Compare commits

...

8 commits

Author SHA1 Message Date
Adam Moussa
31b02e466e
fix(ci): disambiguate concurrency groups across sibling reusable-CI callers (#41)
The group key ci-${{ github.workflow }}-${{ github.ref }} resolves
identically for every job in a caller workflow (github.workflow is the
caller's name in a reusable workflow), so repos calling two reusable CI
workflows from one ci.yaml (e.g. exec-aide python + typescript) had
their jobs cancel each other on every run.

Prefix each group with the reusable workflow's own filename and append
its distinguishing input (source-dirs / working-directory) so sibling
jobs get distinct groups while superseded runs of the same job still
cancel.
2026-06-05 12:30:58 -04:00
Adam Moussa
1cc7236ef6
fix(ci): drop pull-requests write from callable-dependency-review (#40)
Callers grant no explicit permissions, so they pass the org default
read-only token. A reusable workflow cannot request more than its
caller grants, causing startup_failure on every dependency-review run.
dependency-review-action only needs contents: read when not posting
PR comments.
2026-06-05 12:19:06 -04:00
Adam Moussa
2e74e2a670
Pin third-party actions to full commit SHAs (#39)
Replace mutable v1 tag references with immutable commit SHAs so a
compromised or force-moved tag cannot inject code into reusable
workflows. Each pin keeps a # v1 comment for readability.

- claude-code-action in compliance-audit.yaml
- ruby/setup-ruby in cd-mobile-ios.yaml (v1 branch)
2026-06-05 12:13:12 -04:00
Adam Moussa
62d82eae29
Add cancel-in-progress concurrency to reusable CI (#38)
Superseded CI runs on the same ref keep consuming runners and delay
feedback on the latest push. Add a job-level concurrency group keyed
on github.workflow and github.ref so a new push cancels the in-flight
CI run for that branch.

Concurrency is set at the job level rather than the workflow level
because these are workflow_call reusable workflows: workflow-level
concurrency would resolve github.workflow against the caller's context,
collapsing unrelated callers into one group. cd-* deploy workflows are
intentionally left untouched to avoid cancelling in-flight deploys.
2026-06-05 12:12:55 -04:00
Adam Moussa
7aab740e59
chore(ci): bump configure-aws-credentials to v6 (#35)
Bump all aws-actions/configure-aws-credentials references to @v6 (org
target) across the reusable CD workflows. v6 is the verified org standard
alongside actions/checkout@v6.

Ref: engineering-handbook cicd.md (workflow standardization).
2026-06-05 12:12:30 -04:00
Adam Moussa
73b98a66ac
chore(ci): bump actions/checkout to v6 (#34)
Bump all actions/checkout references to @v6 (org target). v4 runs on a
node runtime version that is being deprecated; v6 is the verified org
standard alongside configure-aws-credentials@v6.

Ref: engineering-handbook cicd.md (workflow standardization).
2026-06-05 12:11:44 -04:00
Adam Moussa
81189e6476
Add org-wide default CODEOWNERS (#37)
Set @amoussa1229 as the default owner for all paths so the new
required code-owner review rule on the org main-branch ruleset has
a reviewer to resolve against. The .github repo CODEOWNERS acts as
the org-wide fallback for repos without their own file.
2026-06-05 12:11:40 -04:00
Adam Moussa
3f4bf4f54d
Add dependency-review workflow and Sea Haven PR checklist (#36)
Add a reusable callable-dependency-review workflow that runs
actions/dependency-review-action with fail-on-severity: high, and
append a Sea Haven checklist to the PR template covering infra,
secrets, PITR, Slack, Confluence, memory, and cross-review.
2026-06-05 12:11:36 -04:00
10 changed files with 45 additions and 13 deletions

1
.github/CODEOWNERS vendored Normal file
View file

@ -0,0 +1 @@
* @amoussa1229

View file

@ -16,3 +16,12 @@ PR conventions — see engineering-handbook/pull-requests.md
## Notes
<!-- Anything reviewers should know: migration steps, deploy order, follow-ups, breaking changes. Delete this section if empty. -->
## Sea Haven checklist
- [ ] CDK diff / SAM changeset reviewed (if infra change)
- [ ] Secrets added to Parameter Store / Secrets Manager (not hardcoded)
- [ ] DynamoDB PITR verified on new tables
- [ ] Slack notification tested in staging
- [ ] Confluence Architecture Map updated
- [ ] Memory update queued (if new repo/stack)
- [ ] Cross-review requested (if IAM or Lambda handler signature change)

