name: CI on: pull_request: branches: [main] merge_group: permissions: contents: read jobs: ci: uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@e5691d8a7f96ac4d5a841a82975ff0a4354d53ac # v1.0.7 with: node-version: "24" iam-policy-check: runs-on: ubuntu-latest timeout-minutes: 30 permissions: id-token: write contents: read steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 0 - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: node-version: "24" cache: npm - name: Install dependencies run: npm ci - name: Synthesize organization policies run: npx cdk synth org-governance -o cdk.out --quiet - name: Synthesize base-branch organization policies run: | git fetch origin main git worktree add --detach /tmp/iam-base origin/main npm ci --prefix /tmp/iam-base (cd /tmp/iam-base && npx cdk synth org-governance -o /tmp/iam-base-out --quiet) - name: Configure AWS credentials uses: aws-actions/configure-aws-credentials@e1253824e5c10ff9df46874f81ed3ec929e19cfd # v6.3.0 with: role-to-assume: arn:aws:iam::328440206208:role/githubdeploy-seahaven-org-baseline-policy-check aws-region: us-east-1 # pragma: allowlist secret - name: Check IAM policies run: python3 scripts/check_iam_policies.py --cdk-out cdk.out --base-cdk-out /tmp/iam-base-out --base-repo /tmp/iam-base --self-test