mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-09-30 08:13:12 +00:00
chore(security): add tracked repo-local suppressions for oidc-deploy-roles findings
Makes the .github suppressions TRACKED so the Open SWE daily-report automation (which cannot see ~/.config on the Mac) resolves them: checkov-CKV_AWS_111-88 (permissions-boundary FP) and the accepted-risk checkov-CKV_AWS_109/111-276 on github-cfn-execution-role. NOTE: this reverses the earlier out-of-history decision (#61) for this repo, and :276 is an ACCEPTED-RISK suppression for a REAL (bounded) privesc finding, not an FP. See PR description. Machine-level copy retained until merge.
This commit is contained in:
parent
9fa0a71564
commit
672d651a77
1 changed files with 17 additions and 0 deletions
17
.security-review/suppressions.json
Normal file
17
.security-review/suppressions.json
Normal file
|
|
@ -0,0 +1,17 @@
|
|||
{
|
||||
"_comment": "Repo-local suppressions for the Sea-Haven-Industries/.github repo. Made TRACKED (2026-07-13) so the Open SWE daily-report automation — which clones the repo and cannot see ~/.config on Adam's Mac — resolves these adjudicated findings. This reverses the earlier out-of-history decision (#61) for this repo; see PR description. IDs are review.sh finding IDs: checkov-<check_id>-<file_line>.",
|
||||
"suppressions": [
|
||||
{
|
||||
"id": "checkov-CKV_AWS_111-88",
|
||||
"justification": "False positive on a permissions-boundary policy. oidc-deploy-roles.yaml:88 (LambdaExecutionBoundary) is the boundary ceiling itself, not a grant: effective Lambda permissions are the intersection of this policy and each role's own inline policies, so it cannot escalate access. The Resource:'*' write actions checkov flags (CloudWatch Logs, X-Ray, EC2 ENI lifecycle) mirror the AWS-managed AWSLambdaVPCAccessExecutionRole and cannot be ARN-scoped (log-group and ENI names are created at runtime). Verified proof-or-kill 2026-07-13. Re-review if non-runtime-scoped write actions are added to the boundary."
|
||||
},
|
||||
{
|
||||
"id": "checkov-CKV_AWS_109-276",
|
||||
"justification": "ACCEPTED RISK (Adam, 2026-07-13) on the CloudFormation execution role (github-cfn-execution-role). A CFN execution role must perform IAM permissions-management to provision stack resources. iam:CreateRole is gated by an iam:PermissionsBoundary StringEquals condition (cannot mint unbounded roles); the role is assumable only by cloudformation.amazonaws.com; grants are account/region-scoped. This acceptance ALSO covers the IAMRoleReadAndDelete statement (lines 778-798), which grants iam:UpdateAssumeRolePolicy/DeleteRolePolicy/DetachRolePolicy/UpdateRole on Resource:'*' with NO condition — a privesc primitive that is NOT boundary-gateable (trust-policy edits cannot be constrained by a PermissionsBoundary). Accepted because exploitation is bounded: CFN-only principal, reachable only via the OIDC deploy pipeline scoped to refs/heads/main, and abusing UpdateAssumeRolePolicy against a privileged external role requires first bringing that role under this stack's management. REVISIT TRIGGER: scope the IAMRoleReadAndDelete destructive actions to the SAM role path if the pipeline gains untrusted contributors or main-branch protection is relaxed."
|
||||
},
|
||||
{
|
||||
"id": "checkov-CKV_AWS_111-276",
|
||||
"justification": "ACCEPTED RISK (Adam, 2026-07-13) on github-cfn-execution-role. Same mitigations as CKV_AWS_109-276: a SAM/CFN deploy role inherently needs broad write; grants are account/region-scoped, IAM role creation is boundary-gated, the role is CFN-only assumable. Explicitly includes the IAMRoleReadAndDelete statement (lines 778-798) whose iam:UpdateAssumeRolePolicy et al. run on Resource:'*' without a condition and are not boundary-gateable; accepted on the bounded-exploitability basis in the CKV_AWS_109-276 entry. Same REVISIT TRIGGER."
|
||||
}
|
||||
]
|
||||
}
|
||||
Loading…
Add table
Reference in a new issue