seahaven-org-baseline/package.json
Adam Moussa cc54b1e28b
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
chore(security): add explicit workflow permissions and bump aws-cdk-lib to 2.262.0 (#56)
* docs: update aws profile specified in script (local renaming)

* ci: add least-privilege permissions blocks to workflow callers

Resolves code scanning alerts #3 and #4 (actions/missing-workflow-permissions). Both callable workflows only need contents: read; the dependency-review callable already declares it internally, this caps the caller token to match."

* chore(deps): bump aws-cdk-lib to 2.262.0 for patched brace-expansion

Resolves Dependabot alert #4 (CVE-2026-13149, exponential-time DoS in brace-expansion expand()). The vulnerable 5.0.6 is a bundled dependency inside the aws-cdk-lib tarball, so it cannot be updated independently; 2.262.0 bundles the patched 5.0.7.

Also migrates Stack#addDependency to addStackDependency (deprecated in this release) in bin/app.ts.
2026-07-23 17:38:17 +00:00

26 lines
534 B
JSON

{
"name": "seahaven-org-baseline",
"version": "1.0.0",
"bin": {
"app": "bin/app.js"
},
"scripts": {
"build": "tsc",
"cdk": "cdk",
"synth": "cdk synth",
"deploy": "cdk deploy",
"diff": "cdk diff"
},
"devDependencies": {
"@types/node": "^24.13.3",
"@types/source-map-support": "^0.5.10",
"aws-cdk": "^2.1132.0",
"source-map-support": "^0.5.21",
"tsx": "4.23.1",
"typescript": "~7.0.2"
},
"dependencies": {
"aws-cdk-lib": "2.262.0",
"constructs": "^10.7.0"
}
}