The Lambdas in this stack run on the nodejs22.x runtime, but @types/node
had drifted to ^25 via Dependabot. A too-new types major still compiles,
so the mismatch passed CI while describing APIs absent at runtime.
Repin to ^22 to match the Lambda runtime and add a scoped Dependabot
ignore for @types/node semver-major bumps so the alignment can only be
broken deliberately, alongside a runtime upgrade. Minor/patch within the
major still flow. Sanctioned exception to the no-blanket-ignore rule
(engineering-handbook github-standards Pinning Principle).
Per handbook Pinning Principle: exact pins are kept current by Dependabot version updates gated by CI + dependency review. Blanket ignores let pins rot (see today's fast-uri incident).
* Add dependency-review caller workflow
Add a pull_request-triggered caller that invokes the org-level
callable-dependency-review workflow to scan dependency changes and
fail on high-severity advisories.
* chore: retrigger checks
* chore: retrigger dep review (post-fix)
* chore: add .env to .gitignore
* Add CI workflow
* Fix TypeScript compilation for CI
Add types: ["node"] to tsconfig so tsc resolves Node.js globals
(console, process, __dirname). Add @aws-sdk/client-ssm and
source-map-support as devDependencies for type resolution.