mirror of
https://github.com/Sea-Haven-Industries/forgejo.git
synced 2026-09-30 05:23:11 +00:00
ci: add org PR policy caller
Refs: PLAT-62
This commit is contained in:
parent
0613d8d6b0
commit
1062bb35d6
3 changed files with 61 additions and 0 deletions
6
.github/dependabot.yml
vendored
6
.github/dependabot.yml
vendored
|
|
@ -4,6 +4,8 @@ updates:
|
|||
directory: /
|
||||
schedule:
|
||||
interval: weekly
|
||||
commit-message:
|
||||
prefix: "chore(deps)"
|
||||
assignees:
|
||||
- amoussa1229
|
||||
ignore:
|
||||
|
|
@ -19,6 +21,8 @@ updates:
|
|||
directory: /
|
||||
schedule:
|
||||
interval: weekly
|
||||
commit-message:
|
||||
prefix: "chore(deps)"
|
||||
assignees:
|
||||
- amoussa1229
|
||||
|
||||
|
|
@ -26,5 +30,7 @@ updates:
|
|||
directory: /lambda/backup-verification
|
||||
schedule:
|
||||
interval: weekly
|
||||
commit-message:
|
||||
prefix: "chore(deps)"
|
||||
assignees:
|
||||
- amoussa1229
|
||||
|
|
|
|||
22
.github/workflows/policy.yaml
vendored
Normal file
22
.github/workflows/policy.yaml
vendored
Normal file
|
|
@ -0,0 +1,22 @@
|
|||
name: PR Policy
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
types: [opened, reopened, synchronize, edited, labeled, unlabeled, ready_for_review]
|
||||
|
||||
concurrency:
|
||||
group: "policy-${{ github.event.pull_request.number }}"
|
||||
cancel-in-progress: true
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
issues: read
|
||||
pull-requests: read
|
||||
|
||||
jobs:
|
||||
policy:
|
||||
uses: Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml@9c1ecf942894b19aba5c71b85b41906c6c83b749 # v1.0.5
|
||||
secrets:
|
||||
JIRA_CLOUD_ID: ${{ secrets.JIRA_CLOUD_ID }}
|
||||
JIRA_SERVICE_ACCOUNT_EMAIL: ${{ secrets.JIRA_SERVICE_ACCOUNT_EMAIL }}
|
||||
JIRA_API_TOKEN: ${{ secrets.JIRA_API_TOKEN }}
|
||||
33
AGENTS.md
Normal file
33
AGENTS.md
Normal file
|
|
@ -0,0 +1,33 @@
|
|||
# Sea Haven Org Governance
|
||||
|
||||
> Full engineering standards: [engineering-handbook](https://github.com/Sea-Haven-Industries/engineering-handbook).
|
||||
|
||||
## Branching and PRs
|
||||
|
||||
- Branch prefixes: `feature/`, `fix/`, `hotfix/`, `chore/`, `docs/`, `refactor/`, `release/`
|
||||
- PR titles: `type(scope): description (DEV-123)` — Jira key required (DEV/PLAT/SEC)
|
||||
- PR body sections (exact order): **Summary**, **Validation**, **Tests**, **Notes**
|
||||
- Route work: DEV (product), PLAT (infra/platform), SEC (security)
|
||||
|
||||
## Commits
|
||||
|
||||
- Conventional Commits: `type(scope): description`
|
||||
- Allowed types: `feat fix docs style refactor perf test build ci chore revert release`
|
||||
- No AI-attribution footers
|
||||
|
||||
## Secrets and Security
|
||||
|
||||
- Secrets in AWS Secrets Manager only — never in code, env vars, logs, or commits
|
||||
- Non-secret config in SSM Parameter Store
|
||||
- IAM/IaC/payment/auth changes require security review
|
||||
|
||||
## CI and SHA Pins
|
||||
|
||||
Pin every GitHub Actions ref to a full commit SHA with an inline version comment:
|
||||
|
||||
```yaml
|
||||
uses: actions/checkout@abc123def456 # v4.1.0
|
||||
```
|
||||
|
||||
The deterministic global pre-push security hook must not be bypassed (`--no-verify` requires
|
||||
explicit approval). Linting stays in CI; do not gate on it locally.
|
||||
Loading…
Add table
Reference in a new issue