diff --git a/.github/dependabot.yml b/.github/dependabot.yml index a0eb52f..e09e5ac 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -9,6 +9,8 @@ updates: update-types: - "minor" - "patch" + commit-message: + prefix: "chore(deps)" - package-ecosystem: "pip" directory: "/lambdas/po/email_processor" schedule: @@ -18,6 +20,8 @@ updates: update-types: - "minor" - "patch" + commit-message: + prefix: "chore(deps)" - package-ecosystem: "pip" directory: "/lambdas/wo/email_processor" schedule: @@ -27,6 +31,8 @@ updates: update-types: - "minor" - "patch" + commit-message: + prefix: "chore(deps)" - package-ecosystem: "pip" directory: "/lambdas/wo/web_ui" schedule: @@ -36,6 +42,8 @@ updates: update-types: - "minor" - "patch" + commit-message: + prefix: "chore(deps)" - package-ecosystem: "pip" directory: "/tests" schedule: @@ -45,6 +53,8 @@ updates: update-types: - "minor" - "patch" + commit-message: + prefix: "chore(deps)" - package-ecosystem: "pip" directory: "/lambdas/po/web_ui" schedule: @@ -54,6 +64,8 @@ updates: update-types: - "minor" - "patch" + commit-message: + prefix: "chore(deps)" - package-ecosystem: "pip" directory: "/lambdas/po/site_extractor" schedule: @@ -63,6 +75,8 @@ updates: update-types: - "minor" - "patch" + commit-message: + prefix: "chore(deps)" - package-ecosystem: "github-actions" directory: "/" schedule: @@ -72,6 +86,8 @@ updates: update-types: - "minor" - "patch" + commit-message: + prefix: "chore(deps)" - package-ecosystem: "npm" directory: "/" schedule: @@ -81,3 +97,5 @@ updates: update-types: - "minor" - "patch" + commit-message: + prefix: "chore(deps)" diff --git a/.github/workflows/policy.yaml b/.github/workflows/policy.yaml new file mode 100644 index 0000000..eba1158 --- /dev/null +++ b/.github/workflows/policy.yaml @@ -0,0 +1,22 @@ +name: PR Policy + +on: + pull_request: + types: [opened, reopened, synchronize, edited, labeled, unlabeled, ready_for_review] + +concurrency: + group: "policy-${{ github.event.pull_request.number }}" + cancel-in-progress: true + +permissions: + contents: read + issues: read + pull-requests: read + +jobs: + policy: + uses: Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml@9c1ecf942894b19aba5c71b85b41906c6c83b749 # v1.0.5 + secrets: + JIRA_CLOUD_ID: ${{ secrets.JIRA_CLOUD_ID }} + JIRA_SERVICE_ACCOUNT_EMAIL: ${{ secrets.JIRA_SERVICE_ACCOUNT_EMAIL }} + JIRA_API_TOKEN: ${{ secrets.JIRA_API_TOKEN }} diff --git a/AGENTS.md b/AGENTS.md new file mode 100644 index 0000000..45ba250 --- /dev/null +++ b/AGENTS.md @@ -0,0 +1,25 @@ +# AGENTS.md + +## Sea Haven Governance + +**Standards authority**: The engineering handbook is the single authority for coding standards, naming conventions, and workflow configuration. Do not justify changes by citing it in PR bodies. + +**Work authority**: Jira is the source of truth for work status. Before creating a ticket, search Jira for duplicates. Route product work to DEV, infrastructure and platform work to PLAT, and security work to SEC. + +**Branch names**: Use `feature/`, `fix/`, `hotfix/`, `chore/`, `docs/`, `refactor/`, or `release/` with a kebab-case description. Do not include Jira keys in branch names. Dependabot branches and emergency reverts are exempt from this rule. + +**PR title format**: `type(scope): description (DEV-123)` — Jira key required on every non-exempt PR. Dependabot and permission-controlled emergency reverts are exempt. + +**PR body headings** (exact, in this order): +1. Summary +2. Validation +3. Tests +4. Notes + +**Prohibited**: AI-attribution footers in commits, PRs, comments, or generated artifacts. + +**Security gates**: +- PRs touching payment flows, authentication logic, secret handling, AWS IAM, or untrusted user input require security review. +- IAM role, policy, or resource-permission changes require cross-family review. + +**CI workflow refs**: All `uses:` workflow refs must be pinned to a full commit SHA with an inline version comment — `owner/repo/.github/workflows/file.yaml@ # vX.Y.Z`. No floating tags or branch refs.