* ci: aggregate test and Terraform as ci-complete
Converted callers emit that check so this repo can leave the ci / ci ruleset.
* ci: add Prettier format and format:check
The autofix prettier preset runs npm run format, and CI fails closed when the tree is unformatted.
* refactor(iam): forget in-repo HCP exec roles
Org-baseline owns the apply and plan roles, so this workspace can assume them without a bootstrap window. Prod state forgets the old addresses without destroying the live roles.
* ci(terraform): pin the isolation check to v1.0.21
The pre-release pin cloned the private .github repo with the caller token and the Terraform job failed. v1.0.21 loads the checker from the workflow commit.
* feat(infra): migrate payments-dashboard to HCP Terraform (PLAT-79)
Replace the mgmt SAM stack with a prod-only HCP workspace using the afterhours stub-plus-zip-CD seam so GitHub Actions owns function code and Terraform owns infrastructure.
* fix(infra): pin secret and CMK ARNs for bootstrap-plan
hcptf-bootstrap-plan cannot ssm:GetParameter or DescribeSecret, so the first plan must not data-source those values.
* fix(infra): add EIP describe and DynamoDB CMK grants for first apply
Scoped apply missed ec2:DescribeAddressesAttribute and kms Encrypt/Decrypt/GenerateDataKey on the table CMK.
The four refs pointed at fd60e4c9 with a '# main' comment. That comment
names a branch, so Dependabot rendered its bump PR titles as two full
40-character SHAs. Sea-Haven-Industries/.github now publishes tags.
Repoints all four at 2fbfb2e (v1.0.0) and replaces the comment with the
version. Deliberately v1.0.0 rather than the current v1.0.2, so a
Dependabot run has a newer version to find.
* ci: add least-privilege permissions blocks to workflow callers
Resolves code scanning alerts #4 and #5 (actions/missing-workflow-permissions). Both callable workflows only need contents: read; the dependency-review callable already declares it internally, this caps the caller token to match.
* enhance(email): improve detection of allowed Gusto URLs in email classification
Resolves code scanning alert #2