From 51f7905cc79e45a052f9010cab7cb28a701756de Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Tue, 4 Aug 2026 11:56:37 -0400 Subject: [PATCH] ci: add org PR policy caller (#10) Refs: PLAT-62 --- .github/dependabot.yml | 4 ++++ .github/workflows/policy.yaml | 22 +++++++++++++++++++++ AGENTS.md | 36 +++++++++++++++++++++++++++++++++++ 3 files changed, 62 insertions(+) create mode 100644 .github/workflows/policy.yaml create mode 100644 AGENTS.md diff --git a/.github/dependabot.yml b/.github/dependabot.yml index b6b02e7..bdfccaf 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -4,6 +4,8 @@ updates: directory: "/" schedule: interval: "weekly" + commit-message: + prefix: "chore(deps)" groups: minor-and-patch: update-types: @@ -13,6 +15,8 @@ updates: directory: "/" schedule: interval: "weekly" + commit-message: + prefix: "chore(deps)" groups: minor-and-patch: update-types: diff --git a/.github/workflows/policy.yaml b/.github/workflows/policy.yaml new file mode 100644 index 0000000..eba1158 --- /dev/null +++ b/.github/workflows/policy.yaml @@ -0,0 +1,22 @@ +name: PR Policy + +on: + pull_request: + types: [opened, reopened, synchronize, edited, labeled, unlabeled, ready_for_review] + +concurrency: + group: "policy-${{ github.event.pull_request.number }}" + cancel-in-progress: true + +permissions: + contents: read + issues: read + pull-requests: read + +jobs: + policy: + uses: Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml@9c1ecf942894b19aba5c71b85b41906c6c83b749 # v1.0.5 + secrets: + JIRA_CLOUD_ID: ${{ secrets.JIRA_CLOUD_ID }} + JIRA_SERVICE_ACCOUNT_EMAIL: ${{ secrets.JIRA_SERVICE_ACCOUNT_EMAIL }} + JIRA_API_TOKEN: ${{ secrets.JIRA_API_TOKEN }} diff --git a/AGENTS.md b/AGENTS.md new file mode 100644 index 0000000..af4b51a --- /dev/null +++ b/AGENTS.md @@ -0,0 +1,36 @@ +# AGENTS.md + +## Sea Haven Governance + +**Standards authority**: The engineering handbook is the single authority for coding standards, naming conventions, and workflow configuration. Do not justify changes by citing it in PR bodies. + +**Work authority**: Jira is the source of truth for work status. Before creating a ticket, search Jira for duplicates. Route product work to DEV, infrastructure and platform work to PLAT, and security work to SEC. + +**Branch names**: Use `feature/`, `fix/`, `hotfix/`, `chore/`, `docs/`, `refactor/`, or `release/` with a kebab-case description. Do not include Jira keys in branch names. Dependabot branches and emergency reverts are exempt. + +**PR title format**: `type(scope): description (DEV-123)` — Jira key required on every non-exempt PR. Dependabot and permission-controlled emergency reverts are exempt. + +**PR body headings** (exact, in this order): +1. Summary +2. Validation +3. Tests +4. Notes + +**Prohibited**: AI-attribution footers in commits, PRs, comments, or generated artifacts. + +**Security gates**: +- PRs touching payment flows, authentication logic, secret handling, AWS IAM, or untrusted user input require security review. +- IAM role, policy, or resource-permission changes require cross-family review. + +**CI workflow refs**: All `uses:` refs must be pinned to a 40-char SHA with a `# vX.Y.Z` comment. No floating tags or branch refs. + +## Repository Notes + +This repository is the source of the org-wide pre-push security hook (`review.sh`, `hooks/pre-push`) and the IAM cross-review script (`cross_review.py`). Changes propagate to every developer workstation that has run `install-hooks.sh`. Treat all modifications here as fleet-wide changes. + +**High-impact areas — review carefully:** + +- **`review.sh` / `hooks/pre-push`**: scanner invocation, suppression logic, and exit-code handling run on every developer push across the fleet. +- **`cross_review.py`**: governs which IAM changes trigger mandatory cross-family review. Modifications expand or shrink the review surface org-wide. +- **Scanner suppressions** (`.security-review-skip`, per-file markers): each suppression must document the specific threat excluded and why exclusion is safe. +- **`canary/`**: intentionally insecure fixtures that validate scanner detection. Treat as test infrastructure, not production code; do not add real secrets or live credentials here.