diff --git a/.security-review/suppressions.json b/.security-review/suppressions.json new file mode 100644 index 0000000..e59df9c --- /dev/null +++ b/.security-review/suppressions.json @@ -0,0 +1,17 @@ +{ + "_comment": "Repo-local suppressions for the Sea-Haven-Industries/.github repo. Made TRACKED (2026-07-13) so the Open SWE daily-report automation — which clones the repo and cannot see ~/.config on Adam's Mac — resolves these adjudicated findings. This reverses the earlier out-of-history decision (#61) for this repo; see PR description. IDs are review.sh finding IDs: checkov--.", + "suppressions": [ + { + "id": "checkov-CKV_AWS_111-88", + "justification": "False positive on a permissions-boundary policy. oidc-deploy-roles.yaml:88 (LambdaExecutionBoundary) is the boundary ceiling itself, not a grant: effective Lambda permissions are the intersection of this policy and each role's own inline policies, so it cannot escalate access. The Resource:'*' write actions checkov flags (CloudWatch Logs, X-Ray, EC2 ENI lifecycle) mirror the AWS-managed AWSLambdaVPCAccessExecutionRole and cannot be ARN-scoped (log-group and ENI names are created at runtime). Verified proof-or-kill 2026-07-13. Re-review if non-runtime-scoped write actions are added to the boundary." + }, + { + "id": "checkov-CKV_AWS_109-276", + "justification": "ACCEPTED RISK (Adam, 2026-07-13) on the CloudFormation execution role (github-cfn-execution-role). A CFN execution role must perform IAM permissions-management to provision stack resources. iam:CreateRole is gated by an iam:PermissionsBoundary StringEquals condition (cannot mint unbounded roles); the role is assumable only by cloudformation.amazonaws.com; grants are account/region-scoped. This acceptance ALSO covers the IAMRoleReadAndDelete statement (lines 778-798), which grants iam:UpdateAssumeRolePolicy/DeleteRolePolicy/DetachRolePolicy/UpdateRole on Resource:'*' with NO condition — a privesc primitive that is NOT boundary-gateable (trust-policy edits cannot be constrained by a PermissionsBoundary). Accepted because exploitation is bounded: CFN-only principal, reachable only via the OIDC deploy pipeline scoped to refs/heads/main, and abusing UpdateAssumeRolePolicy against a privileged external role requires first bringing that role under this stack's management. REVISIT TRIGGER: scope the IAMRoleReadAndDelete destructive actions to the SAM role path if the pipeline gains untrusted contributors or main-branch protection is relaxed." + }, + { + "id": "checkov-CKV_AWS_111-276", + "justification": "ACCEPTED RISK (Adam, 2026-07-13) on github-cfn-execution-role. Same mitigations as CKV_AWS_109-276: a SAM/CFN deploy role inherently needs broad write; grants are account/region-scoped, IAM role creation is boundary-gated, the role is CFN-only assumable. Explicitly includes the IAMRoleReadAndDelete statement (lines 778-798) whose iam:UpdateAssumeRolePolicy et al. run on Resource:'*' without a condition and are not boundary-gateable; accepted on the bounded-exploitability basis in the CKV_AWS_109-276 entry. Same REVISIT TRIGGER." + } + ] +}