Commit graph

14 commits

Author SHA1 Message Date
5d60d01e54
Archive: absorbed into seahaven-org-baseline
Stack and deploy role live on, managed from the merged repo. Repo is
archived read-only.
2026-07-14 13:58:47 -04:00
dependabot[bot]
e510a8777d
chore(deps-dev): bump the minor-and-patch group with 2 updates (#13)
---
updated-dependencies:
- dependency-name: "@types/node"
  dependency-version: 24.13.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: aws-cdk
  dependency-version: 2.1130.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Adam Moussa <166072409+amoussa1229@users.noreply.github.com>
2026-07-13 12:41:02 -04:00
dependabot[bot]
236effa359
chore(deps-dev): bump typescript from 6.0.3 to 7.0.2 (#14)
* chore(deps-dev): bump typescript from 6.0.3 to 7.0.2

Bumps [typescript](https://github.com/microsoft/TypeScript) from 6.0.3 to 7.0.2.
- [Release notes](https://github.com/microsoft/TypeScript/releases)
- [Commits](https://github.com/microsoft/TypeScript/commits)

---
updated-dependencies:
- dependency-name: typescript
  dependency-version: 7.0.2
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore: swap ts-node to tsx to bump with typescript 7.0.2 bump

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Adam Moussa <adam@seahavenind.com>
2026-07-13 12:40:04 -04:00
Adam Moussa
9e4998a375
Document CDK app and cdk.json in README (#12)
The README covered the deployed controls, config inputs, and CI/CD but
never explained that the repo is a CDK app or what cdk.json does. Add a
CDK app section describing the cdk.json entry point, project layout
(bin/app.ts and the lib/ constructs), and the local synth/diff/deploy
workflow so contributors can orient without reading the source.
2026-07-10 16:07:28 -04:00
Adam Moussa
ab84ec462d
INFRA-136: add standard labeler caller (#11)
* ci: add standard labeler caller (INFRA-136)

Adds the org standard callable-labeler thin caller, missing on this repo
(present on 26/28 repos; another symptom of the skipped provisioning
checklist). All three permission grants are load-bearing; omitting one
causes a silent startup_failure.

* Update .github/workflows/labeler.yaml

Co-authored-by: seahaven-openswe[bot] <296972425+seahaven-openswe[bot]@users.noreply.github.com>

---------

Co-authored-by: seahaven-openswe[bot] <296972425+seahaven-openswe[bot]@users.noreply.github.com>
2026-07-08 16:36:40 -04:00
Adam Moussa
cd6aa3b383
chore(ci): SHA-pin org reusable-workflow caller refs (INFRA-50) (#10) 2026-07-06 18:27:03 -04:00
Adam Moussa
3e6dffc2a5
chore(ci): add org dependency-review caller (INFRA-125) (#8) 2026-07-06 17:40:53 -04:00
Adam Moussa
c9dd7e7d5c
docs: add README status badges (INFRA-137) (#9) 2026-07-06 17:34:20 -04:00
dependabot[bot]
96b3ca7397
Bump the minor-and-patch group with 2 updates (#7) 2026-07-06 08:09:32 -04:00
dependabot[bot]
81c6ae3a23
Bump aws-cdk from 2.1128.0 to 2.1128.1 in the minor-and-patch group (#6)
Bumps the minor-and-patch group with 1 update: [aws-cdk](https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk).


Updates `aws-cdk` from 2.1128.0 to 2.1128.1
- [Release notes](https://github.com/aws/aws-cdk-cli/releases)
- [Commits](https://github.com/aws/aws-cdk-cli/commits/aws-cdk@v2.1128.1/packages/aws-cdk)

---
updated-dependencies:
- dependency-name: aws-cdk
  dependency-version: 2.1128.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-24 15:54:45 -04:00
Adam Moussa
21b030da77
Ignore @types/node major bumps in Dependabot (#5)
This pure CDK app is built and synthed on Node 24 (no Lambdas), so
@types/node is pinned to ^24. A too-new types major still compiles, so a
major bump passes CI while describing APIs absent at the build Node.

Add a scoped Dependabot ignore for @types/node semver-major bumps so the
alignment can only be broken deliberately, alongside a Node upgrade.
Minor/patch within the major still flow. Sanctioned exception to the
no-blanket-ignore rule (engineering-handbook github-standards Pinning
Principle).
2026-06-24 15:01:23 -04:00
dependabot[bot]
cb3d1ccb94
Bump the minor-and-patch group with 2 updates (#3)
Bumps the minor-and-patch group with 2 updates: [aws-cdk-lib](https://github.com/aws/aws-cdk/tree/HEAD/packages/aws-cdk-lib) and [aws-cdk](https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk).


Updates `aws-cdk-lib` from 2.259.0 to 2.260.0
- [Release notes](https://github.com/aws/aws-cdk/releases)
- [Changelog](https://github.com/aws/aws-cdk/blob/main/CHANGELOG.v2.alpha.md)
- [Commits](https://github.com/aws/aws-cdk/commits/v2.260.0/packages/aws-cdk-lib)

Updates `aws-cdk` from 2.1127.0 to 2.1128.0
- [Release notes](https://github.com/aws/aws-cdk-cli/releases)
- [Commits](https://github.com/aws/aws-cdk-cli/commits/aws-cdk@v2.1128.0/packages/aws-cdk)

---
updated-dependencies:
- dependency-name: aws-cdk-lib
  dependency-version: 2.260.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: aws-cdk
  dependency-version: 2.1128.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-22 13:14:13 -04:00
dependabot[bot]
a21f8ad921
Bump aws-cdk-lib from 2.258.0 to 2.259.0 in the minor-and-patch group (#1)
Bumps the minor-and-patch group with 1 update: [aws-cdk-lib](https://github.com/aws/aws-cdk/tree/HEAD/packages/aws-cdk-lib).


Updates `aws-cdk-lib` from 2.258.0 to 2.259.0
- [Release notes](https://github.com/aws/aws-cdk/releases)
- [Changelog](https://github.com/aws/aws-cdk/blob/main/CHANGELOG.v2.alpha.md)
- [Commits](https://github.com/aws/aws-cdk/commits/v2.259.0/packages/aws-cdk-lib)

---
updated-dependencies:
- dependency-name: aws-cdk-lib
  dependency-version: 2.259.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-16 17:19:33 -04:00
Adam Moussa
10555af9e2 Add account-local security baseline for seahaven-external-dev
Stripped fork of seahaven-account-baseline for the isolated external-dev
account (396287094661). Single stack: AWS Config, GuardDuty, Security Hub
(FSBP + CIS v3.0), IAM Access Analyzer, VPC flow logs (VPC ids via context),
and a $200/mo budget alerting adam@seahaven.com.

Drops all org-level / prod-specific controls (local CloudTrail, CIS metric
alarms, WAF, SES, Bedrock, DynamoDB CMK, Backup) per the isolated-account
design; the org trail already covers this account centrally. Inspector2 is a
documented post-deploy CLI step (no CloudFormation enable resource exists).
2026-06-15 11:26:23 -04:00