ci: add org PR policy caller (PLAT-62) (#40)
Some checks are pending
Deploy / deploy (push) Waiting to run

* ci: add org PR policy caller

Refs: PLAT-62

* fix(ci): name PR policy workflow

Refs: PLAT-62
This commit is contained in:
Adam Moussa 2026-08-04 11:58:00 -04:00 • committed by GitHub
parent 5464a081bd
commit a0dbc92f59
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
3 changed files with 58 additions and 0 deletions

View file

@ -4,6 +4,8 @@ updates:
directory: "/cdk"
schedule:
interval: "weekly"
commit-message:
prefix: "chore(deps)"
groups:
minor-and-patch:
update-types:
@ -14,6 +16,8 @@ updates:
directory: "/lambdas/classifier"
schedule:
interval: "weekly"
commit-message:
prefix: "chore(deps)"
groups:
minor-and-patch:
update-types:
@ -24,6 +28,8 @@ updates:
directory: "/lambdas/slack_post"
schedule:
interval: "weekly"
commit-message:
prefix: "chore(deps)"
groups:
minor-and-patch:
update-types:
@ -34,6 +40,8 @@ updates:
directory: "/"
schedule:
interval: "weekly"
commit-message:
prefix: "chore(deps)"
groups:
minor-and-patch:
update-types:

29
.github/workflows/policy.yaml vendored Normal file
View file

@ -0,0 +1,29 @@
name: PR Policy
on:
pull_request:
types:
- opened
- reopened
- synchronize
- edited
- labeled
- unlabeled
- ready_for_review
concurrency:
group: "policy-${{ github.event.pull_request.number }}"
cancel-in-progress: true
permissions:
contents: read
issues: read
pull-requests: read
jobs:
policy:
uses: Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml@9c1ecf942894b19aba5c71b85b41906c6c83b749 # v1.0.5
secrets:
JIRA_CLOUD_ID: ${{ secrets.JIRA_CLOUD_ID }}
JIRA_SERVICE_ACCOUNT_EMAIL: ${{ secrets.JIRA_SERVICE_ACCOUNT_EMAIL }}
JIRA_API_TOKEN: ${{ secrets.JIRA_API_TOKEN }}

21
AGENTS.md Normal file
View file

@ -0,0 +1,21 @@
# Sea Haven Governance
## Standards and Authority
- **Handbook**: `engineering-handbook` is the standards authority for all conventions.
- **Jira**: work-status authority. Route product work → DEV, infrastructure/platform → PLAT, security → SEC. Search for duplicates before creating a ticket.
## Branches
Use one of: `feature/`, `fix/`, `hotfix/`, `chore/`, `docs/`, `refactor/`, `release/` + kebab-case description. Do not include a Jira key in the branch name.
## Pull Requests
- **Title format**: `type(scope): description (DEV-123)` — every non-exempt PR must end with its Jira key.
- **Body sections** (exactly, in order): `Summary`, `Validation`, `Tests`, `Notes`. Use "None." under Notes when empty.
- State verifiable facts only. Do not justify changes by citing the handbook. No AI-attribution footers.
## Security and Cross-Review
- Sensitive surfaces (payment flows, authentication, secrets handling, untrusted input) require security review.
- IAM role, policy, or resource-permission changes require cross-family review. Lambda handler signature changes alone do not.
## CI and Workflow References
- CI must pass before merge.
- Org-level reusable workflow refs must be pinned to a full commit SHA with a `# vX.Y.Z` comment.