View file

@ -0,0 +1,13 @@
name: Dependency Review
on:
workflow_call:
permissions:
contents: read
jobs:
dependency-review:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v6
- uses: actions/dependency-review-action@v4
with:
fail-on-severity: high

View file

@ -53,7 +53,7 @@ jobs:
runs-on: ubuntu-latest
timeout-minutes: 30
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v6
- uses: docker/setup-qemu-action@v3
if: ${{ inputs.enable-qemu }}
@ -90,7 +90,7 @@ jobs:
pip install -r "$req"
done
- uses: aws-actions/configure-aws-credentials@v4
- uses: aws-actions/configure-aws-credentials@v6
with:
role-to-assume: ${{ secrets.deploy-role-arn }}
aws-region: ${{ inputs.region }}

View file

@ -60,9 +60,9 @@ jobs:
run:
working-directory: ${{ inputs.working-directory }}
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v6
- uses: aws-actions/configure-aws-credentials@v4
- uses: aws-actions/configure-aws-credentials@v6
with:
role-to-assume: ${{ secrets.deploy-role-arn }}
aws-region: ${{ inputs.region }}
@ -73,7 +73,7 @@ jobs:
cache: npm
cache-dependency-path: ${{ inputs.cache-dependency-path }}
- uses: ruby/setup-ruby@v1
- uses: ruby/setup-ruby@afeafc3d1ab54a631816aba4c914a0081c12ff2f # v1
with:
ruby-version: ${{ inputs.ruby-version }}
bundler-cache: true

View file

@ -40,7 +40,7 @@ jobs:
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v6
- uses: actions/setup-python@v5
with:
@ -48,7 +48,7 @@ jobs:
- uses: aws-actions/setup-sam@v2
- uses: aws-actions/configure-aws-credentials@v4
- uses: aws-actions/configure-aws-credentials@v6
with:
role-to-assume: ${{ secrets.deploy-role-arn }}
aws-region: ${{ inputs.region }}

View file

@ -24,11 +24,14 @@ jobs:
ci:
runs-on: ubuntu-latest
timeout-minutes: 20
concurrency:
group: ci-dotnet-${{ github.workflow }}-${{ github.ref }}-${{ inputs.working-directory }}
cancel-in-progress: true
defaults:
run:
working-directory: ${{ inputs.working-directory }}
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v6
- uses: actions/setup-dotnet@v5
with:

View file

@ -48,8 +48,11 @@ jobs:
ci:
runs-on: ubuntu-latest
timeout-minutes: 10
concurrency:
group: ci-python-sam-${{ github.workflow }}-${{ github.ref }}-${{ inputs.source-dirs }}
cancel-in-progress: true
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v6
- uses: actions/setup-python@v5
with:

View file

@ -60,8 +60,11 @@ jobs:
ci:
runs-on: ubuntu-latest
timeout-minutes: 30
concurrency:
group: ci-typescript-cdk-${{ github.workflow }}-${{ github.ref }}-${{ inputs.working-directory }}
cancel-in-progress: true
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v6
- uses: docker/setup-qemu-action@v3
if: ${{ inputs.enable-qemu }}

View file

@ -57,13 +57,13 @@ jobs:
repositories: ${{ matrix.repo }},engineering-handbook
- name: Checkout repo
uses: actions/checkout@v4
uses: actions/checkout@v6
with:
repository: Sea-Haven-Industries/${{ matrix.repo }}
token: ${{ steps.app-token.outputs.token }}
- name: Checkout engineering handbook
uses: actions/checkout@v4
uses: actions/checkout@v6
with:
repository: Sea-Haven-Industries/engineering-handbook
token: ${{ steps.app-token.outputs.token }}
@ -71,7 +71,7 @@ jobs:
- name: Run compliance audit
id: audit
uses: anthropics/claude-code-action@v1
uses: anthropics/claude-code-action@41ea7642c1436fa0ee57aae58347904b71a5af27 # v1
with:
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
prompt: |