seahaven-org-baseline/scripts
Cursor Agent 740ba53d3d
ci(iam): fail closed on widened policies (PLAT-234)
Compare new and removed SCPs, and fail when a Deny shrinks or a Condition
changes. Run CheckNoNewAccess on bootstrap templates from the base repo.
Install the base worktree's own dependencies and warn when analyzer
credentials are skipped.

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
2026-09-28 15:59:18 +00:00
..
cfn-stack-decommission.sh feat(prod): seahaven-prod DynamoDB CMK + site-alerts alarm topic (procurement-ingest migration Phase 0a) (#57) 2026-07-23 15:29:55 -04:00
check_hcp_workspace_triggers.py feat(hcp): flag workspaces that skip source-path file triggers (PLAT-183) (#141) 2026-09-10 21:00:33 +00:00
check_iam_policies.py ci(iam): fail closed on widened policies (PLAT-234) 2026-09-28 15:59:18 +00:00
create-hcptf-bootstrap-roles.sh fix(iam): use unique HCP bootstrap workspace names (PLAT-143) (#138) 2026-09-02 15:51:39 +00:00
delete-terraform-substrate-prod-dev.sh feat(iam): lock app-owned HCP IAM and add bootstrap SCP (PLAT-143) (#137) 2026-09-02 15:22:48 +00:00
iam-user-delete.sh chore(security): add explicit workflow permissions and bump aws-cdk-lib to 2.262.0 (#56) 2026-07-23 17:38:17 +00:00
resource-usage-probe.sh Add cfn-stack-decommission + resource-usage-probe ops scripts (#11) 2026-06-03 13:25:44 -04:00
test_check_hcp_workspace_triggers.py feat(hcp): flag workspaces that skip source-path file triggers (PLAT-183) (#141) 2026-09-10 21:00:33 +00:00