From 09ad86efcd32d70e3b51df18c8780ef08cae53fd Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Tue, 4 Aug 2026 11:32:26 -0400 Subject: [PATCH] ci: add org PR policy caller Refs: PLAT-62 --- .github/dependabot.yml | 6 ++++++ .github/workflows/policy.yaml | 22 ++++++++++++++++++++++ AGENTS.md | 25 +++++++++++++++++++++++++ 3 files changed, 53 insertions(+) create mode 100644 .github/workflows/policy.yaml create mode 100644 AGENTS.md diff --git a/.github/dependabot.yml b/.github/dependabot.yml index ca76eb5..4a6e417 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -13,6 +13,8 @@ updates: patterns: - 'vitest' - '@vitest/*' + commit-message: + prefix: 'chore(deps)' - package-ecosystem: 'npm' directory: '/infra' schedule: @@ -26,6 +28,8 @@ updates: patterns: - 'vitest' - '@vitest/*' + commit-message: + prefix: 'chore(deps)' - package-ecosystem: 'github-actions' directory: '/' schedule: @@ -35,3 +39,5 @@ updates: update-types: - 'minor' - 'patch' + commit-message: + prefix: 'chore(deps)' diff --git a/.github/workflows/policy.yaml b/.github/workflows/policy.yaml new file mode 100644 index 0000000..eba1158 --- /dev/null +++ b/.github/workflows/policy.yaml @@ -0,0 +1,22 @@ +name: PR Policy + +on: + pull_request: + types: [opened, reopened, synchronize, edited, labeled, unlabeled, ready_for_review] + +concurrency: + group: "policy-${{ github.event.pull_request.number }}" + cancel-in-progress: true + +permissions: + contents: read + issues: read + pull-requests: read + +jobs: + policy: + uses: Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml@9c1ecf942894b19aba5c71b85b41906c6c83b749 # v1.0.5 + secrets: + JIRA_CLOUD_ID: ${{ secrets.JIRA_CLOUD_ID }} + JIRA_SERVICE_ACCOUNT_EMAIL: ${{ secrets.JIRA_SERVICE_ACCOUNT_EMAIL }} + JIRA_API_TOKEN: ${{ secrets.JIRA_API_TOKEN }} diff --git a/AGENTS.md b/AGENTS.md new file mode 100644 index 0000000..45ba250 --- /dev/null +++ b/AGENTS.md @@ -0,0 +1,25 @@ +# AGENTS.md + +## Sea Haven Governance + +**Standards authority**: The engineering handbook is the single authority for coding standards, naming conventions, and workflow configuration. Do not justify changes by citing it in PR bodies. + +**Work authority**: Jira is the source of truth for work status. Before creating a ticket, search Jira for duplicates. Route product work to DEV, infrastructure and platform work to PLAT, and security work to SEC. + +**Branch names**: Use `feature/`, `fix/`, `hotfix/`, `chore/`, `docs/`, `refactor/`, or `release/` with a kebab-case description. Do not include Jira keys in branch names. Dependabot branches and emergency reverts are exempt from this rule. + +**PR title format**: `type(scope): description (DEV-123)` — Jira key required on every non-exempt PR. Dependabot and permission-controlled emergency reverts are exempt. + +**PR body headings** (exact, in this order): +1. Summary +2. Validation +3. Tests +4. Notes + +**Prohibited**: AI-attribution footers in commits, PRs, comments, or generated artifacts. + +**Security gates**: +- PRs touching payment flows, authentication logic, secret handling, AWS IAM, or untrusted user input require security review. +- IAM role, policy, or resource-permission changes require cross-family review. + +**CI workflow refs**: All `uses:` workflow refs must be pinned to a full commit SHA with an inline version comment — `owner/repo/.github/workflows/file.yaml@ # vX.Y.Z`. No floating tags or branch refs.