Commit graph

4 commits

Author SHA1 Message Date
d9a8c7fd8f
docs: align organization templates with Cursor conventions
Refs: PLAT-62
2026-08-03 17:36:56 -04:00
1562cbda8e
ci: scope the three reusable CI workflows to contents:read
ci-python-sam, ci-typescript-cdk and ci-dotnet declared no permissions
at any level, unlike every other workflow here. A reusable workflow that
declares nothing inherits the CALLER's token scopes, and these are
called from deploy repos, so a lint/test/synth job could run holding an
OIDC-mintable token it has no use for. None of the three references
GITHUB_TOKEN, github.token, gh, or any secret, so contents:read is all
they need to check out and build.

Also pass node-version explicitly in the cdk-deploy and ci-node
templates. cicd.md requires callers to pin it so lockfileVersion 3 from
local Node 24 / npm 11 cannot drift from the runner, but no template
did. Only these two targets accept the input; sam-deploy, dotnet-eb,
dependency-review and labeler do not, so they are left alone.

Verified against all 22 callers across the org that none grants
permissions omitting contents:read, so no repo's CI breaks on the
caller-cannot-be-exceeded rule.
2026-07-28 12:13:07 -04:00
69b28c6f3a
ci: pin workflow-template refs to commit SHA
Per the updated handbook convention (engineering-handbook PR #18),
reusable-workflow references use full commit SHA pins with a '# main'
comment instead of the mutable @main branch ref. Templates now ship
pinned so new repos start convention-compliant; Dependabot advances
the pin after instantiation. Commented usage examples in ci-static and
ci-typescript-frontend use the <full-commit-sha> placeholder form.
2026-07-27 15:38:18 -04:00
Adam Moussa
7f84f9cfde
INFRA-58 INFRA-59: org starter workflows + issue templates (#43)
* INFRA-59: add org issue templates (bug, feature, infra-change) + config

Adds .github/ISSUE_TEMPLATE/ with bug_report.md, feature_request.md,
infra-change.md (change-control: impact, rollback plan, affected stacks),
and config.yml disabling blank issues + routing ops to INFRA Jira.

* INFRA-58: add org starter workflows wrapping reusable workflows

Adds workflow-templates/ with starters + .properties.json for:
ci-node, ci-python, cdk-deploy, sam-deploy, dependency-review, labeler,
triage. CI/CD starters call the org reusable workflows in
.github/.github/workflows/ at @main with their required inputs/secrets.
2026-06-05 17:26:16 -04:00