mirror of
https://github.com/Sea-Haven-Industries/proposal-system.git
synced 2026-09-30 04:13:13 +00:00
ci: add org PR policy caller (PLAT-62) (#275)
* ci: add org PR policy caller Refs: PLAT-62 * fix(ci): avoid hook-bypass token in AGENTS.md The changed-line guard rejects literal --no-verify in added lines; reword the policy note so Web Frontend Check can pass.
This commit is contained in:
parent
508b7ed9ad
commit
8c1e7ac88b
4 changed files with 83 additions and 0 deletions
26
.github/dependabot.yml
vendored
26
.github/dependabot.yml
vendored
|
|
@ -4,6 +4,8 @@ updates:
|
||||||
directory: /infra
|
directory: /infra
|
||||||
schedule:
|
schedule:
|
||||||
interval: weekly
|
interval: weekly
|
||||||
|
commit-message:
|
||||||
|
prefix: "chore(deps)"
|
||||||
open-pull-requests-limit: 10
|
open-pull-requests-limit: 10
|
||||||
groups:
|
groups:
|
||||||
infra:
|
infra:
|
||||||
|
|
@ -17,6 +19,8 @@ updates:
|
||||||
directory: /web
|
directory: /web
|
||||||
schedule:
|
schedule:
|
||||||
interval: weekly
|
interval: weekly
|
||||||
|
commit-message:
|
||||||
|
prefix: "chore(deps)"
|
||||||
open-pull-requests-limit: 10
|
open-pull-requests-limit: 10
|
||||||
groups:
|
groups:
|
||||||
# @mui/material and @mui/icons-material must move in lockstep (icons
|
# @mui/material and @mui/icons-material must move in lockstep (icons
|
||||||
|
|
@ -40,6 +44,8 @@ updates:
|
||||||
directory: /mobile
|
directory: /mobile
|
||||||
schedule:
|
schedule:
|
||||||
interval: weekly
|
interval: weekly
|
||||||
|
commit-message:
|
||||||
|
prefix: "chore(deps)"
|
||||||
open-pull-requests-limit: 10
|
open-pull-requests-limit: 10
|
||||||
groups:
|
groups:
|
||||||
mobile-npm:
|
mobile-npm:
|
||||||
|
|
@ -53,6 +59,8 @@ updates:
|
||||||
directory: /mobile
|
directory: /mobile
|
||||||
schedule:
|
schedule:
|
||||||
interval: weekly
|
interval: weekly
|
||||||
|
commit-message:
|
||||||
|
prefix: "chore(deps)"
|
||||||
open-pull-requests-limit: 10
|
open-pull-requests-limit: 10
|
||||||
groups:
|
groups:
|
||||||
mobile-bundler:
|
mobile-bundler:
|
||||||
|
|
@ -66,6 +74,8 @@ updates:
|
||||||
directory: /api
|
directory: /api
|
||||||
schedule:
|
schedule:
|
||||||
interval: weekly
|
interval: weekly
|
||||||
|
commit-message:
|
||||||
|
prefix: "chore(deps)"
|
||||||
open-pull-requests-limit: 10
|
open-pull-requests-limit: 10
|
||||||
groups:
|
groups:
|
||||||
api:
|
api:
|
||||||
|
|
@ -79,6 +89,8 @@ updates:
|
||||||
directory: /lambdas/pdf-extract
|
directory: /lambdas/pdf-extract
|
||||||
schedule:
|
schedule:
|
||||||
interval: weekly
|
interval: weekly
|
||||||
|
commit-message:
|
||||||
|
prefix: "chore(deps)"
|
||||||
open-pull-requests-limit: 10
|
open-pull-requests-limit: 10
|
||||||
groups:
|
groups:
|
||||||
pdf-extract:
|
pdf-extract:
|
||||||
|
|
@ -92,6 +104,8 @@ updates:
|
||||||
directory: /lambdas/pdf-generate
|
directory: /lambdas/pdf-generate
|
||||||
schedule:
|
schedule:
|
||||||
interval: weekly
|
interval: weekly
|
