diff --git a/.github/dependabot.yml b/.github/dependabot.yml index e3ba2844..6fc3a401 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -6,6 +6,8 @@ updates: schedule: interval: "weekly" assignees: ["amoussa1229"] + commit-message: + prefix: "chore(deps)" groups: minor-and-patch: update-types: ["minor", "patch"] @@ -19,6 +21,8 @@ updates: schedule: interval: "weekly" assignees: ["amoussa1229"] + commit-message: + prefix: "chore(deps)" groups: minor-and-patch: update-types: ["minor", "patch"] @@ -38,6 +42,8 @@ updates: schedule: interval: "weekly" assignees: ["amoussa1229"] + commit-message: + prefix: "chore(deps)" groups: minor-and-patch: update-types: ["minor", "patch"] @@ -48,6 +54,8 @@ updates: schedule: interval: "weekly" assignees: ["amoussa1229"] + commit-message: + prefix: "chore(deps)" groups: minor-and-patch: update-types: ["minor", "patch"] diff --git a/.github/workflows/policy.yaml b/.github/workflows/policy.yaml new file mode 100644 index 00000000..eba11587 --- /dev/null +++ b/.github/workflows/policy.yaml @@ -0,0 +1,22 @@ +name: PR Policy + +on: + pull_request: + types: [opened, reopened, synchronize, edited, labeled, unlabeled, ready_for_review] + +concurrency: + group: "policy-${{ github.event.pull_request.number }}" + cancel-in-progress: true + +permissions: + contents: read + issues: read + pull-requests: read + +jobs: + policy: + uses: Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml@9c1ecf942894b19aba5c71b85b41906c6c83b749 # v1.0.5 + secrets: + JIRA_CLOUD_ID: ${{ secrets.JIRA_CLOUD_ID }} + JIRA_SERVICE_ACCOUNT_EMAIL: ${{ secrets.JIRA_SERVICE_ACCOUNT_EMAIL }} + JIRA_API_TOKEN: ${{ secrets.JIRA_API_TOKEN }} diff --git a/AGENTS.md b/AGENTS.md index 74180df2..926abe10 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -2,6 +2,22 @@ This file provides guidance to Coding Agents when working with code in this repository. +## Sea Haven governance + +The engineering handbook is the standards authority; Jira is the work-status authority. + +**Routing:** product work → DEV, infrastructure/platform → PLAT, security → SEC. Search Jira for duplicates before creating a ticket; update the existing ticket if one is found. + +**Branches:** `feature/`, `fix/`, `hotfix/`, `chore/`, `docs/`, `refactor/`, or `release/` plus a kebab-case description. Do not include a Jira key in the branch name. + +**PR titles:** `type(scope): description (DEV-123)` — Jira key suffix required on every non-exempt PR. Allowed types: feat fix docs style refactor perf test build ci chore revert release. + +**PR body:** exactly four `##` headings in order: Summary, Validation, Tests, Notes. Use "None." under Notes when empty. State verifiable facts; do not cite the handbook to justify changes. Do not add AI-attribution footers to commits, PRs, or comments. + +**Security gates:** payment, authentication, secrets, IaC/IAM, and untrusted-input changes require security review. IAM role, policy, or resource-permission changes require cross-family review. + +**CI/supply-chain:** every `uses:` in a workflow file must be pinned to a 40-char SHA with a `# vX.Y.Z` comment. + ## Project Open SWE is an open-source coding-agent framework built on **LangGraph** + **Deep Agents** (`deepagents.create_deep_agent`). It runs as a LangGraph app: each thread spawns its own isolated cloud sandbox, and the agent is invoked from Slack, Linear, Jira, Confluence, or GitHub (PR comments, plus auto-review on opened / ready-for-review). diff --git a/CLAUDE.md b/CLAUDE.md index a99b6f7d..1747ef7b 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -1,6 +1,6 @@ # CLAUDE.md -This file provides guidance to Claude Code (claude.ai/code) when working with code in this repository. +This file provides guidance to Claude Code (claude.ai/code) when working with code in this repository. Sea Haven org governance (Jira routing, PR conventions, security gates, CI/SHA pin standards) is defined in the root `AGENTS.md`; this file covers repo-specific guidance only. ## Project