From f16d44882221c0c245a9699e6c649672c5086fdb Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Tue, 4 Aug 2026 14:43:44 -0400 Subject: [PATCH] ci: add org PR policy caller (PLAT-62) (#30) * ci: add org PR policy caller Refs: PLAT-62 * docs(pr): allow 120-character titles Refs: PLAT-62 --- .github/dependabot.yml | 2 ++ .github/workflows/policy.yaml | 22 +++++++++++++++++ AGENTS.md | 46 +++++++++++++++++++++++++++++++++++ pull-requests.md | 2 +- 4 files changed, 71 insertions(+), 1 deletion(-) create mode 100644 .github/workflows/policy.yaml create mode 100644 AGENTS.md diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 1210f19..b7393d5 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -4,6 +4,8 @@ updates: directory: "/" schedule: interval: "weekly" + commit-message: + prefix: "chore(deps)" groups: minor-and-patch: update-types: diff --git a/.github/workflows/policy.yaml b/.github/workflows/policy.yaml new file mode 100644 index 0000000..eba1158 --- /dev/null +++ b/.github/workflows/policy.yaml @@ -0,0 +1,22 @@ +name: PR Policy + +on: + pull_request: + types: [opened, reopened, synchronize, edited, labeled, unlabeled, ready_for_review] + +concurrency: + group: "policy-${{ github.event.pull_request.number }}" + cancel-in-progress: true + +permissions: + contents: read + issues: read + pull-requests: read + +jobs: + policy: + uses: Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml@9c1ecf942894b19aba5c71b85b41906c6c83b749 # v1.0.5 + secrets: + JIRA_CLOUD_ID: ${{ secrets.JIRA_CLOUD_ID }} + JIRA_SERVICE_ACCOUNT_EMAIL: ${{ secrets.JIRA_SERVICE_ACCOUNT_EMAIL }} + JIRA_API_TOKEN: ${{ secrets.JIRA_API_TOKEN }} diff --git a/AGENTS.md b/AGENTS.md new file mode 100644 index 0000000..52e477e --- /dev/null +++ b/AGENTS.md @@ -0,0 +1,46 @@ +# Sea Haven Governance + +**Standards authority:** engineering-handbook · **Status authority:** Jira + +## Routing + +- Product / feature work → DEV +- Infrastructure and platform → PLAT +- Security → SEC + +## Branches + +`feature/`, `fix/`, `hotfix/`, `chore/`, `docs/`, `refactor/`, `release/` + kebab-case description. +No Jira keys in branch names. + +## Pull Requests + +**Title:** `type(scope): description (DEV-123)` — every non-exempt PR ends with its Jira key. + +**Body sections (in order):** Summary · Validation · Tests · Notes — use "None." when a section is empty. +State verifiable facts only. Do not cite the handbook to justify changes. + +Allowed types: `feat` `fix` `docs` `style` `refactor` `perf` `test` `build` `ci` `chore` `revert` `release`. + +## Security Gates + +Changes touching payment flows, authentication, secrets, IaC/IAM, or untrusted user input require +a security review. IAM role, policy, or resource-permission changes require cross-family review. +Lambda handler-signature changes alone do not trigger cross-family review. + +## CI and SHA Pins + +Pin every GitHub Actions ref to a full commit SHA with an inline version comment: + +```yaml +uses: actions/checkout@abc123def456 # v4.1.0 +``` + +The deterministic global pre-push security hook must not be bypassed (`--no-verify` requires +explicit approval). Linting stays in CI; do not gate on it locally. + +## Repository Note + +**Docs-only repository.** CI runs markdownlint and lychee; no build or test artifacts are produced. +The required check context for branch protection is `ci / ci` — the job must be named literally +`ci / ci` to emit that exact context string. Do not rename the job without updating the ruleset. diff --git a/pull-requests.md b/pull-requests.md index 8915659..e71cfba 100644 --- a/pull-requests.md +++ b/pull-requests.md @@ -15,7 +15,7 @@ Each PR should represent a single logical change. If you find yourself writing " - Use the Conventional Commit format with a required Jira key suffix: `type(scope): description (KEY-123)` - `scope` is optional; omit it when the change is broad or no single scope applies - Active keys are `DEV`, `PLAT`, and `SEC` -- Keep the full title under 72 characters +- Keep the full title at or below 120 characters - Describe the change, not the ticket | Good | Bad |