chore(security): add explicit workflow permissions and bump aws-cdk-lib to 2.262.0 (#56)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run

* docs: update aws profile specified in script (local renaming)

* ci: add least-privilege permissions blocks to workflow callers

Resolves code scanning alerts #3 and #4 (actions/missing-workflow-permissions). Both callable workflows only need contents: read; the dependency-review callable already declares it internally, this caps the caller token to match."

* chore(deps): bump aws-cdk-lib to 2.262.0 for patched brace-expansion

Resolves Dependabot alert #4 (CVE-2026-13149, exponential-time DoS in brace-expansion expand()). The vulnerable 5.0.6 is a bundled dependency inside the aws-cdk-lib tarball, so it cannot be updated independently; 2.262.0 bundles the patched 5.0.7.

Also migrates Stack#addDependency to addStackDependency (deprecated in this release) in bin/app.ts.
This commit is contained in:
Adam Moussa 2026-07-23 13:38:17 -04:00 • committed by GitHub
parent 6041abbd23
commit cc54b1e28b
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
7 changed files with 43 additions and 25 deletions

View file

@ -3,6 +3,9 @@ on:
pull_request:
branches: [main]
permissions:
contents: read
jobs:
ci:
uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main

View file

@ -1,6 +1,10 @@
name: Dependency Review
on:
pull_request:
permissions:
contents: read
jobs:
review:
uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main

View file

@ -201,4 +201,4 @@ const backupPrimary = new BackupStack(app, "backup", {
env: { account: "328440206208", region: "us-east-1" },
});
backupPrimary.addDependency(backupOffsite);
backupPrimary.addStackDependency(backupOffsite);

View file

@ -163,7 +163,7 @@ export class BackupStack extends cdk.Stack {
// Cross-region copy destination, referenced by literal ARN (the offsite
// stack is in another region; a literal ARN avoids crossRegionReferences /
// SSM exports). Stack ordering is enforced via addDependency in bin/app.ts.
// SSM exports). Stack ordering is enforced via addStackDependency in bin/app.ts.
const offsiteVault = backup.BackupVault.fromBackupVaultArn(
this,
"OffsiteVaultRef",

