Commit Graph

9077 Commits

Author SHA1 Message Date
Ryan Ahearn
cb4036b1b0 Disable letter-based S3 buckets 2022-09-21 11:22:55 -04:00
Tim Lowden
a3c29cd11c Merge pull request #65 from GSA/deploy-with-credentials
Pass AWS creds to application environment
2022-09-21 11:04:37 -04:00
Ryan Ahearn
fe9cbbeb78 Pass AWS creds to application environment 2022-09-21 10:25:56 -04:00
Ryan Ahearn
66299a01c4 Merge pull request #60 from GSA/terraform-services
Create api db and redis via terraform
2022-09-21 09:05:00 -04:00
Ryan Ahearn
e634191382 Merge pull request #64 from GSA/dependabot/pip/mako-1.2.2
Bump mako from 1.2.0 to 1.2.2
2022-09-20 16:07:43 -04:00
Ryan Ahearn
b835738068 Re-run make freeze-requirements 2022-09-20 15:57:55 -04:00
dependabot[bot]
c067c58133 Bump mako from 1.2.0 to 1.2.2
Bumps [mako](https://github.com/sqlalchemy/mako) from 1.2.0 to 1.2.2.
- [Release notes](https://github.com/sqlalchemy/mako/releases)
- [Changelog](https://github.com/sqlalchemy/mako/blob/main/CHANGES)
- [Commits](https://github.com/sqlalchemy/mako/commits)

---
updated-dependencies:
- dependency-name: mako
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2022-09-16 19:19:51 +00:00
Ryan Ahearn
a892999ea6 Update app name to follow shared terraform module conventions 2022-09-14 11:15:49 -04:00
Ryan Ahearn
bded466a01 Run terraform with CI/CD pipeline 2022-09-14 10:40:05 -04:00
Ryan Ahearn
e85244a3f7 Add basic terraform bootstrap and staging environments 2022-09-14 10:09:09 -04:00
Ryan Ahearn
e79adfaed5 Merge pull request #54 from GSA/jim/090922/killcopilot
remove copilot
2022-09-13 09:40:15 -04:00
jimmoffet
a2f7781984 remove copilot 2022-09-09 13:13:57 -07:00
Ryan Ahearn
eb303b17eb Merge pull request #35 from GSA/jim/090622/updateutilslib
update reqs to use GSA/notifications-utils
2022-09-07 08:33:49 -04:00
jimmoffet
0b477e2bcf update reqs to use GSA/notifications-utils 2022-09-06 18:35:49 -07:00
jimmoffet
5d18e3b78b modify pythonpath in devcontainer config 2022-09-06 16:45:44 -07:00
Ryan Ahearn
355e805eaf Merge pull request #33 from GSA/clean-up-deploy-secrets
Clean up deploy secrets
2022-09-02 13:38:17 -04:00
Ryan Ahearn
def35bf402 Pass ADMIN_CLIENT_SECRET through deploy process 2022-09-02 11:49:51 -04:00
Ryan Ahearn
56d9ac8e62 Remove obsolete manifest.yml.j2 file 2022-09-02 10:53:00 -04:00
Jim Moffet
38a6ea4de4 Merge pull request #29 from 18F/jim/082622/deukifying
de-UKify service and template
2022-08-30 11:14:21 -07:00
jimmoffet
0adc0618b9 comment 2022-08-30 11:05:38 -07:00
jimmoffet
2382846622 fix domain config 2022-08-30 10:58:23 -07:00
jimmoffet
51d31600e5 notify email domain 2022-08-30 09:39:53 -07:00
jimmoffet
a0202dc0ce delete temp template 2022-08-29 19:14:17 -07:00
jimmoffet
02b7a447eb restore purge 2022-08-29 19:13:29 -07:00
jimmoffet
181ae4c60f deukify service and template 2022-08-29 19:10:56 -07:00
Jim Moffet
750a5bf7c9 Merge pull request #28 from 18F/deploy-fix
Specify 1.7.58 buildpack with fix for missing Python.h
2022-08-29 13:34:49 -07:00
Ryan Ahearn
9fc2a345a1 Specify 1.7.58 buildpack with fix for missing Python.h 2022-08-29 15:35:16 -04:00
Jim Moffet
b8001ea96b Merge pull request #26 from 18F/devdocs_update2
Updates to quickstart while onboarding Carly
2022-08-29 10:43:49 -07:00
Ryan Ahearn
b1418b277e Merge pull request #25 from 18F/security-scans
Security & Compliance scans
2022-08-29 13:34:43 -04:00
Ryan Ahearn
f90f32f032 Document how to run the owasp scan locally 2022-08-23 16:59:39 -04:00
Ryan Ahearn
2550464b8f Run scans every day 2022-08-23 16:44:34 -04:00
Ben Klaas
9aa9ea65c2 Updates to quickstart while onboarding Carly 2022-08-22 14:25:39 -05:00
Ryan Ahearn
2df4b42da2 Use api-scan owasp action 2022-08-19 12:23:05 -04:00
Ryan Ahearn
fb188395a9 First cut at running OWASP in github actions 2022-08-19 12:12:58 -04:00
Ryan Ahearn
806e2ad2dc Review and update uses of PRNG 2022-08-19 15:26:12 +00:00
Ryan Ahearn
3c035531aa Clean up and validate low static-scan findings 2022-08-19 14:32:11 +00:00
Ryan Ahearn
53f2519c2a Verify potential sql-injection findings are false positives 2022-08-18 19:07:54 +00:00
Ryan Ahearn
e77cedb039 Clean up xml finding from static-scan 2022-08-18 17:52:44 +00:00
Ryan Ahearn
fb1e6b3e9d Implement bandit static security scan 2022-08-12 17:19:28 -04:00
Ryan Ahearn
6e96ffdc09 Create shared project setup action 2022-08-12 16:34:15 -04:00
Ryan Ahearn
ebc0083330 Add pip-audit github check 2022-08-12 15:22:01 -04:00
Ryan Ahearn
51a9207069 Ignore vuln on mistune included via notifications-utils 2022-08-12 15:22:01 -04:00
Ryan Ahearn
a6669501cc Upgrade pip packages 2022-08-12 15:22:01 -04:00
Ryan Ahearn
2597011cee make audit for python dependency audits 2022-08-12 15:36:48 +00:00
Ben Klaas
55bc3e54ed Merge pull request #23 from 18F/jim/080522/sampleenv
sample env
2022-08-09 09:47:40 -05:00
Jim Moffet
a3002c89db Merge pull request #22 from 18F/devdocs_update
Devdocs update
2022-08-05 09:16:56 -07:00
jimmoffet
9f8ed4e3fc sample env 2022-08-05 09:14:58 -07:00
Ben Klaas
b32585d20d Remove old QUICKSTART 2022-08-05 02:34:29 +00:00
Ben Klaas
9f21018d8e Update QUICKSTART 2022-08-05 02:22:21 +00:00
Jim Moffet
03679453a0 Merge pull request #16 from 18F/ch/run-tests-on-ci
Run tests and deploy from CI
2022-08-02 17:58:25 -07:00