Commit graph

4 commits

Author SHA1 Message Date
dependabot[bot]
236effa359
chore(deps-dev): bump typescript from 6.0.3 to 7.0.2 (#14)
* chore(deps-dev): bump typescript from 6.0.3 to 7.0.2

Bumps [typescript](https://github.com/microsoft/TypeScript) from 6.0.3 to 7.0.2.
- [Release notes](https://github.com/microsoft/TypeScript/releases)
- [Commits](https://github.com/microsoft/TypeScript/commits)

---
updated-dependencies:
- dependency-name: typescript
  dependency-version: 7.0.2
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore: swap ts-node to tsx to bump with typescript 7.0.2 bump

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Adam Moussa <adam@seahavenind.com>
2026-07-13 12:40:04 -04:00
Adam Moussa
9e4998a375
Document CDK app and cdk.json in README (#12)
The README covered the deployed controls, config inputs, and CI/CD but
never explained that the repo is a CDK app or what cdk.json does. Add a
CDK app section describing the cdk.json entry point, project layout
(bin/app.ts and the lib/ constructs), and the local synth/diff/deploy
workflow so contributors can orient without reading the source.
2026-07-10 16:07:28 -04:00
Adam Moussa
c9dd7e7d5c
docs: add README status badges (INFRA-137) (#9) 2026-07-06 17:34:20 -04:00
Adam Moussa
10555af9e2 Add account-local security baseline for seahaven-external-dev
Stripped fork of seahaven-account-baseline for the isolated external-dev
account (396287094661). Single stack: AWS Config, GuardDuty, Security Hub
(FSBP + CIS v3.0), IAM Access Analyzer, VPC flow logs (VPC ids via context),
and a $200/mo budget alerting adam@seahaven.com.

Drops all org-level / prod-specific controls (local CloudTrail, CIS metric
alarms, WAF, SES, Bedrock, DynamoDB CMK, Backup) per the isolated-account
design; the org trail already covers this account centrally. Inspector2 is a
documented post-deploy CLI step (no CloudFormation enable resource exists).
2026-06-15 11:26:23 -04:00