* ci: add least-privilege permissions blocks to workflow callers
Resolves code scanning alerts #3 and #4 (actions/missing-workflow-permissions). Both callable workflows only need contents: read; the dependency-review callable already declares it internally, this caps the caller token to match.
Signed-off-by: Adam Moussa <adam@seahavenind.com>
* build(deps): bump aws-cdk-lib to 2.262.0 to patch brace-expansion
aws-cdk-lib 2.261.0 bundles brace-expansion 5.0.6, which is vulnerable to CVE-2026-13149 (GHSA-3jxr-9vmj-r5cp), an exponential-time DoS in expand(). This was the only path pulling the vulnerable package into the tree. 2.262.0 vendors the patched 5.0.7, resolving Dependabot alert 7.
Because brace-expansion arrives bundled inside the aws-cdk-lib tarball rather than resolved by npm, the aws-cdk-lib bump is the only way to move it.
Signed-off-by: Adam Moussa <adam@seahavenind.com>
* refactor(cdk): drop unreferenced ssm value parameters
fromStringParameterName injects an AWS::SSM::Parameter::Value
CloudFormation parameter to carry the parameter's value, but DoorId
and PhoneIps are only used for grantRead, which builds the ARN from
the name string — so DoorIdParameter and PhoneIpsParameter sat
unreferenced in the template (flagged W2001 by the CloudFormation
validator newly bundled in aws-cdk-lib 2.262.0).
Switching to fromStringParameterAttributes with forceDynamicReference
resolves the value lazily via an SSM dynamic reference, emitting
nothing when unused. Verified the synthesized template is identical
apart from the removed Parameters entries and the CDKMetadata
analytics hash — no IAM or resource changes.
Also re-points the four line-keyed semgrep detect-child-process
suppressions (adjudicated FPs, INFRA-105) to the shifted line
numbers; the findings themselves are unchanged.
Signed-off-by: Adam Moussa <adam@seahavenind.com>
---------
Signed-off-by: Adam Moussa <adam@seahavenind.com>
The Lambdas in this stack run on the nodejs22.x runtime, but @types/node
had drifted to ^25 via Dependabot. A too-new types major still compiles,
so the mismatch passed CI while describing APIs absent at runtime.
Repin to ^22 to match the Lambda runtime and add a scoped Dependabot
ignore for @types/node semver-major bumps so the alignment can only be
broken deliberately, alongside a runtime upgrade. Minor/patch within the
major still flow. Sanctioned exception to the no-blanket-ignore rule
(engineering-handbook github-standards Pinning Principle).
Per handbook Pinning Principle: exact pins are kept current by Dependabot version updates gated by CI + dependency review. Blanket ignores let pins rot (see today's fast-uri incident).
* Add dependency-review caller workflow
Add a pull_request-triggered caller that invokes the org-level
callable-dependency-review workflow to scan dependency changes and
fail on high-severity advisories.
* chore: retrigger checks
* chore: retrigger dep review (post-fix)
* chore: add .env to .gitignore
* Add CI workflow
* Fix TypeScript compilation for CI
Add types: ["node"] to tsconfig so tsc resolves Node.js globals
(console, process, __dirname). Add @aws-sdk/client-ssm and
source-map-support as devDependencies for type resolution.