Commit graph

7 commits

Author SHA1 Message Date
Adam Moussa
2bd78abd9b
Repo hygiene: PR labeler + README badges (INFRA-56/57) (#8)
Some checks failed
Deploy / deploy (push) Has been cancelled
2026-06-11 14:13:40 -04:00
dependabot[bot]
c18e64e396
build(deps): bump boto3 in /src/user_sync in the minor-and-patch group (#6)
Some checks are pending
Deploy / deploy (push) Waiting to run
Bumps the minor-and-patch group in /src/user_sync with 1 update: [boto3](https://github.com/boto/boto3).


Updates `boto3` from 1.43.23 to 1.43.25
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.23...1.43.25)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.25
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-10 18:11:31 -04:00
dependabot[bot]
27700580c8
build(deps): bump boto3 in /src/sla_monitor in the minor-and-patch group (#5)
Bumps the minor-and-patch group in /src/sla_monitor with 1 update: [boto3](https://github.com/boto/boto3).


Updates `boto3` from 1.43.23 to 1.43.25
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.23...1.43.25)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.25
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-10 18:11:26 -04:00
Adam Moussa
e50c8f0876
Attach permissions boundary to all Lambda roles (#7)
Some checks are pending
Deploy / deploy (push) Waiting to run
Adds the seahaven-lambda-execution-boundary policy as a
PermissionsBoundary on all auto-generated Lambda execution
roles via Globals.Function, enabling the cfn-execution-role
scope-down from INFRA-97 to safely allow iam:CreateRole.

No explicit AWS::IAM::Role resources exist in this stack;
the Globals entry covers both SlaMonitorFunction and
UserSyncFunction.

Refs: INFRA-103
2026-06-10 14:14:58 -04:00
Adam Moussa
6b689851d2
fix(deps): pin Python requirements (#2)
Some checks failed
Deploy / deploy (push) Has been cancelled
Pin previously unpinned dependencies to exact versions across the
sla_monitor and user_sync functions for reproducible builds.
2026-06-05 14:13:56 -04:00
Adam Moussa
b7c65cedfb
Add dependency-review caller workflow (#3)
Some checks are pending
Deploy / deploy (push) Waiting to run
* Add dependency-review caller workflow

Add a pull_request-triggered caller that invokes the org-level
callable-dependency-review workflow to scan dependency changes and
fail on high-severity advisories.

* chore: retrigger checks

* chore: retrigger dep review (post-fix)

* style: ruff format src
2026-06-05 12:34:16 -04:00
Adam Moussa
899f07d09c Add unified Front integrations SAM stack
Consolidates front-sla-monitor (Python SAM) and google-user-sync
(JavaScript CDK) into a single Python SAM repo with two Lambdas:
front-sla-monitor and front-user-sync.
2026-05-12 11:24:41 -04:00