The policy-check role trust now matches pull request and merge queue
subjects. A failed assume must fail the job instead of skipping
ValidatePolicy and CheckNoNewAccess.
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
* ci(iam): check synthesized policies with Access Analyzer (PLAT-234)
Adds a CI job that checks bootstrap trust for StringEquals, rejects
lambda writes on the plan refresh template, and runs ValidatePolicy
plus CheckNoNewAccess when the policy-check role can be assumed.
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
* ci(iam): fail closed on widened policies (PLAT-234)
Compare new and removed SCPs, and fail when a Deny shrinks or a Condition
changes. Run CheckNoNewAccess on bootstrap templates from the base repo.
Install the base worktree's own dependencies and warn when analyzer
credentials are skipped.
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
---------
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
* docs: update aws profile specified in script (local renaming)
* ci: add least-privilege permissions blocks to workflow callers
Resolves code scanning alerts #3 and #4 (actions/missing-workflow-permissions). Both callable workflows only need contents: read; the dependency-review callable already declares it internally, this caps the caller token to match."
* chore(deps): bump aws-cdk-lib to 2.262.0 for patched brace-expansion
Resolves Dependabot alert #4 (CVE-2026-13149, exponential-time DoS in brace-expansion expand()). The vulnerable 5.0.6 is a bundled dependency inside the aws-cdk-lib tarball, so it cannot be updated independently; 2.262.0 bundles the patched 5.0.7.
Also migrates Stack#addDependency to addStackDependency (deprecated in this release) in bin/app.ts.