From 672d651a7759aec1a454aa263d9ec66066e48ac0 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Mon, 13 Jul 2026 14:24:29 -0400 Subject: [PATCH] chore(security): add tracked repo-local suppressions for oidc-deploy-roles findings Makes the .github suppressions TRACKED so the Open SWE daily-report automation (which cannot see ~/.config on the Mac) resolves them: checkov-CKV_AWS_111-88 (permissions-boundary FP) and the accepted-risk checkov-CKV_AWS_109/111-276 on github-cfn-execution-role. NOTE: this reverses the earlier out-of-history decision (#61) for this repo, and :276 is an ACCEPTED-RISK suppression for a REAL (bounded) privesc finding, not an FP. See PR description. Machine-level copy retained until merge. --- .security-review/suppressions.json | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) create mode 100644 .security-review/suppressions.json diff --git a/.security-review/suppressions.json b/.security-review/suppressions.json new file mode 100644 index 0000000..e59df9c --- /dev/null +++ b/.security-review/suppressions.json @@ -0,0 +1,17 @@ +{ + "_comment": "Repo-local suppressions for the Sea-Haven-Industries/.github repo. Made TRACKED (2026-07-13) so the Open SWE daily-report automation — which clones the repo and cannot see ~/.config on Adam's Mac — resolves these adjudicated findings. This reverses the earlier out-of-history decision (#61) for this repo; see PR description. IDs are review.sh finding IDs: checkov--.", + "suppressions": [ + { + "id": "checkov-CKV_AWS_111-88", + "justification": "False positive on a permissions-boundary policy. oidc-deploy-roles.yaml:88 (LambdaExecutionBoundary) is the boundary ceiling itself, not a grant: effective Lambda permissions are the intersection of this policy and each role's own inline policies, so it cannot escalate access. The Resource:'*' write actions checkov flags (CloudWatch Logs, X-Ray, EC2 ENI lifecycle) mirror the AWS-managed AWSLambdaVPCAccessExecutionRole and cannot be ARN-scoped (log-group and ENI names are created at runtime). Verified proof-or-kill 2026-07-13. Re-review if non-runtime-scoped write actions are added to the boundary." + }, + { + "id": "checkov-CKV_AWS_109-276", + "justification": "ACCEPTED RISK (Adam, 2026-07-13) on the CloudFormation execution role (github-cfn-execution-role). A CFN execution role must perform IAM permissions-management to provision stack resources. iam:CreateRole is gated by an iam:PermissionsBoundary StringEquals condition (cannot mint unbounded roles); the role is assumable only by cloudformation.amazonaws.com; grants are account/region-scoped. This acceptance ALSO covers the IAMRoleReadAndDelete statement (lines 778-798), which grants iam:UpdateAssumeRolePolicy/DeleteRolePolicy/DetachRolePolicy/UpdateRole on Resource:'*' with NO condition — a privesc primitive that is NOT boundary-gateable (trust-policy edits cannot be constrained by a PermissionsBoundary). Accepted because exploitation is bounded: CFN-only principal, reachable only via the OIDC deploy pipeline scoped to refs/heads/main, and abusing UpdateAssumeRolePolicy against a privileged external role requires first bringing that role under this stack's management. REVISIT TRIGGER: scope the IAMRoleReadAndDelete destructive actions to the SAM role path if the pipeline gains untrusted contributors or main-branch protection is relaxed." + }, + { + "id": "checkov-CKV_AWS_111-276", + "justification": "ACCEPTED RISK (Adam, 2026-07-13) on github-cfn-execution-role. Same mitigations as CKV_AWS_109-276: a SAM/CFN deploy role inherently needs broad write; grants are account/region-scoped, IAM role creation is boundary-gated, the role is CFN-only assumable. Explicitly includes the IAMRoleReadAndDelete statement (lines 778-798) whose iam:UpdateAssumeRolePolicy et al. run on Resource:'*' without a condition and are not boundary-gateable; accepted on the bounded-exploitability basis in the CKV_AWS_109-276 entry. Same REVISIT TRIGGER." + } + ] +}