chore(security): add tracked repo-local suppressions for oidc-deploy-roles findings

Makes the .github suppressions TRACKED so the Open SWE daily-report automation
(which cannot see ~/.config on the Mac) resolves them: checkov-CKV_AWS_111-88
(permissions-boundary FP) and the accepted-risk checkov-CKV_AWS_109/111-276 on
github-cfn-execution-role.

NOTE: this reverses the earlier out-of-history decision (#61) for this repo, and
:276 is an ACCEPTED-RISK suppression for a REAL (bounded) privesc finding, not an
FP. See PR description. Machine-level copy retained until merge.
This commit is contained in:
Adam Moussa 2026-07-13 14:24:29 -04:00
parent 9fa0a71564
commit 672d651a77
No known key found for this signature in database

View file

@ -0,0 +1,17 @@
{
"_comment": "Repo-local suppressions for the Sea-Haven-Industries/.github repo. Made TRACKED (2026-07-13) so the Open SWE daily-report automation — which clones the repo and cannot see ~/.config on Adam's Mac — resolves these adjudicated findings. This reverses the earlier out-of-history decision (#61) for this repo; see PR description. IDs are review.sh finding IDs: checkov-<check_id>-<file_line>.",
"suppressions": [
{
"id": "checkov-CKV_AWS_111-88",
"justification": "False positive on a permissions-boundary policy. oidc-deploy-roles.yaml:88 (LambdaExecutionBoundary) is the boundary ceiling itself, not a grant: effective Lambda permissions are the intersection of this policy and each role's own inline policies, so it cannot escalate access. The Resource:'*' write actions checkov flags (CloudWatch Logs, X-Ray, EC2 ENI lifecycle) mirror the AWS-managed AWSLambdaVPCAccessExecutionRole and cannot be ARN-scoped (log-group and ENI names are created at runtime). Verified proof-or-kill 2026-07-13. Re-review if non-runtime-scoped write actions are added to the boundary."
},
{
"id": "checkov-CKV_AWS_109-276",
"justification": "ACCEPTED RISK (Adam, 2026-07-13) on the CloudFormation execution role (github-cfn-execution-role). A CFN execution role must perform IAM permissions-management to provision stack resources. iam:CreateRole is gated by an iam:PermissionsBoundary StringEquals condition (cannot mint unbounded roles); the role is assumable only by cloudformation.amazonaws.com; grants are account/region-scoped. This acceptance ALSO covers the IAMRoleReadAndDelete statement (lines 778-798), which grants iam:UpdateAssumeRolePolicy/DeleteRolePolicy/DetachRolePolicy/UpdateRole on Resource:'*' with NO condition — a privesc primitive that is NOT boundary-gateable (trust-policy edits cannot be constrained by a PermissionsBoundary). Accepted because exploitation is bounded: CFN-only principal, reachable only via the OIDC deploy pipeline scoped to refs/heads/main, and abusing UpdateAssumeRolePolicy against a privileged external role requires first bringing that role under this stack's management. REVISIT TRIGGER: scope the IAMRoleReadAndDelete destructive actions to the SAM role path if the pipeline gains untrusted contributors or main-branch protection is relaxed."
},
{
"id": "checkov-CKV_AWS_111-276",
"justification": "ACCEPTED RISK (Adam, 2026-07-13) on github-cfn-execution-role. Same mitigations as CKV_AWS_109-276: a SAM/CFN deploy role inherently needs broad write; grants are account/region-scoped, IAM role creation is boundary-gated, the role is CFN-only assumable. Explicitly includes the IAMRoleReadAndDelete statement (lines 778-798) whose iam:UpdateAssumeRolePolicy et al. run on Resource:'*' without a condition and are not boundary-gateable; accepted on the bounded-exploitability basis in the CKV_AWS_109-276 entry. Same REVISIT TRIGGER."
}
]
}