Commit graph

5 commits

Author SHA1 Message Date
Adam Moussa
896bfc7501
Merge pull request #28: docs: align engineering conventions for Cursor migration (PLAT-62)
Some checks are pending
ci / ci / ci (push) Waiting to run
docs: align engineering conventions for Cursor migration (PLAT-62)
2026-08-03 18:01:08 -04:00
fc0e9bdc93
docs(cdk-layout): pin example workflow refs, drop hardcoded account
The CI/CD examples referenced the central reusable workflows at @main,
which contradicts the SHA-pin mandate the CI/CD page states and would be
copied into new repos as a mutable ref. Replace both with the
@<full-commit-sha>  # main placeholder and point at the pinning section.

The bin/app.ts example also hardcoded a specific account ID. Make the
env region-only so the account comes from the deploy credentials and the
synthesized template stays account-agnostic.
2026-07-28 19:42:47 -04:00
Adam Moussa
1c11824196
docs: replace frozen 'blessed version' with automated pin-currency policy (#11)
Exact pins remain (reproducibility) but the pinned version is kept
current by Dependabot version updates gated by CI + dependency review,
not by a number frozen in the handbook. Blanket dependabot ignore
entries are banned; version-specific ignores only, commented and
temporary. Bundled-dep vulnerabilities are a prompt to advance the
pin, never to dismiss the alert.
2026-06-05 12:57:35 -04:00
Adam Moussa
bcb4355c36
docs: move blessed aws-cdk-lib pin to 2.257.0 (#10)
2.253.1 bundles fast-uri 3.1.0 (two high-severity GHSAs, unfixable via
overrides since it ships in the tarball). 2.257.0 bundles patched
fast-uri 3.1.2 and passes npm ci (the 2.254.0 breakage that motivated
the old pin was release-specific).
2026-06-05 12:52:50 -04:00
Adam Moussa
e057e8ab84 Add CDK layout and code review rubric to handbook index
Both pages existed in working drafts but were not linked from the
README table of contents, so they were undiscoverable. Add them to the
index alongside the related SAM layout and code review pages.
2026-06-02 19:36:09 -04:00