* ci: add org PR policy caller Refs: PLAT-62 * docs(pr): allow 120-character titles Refs: PLAT-62
1.6 KiB
Sea Haven Governance
Standards authority: engineering-handbook · Status authority: Jira
Routing
- Product / feature work → DEV
- Infrastructure and platform → PLAT
- Security → SEC
Branches
feature/, fix/, hotfix/, chore/, docs/, refactor/, release/ + kebab-case description.
No Jira keys in branch names.
Pull Requests
Title: type(scope): description (DEV-123) — every non-exempt PR ends with its Jira key.
Body sections (in order): Summary · Validation · Tests · Notes — use "None." when a section is empty. State verifiable facts only. Do not cite the handbook to justify changes.
Allowed types: feat fix docs style refactor perf test build ci chore revert release.
Security Gates
Changes touching payment flows, authentication, secrets, IaC/IAM, or untrusted user input require a security review. IAM role, policy, or resource-permission changes require cross-family review. Lambda handler-signature changes alone do not trigger cross-family review.
CI and SHA Pins
Pin every GitHub Actions ref to a full commit SHA with an inline version comment:
uses: actions/checkout@abc123def456 # v4.1.0
The deterministic global pre-push security hook must not be bypassed (--no-verify requires
explicit approval). Linting stays in CI; do not gate on it locally.
Repository Note
Docs-only repository. CI runs markdownlint and lychee; no build or test artifacts are produced.
The required check context for branch protection is ci / ci — the job must be named literally
ci / ci to emit that exact context string. Do not rename the job without updating the ruleset.