From 2cc26a5a0c68c20e3fef415c2841b8cff2fe2fea Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Tue, 4 Aug 2026 11:24:17 -0400 Subject: [PATCH] ci: add org PR policy caller Refs: PLAT-62 --- .github/dependabot.yml | 4 ++++ .github/workflows/policy.yaml | 30 ++++++++++++++++++++++++++++++ AGENTS.md | 22 ++++++++++++++++++++++ 3 files changed, 56 insertions(+) create mode 100644 .github/workflows/policy.yaml create mode 100644 AGENTS.md diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 14ae532..66dc6bc 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -14,6 +14,8 @@ updates: interval: "weekly" assignees: - "amoussa1229" + commit-message: + prefix: "chore(deps)" groups: minor-and-patch: update-types: @@ -25,6 +27,8 @@ updates: interval: "weekly" assignees: - "amoussa1229" + commit-message: + prefix: "chore(deps)" groups: minor-and-patch: update-types: diff --git a/.github/workflows/policy.yaml b/.github/workflows/policy.yaml new file mode 100644 index 0000000..8798333 --- /dev/null +++ b/.github/workflows/policy.yaml @@ -0,0 +1,30 @@ +name: PR Policy + +on: + pull_request: + types: + - opened + - reopened + - synchronize + - edited + - labeled + - unlabeled + - ready_for_review + +concurrency: + group: "policy-${{ github.event.pull_request.number }}" + cancel-in-progress: true + +permissions: + contents: read + issues: read + pull-requests: read + +jobs: + policy: + uses: Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml@9c1ecf942894b19aba5c71b85b41906c6c83b749 # v1.0.5 + secrets: + JIRA_CLOUD_ID: ${{ secrets.JIRA_CLOUD_ID }} + JIRA_SERVICE_ACCOUNT_EMAIL: ${{ secrets.JIRA_SERVICE_ACCOUNT_EMAIL }} + JIRA_API_TOKEN: ${{ secrets.JIRA_API_TOKEN }} + diff --git a/AGENTS.md b/AGENTS.md new file mode 100644 index 0000000..2550258 --- /dev/null +++ b/AGENTS.md @@ -0,0 +1,22 @@ +# Sea Haven Governance + +## Standards and Authority +- **Handbook**: `engineering-handbook` is the standards authority for all conventions. +- **Jira**: work-status authority. Route product work → DEV, infrastructure/platform → PLAT, security → SEC. Search for duplicates before creating a ticket. + +## Branches +Use one of: `feature/`, `fix/`, `hotfix/`, `chore/`, `docs/`, `refactor/`, `release/` + kebab-case description. Do not include a Jira key in the branch name. + +## Pull Requests +- **Title format**: `type(scope): description (DEV-123)` — every non-exempt PR must end with its Jira key. +- **Body sections** (exactly, in order): `Summary`, `Validation`, `Tests`, `Notes`. Use "None." under Notes when empty. +- State verifiable facts only. Do not justify changes by citing the handbook. No AI-attribution footers. + +## Security and Cross-Review +- Sensitive surfaces (payment flows, authentication, secrets handling, untrusted input) require security review. +- IAM role, policy, or resource-permission changes require cross-family review. Lambda handler signature changes alone do not. + +## CI and Workflow References +- CI must pass before merge. +- Org-level reusable workflow refs must be pinned to a full commit SHA with a `# vX.Y.Z` comment. +