitHub advisory / email)
and SUPPORT.md (Jira INFRA, handbook, security pointer).
The bootstrap IAM stack (oidc-deploy-roles.yaml) had no README coverage:
how to deploy it manually (no CD pipeline; >51KB needs --s3-bucket), the
scoped github-cfn-execution-role contract, and the
seahaven-lambda-execution-boundary ceiling for SAM Lambda roles.
Documents the INFRA-97 / INFRA-103 work.
Parameterized workflows that each repo calls via a thin 3-5 line
caller. All lint, test, and validate steps are toggleable so repos
can adopt incrementally. Covers Python SAM, Python CDK, TypeScript
CDK, and Node.js SAM stacks.
- Reusable PR review workflow (repos call via thin wrapper)
- Weekly compliance audit across all org repos
- Rollout script to push wrapper workflow to all repos
- Uses GitHub App tokens for cross-repo auth (no PAT rotation needed)