mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-10-03 04:33:25 +00:00
Compare commits
8 commits
204958e8d9
...
31b02e466e
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
31b02e466e | ||
|
|
1cc7236ef6 | ||
|
|
2e74e2a670 | ||
|
|
62d82eae29 | ||
|
|
7aab740e59 | ||
|
|
73b98a66ac | ||
|
|
81189e6476 | ||
|
|
3f4bf4f54d |
10 changed files with 45 additions and 13 deletions
1
.github/CODEOWNERS
vendored
Normal file
1
.github/CODEOWNERS
vendored
Normal file
|
|
@ -0,0 +1 @@
|
|||
* @amoussa1229
|
||||
9
.github/PULL_REQUEST_TEMPLATE.md
vendored
9
.github/PULL_REQUEST_TEMPLATE.md
vendored
|
|
@ -16,3 +16,12 @@ PR conventions — see engineering-handbook/pull-requests.md
|
|||
|
||||
## Notes
|
||||
<!-- Anything reviewers should know: migration steps, deploy order, follow-ups, breaking changes. Delete this section if empty. -->
|
||||
|
||||
## Sea Haven checklist
|
||||
- [ ] CDK diff / SAM changeset reviewed (if infra change)
|
||||
- [ ] Secrets added to Parameter Store / Secrets Manager (not hardcoded)
|
||||
- [ ] DynamoDB PITR verified on new tables
|
||||
- [ ] Slack notification tested in staging
|
||||
- [ ] Confluence Architecture Map updated
|
||||
- [ ] Memory update queued (if new repo/stack)
|
||||
- [ ] Cross-review requested (if IAM or Lambda handler signature change)
|
||||
|
|
|
|||
13
.github/workflows/callable-dependency-review.yaml
vendored
Normal file
13
.github/workflows/callable-dependency-review.yaml
vendored
Normal file
|
|
@ -0,0 +1,13 @@
|
|||
name: Dependency Review
|
||||
on:
|
||||
workflow_call:
|
||||
permissions:
|
||||
contents: read
|
||||
jobs:
|
||||
dependency-review:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
- uses: actions/dependency-review-action@v4
|
||||
with:
|
||||
fail-on-severity: high
|
||||
4
.github/workflows/cd-cdk.yaml
vendored
4
.github/workflows/cd-cdk.yaml
vendored
|
|
@ -53,7 +53,7 @@ jobs:
|
|||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 30
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- uses: actions/checkout@v6
|
||||
|
||||
- uses: docker/setup-qemu-action@v3
|
||||
if: ${{ inputs.enable-qemu }}
|
||||
|
|
@ -90,7 +90,7 @@ jobs:
|
|||
pip install -r "$req"
|
||||
done
|
||||
|
||||
- uses: aws-actions/configure-aws-credentials@v4
|
||||
- uses: aws-actions/configure-aws-credentials@v6
|
||||
with:
|
||||
role-to-assume: ${{ secrets.deploy-role-arn }}
|
||||
aws-region: ${{ inputs.region }}
|
||||
|
|
|
|||
6
.github/workflows/cd-mobile-ios.yaml
vendored
6
.github/workflows/cd-mobile-ios.yaml
vendored
|
|
@ -60,9 +60,9 @@ jobs:
|
|||
run:
|
||||
working-directory: ${{ inputs.working-directory }}
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- uses: actions/checkout@v6
|
||||
|
||||
- uses: aws-actions/configure-aws-credentials@v4
|
||||
- uses: aws-actions/configure-aws-credentials@v6
|
||||
with:
|
||||
role-to-assume: ${{ secrets.deploy-role-arn }}
|
||||
aws-region: ${{ inputs.region }}
|
||||
|
|
@ -73,7 +73,7 @@ jobs:
|
|||
cache: npm
|
||||
cache-dependency-path: ${{ inputs.cache-dependency-path }}
|
||||
|
||||
- uses: ruby/setup-ruby@v1
|
||||
- uses: ruby/setup-ruby@afeafc3d1ab54a631816aba4c914a0081c12ff2f # v1
|
||||
with:
|
||||
ruby-version: ${{ inputs.ruby-version }}
|
||||
bundler-cache: true
|
||||
|
|
|
|||
