diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 1210f19..b7393d5 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -4,6 +4,8 @@ updates: directory: "/" schedule: interval: "weekly" + commit-message: + prefix: "chore(deps)" groups: minor-and-patch: update-types: diff --git a/.github/workflows/policy.yaml b/.github/workflows/policy.yaml new file mode 100644 index 0000000..eba1158 --- /dev/null +++ b/.github/workflows/policy.yaml @@ -0,0 +1,22 @@ +name: PR Policy + +on: + pull_request: + types: [opened, reopened, synchronize, edited, labeled, unlabeled, ready_for_review] + +concurrency: + group: "policy-${{ github.event.pull_request.number }}" + cancel-in-progress: true + +permissions: + contents: read + issues: read + pull-requests: read + +jobs: + policy: + uses: Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml@9c1ecf942894b19aba5c71b85b41906c6c83b749 # v1.0.5 + secrets: + JIRA_CLOUD_ID: ${{ secrets.JIRA_CLOUD_ID }} + JIRA_SERVICE_ACCOUNT_EMAIL: ${{ secrets.JIRA_SERVICE_ACCOUNT_EMAIL }} + JIRA_API_TOKEN: ${{ secrets.JIRA_API_TOKEN }} diff --git a/AGENTS.md b/AGENTS.md new file mode 100644 index 0000000..52e477e --- /dev/null +++ b/AGENTS.md @@ -0,0 +1,46 @@ +# Sea Haven Governance + +**Standards authority:** engineering-handbook · **Status authority:** Jira + +## Routing + +- Product / feature work → DEV +- Infrastructure and platform → PLAT +- Security → SEC + +## Branches + +`feature/`, `fix/`, `hotfix/`, `chore/`, `docs/`, `refactor/`, `release/` + kebab-case description. +No Jira keys in branch names. + +## Pull Requests + +**Title:** `type(scope): description (DEV-123)` — every non-exempt PR ends with its Jira key. + +**Body sections (in order):** Summary · Validation · Tests · Notes — use "None." when a section is empty. +State verifiable facts only. Do not cite the handbook to justify changes. + +Allowed types: `feat` `fix` `docs` `style` `refactor` `perf` `test` `build` `ci` `chore` `revert` `release`. + +## Security Gates + +Changes touching payment flows, authentication, secrets, IaC/IAM, or untrusted user input require +a security review. IAM role, policy, or resource-permission changes require cross-family review. +Lambda handler-signature changes alone do not trigger cross-family review. + +## CI and SHA Pins + +Pin every GitHub Actions ref to a full commit SHA with an inline version comment: + +```yaml +uses: actions/checkout@abc123def456 # v4.1.0 +``` + +The deterministic global pre-push security hook must not be bypassed (`--no-verify` requires +explicit approval). Linting stays in CI; do not gate on it locally. + +## Repository Note + +**Docs-only repository.** CI runs markdownlint and lychee; no build or test artifacts are produced. +The required check context for branch protection is `ci / ci` — the job must be named literally +`ci / ci` to emit that exact context string. Do not rename the job without updating the ruleset.