security-review/AGENTS.md

33 lines
2.1 KiB
Markdown
Raw Normal View History

# AGENTS.md
## Sea Haven Governance
**Standards authority**: The engineering handbook is the single authority for coding standards, naming conventions, and workflow configuration. Do not justify changes by citing it in PR bodies.
**Work authority**: Jira is the source of truth for work status. Before creating a ticket, search Jira for duplicates. Route product work to DEV, infrastructure and platform work to PLAT, and security work to SEC.
**Branch names**: Use `feature/`, `fix/`, `hotfix/`, `chore/`, `docs/`, `refactor/`, or `release/` with a kebab-case description. Do not include Jira keys in branch names. Dependabot branches and emergency reverts are exempt.
**PR title format**: `type(scope): description (DEV-123)` — Jira key required on every non-exempt PR. Dependabot and permission-controlled emergency reverts are exempt.
**PR body headings** (exact, in this order):
1. Summary
2. Validation
3. Tests
4. Notes
**Prohibited**: AI-attribution footers in commits, PRs, comments, or generated artifacts.
**CI workflow refs**: All `uses:` refs must be pinned to a 40-char SHA with a `# vX.Y.Z` comment. No floating tags or branch refs.
## Repository Notes
This repository is the source of the org-wide pre-push security hook (`review.sh`, `hooks/pre-push`) and the IAM cross-review script (`cross_review.py`). Changes propagate to every developer workstation that has run `install-hooks.sh`. Treat all modifications here as fleet-wide changes.
**High-impact areas — review carefully:**
- **`review.sh` / `hooks/pre-push`**: scanner invocation, suppression logic, and exit-code handling run on every developer push across the fleet.
- **`cross_review.py`**: governs which IAM changes trigger mandatory cross-family review. Modifications expand or shrink the review surface org-wide.
- **Scanner suppressions** (`.security-review-skip`, per-file markers): each suppression must document the specific threat excluded and why exclusion is safe.
- **`canary/`**: intentionally insecure fixtures that validate scanner detection. Treat as test infrastructure, not production code; do not add real secrets or live credentials here.