From 164e903c94ea9a4e179a3026afb5c22e492d1a58 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Tue, 4 Aug 2026 11:57:37 -0400 Subject: [PATCH] ci: add org PR policy caller (PLAT-62) (#108) * ci: add org PR policy caller Refs: PLAT-62 * fix(ci): name PR policy workflow Refs: PLAT-62 --- .github/dependabot.yml | 18 ++++++++++++++++++ .github/workflows/policy.yaml | 29 +++++++++++++++++++++++++++++ AGENTS.md | 21 +++++++++++++++++++++ 3 files changed, 68 insertions(+) create mode 100644 .github/workflows/policy.yaml create mode 100644 AGENTS.md diff --git a/.github/dependabot.yml b/.github/dependabot.yml index dea8a39..c480666 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -4,6 +4,8 @@ updates: directory: "/" schedule: interval: "weekly" + commit-message: + prefix: "chore(deps)" groups: minor-and-patch: update-types: @@ -14,6 +16,8 @@ updates: directory: "/functions/admin_authorizer" schedule: interval: "weekly" + commit-message: + prefix: "chore(deps)" groups: minor-and-patch: update-types: @@ -24,6 +28,8 @@ updates: directory: "/functions/aggregate_orders" schedule: interval: "weekly" + commit-message: + prefix: "chore(deps)" groups: minor-and-patch: update-types: @@ -34,6 +40,8 @@ updates: directory: "/functions/close_form" schedule: interval: "weekly" + commit-message: + prefix: "chore(deps)" groups: minor-and-patch: update-types: @@ -44,6 +52,8 @@ updates: directory: "/functions/email_report" schedule: interval: "weekly" + commit-message: + prefix: "chore(deps)" groups: minor-and-patch: update-types: @@ -54,6 +64,8 @@ updates: directory: "/functions/slack_notifier" schedule: interval: "weekly" + commit-message: + prefix: "chore(deps)" groups: minor-and-patch: update-types: @@ -64,6 +76,8 @@ updates: directory: "/functions/submit_order" schedule: interval: "weekly" + commit-message: + prefix: "chore(deps)" groups: minor-and-patch: update-types: @@ -74,6 +88,8 @@ updates: directory: "/src/shared" schedule: interval: "weekly" + commit-message: + prefix: "chore(deps)" groups: minor-and-patch: update-types: @@ -84,6 +100,8 @@ updates: directory: "/" schedule: interval: "weekly" + commit-message: + prefix: "chore(deps)" groups: minor-and-patch: update-types: diff --git a/.github/workflows/policy.yaml b/.github/workflows/policy.yaml new file mode 100644 index 0000000..f07274e --- /dev/null +++ b/.github/workflows/policy.yaml @@ -0,0 +1,29 @@ +name: PR Policy + +on: + pull_request: + types: + - opened + - reopened + - synchronize + - edited + - labeled + - unlabeled + - ready_for_review + +concurrency: + group: "policy-${{ github.event.pull_request.number }}" + cancel-in-progress: true + +permissions: + contents: read + issues: read + pull-requests: read + +jobs: + policy: + uses: Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml@9c1ecf942894b19aba5c71b85b41906c6c83b749 # v1.0.5 + secrets: + JIRA_CLOUD_ID: ${{ secrets.JIRA_CLOUD_ID }} + JIRA_SERVICE_ACCOUNT_EMAIL: ${{ secrets.JIRA_SERVICE_ACCOUNT_EMAIL }} + JIRA_API_TOKEN: ${{ secrets.JIRA_API_TOKEN }} diff --git a/AGENTS.md b/AGENTS.md new file mode 100644 index 0000000..77f5e52 --- /dev/null +++ b/AGENTS.md @@ -0,0 +1,21 @@ +# Sea Haven Governance + +## Standards and Authority +- **Handbook**: `engineering-handbook` is the standards authority for all conventions. +- **Jira**: work-status authority. Route product work → DEV, infrastructure/platform → PLAT, security → SEC. Search for duplicates before creating a ticket. + +## Branches +Use one of: `feature/`, `fix/`, `hotfix/`, `chore/`, `docs/`, `refactor/`, `release/` + kebab-case description. Do not include a Jira key in the branch name. + +## Pull Requests +- **Title format**: `type(scope): description (DEV-123)` — every non-exempt PR must end with its Jira key. +- **Body sections** (exactly, in order): `Summary`, `Validation`, `Tests`, `Notes`. Use "None." under Notes when empty. +- State verifiable facts only. Do not justify changes by citing the handbook. No AI-attribution footers. + +## Security and Cross-Review +- Sensitive surfaces (payment flows, authentication, secrets handling, untrusted input) require security review. +- IAM role, policy, or resource-permission changes require cross-family review. Lambda handler signature changes alone do not. + +## CI and Workflow References +- CI must pass before merge. +- Org-level reusable workflow refs must be pinned to a full commit SHA with a `# vX.Y.Z` comment.