Commit graph

6 commits

Author SHA1 Message Date
Adam Moussa
6ce8b96b22
chore(ci): SHA-pin org reusable-workflow caller refs (INFRA-50) (#35) 2026-07-06 18:27:41 -04:00
Adam Moussa
749e5ce4e9
Ignore @types/node major bumps in Dependabot (#31)
This pure CDK app is built and synthed on Node 24 (no Lambdas), so
@types/node is pinned to ^24. A too-new types major still compiles, so a
major bump passes CI while describing APIs absent at the build Node.

Add a scoped Dependabot ignore for @types/node semver-major bumps so the
alignment can only be broken deliberately, alongside a Node upgrade.
Minor/patch within the major still flow. Sanctioned exception to the
no-blanket-ignore rule (engineering-handbook github-standards Pinning
Principle).
2026-06-24 15:01:32 -04:00
Adam Moussa
6a63a4f9b0
Repo hygiene: PR labeler + README badges (INFRA-56/57) (#26) 2026-06-11 14:42:34 -04:00
Adam Moussa
a9d9f12a40
fix(deps): bump aws-cdk-lib pin to 2.257.0 (#15) 2026-06-05 13:01:36 -04:00
Adam Moussa
05b0f95c4f
Add dependency-review caller workflow (#14)
* Add dependency-review caller workflow

Add a pull_request-triggered caller that invokes the org-level
callable-dependency-review workflow to scan dependency changes and
fail on high-severity advisories.

* chore: retrigger checks

* chore: retrigger dep review (post-fix)
2026-06-05 12:26:57 -04:00
Adam Moussa
dc079edb93 Initial account-baseline stack with CloudTrail (audit C-1)
Multi-region CloudTrail with log-file validation, a rotating KMS CMK, an
Object-Lock'd S3 log bucket, and CloudWatch Logs delivery. First resident of
the account-level security baseline; AWS Backup / 3-2-1 (C-7) lands alongside.

IAM/KMS/S3 policies cross-reviewed; review caught a missing CloudTrail KMS
grant, now added (SourceArn + encryption-context scoped).
2026-05-29 17:44:55 -04:00