From 7eda38e41b4ca22203fb9876558ba6008e8547ab Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Mon, 1 Jun 2026 18:59:44 -0400 Subject: [PATCH] Fix conventions check false-positive on Secrets Manager env var names (#32) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The SAM template secret check grepped the 5 lines after `Environment:` for API_KEY|SECRET|TOKEN|PASSWORD|WEBHOOK. That flags env var *names* like `SLACK_BOT_TOKEN_SECRET: my-app/slack-token`, whose value is a Secrets Manager id — i.e. the recommended pattern — so any well-architected template failed CI. Match on the value's shape instead: known inline secret formats (Slack xox* tokens, AWS AKIA keys, GitHub gh*_/PAT tokens, sk- keys, PEM private keys). Secrets Manager references and intrinsic functions no longer trip it, while pasted real secrets still fail the build. --- .github/workflows/ci-python-sam.yaml | 13 ++++++++----- 1 file changed, 8 insertions(+), 5 deletions(-) diff --git a/.github/workflows/ci-python-sam.yaml b/.github/workflows/ci-python-sam.yaml index b7ce42f..a66dc25 100644 --- a/.github/workflows/ci-python-sam.yaml +++ b/.github/workflows/ci-python-sam.yaml @@ -125,11 +125,14 @@ jobs: warn "SAM template: Lambda found but no explicit log retention" fi fi - # Check for secrets in environment variables - if grep -qiE '(API_KEY|SECRET|TOKEN|PASSWORD|WEBHOOK)' "$TEMPLATE" 2>/dev/null; then - if grep -A5 'Environment:' "$TEMPLATE" | grep -qiE '(API_KEY|SECRET|TOKEN|PASSWORD|WEBHOOK)' 2>/dev/null; then - fail "SAM template: possible secret in Lambda environment variables — use Secrets Manager" - fi + # Flag HARDCODED secret values in the template. Secrets Manager + # references (e.g. SLACK_BOT_TOKEN_SECRET: my-app/slack-token) and + # intrinsic functions (!Ref/!Sub/{{resolve:...}}) are the correct + # pattern, so match on the value's shape — not the key name, which + # legitimately contains words like TOKEN/SECRET when pointing at a + # Secrets Manager id. + if grep -qiE '(xox[abprs]-[A-Za-z0-9-]{10,}|AKIA[0-9A-Z]{16}|gh[posu]_[A-Za-z0-9]{20,}|github_pat_[A-Za-z0-9_]{20,}|sk-[A-Za-z0-9]{20,}|-----BEGIN[[:space:]][A-Z ]*PRIVATE KEY-----)' "$TEMPLATE" 2>/dev/null; then + fail "SAM template: hardcoded secret in template — use Secrets Manager" fi fi