Double backslash in single quotes makes ERE match a literal
backslash instead of a dot. No .gitignore entry could pass
this check. Affects both CDK and SAM CI workflows.
* Add QEMU support to CI CDK workflow for cross-platform Docker builds
Mirrors the enable-qemu input from cd-cdk.yaml. Required when CDK
stacks use PythonFunction or other Docker-bundled constructs targeting
arm64 Lambda on x86 CI runners.
* Increase CI timeout for QEMU CDK builds
* Bump default Node.js version to 24 across all reusable workflows
npm 11 (Node 24) generates lockfileVersion 3 which breaks npm ci
on Node 22's npm 10 for repos with aws-cdk-lib bundled deps.
* Add lightweight conventions check to CI workflows
Validates README exists, .env in .gitignore, arm64 architecture,
and log retention in synthesized templates. Runs by default,
opt-out via run-conventions-check: false.
* Add pre-flight stack status checks to CD workflows
Blocks deploy if the CloudFormation stack is in ROLLBACK_COMPLETE,
FAILED, or IN_PROGRESS state. Prevents wasted deploy attempts on
stacks that need manual intervention.
* Add post-deploy health checks to CD workflows
Verifies stack status after deploy, prints outputs, and runs
project-specific scripts/health-check.sh if present.
---------
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Mirrors the enable-qemu input from cd-cdk.yaml. Required when CDK
stacks use PythonFunction or other Docker-bundled constructs targeting
arm64 Lambda on x86 CI runners.
Use GitHub App token (CLAUDE_CI_APP_ID) for cross-repo access when
dispatching reviews via workflow_dispatch. Remove issue_comment,
pull_request_review_comment, and review_requested triggers since
org-level workflows don't propagate those events to other repos.
* Change Claude Code review to on-demand via @claude or review request
Replace automatic PR triggers (opened, ready_for_review) with on-demand
triggers: @claude mentions in PR comments, inline review comments, and
review requests from the 'claude' team.
* Remove unreachable workflow_call event check
workflow_call invocations inherit the caller's event_name, so
github.event_name == 'workflow_call' never matches. The caller's
event context passes through and is handled by the existing
issue_comment/review_requested conditions.
* Fix workflow_call invocations being silently skipped
Add a direct_call boolean input (defaults to true) to workflow_call
so reusable workflow callers bypass the event-specific filtering gate.
Without this, callers triggered by e.g. pull_request opened would
hit the pull_request branch which requires requested_team.slug == 'claude',
causing a silent no-op.
* Fix compliance audit workflow and source standards from handbook
- Add missing permissions (id-token, contents, issues) for OIDC auth
and issue creation
- Fix direct_prompt → prompt (direct_prompt is not a valid input)
- Check out engineering-handbook repo as authoritative standards source
instead of hardcoding the checklist in the workflow
- Create compliance label on-the-fly if it doesn't exist in target repo
* Fix compliance audit violation detection
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
---------
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
- SQS/EC2/SNS as inline policy (managed policy quota is 10)
- cd-sam.yaml now accepts optional parameter-overrides input for
SAM templates with required parameters
- Add cloudformation:CreateChangeSet on aws:transform/* to the shared
CFN execution role (required for SAM's Serverless transform)
- Remove working-directory from pip install step so it finds
requirements.txt at repo root (not just cdk-dir)
Enables Python CDK repos (po-ingest, workorder-ingest) to use the
same reusable workflow. Adds run-cdk-synth, cdk-dir, and node-version
inputs. Refactors dependency install to be shared between pytest and
cdk synth paths.
Parameterized workflows that each repo calls via a thin 3-5 line
caller. All lint, test, and validate steps are toggleable so repos
can adopt incrementally. Covers Python SAM, Python CDK, TypeScript
CDK, and Node.js SAM stacks.
- Reusable PR review workflow (repos call via thin wrapper)
- Weekly compliance audit across all org repos
- Rollout script to push wrapper workflow to all repos
- Uses GitHub App tokens for cross-repo auth (no PAT rotation needed)