||||||
|
commit-message:
|
||||||
|
prefix: "chore(deps)"
|
||||||
open-pull-requests-limit: 10
|
open-pull-requests-limit: 10
|
||||||
groups:
|
groups:
|
||||||
pdf-generate:
|
pdf-generate:
|
||||||
|
|
@ -105,6 +119,8 @@ updates:
|
||||||
directory: /lambdas/library-ingest
|
directory: /lambdas/library-ingest
|
||||||
schedule:
|
schedule:
|
||||||
interval: weekly
|
interval: weekly
|
||||||
|
commit-message:
|
||||||
|
prefix: "chore(deps)"
|
||||||
open-pull-requests-limit: 10
|
open-pull-requests-limit: 10
|
||||||
groups:
|
groups:
|
||||||
library-ingest:
|
library-ingest:
|
||||||
|
|
@ -118,6 +134,8 @@ updates:
|
||||||
directory: /lambdas/suggestions
|
directory: /lambdas/suggestions
|
||||||
schedule:
|
schedule:
|
||||||
interval: weekly
|
interval: weekly
|
||||||
|
commit-message:
|
||||||
|
prefix: "chore(deps)"
|
||||||
open-pull-requests-limit: 10
|
open-pull-requests-limit: 10
|
||||||
groups:
|
groups:
|
||||||
suggestions:
|
suggestions:
|
||||||
|
|
@ -131,6 +149,8 @@ updates:
|
||||||
directory: /lambdas/aurora-pgvector-init
|
directory: /lambdas/aurora-pgvector-init
|
||||||
schedule:
|
schedule:
|
||||||
interval: weekly
|
interval: weekly
|
||||||
|
commit-message:
|
||||||
|
prefix: "chore(deps)"
|
||||||
open-pull-requests-limit: 10
|
open-pull-requests-limit: 10
|
||||||
groups:
|
groups:
|
||||||
aurora-pgvector-init:
|
aurora-pgvector-init:
|
||||||
|
|
@ -144,6 +164,8 @@ updates:
|
||||||
directory: /lambdas/tests
|
directory: /lambdas/tests
|
||||||
schedule:
|
schedule:
|
||||||
interval: weekly
|
interval: weekly
|
||||||
|
commit-message:
|
||||||
|
prefix: "chore(deps)"
|
||||||
open-pull-requests-limit: 10
|
open-pull-requests-limit: 10
|
||||||
groups:
|
groups:
|
||||||
lambdas-tests:
|
lambdas-tests:
|
||||||
|
|
@ -157,6 +179,8 @@ updates:
|
||||||
directory: /shared/api-contracts
|
directory: /shared/api-contracts
|
||||||
schedule:
|
schedule:
|
||||||
interval: weekly
|
interval: weekly
|
||||||
|
commit-message:
|
||||||
|
prefix: "chore(deps)"
|
||||||
open-pull-requests-limit: 10
|
open-pull-requests-limit: 10
|
||||||
groups:
|
groups:
|
||||||
api-contracts:
|
api-contracts:
|
||||||
|
|
@ -170,6 +194,8 @@ updates:
|
||||||
directory: /
|
directory: /
|
||||||
schedule:
|
schedule:
|
||||||
interval: weekly
|
interval: weekly
|
||||||
|
commit-message:
|
||||||
|
prefix: "chore(deps)"
|
||||||
open-pull-requests-limit: 10
|
open-pull-requests-limit: 10
|
||||||
groups:
|
groups:
|
||||||
github-actions:
|
github-actions:
|
||||||
|
|
|
||||||
22
.github/workflows/policy.yaml
vendored
Normal file
22
.github/workflows/policy.yaml
vendored
Normal file
|
|
@ -0,0 +1,22 @@
|
||||||
|
name: PR Policy
|
||||||
|
|
||||||
|
on:
|
||||||
|
pull_request:
|
||||||
|
types: [opened, reopened, synchronize, edited, labeled, unlabeled, ready_for_review]
|
||||||
|
|
||||||
|
concurrency:
|
||||||
|
group: "policy-${{ github.event.pull_request.number }}"
|
||||||
|
cancel-in-progress: true
