From 6041abbd23a9e34c0313720075c021b99d1ce1db Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 17 Jul 2026 18:42:15 -0400 Subject: [PATCH 1/2] build(deps): bump the minor-and-patch group with 3 updates (#55) Bumps the minor-and-patch group with 3 updates: [constructs](https://github.com/aws/constructs), [aws-cdk](https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk) and [tsx](https://github.com/privatenumber/tsx). Updates `constructs` from 10.6.0 to 10.7.0 - [Release notes](https://github.com/aws/constructs/releases) - [Commits](https://github.com/aws/constructs/compare/v10.6.0...v10.7.0) Updates `aws-cdk` from 2.1130.0 to 2.1132.0 - [Release notes](https://github.com/aws/aws-cdk-cli/releases) - [Commits](https://github.com/aws/aws-cdk-cli/commits/aws-cdk@v2.1132.0/packages/aws-cdk) Updates `tsx` from 4.23.0 to 4.23.1 - [Release notes](https://github.com/privatenumber/tsx/releases) - [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs) - [Commits](https://github.com/privatenumber/tsx/compare/v4.23.0...v4.23.1) --- updated-dependencies: - dependency-name: constructs dependency-version: 10.7.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: aws-cdk dependency-version: 2.1132.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: tsx dependency-version: 4.23.1 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: minor-and-patch ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- package-lock.json | 24 ++++++++++++------------ package.json | 6 +++--- 2 files changed, 15 insertions(+), 15 deletions(-) diff --git a/package-lock.json b/package-lock.json index 9493f42..a969fe0 100644 --- a/package-lock.json +++ b/package-lock.json @@ -9,7 +9,7 @@ "version": "1.0.0", "dependencies": { "aws-cdk-lib": "2.261.0", - "constructs": "^10.0.0" + "constructs": "^10.7.0" }, "bin": { "app": "bin/app.js" @@ -17,9 +17,9 @@ "devDependencies": { "@types/node": "^24.13.3", "@types/source-map-support": "^0.5.10", - "aws-cdk": "^2.1130.0", + "aws-cdk": "^2.1132.0", "source-map-support": "^0.5.21", - "tsx": "4.23.0", + "tsx": "4.23.1", "typescript": "~7.0.2" } }, @@ -874,9 +874,9 @@ } }, "node_modules/aws-cdk": { - "version": "2.1130.0", - "resolved": "https://registry.npmjs.org/aws-cdk/-/aws-cdk-2.1130.0.tgz", - "integrity": "sha512-LgSKHFTGhoT/lML48uiYIpdSHCwZLvUx/uZu5MqcZjh+OwWzM8nCxXY+OjKG3yASlx5JxeulXm4sRaUYo48qFQ==", + "version": "2.1132.0", + "resolved": "https://registry.npmjs.org/aws-cdk/-/aws-cdk-2.1132.0.tgz", + "integrity": "sha512-kcIzBZQO+2v+F97iaeI29fdOUQEx44wr0qDb9HXNqdU82V+1ZKI1KuFlHwH2nq7+6iNc1bu60se4hFf+2d7vXg==", "dev": true, "license": "Apache-2.0", "bin": { @@ -1095,9 +1095,9 @@ "license": "MIT" }, "node_modules/constructs": { - "version": "10.6.0", - "resolved": "https://registry.npmjs.org/constructs/-/constructs-10.6.0.tgz", - "integrity": "sha512-TxHOnBO5zMo/G76ykzGF/wMpEHu257TbWiIxP9K0Yv/+t70UzgBQiTqjkAsWOPC6jW91DzJI0+ehQV6xDRNBuQ==", + "version": "10.7.0", + "resolved": "https://registry.npmjs.org/constructs/-/constructs-10.7.0.tgz", + "integrity": "sha512-Vzwc30bMywc7DCzX8XOyuZbsBmfXTCrn6HHmhhELZK1J5dnUWwJ5uL7hBXGGq7xFPVOOO6cs9FwaxOshAxgcWQ==", "license": "Apache-2.0" }, "node_modules/esbuild": { @@ -1179,9 +1179,9 @@ } }, "node_modules/tsx": { - "version": "4.23.0", - "resolved": "https://registry.npmjs.org/tsx/-/tsx-4.23.0.tgz", - "integrity": "sha512-eUdUIaCr963q2h5u3+QwvYp0+eqPvn+egeqZUm0hwERCqqx1E3kK5ehbGCvqSE5MQAULr67ww0cA3jKc3YkM1w==", + "version": "4.23.1", + "resolved": "https://registry.npmjs.org/tsx/-/tsx-4.23.1.tgz", + "integrity": "sha512-GQHnkIfxyx1wYCOS/wonik5MVRZU9hi1TEZmzGZSCJB1y9YgoZ8H6itNE/u4suE+yLmOzuE4E5S4TZ/ZX2wcWQ==", "dev": true, "license": "MIT", "dependencies": { diff --git a/package.json b/package.json index 7ec5b7e..e4b2f29 100644 --- a/package.json +++ b/package.json @@ -14,13 +14,13 @@ "devDependencies": { "@types/node": "^24.13.3", "@types/source-map-support": "^0.5.10", - "aws-cdk": "^2.1130.0", + "aws-cdk": "^2.1132.0", "source-map-support": "^0.5.21", - "tsx": "4.23.0", + "tsx": "4.23.1", "typescript": "~7.0.2" }, "dependencies": { "aws-cdk-lib": "2.261.0", - "constructs": "^10.0.0" + "constructs": "^10.7.0" } } From cc54b1e28b3f21ed276f5b2cc2aa8e69b3f4eb4e Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Thu, 23 Jul 2026 13:38:17 -0400 Subject: [PATCH 2/2] chore(security): add explicit workflow permissions and bump aws-cdk-lib to 2.262.0 (#56) * docs: update aws profile specified in script (local renaming) * ci: add least-privilege permissions blocks to workflow callers Resolves code scanning alerts #3 and #4 (actions/missing-workflow-permissions). Both callable workflows only need contents: read; the dependency-review callable already declares it internally, this caps the caller token to match." * chore(deps): bump aws-cdk-lib to 2.262.0 for patched brace-expansion Resolves Dependabot alert #4 (CVE-2026-13149, exponential-time DoS in brace-expansion expand()). The vulnerable 5.0.6 is a bundled dependency inside the aws-cdk-lib tarball, so it cannot be updated independently; 2.262.0 bundles the patched 5.0.7. Also migrates Stack#addDependency to addStackDependency (deprecated in this release) in bin/app.ts. --- .github/workflows/ci.yaml | 3 ++ .github/workflows/dependency-review.yml | 4 ++ bin/app.ts | 2 +- lib/backup-stack.ts | 2 +- package-lock.json | 53 +++++++++++++++---------- package.json | 2 +- scripts/iam-user-delete.sh | 2 +- 7 files changed, 43 insertions(+), 25 deletions(-) diff --git a/.github/workflows/ci.yaml b/.github/workflows/ci.yaml index 4841ebe..42403b4 100644 --- a/.github/workflows/ci.yaml +++ b/.github/workflows/ci.yaml @@ -3,6 +3,9 @@ on: pull_request: branches: [main] +permissions: + contents: read + jobs: ci: uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main diff --git a/.github/workflows/dependency-review.yml b/.github/workflows/dependency-review.yml index 2cd8119..42002bb 100644 --- a/.github/workflows/dependency-review.yml +++ b/.github/workflows/dependency-review.yml @@ -1,6 +1,10 @@ name: Dependency Review on: pull_request: + +permissions: + contents: read + jobs: review: uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main diff --git a/bin/app.ts b/bin/app.ts index 945180a..b24f3c6 100644 --- a/bin/app.ts +++ b/bin/app.ts @@ -201,4 +201,4 @@ const backupPrimary = new BackupStack(app, "backup", { env: { account: "328440206208", region: "us-east-1" }, }); -backupPrimary.addDependency(backupOffsite); +backupPrimary.addStackDependency(backupOffsite); diff --git a/lib/backup-stack.ts b/lib/backup-stack.ts index a18f28b..763f322 100644 --- a/lib/backup-stack.ts +++ b/lib/backup-stack.ts @@ -163,7 +163,7 @@ export class BackupStack extends cdk.Stack { // Cross-region copy destination, referenced by literal ARN (the offsite // stack is in another region; a literal ARN avoids crossRegionReferences / - // SSM exports). Stack ordering is enforced via addDependency in bin/app.ts. + // SSM exports). Stack ordering is enforced via addStackDependency in bin/app.ts. const offsiteVault = backup.BackupVault.fromBackupVaultArn( this, "OffsiteVaultRef", diff --git a/package-lock.json b/package-lock.json index a969fe0..96494f8 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1,14 +1,14 @@ { - "name": "seahaven-account-baseline", + "name": "seahaven-org-baseline", "version": "1.0.0", "lockfileVersion": 3, "requires": true, "packages": { "": { - "name": "seahaven-account-baseline", + "name": "seahaven-org-baseline", "version": "1.0.0", "dependencies": { - "aws-cdk-lib": "2.261.0", + "aws-cdk-lib": "2.262.0", "constructs": "^10.7.0" }, "bin": { @@ -36,9 +36,9 @@ "license": "Apache-2.0" }, "node_modules/@aws-cdk/cloud-assembly-schema": { - "version": "54.2.0", - "resolved": "https://registry.npmjs.org/@aws-cdk/cloud-assembly-schema/-/cloud-assembly-schema-54.2.0.tgz", - "integrity": "sha512-u3lFXmiXSBozxGBmKTCVD/2mTDsaXzLZH3KYiIQKcB+zPldXOeE5TnooBgKV9ih2jVTo8ML0HpkhfAq2eiv0eQ==", + "version": "54.13.0", + "resolved": "https://registry.npmjs.org/@aws-cdk/cloud-assembly-schema/-/cloud-assembly-schema-54.13.0.tgz", + "integrity": "sha512-C6LS1YxugR7j6BPVjhVsWRu/VNN8eoGDOf7dHafPviz6Y5Nv/FjVIGIPoC6jJmgJcea7VOM9TPHbBEwapCUySg==", "bundleDependencies": [ "jsonschema", "semver" @@ -46,7 +46,7 @@ "license": "Apache-2.0", "dependencies": { "jsonschema": "^1.5.0", - "semver": "^7.8.1" + "semver": "^7.8.5" }, "engines": { "node": ">= 18.0.0" @@ -61,7 +61,7 @@ } }, "node_modules/@aws-cdk/cloud-assembly-schema/node_modules/semver": { - "version": "7.8.1", + "version": "7.8.5", "inBundle": true, "license": "ISC", "bin": { @@ -887,10 +887,11 @@ } }, "node_modules/aws-cdk-lib": { - "version": "2.261.0", - "resolved": "https://registry.npmjs.org/aws-cdk-lib/-/aws-cdk-lib-2.261.0.tgz", - "integrity": "sha512-e52e3Abjg0HkuRWlWwtSv5+ZiMW1rhCDdL9ff7lzWXInU8xdfLJpuoimfa0IJwjiNGyphppgg52Azx9M80OA0g==", + "version": "2.262.0", + "resolved": "https://registry.npmjs.org/aws-cdk-lib/-/aws-cdk-lib-2.262.0.tgz", + "integrity": "sha512-6zRVoWRd8kQs9ZZ9xhERSm36W8uWS2vW3/g9Zx0xlhvRRiUwTc80bzfJkohKGdT/5AOW+wy6fSDvohavG94pcA==", "bundleDependencies": [ + "@aws/cloudformation-validate", "@balena/dockerignore", "@aws-cdk/cloud-assembly-api", "case", @@ -907,17 +908,18 @@ "dependencies": { "@aws-cdk/asset-awscli-v1": "2.2.282", "@aws-cdk/asset-node-proxy-agent-v6": "^2.1.2", - "@aws-cdk/cloud-assembly-api": "^2.2.5", - "@aws-cdk/cloud-assembly-schema": "^54.0.0", + "@aws-cdk/cloud-assembly-api": "^2.2.6", + "@aws-cdk/cloud-assembly-schema": "^54.11.0", + "@aws/cloudformation-validate": "1.5.0-beta", "@balena/dockerignore": "^1.0.2", "case": "1.6.3", - "fs-extra": "^11.3.5", + "fs-extra": "^11.3.6", "ignore": "^5.3.2", "jsonschema": "^1.5.0", "mime-types": "^2.1.35", "minimatch": "^10.2.5", "punycode": "^2.3.1", - "semver": "^7.8.1", + "semver": "^7.8.5", "yaml": "1.10.3" }, "engines": { @@ -928,18 +930,27 @@ } }, "node_modules/aws-cdk-lib/node_modules/@aws-cdk/cloud-assembly-api": { - "version": "2.2.5", + "version": "2.2.6", "inBundle": true, "license": "Apache-2.0", "dependencies": { "jsonschema": "^1.5.0", - "semver": "^7.8.0" + "semver": "^7.8.4" }, "engines": { "node": ">= 18.0.0" }, "peerDependencies": { - "@aws-cdk/cloud-assembly-schema": ">=53.28.0" + "@aws-cdk/cloud-assembly-schema": ">=54.5.0" + } + }, + "node_modules/aws-cdk-lib/node_modules/@aws/cloudformation-validate": { + "version": "1.5.0-beta", + "inBundle": true, + "license": "Apache-2.0", + "engines": { + "node": "^22.15.0", + "npm": ">=10.5.0" } }, "node_modules/aws-cdk-lib/node_modules/@balena/dockerignore": { @@ -956,7 +967,7 @@ } }, "node_modules/aws-cdk-lib/node_modules/brace-expansion": { - "version": "5.0.6", + "version": "5.0.7", "inBundle": true, "license": "MIT", "dependencies": { @@ -975,7 +986,7 @@ } }, "node_modules/aws-cdk-lib/node_modules/fs-extra": { - "version": "11.3.5", + "version": "11.3.6", "inBundle": true, "license": "MIT", "dependencies": { @@ -1061,7 +1072,7 @@ } }, "node_modules/aws-cdk-lib/node_modules/semver": { - "version": "7.8.1", + "version": "7.8.5", "inBundle": true, "license": "ISC", "bin": { diff --git a/package.json b/package.json index e4b2f29..72bfc25 100644 --- a/package.json +++ b/package.json @@ -20,7 +20,7 @@ "typescript": "~7.0.2" }, "dependencies": { - "aws-cdk-lib": "2.261.0", + "aws-cdk-lib": "2.262.0", "constructs": "^10.7.0" } } diff --git a/scripts/iam-user-delete.sh b/scripts/iam-user-delete.sh index dbd80a2..fa9bfed 100755 --- a/scripts/iam-user-delete.sh +++ b/scripts/iam-user-delete.sh @@ -13,7 +13,7 @@ # scripts/iam-user-delete.sh [--profile NAME] [--yes] USER [USER ...] # # --profile NAME AWS CLI profile (default: $AWS_PROFILE or the default chain). -# Post-SSO-cutover this is normally `amoussa-seahaven`. +# Post-SSO-cutover this is normally `seahaven-mgmt`. # --yes Skip the per-user confirmation prompt. # # Safety: