engineering-handbook/AGENTS.md
Adam Moussa f16d448822
Some checks are pending
ci / ci / ci (push) Waiting to run
ci: add org PR policy caller (PLAT-62) (#30)
* ci: add org PR policy caller

Refs: PLAT-62

* docs(pr): allow 120-character titles

Refs: PLAT-62
2026-08-04 14:43:44 -04:00

46 lines
1.6 KiB
Markdown

# Sea Haven Governance
**Standards authority:** engineering-handbook · **Status authority:** Jira
## Routing
- Product / feature work → DEV
- Infrastructure and platform → PLAT
- Security → SEC
## Branches
`feature/`, `fix/`, `hotfix/`, `chore/`, `docs/`, `refactor/`, `release/` + kebab-case description.
No Jira keys in branch names.
## Pull Requests
**Title:** `type(scope): description (DEV-123)` — every non-exempt PR ends with its Jira key.
**Body sections (in order):** Summary · Validation · Tests · Notes — use "None." when a section is empty.
State verifiable facts only. Do not cite the handbook to justify changes.
Allowed types: `feat` `fix` `docs` `style` `refactor` `perf` `test` `build` `ci` `chore` `revert` `release`.
## Security Gates
Changes touching payment flows, authentication, secrets, IaC/IAM, or untrusted user input require
a security review. IAM role, policy, or resource-permission changes require cross-family review.
Lambda handler-signature changes alone do not trigger cross-family review.
## CI and SHA Pins
Pin every GitHub Actions ref to a full commit SHA with an inline version comment:
```yaml
uses: actions/checkout@abc123def456 # v4.1.0
```
The deterministic global pre-push security hook must not be bypassed (`--no-verify` requires
explicit approval). Linting stays in CI; do not gate on it locally.
## Repository Note
**Docs-only repository.** CI runs markdownlint and lychee; no build or test artifacts are produced.
The required check context for branch protection is `ci / ci` — the job must be named literally
`ci / ci` to emit that exact context string. Do not rename the job without updating the ruleset.