mirror of
https://github.com/Sea-Haven-Industries/engineering-handbook.git
synced 2026-09-30 09:13:14 +00:00
47 lines
1.6 KiB
Markdown
47 lines
1.6 KiB
Markdown
|
|
# Sea Haven Governance
|
||
|
|
|
||
|
|
**Standards authority:** engineering-handbook · **Status authority:** Jira
|
||
|
|
|
||
|
|
## Routing
|
||
|
|
|
||
|
|
- Product / feature work → DEV
|
||
|
|
- Infrastructure and platform → PLAT
|
||
|
|
- Security → SEC
|
||
|
|
|
||
|
|
## Branches
|
||
|
|
|
||
|
|
`feature/`, `fix/`, `hotfix/`, `chore/`, `docs/`, `refactor/`, `release/` + kebab-case description.
|
||
|
|
No Jira keys in branch names.
|
||
|
|
|
||
|
|
## Pull Requests
|
||
|
|
|
||
|
|
**Title:** `type(scope): description (DEV-123)` — every non-exempt PR ends with its Jira key.
|
||
|
|
|
||
|
|
**Body sections (in order):** Summary · Validation · Tests · Notes — use "None." when a section is empty.
|
||
|
|
State verifiable facts only. Do not cite the handbook to justify changes.
|
||
|
|
|
||
|
|
Allowed types: `feat` `fix` `docs` `style` `refactor` `perf` `test` `build` `ci` `chore` `revert` `release`.
|
||
|
|
|
||
|
|
## Security Gates
|
||
|
|
|
||
|
|
Changes touching payment flows, authentication, secrets, IaC/IAM, or untrusted user input require
|
||
|
|
a security review. IAM role, policy, or resource-permission changes require cross-family review.
|
||
|
|
Lambda handler-signature changes alone do not trigger cross-family review.
|
||
|
|
|
||
|
|
## CI and SHA Pins
|
||
|
|
|
||
|
|
Pin every GitHub Actions ref to a full commit SHA with an inline version comment:
|
||
|
|
|
||
|
|
```yaml
|
||
|
|
uses: actions/checkout@abc123def456 # v4.1.0
|
||
|
|
```
|
||
|
|
|
||
|
|
The deterministic global pre-push security hook must not be bypassed (`--no-verify` requires
|
||
|
|
explicit approval). Linting stays in CI; do not gate on it locally.
|
||
|
|
|
||
|
|
## Repository Note
|
||
|
|
|
||
|
|
**Docs-only repository.** CI runs markdownlint and lychee; no build or test artifacts are produced.
|
||
|
|
The required check context for branch protection is `ci / ci` — the job must be named literally
|
||
|
|
`ci / ci` to emit that exact context string. Do not rename the job without updating the ruleset.
|