4
.github/workflows/cd-sam.yaml
vendored
4
.github/workflows/cd-sam.yaml
vendored
|
|
@ -40,7 +40,7 @@ jobs:
|
|||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 15
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- uses: actions/checkout@v6
|
||||
|
||||
- uses: actions/setup-python@v5
|
||||
with:
|
||||
|
|
@ -48,7 +48,7 @@ jobs:
|
|||
|
||||
- uses: aws-actions/setup-sam@v2
|
||||
|
||||
- uses: aws-actions/configure-aws-credentials@v4
|
||||
- uses: aws-actions/configure-aws-credentials@v6
|
||||
with:
|
||||
role-to-assume: ${{ secrets.deploy-role-arn }}
|
||||
aws-region: ${{ inputs.region }}
|
||||
|
|
|
|||
5
.github/workflows/ci-dotnet.yaml
vendored
5
.github/workflows/ci-dotnet.yaml
vendored
|
|
@ -24,11 +24,14 @@ jobs:
|
|||
ci:
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 20
|
||||
concurrency:
|
||||
group: ci-dotnet-${{ github.workflow }}-${{ github.ref }}-${{ inputs.working-directory }}
|
||||
cancel-in-progress: true
|
||||
defaults:
|
||||
run:
|
||||
working-directory: ${{ inputs.working-directory }}
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- uses: actions/checkout@v6
|
||||
|
||||
- uses: actions/setup-dotnet@v5
|
||||
with:
|
||||
|
|
|
|||
5
.github/workflows/ci-python-sam.yaml
vendored
5
.github/workflows/ci-python-sam.yaml
vendored
|
|
@ -48,8 +48,11 @@ jobs:
|
|||
ci:
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 10
|
||||
concurrency:
|
||||
group: ci-python-sam-${{ github.workflow }}-${{ github.ref }}-${{ inputs.source-dirs }}
|
||||
cancel-in-progress: true
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- uses: actions/checkout@v6
|
||||
|
||||
- uses: actions/setup-python@v5
|
||||
with:
|
||||
|
|
|
|||
5
.github/workflows/ci-typescript-cdk.yaml
vendored
5
.github/workflows/ci-typescript-cdk.yaml
vendored
|
|
@ -60,8 +60,11 @@ jobs:
|
|||
ci:
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 30
|
||||
concurrency:
|
||||
group: ci-typescript-cdk-${{ github.workflow }}-${{ github.ref }}-${{ inputs.working-directory }}
|
||||
cancel-in-progress: true
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- uses: actions/checkout@v6
|
||||
|
||||
- uses: docker/setup-qemu-action@v3
|
||||
if: ${{ inputs.enable-qemu }}
|
||||
|
|
|
|||
6
.github/workflows/compliance-audit.yaml
vendored
6
.github/workflows/compliance-audit.yaml
vendored
|
|
@ -57,13 +57,13 @@ jobs:
|
|||
repositories: ${{ matrix.repo }},engineering-handbook
|
||||
|
||||
- name: Checkout repo
|
||||
uses: actions/checkout@v4
|
||||
uses: actions/checkout@v6
|
||||
with:
|
||||
repository: Sea-Haven-Industries/${{ matrix.repo }}
|
||||
token: ${{ steps.app-token.outputs.token }}
|
||||
|
||||
- name: Checkout engineering handbook
|
||||
uses: actions/checkout@v4
|
||||
uses: actions/checkout@v6
|
||||
with:
|
||||
repository: Sea-Haven-Industries/engineering-handbook
|
||||
token: ${{ steps.app-token.outputs.token }}
|
||||
|
|
@ -71,7 +71,7 @@ jobs:
|
|||
|
||||
- name: Run compliance audit
|
||||
id: audit
|
||||
uses: anthropics/claude-code-action@v1
|
||||
uses: anthropics/claude-code-action@41ea7642c1436fa0ee57aae58347904b71a5af27 # v1
|
||||
with:
|
||||
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
|
||||
prompt: |
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue