Merge branch 'main' into chore/resolve-open-security-alerts

This commit is contained in:
Adam Moussa 2026-07-23 15:06:55 -04:00 • committed by GitHub
commit 6dc17bc4a6
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -89,11 +89,10 @@ The export reaches S3 by **direct upload or a local drop-folder**, never SES/ema
## Repo-specific rules
- **kebab-case** everything (repo, stack, bucket, Lambda, role). Buckets `apm-wo-analysis-*-328440206208`.
- **Secrets → Secrets Manager** (`apm-wo-analysis/anthropic-api-key`); operational config → SSM.
- **Mandatory cross-review** (`cross_reviewer`, GPT-4.1) on any IAM/policy change or Lambda handler-signature change before merge — run via `python3 ~/Documents/repositories/seahaven/security-review/cross_review.py "<task>"` (orchestrator archived 2026-07-14; cross_reviewer now lives in the `security-review` repo). Flag as outstanding if `cross_review.py` is unavailable.
- Global Sea Haven rules and the engineering handbook apply (naming, secrets placement, cross-review gates, README/Confluence updates, ruff before push).
- Buckets: `apm-wo-analysis-*-328440206208`. Anthropic API key secret: `apm-wo-analysis/anthropic-api-key`.
- Smoke-test the classifier against a **real export** before declaring any classification change done (see the pre-action-smoke-test preference).
- README + the Confluence "AWS Architecture Map" (page 1540098) updated **in the same work** as any architecture change. Update the `apm-wo-comment-analysis` project memory on status/resource changes.
- Confluence page for architecture changes: "AWS Architecture Map" (page 1540098). Project memory: `apm-wo-comment-analysis`.
---
@ -104,12 +103,12 @@ Repo-specific subagents live in `.claude/agents/`:
- **slack-blockkit-designer** — owns the daily post / alert / modal Block Kit.
- **grafana-author** — owns the dashboards-as-code JSON and Athena SQL.
Most build work (CDK, Lambda code, git, deploys) stays native. Delegate the IAM/handler review to `cross_reviewer` (orchestrator since archived; use `cross_review.py` in `security-review`); use the `sh-*` skills at provisioning, review, and documentation boundaries.
Most build work (CDK, Lambda code, git, deploys) stays native. For the IAM/handler review, run `cross_review.py` (`~/Documents/repositories/seahaven/security-review/`); use the `sh-*` skills at provisioning, review, and documentation boundaries.
---
## Local dev
- pyenv Python 3.12; `ruff check` + `ruff format --check` before pushing (hook-enforced).
- pyenv Python 3.12.
- Sample export for smoke-tests: `~/Downloads/_documents/Sheet1-1.xlsx` (raw single-sheet, HTML-wrapped comments).
- `cdk synth` must pass in CI before merge; no manual prod deploys.