53
package-lock.json generated
View file

@ -1,14 +1,14 @@
{
"name": "seahaven-account-baseline",
"name": "seahaven-org-baseline",
"version": "1.0.0",
"lockfileVersion": 3,
"requires": true,
"packages": {
"": {
"name": "seahaven-account-baseline",
"name": "seahaven-org-baseline",
"version": "1.0.0",
"dependencies": {
"aws-cdk-lib": "2.261.0",
"aws-cdk-lib": "2.262.0",
"constructs": "^10.7.0"
},
"bin": {
@ -36,9 +36,9 @@
"license": "Apache-2.0"
},
"node_modules/@aws-cdk/cloud-assembly-schema": {
"version": "54.2.0",
"resolved": "https://registry.npmjs.org/@aws-cdk/cloud-assembly-schema/-/cloud-assembly-schema-54.2.0.tgz",
"integrity": "sha512-u3lFXmiXSBozxGBmKTCVD/2mTDsaXzLZH3KYiIQKcB+zPldXOeE5TnooBgKV9ih2jVTo8ML0HpkhfAq2eiv0eQ==",
"version": "54.13.0",
"resolved": "https://registry.npmjs.org/@aws-cdk/cloud-assembly-schema/-/cloud-assembly-schema-54.13.0.tgz",
"integrity": "sha512-C6LS1YxugR7j6BPVjhVsWRu/VNN8eoGDOf7dHafPviz6Y5Nv/FjVIGIPoC6jJmgJcea7VOM9TPHbBEwapCUySg==",
"bundleDependencies": [
"jsonschema",
"semver"
@ -46,7 +46,7 @@
"license": "Apache-2.0",
"dependencies": {
"jsonschema": "^1.5.0",
"semver": "^7.8.1"
"semver": "^7.8.5"
},
"engines": {
"node": ">= 18.0.0"
@ -61,7 +61,7 @@
}
},
"node_modules/@aws-cdk/cloud-assembly-schema/node_modules/semver": {
"version": "7.8.1",
"version": "7.8.5",
"inBundle": true,
"license": "ISC",
"bin": {
@ -887,10 +887,11 @@
}
},
"node_modules/aws-cdk-lib": {
"version": "2.261.0",
"resolved": "https://registry.npmjs.org/aws-cdk-lib/-/aws-cdk-lib-2.261.0.tgz",
"integrity": "sha512-e52e3Abjg0HkuRWlWwtSv5+ZiMW1rhCDdL9ff7lzWXInU8xdfLJpuoimfa0IJwjiNGyphppgg52Azx9M80OA0g==",
"version": "2.262.0",
"resolved": "https://registry.npmjs.org/aws-cdk-lib/-/aws-cdk-lib-2.262.0.tgz",
"integrity": "sha512-6zRVoWRd8kQs9ZZ9xhERSm36W8uWS2vW3/g9Zx0xlhvRRiUwTc80bzfJkohKGdT/5AOW+wy6fSDvohavG94pcA==",
"bundleDependencies": [
"@aws/cloudformation-validate",
"@balena/dockerignore",
"@aws-cdk/cloud-assembly-api",
"case",
@ -907,17 +908,18 @@
"dependencies": {
"@aws-cdk/asset-awscli-v1": "2.2.282",
"@aws-cdk/asset-node-proxy-agent-v6": "^2.1.2",
"@aws-cdk/cloud-assembly-api": "^2.2.5",
"@aws-cdk/cloud-assembly-schema": "^54.0.0",
"@aws-cdk/cloud-assembly-api": "^2.2.6",
"@aws-cdk/cloud-assembly-schema": "^54.11.0",
"@aws/cloudformation-validate": "1.5.0-beta",
"@balena/dockerignore": "^1.0.2",
"case": "1.6.3",
"fs-extra": "^11.3.5",
"fs-extra": "^11.3.6",
"ignore": "^5.3.2",
"jsonschema": "^1.5.0",
"mime-types": "^2.1.35",
"minimatch": "^10.2.5",
"punycode": "^2.3.1",
"semver": "^7.8.1",
"semver": "^7.8.5",
"yaml": "1.10.3"
},
"engines": {
@ -928,18 +930,27 @@
}
},
"node_modules/aws-cdk-lib/node_modules/@aws-cdk/cloud-assembly-api": {
"version": "2.2.5",
"version": "2.2.6",
"inBundle": true,
"license": "Apache-2.0",
"dependencies": {
"jsonschema": "^1.5.0",
"semver": "^7.8.0"
"semver": "^7.8.4"
},
"engines": {
"node": ">= 18.0.0"
},
"peerDependencies": {
"@aws-cdk/cloud-assembly-schema": ">=53.28.0"
"@aws-cdk/cloud-assembly-schema": ">=54.5.0"
}
},
"node_modules/aws-cdk-lib/node_modules/@aws/cloudformation-validate": {
"version": "1.5.0-beta",
"inBundle": true,
"license": "Apache-2.0",
"engines": {
"node": "^22.15.0",
"npm": ">=10.5.0"
}
},
"node_modules/aws-cdk-lib/node_modules/@balena/dockerignore": {
@ -956,7 +967,7 @@
}
},
"node_modules/aws-cdk-lib/node_modules/brace-expansion": {
"version": "5.0.6",
"version": "5.0.7",
"inBundle": true,
"license": "MIT",
"dependencies": {
@ -975,7 +986,7 @@
}
},
"node_modules/aws-cdk-lib/node_modules/fs-extra": {
"version": "11.3.5",
"version": "11.3.6",
"inBundle": true,
"license": "MIT",
"dependencies": {
@ -1061,7 +1072,7 @@
}
},
"node_modules/aws-cdk-lib/node_modules/semver": {
"version": "7.8.1",
"version": "7.8.5",
"inBundle": true,
"license": "ISC",
"bin": {

View file

@ -20,7 +20,7 @@
"typescript": "~7.0.2"
},
"dependencies": {
"aws-cdk-lib": "2.261.0",
"aws-cdk-lib": "2.262.0",
"constructs": "^10.7.0"
}
}

View file

@ -13,7 +13,7 @@
# scripts/iam-user-delete.sh [--profile NAME] [--yes] USER [USER ...]
#
# --profile NAME AWS CLI profile (default: $AWS_PROFILE or the default chain).
# Post-SSO-cutover this is normally `amoussa-seahaven`.
# Post-SSO-cutover this is normally `seahaven-mgmt`.
# --yes Skip the per-user confirmation prompt.
#
# Safety: