diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 325f014..84e365b 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -4,6 +4,8 @@ updates: directory: / schedule: interval: weekly + commit-message: + prefix: "chore(deps)" assignees: - amoussa1229 ignore: @@ -19,6 +21,8 @@ updates: directory: / schedule: interval: weekly + commit-message: + prefix: "chore(deps)" assignees: - amoussa1229 @@ -26,5 +30,7 @@ updates: directory: /lambda/backup-verification schedule: interval: weekly + commit-message: + prefix: "chore(deps)" assignees: - amoussa1229 diff --git a/.github/workflows/policy.yaml b/.github/workflows/policy.yaml new file mode 100644 index 0000000..eba1158 --- /dev/null +++ b/.github/workflows/policy.yaml @@ -0,0 +1,22 @@ +name: PR Policy + +on: + pull_request: + types: [opened, reopened, synchronize, edited, labeled, unlabeled, ready_for_review] + +concurrency: + group: "policy-${{ github.event.pull_request.number }}" + cancel-in-progress: true + +permissions: + contents: read + issues: read + pull-requests: read + +jobs: + policy: + uses: Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml@9c1ecf942894b19aba5c71b85b41906c6c83b749 # v1.0.5 + secrets: + JIRA_CLOUD_ID: ${{ secrets.JIRA_CLOUD_ID }} + JIRA_SERVICE_ACCOUNT_EMAIL: ${{ secrets.JIRA_SERVICE_ACCOUNT_EMAIL }} + JIRA_API_TOKEN: ${{ secrets.JIRA_API_TOKEN }} diff --git a/AGENTS.md b/AGENTS.md new file mode 100644 index 0000000..3038235 --- /dev/null +++ b/AGENTS.md @@ -0,0 +1,33 @@ +# Sea Haven Org Governance + +> Full engineering standards: [engineering-handbook](https://github.com/Sea-Haven-Industries/engineering-handbook). + +## Branching and PRs + +- Branch prefixes: `feature/`, `fix/`, `hotfix/`, `chore/`, `docs/`, `refactor/`, `release/` +- PR titles: `type(scope): description (DEV-123)` — Jira key required (DEV/PLAT/SEC) +- PR body sections (exact order): **Summary**, **Validation**, **Tests**, **Notes** +- Route work: DEV (product), PLAT (infra/platform), SEC (security) + +## Commits + +- Conventional Commits: `type(scope): description` +- Allowed types: `feat fix docs style refactor perf test build ci chore revert release` +- No AI-attribution footers + +## Secrets and Security + +- Secrets in AWS Secrets Manager only — never in code, env vars, logs, or commits +- Non-secret config in SSM Parameter Store +- IAM/IaC/payment/auth changes require security review + +## CI and SHA Pins + +Pin every GitHub Actions ref to a full commit SHA with an inline version comment: + +```yaml +uses: actions/checkout@abc123def456 # v4.1.0 +``` + +The deterministic global pre-push security hook must not be bypassed (`--no-verify` requires +explicit approval). Linting stays in CI; do not gate on it locally.