Agents no longer treat a security review or a cross-family review as a merge gate.
2.1 KiB
AGENTS.md
Sea Haven Governance
Standards authority: The engineering handbook is the single authority for coding standards, naming conventions, and workflow configuration. Do not justify changes by citing it in PR bodies.
Work authority: Jira is the source of truth for work status. Before creating a ticket, search Jira for duplicates. Route product work to DEV, infrastructure and platform work to PLAT, and security work to SEC.
Branch names: Use feature/, fix/, hotfix/, chore/, docs/, refactor/, or release/ with a kebab-case description. Do not include Jira keys in branch names. Dependabot branches and emergency reverts are exempt.
PR title format: type(scope): description (DEV-123) — Jira key required on every non-exempt PR. Dependabot and permission-controlled emergency reverts are exempt.
PR body headings (exact, in this order):
- Summary
- Validation
- Tests
- Notes
Prohibited: AI-attribution footers in commits, PRs, comments, or generated artifacts.
CI workflow refs: All uses: refs must be pinned to a 40-char SHA with a # vX.Y.Z comment. No floating tags or branch refs.
Repository Notes
This repository is the source of the org-wide pre-push security hook (review.sh, hooks/pre-push) and the IAM cross-review script (cross_review.py). Changes propagate to every developer workstation that has run install-hooks.sh. Treat all modifications here as fleet-wide changes.
High-impact areas — review carefully:
review.sh/hooks/pre-push: scanner invocation, suppression logic, and exit-code handling run on every developer push across the fleet.cross_review.py: governs which IAM changes trigger mandatory cross-family review. Modifications expand or shrink the review surface org-wide.- Scanner suppressions (
.security-review-skip, per-file markers): each suppression must document the specific threat excluded and why exclusion is safe. canary/: intentionally insecure fixtures that validate scanner detection. Treat as test infrastructure, not production code; do not add real secrets or live credentials here.