* ci(iam): check synthesized policies with Access Analyzer (PLAT-234)
Adds a CI job that checks bootstrap trust for StringEquals, rejects
lambda writes on the plan refresh template, and runs ValidatePolicy
plus CheckNoNewAccess when the policy-check role can be assumed.
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
* ci(iam): fail closed on widened policies (PLAT-234)
Compare new and removed SCPs, and fail when a Deny shrinks or a Condition
changes. Run CheckNoNewAccess on bootstrap templates from the base repo.
Install the base worktree's own dependencies and warn when analyzer
credentials are skipped.
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
---------
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>