Commit graph

4 commits

Author SHA1 Message Date
Adam Moussa
517f41eb7f
ci: add org PR policy caller (#74)
Some checks failed
Deploy / deploy-management (push) Has been cancelled
Deploy / deploy-external-dev (push) Has been cancelled
Deploy / deploy-security (push) Has been cancelled
Deploy / deploy-dev (push) Has been cancelled
Deploy / deploy-prod (push) Has been cancelled
Refs: PLAT-62
2026-08-04 11:56:30 -04:00
Adam Moussa
749e5ce4e9
Ignore @types/node major bumps in Dependabot (#31)
Some checks are pending
Deploy / deploy (push) Waiting to run
This pure CDK app is built and synthed on Node 24 (no Lambdas), so
@types/node is pinned to ^24. A too-new types major still compiles, so a
major bump passes CI while describing APIs absent at the build Node.

Add a scoped Dependabot ignore for @types/node semver-major bumps so the
alignment can only be broken deliberately, alongside a Node upgrade.
Minor/patch within the major still flow. Sanctioned exception to the
no-blanket-ignore rule (engineering-handbook github-standards Pinning
Principle).
2026-06-24 15:01:32 -04:00
Adam Moussa
a9d9f12a40
fix(deps): bump aws-cdk-lib pin to 2.257.0 (#15)
Some checks are pending
Deploy / deploy (push) Waiting to run
2026-06-05 13:01:36 -04:00
Adam Moussa
dc079edb93 Initial account-baseline stack with CloudTrail (audit C-1)
Multi-region CloudTrail with log-file validation, a rotating KMS CMK, an
Object-Lock'd S3 log bucket, and CloudWatch Logs delivery. First resident of
the account-level security baseline; AWS Backup / 3-2-1 (C-7) lands alongside.

IAM/KMS/S3 policies cross-reviewed; review caught a missing CloudTrail KMS
grant, now added (SourceArn + encryption-context scoped).
2026-05-29 17:44:55 -04:00