chore(security): add explicit workflow permissions and bump aws-cdk-lib to 2.262.0 (#56)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run

* docs: update aws profile specified in script (local renaming)

* ci: add least-privilege permissions blocks to workflow callers

Resolves code scanning alerts #3 and #4 (actions/missing-workflow-permissions). Both callable workflows only need contents: read; the dependency-review callable already declares it internally, this caps the caller token to match."

* chore(deps): bump aws-cdk-lib to 2.262.0 for patched brace-expansion

Resolves Dependabot alert #4 (CVE-2026-13149, exponential-time DoS in brace-expansion expand()). The vulnerable 5.0.6 is a bundled dependency inside the aws-cdk-lib tarball, so it cannot be updated independently; 2.262.0 bundles the patched 5.0.7.

Also migrates Stack#addDependency to addStackDependency (deprecated in this release) in bin/app.ts.
This commit is contained in:
Adam Moussa 2026-07-23 13:38:17 -04:00 • committed by GitHub
parent 6041abbd23
commit cc54b1e28b
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
7 changed files with 43 additions and 25 deletions

View file

@ -3,6 +3,9 @@ on:
pull_request: pull_request:
branches: [main] branches: [main]
permissions:
contents: read
jobs: jobs:
ci: ci:
uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main

View file

@ -1,6 +1,10 @@
name: Dependency Review name: Dependency Review
on: on:
pull_request: pull_request:
permissions:
contents: read
jobs: jobs:
review: review:
uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main

View file

@ -201,4 +201,4 @@ const backupPrimary = new BackupStack(app, "backup", {
env: { account: "328440206208", region: "us-east-1" }, env: { account: "328440206208", region: "us-east-1" },
}); });
backupPrimary.addDependency(backupOffsite); backupPrimary.addStackDependency(backupOffsite);

View file

@ -163,7 +163,7 @@ export class BackupStack extends cdk.Stack {
// Cross-region copy destination, referenced by literal ARN (the offsite // Cross-region copy destination, referenced by literal ARN (the offsite
// stack is in another region; a literal ARN avoids crossRegionReferences / // stack is in another region; a literal ARN avoids crossRegionReferences /
// SSM exports). Stack ordering is enforced via addDependency in bin/app.ts. // SSM exports). Stack ordering is enforced via addStackDependency in bin/app.ts.
const offsiteVault = backup.BackupVault.fromBackupVaultArn( const offsiteVault = backup.BackupVault.fromBackupVaultArn(
this, this,
"OffsiteVaultRef", "OffsiteVaultRef",

53
package-lock.json generated
View file

@ -1,14 +1,14 @@
{ {
"name": "seahaven-account-baseline", "name": "seahaven-org-baseline",
"version": "1.0.0", "version": "1.0.0",
"lockfileVersion": 3, "lockfileVersion": 3,
"requires": true, "requires": true,
"packages": { "packages": {
"": { "": {
"name": "seahaven-account-baseline", "name": "seahaven-org-baseline",
"version": "1.0.0", "version": "1.0.0",
"dependencies": { "dependencies": {
"aws-cdk-lib": "2.261.0", "aws-cdk-lib": "2.262.0",
"constructs": "^10.7.0" "constructs": "^10.7.0"
}, },
"bin": { "bin": {
@ -36,9 +36,9 @@
"license": "Apache-2.0" "license": "Apache-2.0"
}, },
"node_modules/@aws-cdk/cloud-assembly-schema": { "node_modules/@aws-cdk/cloud-assembly-schema": {
"version": "54.2.0", "version": "54.13.0",
"resolved": "https://registry.npmjs.org/@aws-cdk/cloud-assembly-schema/-/cloud-assembly-schema-54.2.0.tgz", "resolved": "https://registry.npmjs.org/@aws-cdk/cloud-assembly-schema/-/cloud-assembly-schema-54.13.0.tgz",
"integrity": "sha512-u3lFXmiXSBozxGBmKTCVD/2mTDsaXzLZH3KYiIQKcB+zPldXOeE5TnooBgKV9ih2jVTo8ML0HpkhfAq2eiv0eQ==", "integrity": "sha512-C6LS1YxugR7j6BPVjhVsWRu/VNN8eoGDOf7dHafPviz6Y5Nv/FjVIGIPoC6jJmgJcea7VOM9TPHbBEwapCUySg==",
"bundleDependencies": [ "bundleDependencies": [
"jsonschema", "jsonschema",
"semver" "semver"
@ -46,7 +46,7 @@
"license": "Apache-2.0", "license": "Apache-2.0",
"dependencies": { "dependencies": {
"jsonschema": "^1.5.0", "jsonschema": "^1.5.0",
"semver": "^7.8.1" "semver": "^7.8.5"
}, },
"engines": { "engines": {
"node": ">= 18.0.0" "node": ">= 18.0.0"
@ -61,7 +61,7 @@
} }
}, },
"node_modules/@aws-cdk/cloud-assembly-schema/node_modules/semver": { "node_modules/@aws-cdk/cloud-assembly-schema/node_modules/semver": {
"version": "7.8.1", "version": "7.8.5",
"inBundle": true, "inBundle": true,
"license": "ISC", "license": "ISC",
"bin": { "bin": {
@ -887,10 +887,11 @@
} }
}, },
"node_modules/aws-cdk-lib": { "node_modules/aws-cdk-lib": {
"version": "2.261.0", "version": "2.262.0",
"resolved": "https://registry.npmjs.org/aws-cdk-lib/-/aws-cdk-lib-2.261.0.tgz", "resolved": "https://registry.npmjs.org/aws-cdk-lib/-/aws-cdk-lib-2.262.0.tgz",
"integrity": "sha512-e52e3Abjg0HkuRWlWwtSv5+ZiMW1rhCDdL9ff7lzWXInU8xdfLJpuoimfa0IJwjiNGyphppgg52Azx9M80OA0g==", "integrity": "sha512-6zRVoWRd8kQs9ZZ9xhERSm36W8uWS2vW3/g9Zx0xlhvRRiUwTc80bzfJkohKGdT/5AOW+wy6fSDvohavG94pcA==",
"bundleDependencies": [ "bundleDependencies": [
"@aws/cloudformation-validate",
"@balena/dockerignore", "@balena/dockerignore",
"@aws-cdk/cloud-assembly-api", "@aws-cdk/cloud-assembly-api",
"case", "case",
@ -907,17 +908,18 @@
"dependencies": { "dependencies": {
"@aws-cdk/asset-awscli-v1": "2.2.282", "@aws-cdk/asset-awscli-v1": "2.2.282",
"@aws-cdk/asset-node-proxy-agent-v6": "^2.1.2", "@aws-cdk/asset-node-proxy-agent-v6": "^2.1.2",
"@aws-cdk/cloud-assembly-api": "^2.2.5", "@aws-cdk/cloud-assembly-api": "^2.2.6",
"@aws-cdk/cloud-assembly-schema": "^54.0.0", "@aws-cdk/cloud-assembly-schema": "^54.11.0",
"@aws/cloudformation-validate": "1.5.0-beta",
"@balena/dockerignore": "^1.0.2", "@balena/dockerignore": "^1.0.2",
"case": "1.6.3", "case": "1.6.3",
"fs-extra": "^11.3.5", "fs-extra": "^11.3.6",
"ignore": "^5.3.2", "ignore": "^5.3.2",
"jsonschema": "^1.5.0", "jsonschema": "^1.5.0",
"mime-types": "^2.1.35", "mime-types": "^2.1.35",
"minimatch": "^10.2.5", "minimatch": "^10.2.5",
"punycode": "^2.3.1", "punycode": "^2.3.1",
"semver": "^7.8.1", "semver": "^7.8.5",
"yaml": "1.10.3" "yaml": "1.10.3"
}, },
"engines": { "engines": {
@ -928,18 +930,27 @@
} }
}, },
"node_modules/aws-cdk-lib/node_modules/@aws-cdk/cloud-assembly-api": { "node_modules/aws-cdk-lib/node_modules/@aws-cdk/cloud-assembly-api": {
"version": "2.2.5", "version": "2.2.6",
"inBundle": true, "inBundle": true,
"license": "Apache-2.0", "license": "Apache-2.0",
"dependencies": { "dependencies": {
"jsonschema": "^1.5.0", "jsonschema": "^1.5.0",
"semver": "^7.8.0" "semver": "^7.8.4"
}, },
"engines": { "engines": {
"node": ">= 18.0.0" "node": ">= 18.0.0"
}, },
"peerDependencies": { "peerDependencies": {
"@aws-cdk/cloud-assembly-schema": ">=53.28.0" "@aws-cdk/cloud-assembly-schema": ">=54.5.0"
}
},
"node_modules/aws-cdk-lib/node_modules/@aws/cloudformation-validate": {
"version": "1.5.0-beta",
"inBundle": true,
"license": "Apache-2.0",
"engines": {
"node": "^22.15.0",
"npm": ">=10.5.0"
} }
}, },
"node_modules/aws-cdk-lib/node_modules/@balena/dockerignore": { "node_modules/aws-cdk-lib/node_modules/@balena/dockerignore": {
@ -956,7 +967,7 @@
} }
}, },
"node_modules/aws-cdk-lib/node_modules/brace-expansion": { "node_modules/aws-cdk-lib/node_modules/brace-expansion": {
"version": "5.0.6", "version": "5.0.7",
"inBundle": true, "inBundle": true,
"license": "MIT", "license": "MIT",
"dependencies": { "dependencies": {
@ -975,7 +986,7 @@
} }
}, },
"node_modules/aws-cdk-lib/node_modules/fs-extra": { "node_modules/aws-cdk-lib/node_modules/fs-extra": {
"version": "11.3.5", "version": "11.3.6",
"inBundle": true, "inBundle": true,
"license": "MIT", "license": "MIT",
"dependencies": { "dependencies": {
@ -1061,7 +1072,7 @@
} }
}, },
"node_modules/aws-cdk-lib/node_modules/semver": { "node_modules/aws-cdk-lib/node_modules/semver": {
"version": "7.8.1", "version": "7.8.5",
"inBundle": true, "inBundle": true,
"license": "ISC", "license": "ISC",
"bin": { "bin": {

View file

@ -20,7 +20,7 @@
"typescript": "~7.0.2" "typescript": "~7.0.2"
}, },
"dependencies": { "dependencies": {
"aws-cdk-lib": "2.261.0", "aws-cdk-lib": "2.262.0",
"constructs": "^10.7.0" "constructs": "^10.7.0"
} }
} }

View file

@ -13,7 +13,7 @@
# scripts/iam-user-delete.sh [--profile NAME] [--yes] USER [USER ...] # scripts/iam-user-delete.sh [--profile NAME] [--yes] USER [USER ...]
# #
# --profile NAME AWS CLI profile (default: $AWS_PROFILE or the default chain). # --profile NAME AWS CLI profile (default: $AWS_PROFILE or the default chain).
# Post-SSO-cutover this is normally `amoussa-seahaven`. # Post-SSO-cutover this is normally `seahaven-mgmt`.
# --yes Skip the per-user confirmation prompt. # --yes Skip the per-user confirmation prompt.
# #
# Safety: # Safety: