procurement-ingest/AGENTS.md
Adam Moussa 25a2ed461c
Some checks are pending
Deploy / deploy (push) Waiting to run
ci: add org PR policy caller (#155)
Refs: PLAT-62
2026-08-04 11:56:24 -04:00

25 lines
1.4 KiB
Markdown

# AGENTS.md
## Sea Haven Governance
**Standards authority**: The engineering handbook is the single authority for coding standards, naming conventions, and workflow configuration. Do not justify changes by citing it in PR bodies.
**Work authority**: Jira is the source of truth for work status. Before creating a ticket, search Jira for duplicates. Route product work to DEV, infrastructure and platform work to PLAT, and security work to SEC.
**Branch names**: Use `feature/`, `fix/`, `hotfix/`, `chore/`, `docs/`, `refactor/`, or `release/` with a kebab-case description. Do not include Jira keys in branch names. Dependabot branches and emergency reverts are exempt from this rule.
**PR title format**: `type(scope): description (DEV-123)` — Jira key required on every non-exempt PR. Dependabot and permission-controlled emergency reverts are exempt.
**PR body headings** (exact, in this order):
1. Summary
2. Validation
3. Tests
4. Notes
**Prohibited**: AI-attribution footers in commits, PRs, comments, or generated artifacts.
**Security gates**:
- PRs touching payment flows, authentication logic, secret handling, AWS IAM, or untrusted user input require security review.
- IAM role, policy, or resource-permission changes require cross-family review.
**CI workflow refs**: All `uses:` workflow refs must be pinned to a full commit SHA with an inline version comment — `owner/repo/.github/workflows/file.yaml@<full-sha> # vX.Y.Z`. No floating tags or branch refs.