ci: add org PR policy caller (PLAT-62) (#69)

* ci: add org PR policy caller

Refs: PLAT-62

* ci: update callable-pr-policy to v1.0.6

* chore: retrigger PR checks
This commit is contained in:
Adam Moussa 2026-08-07 10:54:07 -04:00 • committed by GitHub
parent 0613d8d6b0
commit d0659ebf6f
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
3 changed files with 61 additions and 0 deletions

View file

@ -4,6 +4,8 @@ updates:
directory: /
schedule:
interval: weekly
commit-message:
prefix: "chore(deps)"
assignees:
- amoussa1229
ignore:
@ -19,6 +21,8 @@ updates:
directory: /
schedule:
interval: weekly
commit-message:
prefix: "chore(deps)"
assignees:
- amoussa1229
@ -26,5 +30,7 @@ updates:
directory: /lambda/backup-verification
schedule:
interval: weekly
commit-message:
prefix: "chore(deps)"
assignees:
- amoussa1229

22
.github/workflows/policy.yaml vendored Normal file
View file

@ -0,0 +1,22 @@
name: PR Policy
on:
pull_request:
types: [opened, reopened, synchronize, edited, labeled, unlabeled, ready_for_review]
concurrency:
group: "policy-${{ github.event.pull_request.number }}"
cancel-in-progress: true
permissions:
contents: read
issues: read
pull-requests: read
jobs:
policy:
uses: Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml@7ac3528750b346f181347bb09f6af927a1c0aa14 # v1.0.6
secrets:
JIRA_CLOUD_ID: ${{ secrets.JIRA_CLOUD_ID }}
JIRA_SERVICE_ACCOUNT_EMAIL: ${{ secrets.JIRA_SERVICE_ACCOUNT_EMAIL }}
JIRA_API_TOKEN: ${{ secrets.JIRA_API_TOKEN }}

33
AGENTS.md Normal file
View file

@ -0,0 +1,33 @@
# Sea Haven Org Governance
> Full engineering standards: [engineering-handbook](https://github.com/Sea-Haven-Industries/engineering-handbook).
## Branching and PRs
- Branch prefixes: `feature/`, `fix/`, `hotfix/`, `chore/`, `docs/`, `refactor/`, `release/`
- PR titles: `type(scope): description (DEV-123)` — Jira key required (DEV/PLAT/SEC)
- PR body sections (exact order): **Summary**, **Validation**, **Tests**, **Notes**
- Route work: DEV (product), PLAT (infra/platform), SEC (security)
## Commits
- Conventional Commits: `type(scope): description`
- Allowed types: `feat fix docs style refactor perf test build ci chore revert release`
- No AI-attribution footers
## Secrets and Security
- Secrets in AWS Secrets Manager only — never in code, env vars, logs, or commits
- Non-secret config in SSM Parameter Store
- IAM/IaC/payment/auth changes require security review
## CI and SHA Pins
Pin every GitHub Actions ref to a full commit SHA with an inline version comment:
```yaml
uses: actions/checkout@abc123def456 # v4.1.0
```
The deterministic global pre-push security hook must not be bypassed (`--no-verify` requires
explicit approval). Linting stays in CI; do not gate on it locally.