Commit graph

139 commits

Author SHA1 Message Date
b7ad15cc59
Merge remote-tracking branch 'origin/main' into feature/136-admin-slack-modals 2026-07-02 16:10:25 -04:00
amoussa1229
df6b32bdb9 Update changelog date to July 02, 2026 2026-07-02 19:59:36 +00:00
dependabot[bot]
11afaf1f1f
Update boto3 requirement from >=1.43.36 to >=1.43.39 in /src/slack-bot (#148)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.36...1.43.39)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.38
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-02 15:29:18 -04:00
dependabot[bot]
bc7fba40dd
Update boto3 requirement from >=1.43.36 to >=1.43.38 in /src/shared (#146)
Some checks failed
Deploy / deploy (push) Has been cancelled
Deploy / release (push) Has been cancelled
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.36...1.43.38)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.38
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-01 01:06:00 +00:00
dependabot[bot]
61a7ba8ca4
Update boto3 requirement from >=1.43.36 to >=1.43.38 in /src/roster-sync (#145)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.36...1.43.38)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.38
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-01 01:01:52 +00:00
dependabot[bot]
9a9c776da3
Update boto3 requirement from >=1.43.36 to >=1.43.38 in /src/weekly-post (#149)
Some checks are pending
Deploy / deploy (push) Waiting to run
Deploy / release (push) Blocked by required conditions
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.36...1.43.38)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.38
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-30 23:53:36 +00:00
dependabot[bot]
e57560b87c
Update slack-bolt requirement in /src/slack-bot (#147)
Updates the requirements on [slack-bolt](https://github.com/slackapi/bolt-python) to permit the latest version.
- [Release notes](https://github.com/slackapi/bolt-python/releases)
- [Commits](https://github.com/slackapi/bolt-python/compare/v1.28.0...v1.29.0)

---
updated-dependencies:
- dependency-name: slack-bolt
  dependency-version: 1.29.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-30 23:49:32 +00:00
dependabot[bot]
c0b2a41e34
Update boto3 requirement in /src/ring-scheduler (#144)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.36...1.43.38)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.38
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-30 19:45:36 -04:00
Adam Moussa
f7c44778b5
[#142] Fix payroll email: SES domain identity + send-as pin + failure alarm (#143)
Some checks failed
Deploy / deploy (push) Has been cancelled
Deploy / release (push) Has been cancelled
The weekly-post pay-summary email to payroll failed with SES AccessDenied
every Monday since v1.10.1: the role granted ses:SendEmail on
identity/noreply@seahaven.com, but that address is not a verified SES
identity — it is covered by the verified domain identity seahaven.com,
which is what SES authorizes against. Grant the domain ARN instead.

Pin the grant with a ses:FromAddress condition (= noreply@seahaven.com,
the existing SES_SENDER) so the domain-wide identity can't be used to
send-as any other @seahaven.com mailbox (BEC blast radius). Surfaced by
/sh-security-review; matches the existing single-sender intent.

Add a CloudWatch metric-filter alarm on the swallowed "Failed to send
pay summary" log line -> site-alerts. The email send is wrapped in
try/except so a delivery failure never increments the Lambda Errors
metric; this is the only signal that surfaces a silent payroll failure.

Closes #142
2026-06-29 15:10:02 -04:00
seahaven-openswe[bot]
254f6b989f
[#135] Stick weekly schedule post to bottom of channel (#139)
Some checks failed
Deploy / deploy (push) Has been cancelled
Deploy / release (push) Has been cancelled
2026-06-27 15:45:01 -04:00
seahaven-openswe[bot]
e02caab120 Add Slack admin modals + App Home admin section
Replace the two most error-prone positional admin commands with Block Kit
modals (override and holiday-add) opened from a new App Home admin section,
while keeping the typed subcommands as a fallback. Validation and side
effects are factored into shared helpers so the modal and command paths
can't drift, and every action/view handler re-checks is_admin against
get_admin_users() so a modal opened from Home can't bypass authorization.
Adds Schedule.list_overrides for the upcoming-overrides overview.

Refs: #136
2026-06-26 20:47:04 +00:00
seahaven-openswe[bot]
b8ab4d6b77
[#134] Clarify dropping a shift and differentiate night rows (#138)
Some checks are pending
Deploy / deploy (push) Waiting to run
Deploy / release (push) Blocked by required conditions
* Expand /oncall date parser to accept more formats

Users entering everyday forms like 7/3/26 hit a generic parse
failure because the parser only accepted four-digit years and a
bare m/d. Add two-digit-year and month-name (with optional
ordinal/year) formats, treating explicit-year inputs as fixed and
keeping the year-less roll-forward for bare m/d. Update the help
text and per-command parse hints to match.

Refs: #133

* Let drop pick a shift and flag night rows

Drop now accepts an optional [day|night|holiday] qualifier and, when a
date carries more than one shift the user holds, asks which to drop
instead of silently releasing the holiday or weekend day shift. The
static post also tags day/night rows with distinct glyphs and labels on
weekdays, so the after-hours row is unmistakable.

Refs: #134

* Refine night-row labeling and drop notifications

Weekday rows are night-only, so the moon glyph alone marks the
after-hours shift; the verbose time-range label is kept only on
weekend rows where day and night shifts coexist. Channel shift-change
notifications now label the shift on every day for parity. Thread the
caller's user_id through the regular-drop path instead of re-reading it
off the employee record, and document the user-facing changes.

Refs: #134

---------

Co-authored-by: amoussa1229 <166072409+amoussa1229@users.noreply.github.com>
2026-06-26 15:19:22 -04:00
seahaven-openswe[bot]
eb78a98de0
[#133] Expand /oncall date parser to accept more formats (#137)
* Expand /oncall date parser to accept more formats

Users entering everyday forms like 7/3/26 hit a generic parse
failure because the parser only accepted four-digit years and a
bare m/d. Add two-digit-year and month-name (with optional
ordinal/year) formats, treating explicit-year inputs as fixed and
keeping the year-less roll-forward for bare m/d. Update the help
text and per-command parse hints to match.

Refs: #133

* Add dash 4-digit year format and pin year boundary

Dash inputs like 7-3-2026 previously returned None because only the
slash variant had a 4-digit-year format. Add %m-%d-%Y so dash and slash
behave alike, and pin the two-digit-year century boundary with a test.

Refs: #133

---------

Co-authored-by: amoussa1229 <166072409+amoussa1229@users.noreply.github.com>
2026-06-26 15:07:02 -04:00
dependabot[bot]
b304121cff
Bump actions/checkout from 6 to 7 (#127)
Some checks are pending
Deploy / deploy (push) Waiting to run
Deploy / release (push) Blocked by required conditions
Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v6...v7)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-26 12:32:32 -04:00
dependabot[bot]
c5f17c77dc
Update boto3 requirement from >=1.43.31 to >=1.43.36 in /src/weekly-post (#132)
Some checks failed
Deploy / deploy (push) Has been cancelled
Deploy / release (push) Has been cancelled
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.31...1.43.36)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.36
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-24 00:53:03 +00:00
dependabot[bot]
8c2418b675
Update boto3 requirement from >=1.43.31 to >=1.43.36 in /src/slack-bot (#131)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.31...1.43.36)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.36
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-24 00:49:22 +00:00
dependabot[bot]
9be3754b31
Update boto3 requirement from >=1.43.31 to >=1.43.36 in /src/shared (#130)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.31...1.43.36)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.36
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-24 00:45:49 +00:00
dependabot[bot]
57c2f3f258
Update boto3 requirement from >=1.43.31 to >=1.43.36 in /src/roster-sync (#129)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.31...1.43.36)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.36
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-23 20:42:18 -04:00
dependabot[bot]
b4a7624060
Update boto3 requirement in /src/ring-scheduler (#128)
Some checks are pending
Deploy / deploy (push) Waiting to run
Deploy / release (push) Blocked by required conditions
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.31...1.43.36)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.36
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-23 20:24:05 -04:00
Adam Moussa
bdff6bee30
INFRA-106: nightly-sweep security remediation (auth/race/IAM) (#125)
Some checks failed
Deploy / deploy (push) Has been cancelled
Deploy / release (push) Has been cancelled
* Fix auth and race-condition flaws in shift commands

Four confirmed findings from the 2026-06-17 security sweep:

- register_user let any Slack user overwrite an extension already
  bound to a different user (account takeover). Add a DynamoDB
  ConditionExpression so a write only succeeds when the extension is
  unclaimed or already this user's; raise ExtensionAlreadyRegistered
  otherwise and surface a clear Slack message.
- The `rate` subcommand was routed without the is_admin flag, so any
  user could set $0 pay rates. Gate _handle_rate on is_admin, matching
  the admin-command guard.
- `/oncall pick` used a plain put_item (TOCTOU): two concurrent picks
  both won. Use the atomic claim_open_shift conditional claim so the
  loser gets an "already picked up" message.
- swap-accept overwrote a shift independently claimed after the swap
  was initiated. Add reassign_if_held_by, a conditional write that only
  applies the swap while the override is still the requester's (or on
  the weekly fallback), and notify the accepter otherwise.

Add tests for the register-ownership guard and the rate admin guard.

Refs: INFRA

* Scope shift-manager Lambda IAM to least privilege

The nightly sweep flagged four over-broad permissions. Scope each to
only what the function actually reads (verified against source):

- WeeklyPost: secrets to slack-bot-token-* only (was the whole
  afterhours-shift-manager/* namespace); SES SendEmail to the single
  noreply@seahaven.com identity (was identity/*).
- RosterSync and RingScheduler: secrets to 3cx-* only (was the whole
  namespace); both read only the 3cx domain/client-id/client-secret.

SlackBotFunction and HolidayRouter wildcards are left unchanged — out
of scope for this sweep.

Refs: INFRA

* fix: re-validate shift holder on swap-accept (sh-security-review RIHB-1)

reassign_if_held_by trusted 'no override row' as 'still the requester's',
but a weekly-held shift also has no override row. An admin clear or weekly
edit between swap-init and accept could move the shift to a third party
with no override, letting the accept steal it (CWE-367, confirmed HIGH).
Re-resolve the current holder at accept and abort if it is no longer the
requester. Adds regression test + seeds the holder in existing accept tests.

* fix: complete IAM least-privilege sweep (sh-security-review)

HolidayRouter secrets scope afterhours-shift-manager/* -> /3cx-* (reads
only 3cx secrets); RingScheduler DynamoDBCrudPolicy -> DynamoDBReadPolicy
(read-only at runtime). SlackBot wildcard left as-is (reads across all
sub-prefixes; verified defensible).
2026-06-18 12:05:25 -04:00
Adam Moussa
90c10d38d3
Add CloudWatch alarm coverage for all functions, table, and HTTP API (#126)
Some checks are pending
Deploy / deploy (push) Waiting to run
Deploy / release (push) Blocked by required conditions
* Add CloudWatch alarm coverage for all functions, table, and HTTP API

Extend the in-template Lambda-<Metric>-<fn> alarm convention to full coverage:

- Errors (Sum, >=1/5min) for roster-sync and release-notifier, plus orphan
  adoption of slack-bot and weekly-post (live alarms of those exact names
  already exist outside the stack and must be deleted before deploy).
- Duration (Maximum, ~80% of timeout, 2-of-3) for all six functions.
- Throttles (Sum, >=1/5min) for all six functions.
- DynamoDB ThrottledRequests (Sum, >=1/5min) on afterhours-shifts. SystemErrors
  omitted: AWS emits it only per-Operation, so a TableName-only alarm would sit
  permanently in INSUFFICIENT_DATA.
- API Gateway v2 4xx (>=5), 5xx (>=1), and p99 Latency (~3000ms, 2-of-3) on the
  implicit ServerlessHttpApi.

All alarms page the shared site-alerts SNS topic, no OKActions,
TreatMissingData notBreaching. README updated with a Monitoring & Alarms section.

Duration and API latency thresholds pending sign-off.

* Fix DynamoDB throttle alarm metric: use Read/WriteThrottleEvents

ThrottledRequests is not emitted at the TableName-only dimension (only
TableName+Operation), so the table-level alarm would sit permanently in
INSUFFICIENT_DATA and never fire. Replace with ReadThrottleEvents and
WriteThrottleEvents, which AWS/DynamoDB emits at the TableName dimension.

* Correct DynamoDB alarm docs and drop sign-off wording

README DynamoDB section now lists the alarms actually shipped
(DDB-ReadThrottle / DDB-WriteThrottle on Read/WriteThrottleEvents) instead
of the stale ThrottledRequests alarm. Thresholds are owner-approved, so
remove PENDING ADAM SIGN-OFF wording from template.yaml comments.
2026-06-17 14:45:47 -04:00
Adam Moussa
06bcb9b1b7
Add CloudWatch error alarm for afterhours-ring-scheduler (#123)
Some checks are pending
Deploy / deploy (push) Waiting to run
Deploy / release (push) Blocked by required conditions
The live afterhours-ring-scheduler Lambda had no error alarm. Add a
CloudWatch Errors alarm mirroring the existing HolidayRouterErrorAlarm:
AWS/Lambda Errors, Sum over one 5-min period, threshold >=1, missing
data notBreaching, paging the site-alerts SNS topic.

The orphaned Lambda-Errors-3cx-ring-group-scheduler alarm (pointing at
a renamed/absent function) is being removed separately.
2026-06-17 12:08:04 -04:00
Adam Moussa
54b585776b
Fix holiday router 3CX IVR calls (Receptionists entity, not IVRs) (#124)
get_ivr/set_ivr_routes/extract_ivr_routes targeted a nonexistent IVRs entity
set with an Options[].Route/TimeoutForward shape. The live 3CX IVR is the
Receptionists entity: the no-input/timeout route is the scalar TimeoutForwardDN,
and the key-0 route is a child of the Forwards collection (matched by Input=='0'),
written via a parent deep-PATCH. Routes are now destination numbers. Caught by the
live prod round-trip (get_ivr returned 405) before any holiday ran; rewritten and
re-verified against the live PBX. v1.11.1.
2026-06-17 12:04:10 -04:00
Adam Moussa
88e782c205
Add holiday shifts with 3CX routing and late-pickup approval (#121)
Some checks are pending
Deploy / deploy (push) Waiting to run
Deploy / release (push) Blocked by required conditions
Holiday day-shifts (08:00-17:00 ET) with N slots and 1.5x pay. A new
afterhours-holiday-router Lambda, fired by per-holiday EventBridge Scheduler
one-offs, repoints IVR 800 (key-0 + no-input/timeout) to holiday queue 802 and
sets 802's membership to the day's assignees (ext 100 fallback when unfilled),
reverting at 17:00. Pickups after a shift starts go through an admin Approve/Deny
flow for both regular and holiday shifts. Pay (weekly post + /oncall pay) shows
holiday rates distinctly.

Adds HOLIDAY and PICKUP_REQUEST DynamoDB record types, scheduler IAM scoped to
holiday-* schedules with conditioned PassRole, and the holiday-router function
with a 60-day log group and error alarm.
2026-06-17 11:14:29 -04:00
dependabot[bot]
9353b9222b
Update boto3 requirement from >=1.43.27 to >=1.43.31 in /src/weekly-post (#120)
Some checks are pending
Deploy / deploy (push) Waiting to run
Deploy / release (push) Blocked by required conditions
2026-06-17 01:06:19 +00:00
dependabot[bot]
36232f4ae4
Update boto3 requirement from >=1.43.27 to >=1.43.31 in /src/slack-bot (#119) 2026-06-17 01:04:12 +00:00
dependabot[bot]
7362d89a0d
Update boto3 requirement from >=1.43.27 to >=1.43.31 in /src/shared (#118) 2026-06-17 01:01:45 +00:00
dependabot[bot]
d836f8fbf0
Update boto3 requirement from >=1.43.27 to >=1.43.31 in /src/roster-sync (#117) 2026-06-17 00:59:53 +00:00
dependabot[bot]
4815e4032b
Update boto3 requirement in /src/ring-scheduler (#116) 2026-06-16 20:56:31 -04:00
dependabot[bot]
3099046527
Bump actions/setup-python from 5 to 6 (#115) 2026-06-16 20:52:56 -04:00
Adam Moussa
1e1e5176a3
Fix payroll summary email (SES config-set permission) + isolate failures (#114)
Some checks failed
Deploy / deploy (push) Has been cancelled
Deploy / release (push) Has been cancelled
* Fix payroll email: grant SES config-set permission + isolate failures

The weekly pay-summary email to payroll has been failing with SES
AccessDenied since 2026-06-08. The sending identity (seahaven.com) gained
a default configuration set (seahaven-email-events), and SES authorizes
SendEmail against the config-set ARN as well as the identity — but the
WeeklyPostFunction role only granted ses:SendEmail on identity/*.

- template.yaml: add the configuration-set ARN (scoped to the known set
  name) to the SES policy so sends are authorized again.
- weekly-post/app.py: wrap _send_pay_email in try/except so a delivery
  failure can never abort the handler before the Slack schedule post.
  Previously the SES error also blocked the two-week schedule post.
- Add a regression test covering the isolation.

Cross-family GPT-4.1 IAM review: APPROVE.

* Bump to v1.10.1 in CHANGELOG and sync App Home copy
2026-06-15 13:24:32 -04:00
Adam Moussa
8e90d41b6c
Point release-notify invoke role trust at deploy.yaml (#113)
Some checks failed
Deploy / deploy (push) Has been cancelled
Deploy / release (push) Has been cancelled
The release job moved from release.yaml into deploy.yaml to clear
CodeQL's workflow_run findings, but the OIDC invoke role's trust still
pinned job_workflow_ref to release.yaml. That denied the AssumeRole at
the release job's Configure-AWS step, so the v1.10.0 announcement never
fired. Point the condition at deploy.yaml (the inline release job's
top-level workflow) so the token's job_workflow_ref matches.
2026-06-12 11:42:55 -04:00
Adam Moussa
53c85f7eed
Add changelog-driven releases and App Home tab (#112)
Some checks are pending
Deploy / deploy (push) Waiting to run
Deploy / release (push) Blocked by required conditions
* Add changelog-driven releases and App Home tab

Version the bot continuously from CHANGELOG.md (the single source of
truth for both the version and the staff-readable notes) and surface
changes to users in two ways:

- A new afterhours-release-notifier Lambda posts a "What's New" message
  to the shift channel on minor/major releases (patches stay silent).
- The bot gains an App Home "About" tab showing what it does, the
  command list, and the current version's notes.

release.yaml runs on Deploy success (not release:published — GITHUB_TOKEN
events don't start downstream workflows), checks out the deployed commit,
and tags + publishes a GitHub Release + invokes the notifier. It assumes a
dedicated, boundary-carrying OIDC role scoped to InvokeFunction on the
notifier; the account's cfn role gates role creation on that boundary.
The manual Version Bump workflow is retired. A CI guard enforces that a
CHANGELOG edit is a clean SemVer bump and that the in-package copy matches.

* Harden release workflow and regex against CodeQL findings

Address three code-scanning alerts on the PR:

- Critical (actions/untrusted-checkout): split release.yaml into a
  read-only `prepare` job that checks out and runs repo code, and a
  privileged `publish` job (contents:write + OIDC) that never checks out
  repo code — it tags, releases, and invokes purely through the GitHub
  and AWS APIs. Also assert head_branch == main.
- High x2 (py/polynomial-redos): rewrite the italic and link regexes in
  markdown_to_mrkdwn with possessive quantifiers and exclusive character
  classes so they run in linear time on adversarial input. Adds a
  regression test.

* Move release/announce into Deploy workflow to clear CodeQL

The workflow_run-triggered release.yaml kept tripping CodeQL's
privileged-context rules (untrusted-checkout, then cache-poisoning) —
CodeQL distrusts any workflow_run that checks out a ref, regardless of
the main-only guarantee, and there is no autofix.

