docs(review): retire security and cross-family review gates

Those reviews are no longer merge gates. A new deploy workflow still needs its job_workflow_ref on the deploy role.
This commit is contained in:
Adam Moussa 2026-09-26 16:52:30 -04:00
parent 668a9e43bb
commit 10f72b4a33
No known key found for this signature in database
4 changed files with 2 additions and 16 deletions

View file

@ -22,12 +22,6 @@ State verifiable facts only. Do not cite the handbook to justify changes.
Allowed types: `feat` `fix` `docs` `style` `refactor` `perf` `test` `build` `ci` `chore` `revert` `release`.
## Security Gates
Changes touching payment flows, authentication, secrets, IaC/IAM, or untrusted user input require
a security review. IAM role, policy, or resource-permission changes require cross-family review.
Lambda handler-signature changes alone do not trigger cross-family review.
## CI and SHA Pins
Pin every GitHub Actions ref to a full commit SHA with an inline version comment:

View file

@ -142,7 +142,7 @@ IAM role `githubdeploy-<repo>`, owned by workload Terraform.
- `job_workflow_ref`: `Sea-Haven-Industries/.github/.github/workflows/cd-hcp-fargate.yaml@*` (and `cd-hcp-spa.yaml`)
- `workflow_ref`: the thin caller still `Sea-Haven-Industries/<repo>/.github/workflows/deploy-api.yaml@refs/heads/main` and `@refs/tags/v*`
Adding a reusable is a cross-family IAM change. Adding an app still adds `workflow_ref` for that caller. Do not pin trust to only `ref:refs/heads/main`.
Adding an app adds `workflow_ref` for that caller. Do not pin trust to only `ref:refs/heads/main`.
**Permissions.** Only what the workflows write:

View file

@ -50,14 +50,6 @@ When a reviewer identifies a finding that won't be addressed in the current PR,
Deferred findings handled informally (retro notes, mental to-do lists, "we'll get to it") fall through the cracks. A ticket in the Jira backlog is the minimum bar for accountability.
## Security Review Gates
Two separate gates apply to security-sensitive changes:
**Cross-family review (`cross_review.py`):** Required when the change touches IAM roles, IAM policies, or resource permission boundaries. Run the stateless GPT cross-reviewer via `cross_review.py` in the `security-review` repo. It produces findings-to-verify, not a gospel verdict. After two rounds without convergence, stop and disposition the remainder with Adam. Lambda handler signatures are not a cross-review trigger.
**Security review:** Required when the change touches sensitive authentication paths, secrets handling, IaC/IAM definitions, payment flows, or surfaces that accept untrusted input. These surfaces warrant a structured security review pass in addition to standard code review.
## Turnaround
- Aim to review within one business day of being requested

View file

@ -43,7 +43,7 @@ Write `/<repo>/deploy/*` (see [hcp-terraform.md](hcp-terraform.md#deploy-contrac
### `iam_github_deploy.tf`
The `githubdeploy-<repo>` role only. Trust and permissions are in [cicd.md](cicd.md#github-deploy-role). Adding a deploy workflow means adding its `job_workflow_ref` here. That is a cross-family IAM change.
The `githubdeploy-<repo>` role only. Trust and permissions are in [cicd.md](cicd.md#github-deploy-role). Adding a deploy workflow means adding its `job_workflow_ref` here.
Do **not** add `hcp_iam.tf`. `hcptf-<repo>` and `hcptf-<repo>-plan` live in `seahaven-org-baseline`.