Commit graph

6 commits

Author SHA1 Message Date
Adam Moussa
41a87fd701 ci: declare workflow permissions and normalize block spacing 2026-07-28 18:08:01 -04:00
Adam Moussa
261ceafc2a ci(deps): pin org reusable workflows to v1.0.2 2026-07-28 17:58:15 -04:00
Adam Moussa
dbd41bb52c
chore(security): add repo-local suppressions for adjudicated IAM FPs (#3)
Some checks failed
Deploy / deploy (push) Has been cancelled
Moves proof-or-kill-verified checkov false positives on bootstrap.yaml ExecRole
(CFN-only role, ARN-scoped IAM-user actions gated by an explicit anti-escalation
Deny; KMS CreateKey Resource:* inherent to key creation) from machine-level to a
tracked repo-local .security-review/suppressions.json so the Open SWE
daily-report automation resolves them. Machine-level copy retained until merge.
2026-07-13 14:30:58 -04:00
Adam Moussa
6e9749fe07
fix(ci): grant exec role cloudformation:CreateChangeSet on the SAM transform (#2)
Some checks failed
Deploy / deploy (push) Has been cancelled
The dedicated CFN exec role hit AccessDenied on CreateChangeSet against
arn:...:aws:transform/Serverless-2016-10-31 during the first CI deploy
(template uses Transform: AWS::Serverless-2016-10-31). Scoped grant on that
transform ARN only. Cross-review: APPROVE (non-escalating).
2026-07-10 16:08:49 -04:00
Adam Moussa
1ec33d2937
chore: tag the access-log bucket (#1)
* chore: tag the access-log bucket

Trivial resource change to exercise the CI deploy pipeline end-to-end
(OIDC deploy role + dedicated sh-openswe-traces-cfn-exec-role).

* chore: gitignore .env (CI conventions check)
2026-07-10 15:59:17 -04:00
0dea585c1a
feat: sh-openswe-traces — LangSmith bulk-export trace archive
Storage-only SAM stack (S3 + KMS CMK + write-only IAM writer + Secrets Manager
holder) as the S3 destination for LangSmith Bulk Export of Open SWE traces, for
long-horizon auditing and prompt improvement (Athena over Parquet).

- template.yaml: versioned SSE-KMS bucket, access-log bucket, TLS-only policy,
  DEEP_ARCHIVE lifecycle; least-privilege LangSmith writer (bucket-wide PutObject,
  ViaService-scoped KMS, no read/delete).
- bootstrap.yaml: dedicated OIDC deploy role + least-privilege CFN exec role so CI
  never touches the shared execution role.
- CI/CD via reusable ci-python-sam / cd-sam workflows.

IAM passed GPT-4.1 cross-review + /sh-security-review (no blocking findings).
2026-07-10 15:45:23 -04:00