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
issues: read
|
||||||
|
pull-requests: read
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
policy:
|
||||||
|
uses: Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml@9c1ecf942894b19aba5c71b85b41906c6c83b749 # v1.0.5
|
||||||
|
secrets:
|
||||||
|
JIRA_CLOUD_ID: ${{ secrets.JIRA_CLOUD_ID }}
|
||||||
|
JIRA_SERVICE_ACCOUNT_EMAIL: ${{ secrets.JIRA_SERVICE_ACCOUNT_EMAIL }}
|
||||||
|
JIRA_API_TOKEN: ${{ secrets.JIRA_API_TOKEN }}
|
||||||
33
AGENTS.md
Normal file
33
AGENTS.md
Normal file
|
|
@ -0,0 +1,33 @@
|
||||||
|
# Sea Haven Org Governance
|
||||||
|
|
||||||
|
> Full engineering standards: [engineering-handbook](https://github.com/Sea-Haven-Industries/engineering-handbook).
|
||||||
|
|
||||||
|
## Branching and PRs
|
||||||
|
|
||||||
|
- Branch prefixes: `feature/`, `fix/`, `hotfix/`, `chore/`, `docs/`, `refactor/`, `release/`
|
||||||
|
- PR titles: `type(scope): description (DEV-123)` — Jira key required (DEV/PLAT/SEC)
|
||||||
|
- PR body sections (exact order): **Summary**, **Validation**, **Tests**, **Notes**
|
||||||
|
- Route work: DEV (product), PLAT (infra/platform), SEC (security)
|
||||||
|
|
||||||
|
## Commits
|
||||||
|
|
||||||
|
- Conventional Commits: `type(scope): description`
|
||||||
|
- Allowed types: `feat fix docs style refactor perf test build ci chore revert release`
|
||||||
|
- No AI-attribution footers
|
||||||
|
|
||||||
|
## Secrets and Security
|
||||||
|
|
||||||
|
- Secrets in AWS Secrets Manager only — never in code, env vars, logs, or commits
|
||||||
|
- Non-secret config in SSM Parameter Store
|
||||||
|
- IAM/IaC/payment/auth changes require security review
|
||||||
|
|
||||||
|
## CI and SHA Pins
|
||||||
|
|
||||||
|
Pin every GitHub Actions ref to a full commit SHA with an inline version comment:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
uses: actions/checkout@abc123def456 # v4.1.0
|
||||||
|
```
|
||||||
|
|
||||||
|
The deterministic global pre-push security hook must not be bypassed (skipping Git hooks
|
||||||
|
requires explicit approval). Linting stays in CI; do not gate on it locally.
|
||||||
|
|
@ -1,5 +1,7 @@
|
||||||
# Proposal System - Claude Code Project Memory
|
# Proposal System - Claude Code Project Memory
|
||||||
|
|
||||||
|
> For Sea Haven org-wide governance (branching, PR conventions, secrets policy), see [AGENTS.md](./AGENTS.md).
|
||||||
|
|
||||||
## Project Overview
|
## Project Overview
|
||||||
|
|
||||||
Proposal management platform for Sea Haven Industries. Dispatchers submit service requests, AI generates draft line items via Bedrock RAG, admins review/approve in a pricing workspace, system produces branded PDFs.
|
Proposal management platform for Sea Haven Industries. Dispatchers submit service requests, AI generates draft line items via Bedrock RAG, admins review/approve in a pricing workspace, system produces branded PDFs.
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue