mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-09-30 05:43:17 +00:00
chore(security): add explicit workflow permissions and bump aws-cdk-lib to 2.262.0 (#56)
* docs: update aws profile specified in script (local renaming) * ci: add least-privilege permissions blocks to workflow callers Resolves code scanning alerts #3 and #4 (actions/missing-workflow-permissions). Both callable workflows only need contents: read; the dependency-review callable already declares it internally, this caps the caller token to match." * chore(deps): bump aws-cdk-lib to 2.262.0 for patched brace-expansion Resolves Dependabot alert #4 (CVE-2026-13149, exponential-time DoS in brace-expansion expand()). The vulnerable 5.0.6 is a bundled dependency inside the aws-cdk-lib tarball, so it cannot be updated independently; 2.262.0 bundles the patched 5.0.7. Also migrates Stack#addDependency to addStackDependency (deprecated in this release) in bin/app.ts.
This commit is contained in:
parent
6041abbd23
commit
cc54b1e28b
7 changed files with 43 additions and 25 deletions
3
.github/workflows/ci.yaml
vendored
3
.github/workflows/ci.yaml
vendored
|
|
@ -3,6 +3,9 @@ on:
|
||||||
pull_request:
|
pull_request:
|
||||||
branches: [main]
|
branches: [main]
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
ci:
|
ci:
|
||||||
uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main
|
uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main
|
||||||
|
|
|
||||||
4
.github/workflows/dependency-review.yml
vendored
4
.github/workflows/dependency-review.yml
vendored
|
|
@ -1,6 +1,10 @@
|
||||||
name: Dependency Review
|
name: Dependency Review
|
||||||
on:
|
on:
|
||||||
pull_request:
|
pull_request:
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
review:
|
review:
|
||||||
uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main
|
uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main
|
||||||
|
|
|
||||||
|
|
@ -201,4 +201,4 @@ const backupPrimary = new BackupStack(app, "backup", {
|
||||||
env: { account: "328440206208", region: "us-east-1" },
|
env: { account: "328440206208", region: "us-east-1" },
|
||||||
});
|
});
|
||||||
|
|
||||||
backupPrimary.addDependency(backupOffsite);
|
backupPrimary.addStackDependency(backupOffsite);
|
||||||
|
|
|
||||||
|
|
@ -163,7 +163,7 @@ export class BackupStack extends cdk.Stack {
|
||||||
|
|
||||||
// Cross-region copy destination, referenced by literal ARN (the offsite
|
// Cross-region copy destination, referenced by literal ARN (the offsite
|
||||||
// stack is in another region; a literal ARN avoids crossRegionReferences /
|
// stack is in another region; a literal ARN avoids crossRegionReferences /
|
||||||
// SSM exports). Stack ordering is enforced via addDependency in bin/app.ts.
|
// SSM exports). Stack ordering is enforced via addStackDependency in bin/app.ts.
|
||||||
const offsiteVault = backup.BackupVault.fromBackupVaultArn(
|
const offsiteVault = backup.BackupVault.fromBackupVaultArn(
|
||||||
this,
|
this,
|
||||||
"OffsiteVaultRef",
|
"OffsiteVaultRef",
|
||||||
|
|
|
||||||
53
package-lock.json
generated
53
package-lock.json
generated
|
|
@ -1,14 +1,14 @@
|
||||||
{
|
{
|
||||||
"name": "seahaven-account-baseline",
|
"name": "seahaven-org-baseline",
|
||||||
"version": "1.0.0",
|
"version": "1.0.0",
|
||||||
"lockfileVersion": 3,
|
"lockfileVersion": 3,
|
||||||
"requires": true,
|
"requires": true,
|
||||||
"packages": {
|
"packages": {
|
||||||
"": {
|
"": {
|
||||||
"name": "seahaven-account-baseline",
|
"name": "seahaven-org-baseline",
|
||||||
"version": "1.0.0",
|
"version": "1.0.0",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"aws-cdk-lib": "2.261.0",
|
"aws-cdk-lib": "2.262.0",
|
||||||
"constructs": "^10.7.0"
|
"constructs": "^10.7.0"
|
||||||
},
|
},
|
||||||
"bin": {
|
"bin": {
|
||||||
|
|
@ -36,9 +36,9 @@
|
||||||
"license": "Apache-2.0"
|
"license": "Apache-2.0"
|
||||||
},
|
},
|
||||||
"node_modules/@aws-cdk/cloud-assembly-schema": {
|
"node_modules/@aws-cdk/cloud-assembly-schema": {
|
||||||
"version": "54.2.0",
|
"version": "54.13.0",
|
||||||
"resolved": "https://registry.npmjs.org/@aws-cdk/cloud-assembly-schema/-/cloud-assembly-schema-54.2.0.tgz",
|
"resolved": "https://registry.npmjs.org/@aws-cdk/cloud-assembly-schema/-/cloud-assembly-schema-54.13.0.tgz",
|
||||||
"integrity": "sha512-u3lFXmiXSBozxGBmKTCVD/2mTDsaXzLZH3KYiIQKcB+zPldXOeE5TnooBgKV9ih2jVTo8ML0HpkhfAq2eiv0eQ==",
|
"integrity": "sha512-C6LS1YxugR7j6BPVjhVsWRu/VNN8eoGDOf7dHafPviz6Y5Nv/FjVIGIPoC6jJmgJcea7VOM9TPHbBEwapCUySg==",
|
||||||
"bundleDependencies": [
|
"bundleDependencies": [
|
||||||
"jsonschema",
|
"jsonschema",
|
||||||
"semver"
|
"semver"
|
||||||
|
|
@ -46,7 +46,7 @@
|
||||||
"license": "Apache-2.0",
|
"license": "Apache-2.0",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"jsonschema": "^1.5.0",
|
"jsonschema": "^1.5.0",
|
||||||
"semver": "^7.8.1"
|
"semver": "^7.8.5"
|
||||||
},
|
},
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": ">= 18.0.0"
|
"node": ">= 18.0.0"
|
||||||
|
|
@ -61,7 +61,7 @@
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@aws-cdk/cloud-assembly-schema/node_modules/semver": {
|
"node_modules/@aws-cdk/cloud-assembly-schema/node_modules/semver": {
|
||||||
"version": "7.8.1",
|
"version": "7.8.5",
|
||||||
"inBundle": true,
|
"inBundle": true,
|
||||||
"license": "ISC",
|
"license": "ISC",
|
||||||
"bin": {
|
"bin": {
|
||||||
|
|
@ -887,10 +887,11 @@
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/aws-cdk-lib": {
|
"node_modules/aws-cdk-lib": {
|
||||||
"version": "2.261.0",
|
"version": "2.262.0",
|
||||||
"resolved": "https://registry.npmjs.org/aws-cdk-lib/-/aws-cdk-lib-2.261.0.tgz",
|
"resolved": "https://registry.npmjs.org/aws-cdk-lib/-/aws-cdk-lib-2.262.0.tgz",
|
||||||
"integrity": "sha512-e52e3Abjg0HkuRWlWwtSv5+ZiMW1rhCDdL9ff7lzWXInU8xdfLJpuoimfa0IJwjiNGyphppgg52Azx9M80OA0g==",
|
"integrity": "sha512-6zRVoWRd8kQs9ZZ9xhERSm36W8uWS2vW3/g9Zx0xlhvRRiUwTc80bzfJkohKGdT/5AOW+wy6fSDvohavG94pcA==",
|
||||||
"bundleDependencies": [
|
"bundleDependencies": [
|
||||||
|
"@aws/cloudformation-validate",
|
||||||
"@balena/dockerignore",
|
"@balena/dockerignore",
|
||||||
"@aws-cdk/cloud-assembly-api",
|
"@aws-cdk/cloud-assembly-api",
|
||||||
"case",
|
"case",
|
||||||
|
|
@ -907,17 +908,18 @@
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@aws-cdk/asset-awscli-v1": "2.2.282",
|
"@aws-cdk/asset-awscli-v1": "2.2.282",
|
||||||
"@aws-cdk/asset-node-proxy-agent-v6": "^2.1.2",
|
"@aws-cdk/asset-node-proxy-agent-v6": "^2.1.2",
|
||||||
"@aws-cdk/cloud-assembly-api": "^2.2.5",
|
"@aws-cdk/cloud-assembly-api": "^2.2.6",
|
||||||
"@aws-cdk/cloud-assembly-schema": "^54.0.0",
|
"@aws-cdk/cloud-assembly-schema": "^54.11.0",
|
||||||
|
"@aws/cloudformation-validate": "1.5.0-beta",
|
||||||
"@balena/dockerignore": "^1.0.2",
|
"@balena/dockerignore": "^1.0.2",
|
||||||
"case": "1.6.3",
|
"case": "1.6.3",
|
||||||
"fs-extra": "^11.3.5",
|
"fs-extra": "^11.3.6",
|
||||||
"ignore": "^5.3.2",
|
"ignore": "^5.3.2",
|
||||||
"jsonschema": "^1.5.0",
|
"jsonschema": "^1.5.0",
|
||||||
"mime-types": "^2.1.35",
|
"mime-types": "^2.1.35",
|
||||||
"minimatch": "^10.2.5",
|
"minimatch": "^10.2.5",
|
||||||
