fix(scripts): ensure temp GCP SA key cleanup via EXIT trap (SEC-28) (#70)

* chore(deps): bump aws-cdk-lib from 2.262.2 to 2.263.0

Bumps [aws-cdk-lib](https://github.com/aws/aws-cdk/tree/HEAD/packages/aws-cdk-lib) from 2.262.2 to 2.263.0.
- [Release notes](https://github.com/aws/aws-cdk/releases)
- [Changelog](https://github.com/aws/aws-cdk/blob/main/CHANGELOG.v2.alpha.md)
- [Commits](https://github.com/aws/aws-cdk/commits/v2.263.0/packages/aws-cdk-lib)

---
updated-dependencies:
- dependency-name: aws-cdk-lib
  dependency-version: 2.263.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore(deps-dev): bump tsx from 4.23.1 to 4.23.5

Bumps [tsx](https://github.com/privatenumber/tsx) from 4.23.1 to 4.23.5.
- [Release notes](https://github.com/privatenumber/tsx/releases)
- [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs)
- [Commits](https://github.com/privatenumber/tsx/compare/v4.23.1...v4.23.5)

---
updated-dependencies:
- dependency-name: tsx
  dependency-version: 4.23.5
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

* fix: add trap to ensure temp key file removal after GCP SA key creation

* fix(scripts): delete temp GCP key before success message

* chore(deps): drop cdk-lib and tsx bumps from this PR

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
This commit is contained in:
Adam Moussa 2026-08-07 10:58:30 -04:00 • committed by GitHub
parent 43d1ff48c0
commit 32786de262
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -102,6 +102,7 @@ echo "Granted objectViewer to $SA_EMAIL."
echo "" echo ""
echo "--- Step 9: Create and store service account key ---" echo "--- Step 9: Create and store service account key ---"
KEY_FILE=$(mktemp) KEY_FILE=$(mktemp)
trap 'rm -f "$KEY_FILE"' EXIT
$GCLOUD iam service-accounts keys create "$KEY_FILE" --iam-account="$SA_EMAIL" $GCLOUD iam service-accounts keys create "$KEY_FILE" --iam-account="$SA_EMAIL"
echo "Service account key created." echo "Service account key created."