mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-10-01 01:43:11 +00:00
Add a reusable callable-dependency-review workflow that runs actions/dependency-review-action with fail-on-severity: high, and append a Sea Haven checklist to the PR template covering infra, secrets, PITR, Slack, Confluence, memory, and cross-review.
27 lines
1.3 KiB
Markdown
27 lines
1.3 KiB
Markdown
<!--
|
|
PR conventions — see engineering-handbook/pull-requests.md
|
|
- Title: imperative mood, under 70 chars, describe the change not the ticket (e.g. "Add receipt parser Lambda", not "PROJ-123" or "Bug fix").
|
|
- Scope: one logical change per PR. If the title needs an "and", split it.
|
|
- Jira: put the issue key in the branch name or this PR title (e.g. [PROJ-123]) to link the PR into the Jira issue's development panel. Omit if the work has no ticket.
|
|
-->
|
|
|
|
## Summary
|
|
<!-- What changed and why — 1-3 sentences. Explain the motivation, not just the diff. -->
|
|
|
|
## Validation
|
|
<!-- How you verified it works — steps taken, commands run, screenshots if UI. -->
|
|
|
|
## Tests
|
|
<!-- What tests were added, updated, or run. If no automated tests, explain the manual testing. -->
|
|
|
|
## Notes
|
|
<!-- Anything reviewers should know: migration steps, deploy order, follow-ups, breaking changes. Delete this section if empty. -->
|
|
|
|
## Sea Haven checklist
|
|
- [ ] CDK diff / SAM changeset reviewed (if infra change)
|
|
- [ ] Secrets added to Parameter Store / Secrets Manager (not hardcoded)
|
|
- [ ] DynamoDB PITR verified on new tables
|
|
- [ ] Slack notification tested in staging
|
|
- [ ] Confluence Architecture Map updated
|
|
- [ ] Memory update queued (if new repo/stack)
|
|
- [ ] Cross-review requested (if IAM or Lambda handler signature change)
|