Fold the release job into deploy.yaml gated on `needs: deploy`. A
push-to-main run is a trusted context, so checking out and running repo
code with write/OIDC is safe there. This still gates on deploy success
and serializes via the deploy concurrency group, and removes the
separate workflow entirely.
2026-06-11 19:41:31 -04:00
dependabot[bot]
1c9ddaeadf
Update boto3 requirement from >=1.43.26 to >=1.43.27 in /src/weekly-post (#111)
Some checks are pending
Deploy / deploy (push) Waiting to run
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.26...1.43.27)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.27
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-11 14:31:13 -04:00
dependabot[bot]
ef4fafb943
Update boto3 requirement from >=1.43.26 to >=1.43.27 in /src/slack-bot (#110)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.26...1.43.27)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.27
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-11 14:31:09 -04:00
dependabot[bot]
c1d76390b0
Update boto3 requirement from >=1.43.26 to >=1.43.27 in /src/shared (#109)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.26...1.43.27)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.27
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-11 14:31:05 -04:00
dependabot[bot]
0c8eb14f55
Update boto3 requirement from >=1.43.26 to >=1.43.27 in /src/roster-sync (#108)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.26...1.43.27)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.27
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-11 14:31:00 -04:00
dependabot[bot]
1a5faa53f8
Update boto3 requirement in /src/ring-scheduler (#107)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.26...1.43.27)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.27
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-11 14:30:56 -04:00
Adam Moussa
2995f6b3ea
Repo hygiene: PR labeler + README badges + dependabot (INFRA-56/57/66) (#106) 2026-06-11 14:13:35 -04:00
dependabot[bot]
b4798c12fe
Update boto3 requirement from >=1.43.22 to >=1.43.26 in /src/weekly-post (#104)
Some checks are pending
Deploy / deploy (push) Waiting to run
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.22...1.43.26)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.26
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-10 18:12:07 -04:00
dependabot[bot]
e007b10e81
Update boto3 requirement from >=1.43.22 to >=1.43.26 in /src/slack-bot (#103)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.22...1.43.26)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.26
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-10 18:12:02 -04:00
dependabot[bot]
43680b7f8f
Update boto3 requirement from >=1.43.22 to >=1.43.26 in /src/shared (#102)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.22...1.43.26)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.26
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-10 18:11:58 -04:00
dependabot[bot]
4b5006da9a
Update boto3 requirement from >=1.43.22 to >=1.43.26 in /src/roster-sync (#101)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.22...1.43.26)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.26
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-10 18:11:54 -04:00
dependabot[bot]
27dfe4bf8e
Update boto3 requirement in /src/ring-scheduler (#100)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.22...1.43.26)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.26
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-10 18:11:49 -04:00
Adam Moussa
424be7c2da
Attach permissions boundary to all Lambda execution roles (#105)
Some checks are pending
Deploy / deploy (push) Waiting to run
Applies seahaven-lambda-execution-boundary to all SAM auto-generated
function execution roles via Globals.Function.PermissionsBoundary.
Required so the github-cfn-execution-role scope-down (INFRA-97) can
safely constrain role creation without blocking Lambda deploys.

No explicit AWS::IAM::Role resources exist in this template.

Refs: INFRA-103
2026-06-10 14:14:46 -04:00
Adam Moussa
efa4bc569d
INFRA-28: add HTTP API access logging and throttling (audit M-18) (#98)
Some checks failed
Deploy / deploy (push) Has been cancelled
Add AccessLogSettings on the implicit HTTP API stage pointing at a new
/aws/apigateway/afterhours-shift-manager log group with 90-day retention,
plus DefaultRouteSettings throttling (100 rps / 50 burst). Mirrors the
M-18 pattern landed on payments-dashboard.
2026-06-05 17:47:41 -04:00
Adam Moussa
9bea3ed4c7
Add dependency-review caller workflow (#97)
Some checks are pending
Deploy / deploy (push) Waiting to run
* Add dependency-review caller workflow

Add a pull_request-triggered caller that invokes the org-level
callable-dependency-review workflow to scan dependency changes and
fail on high-severity advisories.

* chore: retrigger checks

* chore: retrigger dep review (post-fix)
2026-06-05 12:26:41 -04:00
dependabot[bot]
abf9a5cded
Update boto3 requirement from >=1.43.19 to >=1.43.22 in /src/weekly-post (#96)
Some checks failed
Deploy / deploy (push) Has been cancelled
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.19...1.43.22)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.22
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-04 01:00:31 +00:00
dependabot[bot]
fedecbf30c
Update boto3 requirement from >=1.43.19 to >=1.43.22 in /src/slack-bot (#95)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.19...1.43.22)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.22
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-04 01:00:12 +00:00
dependabot[bot]
0aef0c98a3
Update boto3 requirement from >=1.43.19 to >=1.43.22 in /src/shared (#94)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.19...1.43.22)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.22
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-04 00:59:59 +00:00