# Sea Haven Governance **Standards authority:** engineering-handbook · **Status authority:** Jira ## Routing - Product / feature work → DEV - Infrastructure and platform → PLAT - Security → SEC ## Branches `feature/`, `fix/`, `hotfix/`, `chore/`, `docs/`, `refactor/`, `release/` + kebab-case description. No Jira keys in branch names. ## Pull Requests **Title:** `type(scope): description (DEV-123)` — every non-exempt PR ends with its Jira key. **Body sections (in order):** Summary · Validation · Tests · Notes — use "None." when a section is empty. State verifiable facts only. Do not cite the handbook to justify changes. Allowed types: `feat` `fix` `docs` `style` `refactor` `perf` `test` `build` `ci` `chore` `revert` `release`. ## CI and SHA Pins Pin every GitHub Actions ref to a full commit SHA with an inline version comment: ```yaml uses: actions/checkout@abc123def456 # v4.1.0 ``` The deterministic global pre-push security hook must not be bypassed (`--no-verify` requires explicit approval). Linting stays in CI; do not gate on it locally. ## Repository Note **High-blast AWS org/IAM substrate.** This repo synthesises and diffs the organisation-level CDK stack. Always run `cdk synth` and review `cdk diff` output before raising a PR. ## Cursor Cloud specific instructions CI pins Node 24. On this VM, `node` on `PATH` can resolve to an older binary under `/exec-daemon` ahead of nvm. Select Node 24 in the same shell before `npm` or `cdk`: ```bash export NVM_DIR="$HOME/.nvm" . "$NVM_DIR/nvm.sh" nvm use 24 export PATH="$(dirname "$(nvm which 24)"):$PATH" ``` Canonical checks: `npm ci`, `npm run build`, `npx cdk synth`. Also run `cdk diff` for every stack this change touches and review the output before opening the PR. Do not `cdk deploy` from this environment.