ci: add org PR policy caller

Refs: PLAT-62
This commit is contained in:
Adam Moussa 2026-08-04 11:32:26 -04:00
parent 70524fe5cb
commit 5ea21991d8
No known key found for this signature in database
3 changed files with 70 additions and 0 deletions

View file

@ -4,6 +4,8 @@ updates:
directory: "/" directory: "/"
schedule: schedule:
interval: "weekly" interval: "weekly"
commit-message:
prefix: "chore(deps)"
groups: groups:
minor-and-patch: minor-and-patch:
update-types: update-types:
@ -14,6 +16,8 @@ updates:
directory: "/" directory: "/"
schedule: schedule:
interval: "weekly" interval: "weekly"
commit-message:
prefix: "chore(deps)"
groups: groups:
minor-and-patch: minor-and-patch:
update-types: update-types:

22
.github/workflows/policy.yaml vendored Normal file
View file

@ -0,0 +1,22 @@
name: PR Policy
on:
pull_request:
types: [opened, reopened, synchronize, edited, labeled, unlabeled, ready_for_review]
concurrency:
group: "policy-${{ github.event.pull_request.number }}"
cancel-in-progress: true
permissions:
contents: read
issues: read
pull-requests: read
jobs:
policy:
uses: Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml@9c1ecf942894b19aba5c71b85b41906c6c83b749 # v1.0.5
secrets:
JIRA_CLOUD_ID: ${{ secrets.JIRA_CLOUD_ID }}
JIRA_SERVICE_ACCOUNT_EMAIL: ${{ secrets.JIRA_SERVICE_ACCOUNT_EMAIL }}
JIRA_API_TOKEN: ${{ secrets.JIRA_API_TOKEN }}

44
AGENTS.md Normal file
View file

@ -0,0 +1,44 @@
# Sea Haven Governance
**Standards authority:** engineering-handbook · **Status authority:** Jira
## Routing
- Product / feature work → DEV
- Infrastructure and platform → PLAT
- Security → SEC
## Branches
`feature/`, `fix/`, `hotfix/`, `chore/`, `docs/`, `refactor/`, `release/` + kebab-case description.
No Jira keys in branch names.
## Pull Requests
**Title:** `type(scope): description (DEV-123)` — every non-exempt PR ends with its Jira key.
**Body sections (in order):** Summary · Validation · Tests · Notes — use "None." when a section is empty.
State verifiable facts only. Do not cite the handbook to justify changes.
Allowed types: `feat` `fix` `docs` `style` `refactor` `perf` `test` `build` `ci` `chore` `revert` `release`.
## Security Gates
Changes touching payment flows, authentication, secrets, IaC/IAM, or untrusted user input require
a security review. IAM role, policy, or resource-permission changes require cross-family review.
Lambda handler-signature changes alone do not trigger cross-family review.
## CI and SHA Pins
Pin every GitHub Actions ref to a full commit SHA with an inline version comment:
```yaml
uses: actions/checkout@abc123def456 # v4.1.0
```
The deterministic global pre-push security hook must not be bypassed (`--no-verify` requires
explicit approval). Linting stays in CI; do not gate on it locally.
## Repository Note
Generic governance applies. Route product work to DEV, platform/infra to PLAT.