mirror of
https://github.com/Sea-Haven-Industries/pr-reviewer.git
synced 2026-09-30 05:43:16 +00:00
parent
c071c5cc17
commit
34bf979c8c
3 changed files with 51 additions and 0 deletions
4
.github/dependabot.yml
vendored
4
.github/dependabot.yml
vendored
|
|
@ -5,9 +5,13 @@ updates:
|
||||||
schedule:
|
schedule:
|
||||||
interval: "weekly"
|
interval: "weekly"
|
||||||
open-pull-requests-limit: 5
|
open-pull-requests-limit: 5
|
||||||
|
commit-message:
|
||||||
|
prefix: "chore(deps)"
|
||||||
|
|
||||||
- package-ecosystem: "github-actions"
|
- package-ecosystem: "github-actions"
|
||||||
directory: "/"
|
directory: "/"
|
||||||
schedule:
|
schedule:
|
||||||
interval: "weekly"
|
interval: "weekly"
|
||||||
open-pull-requests-limit: 5
|
open-pull-requests-limit: 5
|
||||||
|
commit-message:
|
||||||
|
prefix: "chore(deps)"
|
||||||
|
|
|
||||||
22
.github/workflows/policy.yaml
vendored
Normal file
22
.github/workflows/policy.yaml
vendored
Normal file
|
|
@ -0,0 +1,22 @@
|
||||||
|
name: PR Policy
|
||||||
|
|
||||||
|
on:
|
||||||
|
pull_request:
|
||||||
|
types: [opened, reopened, synchronize, edited, labeled, unlabeled, ready_for_review]
|
||||||
|
|
||||||
|
concurrency:
|
||||||
|
group: "policy-${{ github.event.pull_request.number }}"
|
||||||
|
cancel-in-progress: true
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
issues: read
|
||||||
|
pull-requests: read
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
policy:
|
||||||
|
uses: Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml@9c1ecf942894b19aba5c71b85b41906c6c83b749 # v1.0.5
|
||||||
|
secrets:
|
||||||
|
JIRA_CLOUD_ID: ${{ secrets.JIRA_CLOUD_ID }}
|
||||||
|
JIRA_SERVICE_ACCOUNT_EMAIL: ${{ secrets.JIRA_SERVICE_ACCOUNT_EMAIL }}
|
||||||
|
JIRA_API_TOKEN: ${{ secrets.JIRA_API_TOKEN }}
|
||||||
25
AGENTS.md
Normal file
25
AGENTS.md
Normal file
|
|
@ -0,0 +1,25 @@
|
||||||
|
# AGENTS.md
|
||||||
|
|
||||||
|
## Sea Haven Governance
|
||||||
|
|
||||||
|
**Standards authority**: The engineering handbook is the single authority for coding standards, naming conventions, and workflow configuration. Do not justify changes by citing it in PR bodies.
|
||||||
|
|
||||||
|
**Work authority**: Jira is the source of truth for work status. Before creating a ticket, search Jira for duplicates. Route product work to DEV, infrastructure and platform work to PLAT, and security work to SEC.
|
||||||
|
|
||||||
|
**Branch names**: Use `feature/`, `fix/`, `hotfix/`, `chore/`, `docs/`, `refactor/`, or `release/` with a kebab-case description. Do not include Jira keys in branch names. Dependabot branches and emergency reverts are exempt from this rule.
|
||||||
|
|
||||||
|
**PR title format**: `type(scope): description (DEV-123)` — Jira key required on every non-exempt PR. Dependabot and permission-controlled emergency reverts are exempt.
|
||||||
|
|
||||||
|
**PR body headings** (exact, in this order):
|
||||||
|
1. Summary
|
||||||
|
2. Validation
|
||||||
|
3. Tests
|
||||||
|
4. Notes
|
||||||
|
|
||||||
|
**Prohibited**: AI-attribution footers in commits, PRs, comments, or generated artifacts.
|
||||||
|
|
||||||
|
**Security gates**:
|
||||||
|
- PRs touching payment flows, authentication logic, secret handling, AWS IAM, or untrusted user input require security review.
|
||||||
|
- IAM role, policy, or resource-permission changes require cross-family review.
|
||||||
|
|
||||||
|
**CI workflow refs**: All `uses:` workflow refs must be pinned to a full commit SHA with an inline version comment — `owner/repo/.github/workflows/file.yaml@<full-sha> # vX.Y.Z`. No floating tags or branch refs.
|
||||||
Loading…
Add table
Reference in a new issue