From 8c1e7ac88b2d31bf3c384bbd8a952d8a5e7b0f23 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Wed, 5 Aug 2026 19:27:50 -0400 Subject: [PATCH] ci: add org PR policy caller (PLAT-62) (#275) * ci: add org PR policy caller Refs: PLAT-62 * fix(ci): avoid hook-bypass token in AGENTS.md The changed-line guard rejects literal --no-verify in added lines; reword the policy note so Web Frontend Check can pass. --- .github/dependabot.yml | 26 ++++++++++++++++++++++++++ .github/workflows/policy.yaml | 22 ++++++++++++++++++++++ AGENTS.md | 33 +++++++++++++++++++++++++++++++++ CLAUDE.md | 2 ++ 4 files changed, 83 insertions(+) create mode 100644 .github/workflows/policy.yaml create mode 100644 AGENTS.md diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 0b7370b..12f5ad2 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -4,6 +4,8 @@ updates: directory: /infra schedule: interval: weekly + commit-message: + prefix: "chore(deps)" open-pull-requests-limit: 10 groups: infra: @@ -17,6 +19,8 @@ updates: directory: /web schedule: interval: weekly + commit-message: + prefix: "chore(deps)" open-pull-requests-limit: 10 groups: # @mui/material and @mui/icons-material must move in lockstep (icons @@ -40,6 +44,8 @@ updates: directory: /mobile schedule: interval: weekly + commit-message: + prefix: "chore(deps)" open-pull-requests-limit: 10 groups: mobile-npm: @@ -53,6 +59,8 @@ updates: directory: /mobile schedule: interval: weekly + commit-message: + prefix: "chore(deps)" open-pull-requests-limit: 10 groups: mobile-bundler: @@ -66,6 +74,8 @@ updates: directory: /api schedule: interval: weekly + commit-message: + prefix: "chore(deps)" open-pull-requests-limit: 10 groups: api: @@ -79,6 +89,8 @@ updates: directory: /lambdas/pdf-extract schedule: interval: weekly + commit-message: + prefix: "chore(deps)" open-pull-requests-limit: 10 groups: pdf-extract: @@ -92,6 +104,8 @@ updates: directory: /lambdas/pdf-generate schedule: interval: weekly + commit-message: + prefix: "chore(deps)" open-pull-requests-limit: 10 groups: pdf-generate: @@ -105,6 +119,8 @@ updates: directory: /lambdas/library-ingest schedule: interval: weekly + commit-message: + prefix: "chore(deps)" open-pull-requests-limit: 10 groups: library-ingest: @@ -118,6 +134,8 @@ updates: directory: /lambdas/suggestions schedule: interval: weekly + commit-message: + prefix: "chore(deps)" open-pull-requests-limit: 10 groups: suggestions: @@ -131,6 +149,8 @@ updates: directory: /lambdas/aurora-pgvector-init schedule: interval: weekly + commit-message: + prefix: "chore(deps)" open-pull-requests-limit: 10 groups: aurora-pgvector-init: @@ -144,6 +164,8 @@ updates: directory: /lambdas/tests schedule: interval: weekly + commit-message: + prefix: "chore(deps)" open-pull-requests-limit: 10 groups: lambdas-tests: @@ -157,6 +179,8 @@ updates: directory: /shared/api-contracts schedule: interval: weekly + commit-message: + prefix: "chore(deps)" open-pull-requests-limit: 10 groups: api-contracts: @@ -170,6 +194,8 @@ updates: directory: / schedule: interval: weekly + commit-message: + prefix: "chore(deps)" open-pull-requests-limit: 10 groups: github-actions: diff --git a/.github/workflows/policy.yaml b/.github/workflows/policy.yaml new file mode 100644 index 0000000..eba1158 --- /dev/null +++ b/.github/workflows/policy.yaml @@ -0,0 +1,22 @@ +name: PR Policy + +on: + pull_request: + types: [opened, reopened, synchronize, edited, labeled, unlabeled, ready_for_review] + +concurrency: + group: "policy-${{ github.event.pull_request.number }}" + cancel-in-progress: true + +permissions: + contents: read + issues: read + pull-requests: read + +jobs: + policy: + uses: Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml@9c1ecf942894b19aba5c71b85b41906c6c83b749 # v1.0.5 + secrets: + JIRA_CLOUD_ID: ${{ secrets.JIRA_CLOUD_ID }} + JIRA_SERVICE_ACCOUNT_EMAIL: ${{ secrets.JIRA_SERVICE_ACCOUNT_EMAIL }} + JIRA_API_TOKEN: ${{ secrets.JIRA_API_TOKEN }} diff --git a/AGENTS.md b/AGENTS.md new file mode 100644 index 0000000..fdd5bb0 --- /dev/null +++ b/AGENTS.md @@ -0,0 +1,33 @@ +# Sea Haven Org Governance + +> Full engineering standards: [engineering-handbook](https://github.com/Sea-Haven-Industries/engineering-handbook). + +## Branching and PRs + +- Branch prefixes: `feature/`, `fix/`, `hotfix/`, `chore/`, `docs/`, `refactor/`, `release/` +- PR titles: `type(scope): description (DEV-123)` — Jira key required (DEV/PLAT/SEC) +- PR body sections (exact order): **Summary**, **Validation**, **Tests**, **Notes** +- Route work: DEV (product), PLAT (infra/platform), SEC (security) + +## Commits + +- Conventional Commits: `type(scope): description` +- Allowed types: `feat fix docs style refactor perf test build ci chore revert release` +- No AI-attribution footers + +## Secrets and Security + +- Secrets in AWS Secrets Manager only — never in code, env vars, logs, or commits +- Non-secret config in SSM Parameter Store +- IAM/IaC/payment/auth changes require security review + +## CI and SHA Pins + +Pin every GitHub Actions ref to a full commit SHA with an inline version comment: + +```yaml +uses: actions/checkout@abc123def456 # v4.1.0 +``` + +The deterministic global pre-push security hook must not be bypassed (skipping Git hooks +requires explicit approval). Linting stays in CI; do not gate on it locally. diff --git a/CLAUDE.md b/CLAUDE.md index 900a38e..23d63ac 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -1,5 +1,7 @@ # Proposal System - Claude Code Project Memory +> For Sea Haven org-wide governance (branching, PR conventions, secrets policy), see [AGENTS.md](./AGENTS.md). + ## Project Overview Proposal management platform for Sea Haven Industries. Dispatchers submit service requests, AI generates draft line items via Bedrock RAG, admins review/approve in a pricing workspace, system produces branded PDFs.