diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 5ace460..d1a3f4b 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -4,3 +4,5 @@ updates: directory: "/" schedule: interval: "weekly" + commit-message: + prefix: "chore(deps)" diff --git a/.github/workflows/policy.yaml b/.github/workflows/policy.yaml new file mode 100644 index 0000000..eba1158 --- /dev/null +++ b/.github/workflows/policy.yaml @@ -0,0 +1,22 @@ +name: PR Policy + +on: + pull_request: + types: [opened, reopened, synchronize, edited, labeled, unlabeled, ready_for_review] + +concurrency: + group: "policy-${{ github.event.pull_request.number }}" + cancel-in-progress: true + +permissions: + contents: read + issues: read + pull-requests: read + +jobs: + policy: + uses: Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml@9c1ecf942894b19aba5c71b85b41906c6c83b749 # v1.0.5 + secrets: + JIRA_CLOUD_ID: ${{ secrets.JIRA_CLOUD_ID }} + JIRA_SERVICE_ACCOUNT_EMAIL: ${{ secrets.JIRA_SERVICE_ACCOUNT_EMAIL }} + JIRA_API_TOKEN: ${{ secrets.JIRA_API_TOKEN }} diff --git a/AGENTS.md b/AGENTS.md new file mode 100644 index 0000000..c10461e --- /dev/null +++ b/AGENTS.md @@ -0,0 +1,35 @@ +# AGENTS.md + +## Sea Haven Governance + +**Standards authority**: The engineering handbook is the single authority for coding standards, naming conventions, and workflow configuration. Do not justify changes by citing it in PR bodies. + +**Work authority**: Jira is the source of truth for work status. Before creating a ticket, search Jira for duplicates. Route product work to DEV, infrastructure and platform work to PLAT, and security work to SEC. + +**Branch names**: Use `feature/`, `fix/`, `hotfix/`, `chore/`, `docs/`, `refactor/`, or `release/` with a kebab-case description. Do not include Jira keys in branch names. Dependabot branches and emergency reverts are exempt. + +**PR title format**: `type(scope): description (DEV-123)` — Jira key required on every non-exempt PR. Dependabot and permission-controlled emergency reverts are exempt. + +**PR body headings** (exact, in this order): +1. Summary +2. Validation +3. Tests +4. Notes + +**Prohibited**: AI-attribution footers in commits, PRs, comments, or generated artifacts. + +**Security gates**: +- PRs touching payment flows, authentication logic, secret handling, AWS IAM, or untrusted user input require security review. +- IAM role, policy, or resource-permission changes require cross-family review. + +**CI workflow refs**: All `uses:` refs must be pinned to a 40-char SHA with a `# vX.Y.Z` comment. No floating tags or branch refs. + +## Repository Notes + +This repo drives the SHOC PR review pipeline and is included in the org-wide policy rollout. SHOC product repos (`shoc-frontend-new`, `shoc-backend`) are excluded from automated review scope but are checked out read-only by this runner. + +**Do not edit these workflows:** + +- `.github/workflows/ci.yaml` — thin caller whose `ci / ci` check context satisfies the org branch-protection rule; structure must not change. +- `.github/workflows/ci-runner-checks.yaml` — bespoke reusable CI for shell/workflow tooling; no standard org template applies here. +- `.github/workflows/review-pr.yml` — manually dispatched two-job review pipeline with an intentional security boundary between the untrusted `gates` job and the secret-bearing `review` job. Do not merge these jobs; the isolation is a deliberate security control documented in the workflow header comment.