diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 2a2109c..34f3e5f 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -4,6 +4,8 @@ updates: directory: "/src/sla_monitor" schedule: interval: "weekly" + commit-message: + prefix: "chore(deps)" groups: minor-and-patch: update-types: @@ -13,6 +15,8 @@ updates: directory: "/src/user_sync" schedule: interval: "weekly" + commit-message: + prefix: "chore(deps)" groups: minor-and-patch: update-types: @@ -22,6 +26,8 @@ updates: directory: "/" schedule: interval: "weekly" + commit-message: + prefix: "chore(deps)" groups: minor-and-patch: update-types: diff --git a/.github/workflows/policy.yaml b/.github/workflows/policy.yaml new file mode 100644 index 0000000..f07274e --- /dev/null +++ b/.github/workflows/policy.yaml @@ -0,0 +1,29 @@ +name: PR Policy + +on: + pull_request: + types: + - opened + - reopened + - synchronize + - edited + - labeled + - unlabeled + - ready_for_review + +concurrency: + group: "policy-${{ github.event.pull_request.number }}" + cancel-in-progress: true + +permissions: + contents: read + issues: read + pull-requests: read + +jobs: + policy: + uses: Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml@9c1ecf942894b19aba5c71b85b41906c6c83b749 # v1.0.5 + secrets: + JIRA_CLOUD_ID: ${{ secrets.JIRA_CLOUD_ID }} + JIRA_SERVICE_ACCOUNT_EMAIL: ${{ secrets.JIRA_SERVICE_ACCOUNT_EMAIL }} + JIRA_API_TOKEN: ${{ secrets.JIRA_API_TOKEN }} diff --git a/AGENTS.md b/AGENTS.md new file mode 100644 index 0000000..77f5e52 --- /dev/null +++ b/AGENTS.md @@ -0,0 +1,21 @@ +# Sea Haven Governance + +## Standards and Authority +- **Handbook**: `engineering-handbook` is the standards authority for all conventions. +- **Jira**: work-status authority. Route product work → DEV, infrastructure/platform → PLAT, security → SEC. Search for duplicates before creating a ticket. + +## Branches +Use one of: `feature/`, `fix/`, `hotfix/`, `chore/`, `docs/`, `refactor/`, `release/` + kebab-case description. Do not include a Jira key in the branch name. + +## Pull Requests +- **Title format**: `type(scope): description (DEV-123)` — every non-exempt PR must end with its Jira key. +- **Body sections** (exactly, in order): `Summary`, `Validation`, `Tests`, `Notes`. Use "None." under Notes when empty. +- State verifiable facts only. Do not justify changes by citing the handbook. No AI-attribution footers. + +## Security and Cross-Review +- Sensitive surfaces (payment flows, authentication, secrets handling, untrusted input) require security review. +- IAM role, policy, or resource-permission changes require cross-family review. Lambda handler signature changes alone do not. + +## CI and Workflow References +- CI must pass before merge. +- Org-level reusable workflow refs must be pinned to a full commit SHA with a `# vX.Y.Z` comment.