stampli-bulk-editor/AGENTS.md
Adam Moussa 53342c13ff
ci: add org PR policy caller (#17)
Refs: PLAT-62
2026-08-04 11:56:46 -04:00

1.4 KiB

Sea Haven Governance

Standards authority: engineering-handbook · Status authority: Jira

Routing

  • Product / feature work → DEV
  • Infrastructure and platform → PLAT
  • Security → SEC

Branches

feature/, fix/, hotfix/, chore/, docs/, refactor/, release/ + kebab-case description. No Jira keys in branch names.

Pull Requests

Title: type(scope): description (DEV-123) — every non-exempt PR ends with its Jira key.

Body sections (in order): Summary · Validation · Tests · Notes — use "None." when a section is empty. State verifiable facts only. Do not cite the handbook to justify changes.

Allowed types: feat fix docs style refactor perf test build ci chore revert release.

Security Gates

Changes touching payment flows, authentication, secrets, IaC/IAM, or untrusted user input require a security review. IAM role, policy, or resource-permission changes require cross-family review. Lambda handler-signature changes alone do not trigger cross-family review.

CI and SHA Pins

Pin every GitHub Actions ref to a full commit SHA with an inline version comment:

uses: actions/checkout@abc123def456 # v4.1.0

The deterministic global pre-push security hook must not be bypassed (--no-verify requires explicit approval). Linting stays in CI; do not gate on it locally.

Repository Note

Generic governance applies. Route product work to DEV, platform/infra to PLAT.