docs(agents): drop security review gates (#156)
Some checks failed
Deploy / deploy-management (push) Has been cancelled
Deploy / deploy-external-dev (push) Has been cancelled
Deploy / deploy-security (push) Has been cancelled
Deploy / deploy-dev (push) Has been cancelled
Deploy / deploy-prod (push) Has been cancelled

Agents no longer treat a security review or a cross-family review as a merge gate.
This commit is contained in:
Adam Moussa 2026-09-26 17:18:04 -04:00 • committed by GitHub
parent 617987c4a8
commit d80295c005
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -22,12 +22,6 @@ State verifiable facts only. Do not cite the handbook to justify changes.
Allowed types: `feat` `fix` `docs` `style` `refactor` `perf` `test` `build` `ci` `chore` `revert` `release`.
## Security Gates
Changes touching payment flows, authentication, secrets, IaC/IAM, or untrusted user input require
a security review. IAM role, policy, or resource-permission changes require cross-family review.
Lambda handler-signature changes alone do not trigger cross-family review.
## CI and SHA Pins
Pin every GitHub Actions ref to a full commit SHA with an inline version comment:
@ -42,6 +36,4 @@ explicit approval). Linting stays in CI; do not gate on it locally.
## Repository Note
**High-blast AWS org/IAM substrate.** This repo synthesises and diffs the organisation-level CDK
stack. Always run `cdk synth` and review `cdk diff` output before raising a PR. Every IAM role,
policy, or resource-permission change requires cross-family review regardless of change size.
Do not merge IAM-touching PRs without a completed cross-family sign-off comment on the PR.
stack. Always run `cdk synth` and review `cdk diff` output before raising a PR.