"punycode": "^2.3.1",
|
"punycode": "^2.3.1",
|
||||||
"semver": "^7.8.1",
|
"semver": "^7.8.5",
|
||||||
"yaml": "1.10.3"
|
"yaml": "1.10.3"
|
||||||
},
|
},
|
||||||
"engines": {
|
"engines": {
|
||||||
|
|
@ -928,18 +930,27 @@
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/aws-cdk-lib/node_modules/@aws-cdk/cloud-assembly-api": {
|
"node_modules/aws-cdk-lib/node_modules/@aws-cdk/cloud-assembly-api": {
|
||||||
"version": "2.2.5",
|
"version": "2.2.6",
|
||||||
"inBundle": true,
|
"inBundle": true,
|
||||||
"license": "Apache-2.0",
|
"license": "Apache-2.0",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"jsonschema": "^1.5.0",
|
"jsonschema": "^1.5.0",
|
||||||
"semver": "^7.8.0"
|
"semver": "^7.8.4"
|
||||||
},
|
},
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": ">= 18.0.0"
|
"node": ">= 18.0.0"
|
||||||
},
|
},
|
||||||
"peerDependencies": {
|
"peerDependencies": {
|
||||||
"@aws-cdk/cloud-assembly-schema": ">=53.28.0"
|
"@aws-cdk/cloud-assembly-schema": ">=54.5.0"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"node_modules/aws-cdk-lib/node_modules/@aws/cloudformation-validate": {
|
||||||
|
"version": "1.5.0-beta",
|
||||||
|
"inBundle": true,
|
||||||
|
"license": "Apache-2.0",
|
||||||
|
"engines": {
|
||||||
|
"node": "^22.15.0",
|
||||||
|
"npm": ">=10.5.0"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/aws-cdk-lib/node_modules/@balena/dockerignore": {
|
"node_modules/aws-cdk-lib/node_modules/@balena/dockerignore": {
|
||||||
|
|
@ -956,7 +967,7 @@
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/aws-cdk-lib/node_modules/brace-expansion": {
|
"node_modules/aws-cdk-lib/node_modules/brace-expansion": {
|
||||||
"version": "5.0.6",
|
"version": "5.0.7",
|
||||||
"inBundle": true,
|
"inBundle": true,
|
||||||
"license": "MIT",
|
"license": "MIT",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
|
|
@ -975,7 +986,7 @@
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/aws-cdk-lib/node_modules/fs-extra": {
|
"node_modules/aws-cdk-lib/node_modules/fs-extra": {
|
||||||
"version": "11.3.5",
|
"version": "11.3.6",
|
||||||
"inBundle": true,
|
"inBundle": true,
|
||||||
"license": "MIT",
|
"license": "MIT",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
|
|
@ -1061,7 +1072,7 @@
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/aws-cdk-lib/node_modules/semver": {
|
"node_modules/aws-cdk-lib/node_modules/semver": {
|
||||||
"version": "7.8.1",
|
"version": "7.8.5",
|
||||||
"inBundle": true,
|
"inBundle": true,
|
||||||
"license": "ISC",
|
"license": "ISC",
|
||||||
"bin": {
|
"bin": {
|
||||||
|
|
|
||||||
|
|
@ -20,7 +20,7 @@
|
||||||
"typescript": "~7.0.2"
|
"typescript": "~7.0.2"
|
||||||
},
|
},
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"aws-cdk-lib": "2.261.0",
|
"aws-cdk-lib": "2.262.0",
|
||||||
"constructs": "^10.7.0"
|
"constructs": "^10.7.0"
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
|
||||||
|
|
@ -13,7 +13,7 @@
|
||||||
# scripts/iam-user-delete.sh [--profile NAME] [--yes] USER [USER ...]
|
# scripts/iam-user-delete.sh [--profile NAME] [--yes] USER [USER ...]
|
||||||
#
|
#
|
||||||
# --profile NAME AWS CLI profile (default: $AWS_PROFILE or the default chain).
|
# --profile NAME AWS CLI profile (default: $AWS_PROFILE or the default chain).
|
||||||
# Post-SSO-cutover this is normally `amoussa-seahaven`.
|
# Post-SSO-cutover this is normally `seahaven-mgmt`.
|
||||||
# --yes Skip the per-user confirmation prompt.
|
# --yes Skip the per-user confirmation prompt.
|
||||||
#
|
#
|
||||||
# Safety:
|
# Safety:
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue