ci: add org PR policy caller (PLAT-62) (#52)

* ci: add org PR policy caller

Refs: PLAT-62

* ci: update PR policy workflow to v1.0.7
This commit is contained in:
Adam Moussa 2026-08-11 12:04:16 -04:00 • committed by GitHub
parent b5aa1a70e0
commit 8136cb60c3
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
3 changed files with 53 additions and 0 deletions

View file

@ -13,6 +13,8 @@ updates:
patterns:
- 'vitest'
- '@vitest/*'
commit-message:
prefix: 'chore(deps)'
- package-ecosystem: 'npm'
directory: '/infra'
schedule:
@ -26,6 +28,8 @@ updates:
patterns:
- 'vitest'
- '@vitest/*'
commit-message:
prefix: 'chore(deps)'
- package-ecosystem: 'github-actions'
directory: '/'
schedule:
@ -35,3 +39,5 @@ updates:
update-types:
- 'minor'
- 'patch'
commit-message:
prefix: 'chore(deps)'

22
.github/workflows/policy.yaml vendored Normal file
View file

@ -0,0 +1,22 @@
name: PR Policy
on:
pull_request:
types: [opened, reopened, synchronize, edited, labeled, unlabeled, ready_for_review]
concurrency:
group: "policy-${{ github.event.pull_request.number }}"
cancel-in-progress: true
permissions:
contents: read
issues: read
pull-requests: read
jobs:
policy:
uses: Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml@e5691d8a7f96ac4d5a841a82975ff0a4354d53ac # v1.0.7
secrets:
JIRA_CLOUD_ID: ${{ secrets.JIRA_CLOUD_ID }}
JIRA_SERVICE_ACCOUNT_EMAIL: ${{ secrets.JIRA_SERVICE_ACCOUNT_EMAIL }}
JIRA_API_TOKEN: ${{ secrets.JIRA_API_TOKEN }}

25
AGENTS.md Normal file
View file

@ -0,0 +1,25 @@
# AGENTS.md
## Sea Haven Governance
**Standards authority**: The engineering handbook is the single authority for coding standards, naming conventions, and workflow configuration. Do not justify changes by citing it in PR bodies.
**Work authority**: Jira is the source of truth for work status. Before creating a ticket, search Jira for duplicates. Route product work to DEV, infrastructure and platform work to PLAT, and security work to SEC.
**Branch names**: Use `feature/`, `fix/`, `hotfix/`, `chore/`, `docs/`, `refactor/`, or `release/` with a kebab-case description. Do not include Jira keys in branch names. Dependabot branches and emergency reverts are exempt from this rule.
**PR title format**: `type(scope): description (DEV-123)` — Jira key required on every non-exempt PR. Dependabot and permission-controlled emergency reverts are exempt.
**PR body headings** (exact, in this order):
1. Summary
2. Validation
3. Tests
4. Notes
**Prohibited**: AI-attribution footers in commits, PRs, comments, or generated artifacts.
**Security gates**:
- PRs touching payment flows, authentication logic, secret handling, AWS IAM, or untrusted user input require security review.
- IAM role, policy, or resource-permission changes require cross-family review.
**CI workflow refs**: All `uses:` workflow refs must be pinned to a full commit SHA with an inline version comment — `owner/repo/.github/workflows/file.yaml@<full-sha> # vX.Y.Z`. No floating tags or branch refs.