mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-10-07 00:02:00 +00:00
Compare commits
2 commits
4f68b535f0
...
e497c5f347
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
e497c5f347 | ||
|
|
7733c6c6d1 |
1 changed files with 9 additions and 1 deletions
|
|
@ -1381,6 +1381,12 @@ Resources:
|
|||
|
||||
|
||||
|
||||
# PLAT-234 principal only. The checks are seahaven-org-baseline pull request
|
||||
# 160: .github/workflows/ci.yaml job iam-policy-check and
|
||||
# scripts/check_iam_policies.py. That job assumes this role. It asserts
|
||||
# StringEquals on the bootstrap trust templates, no lambda write on the
|
||||
# plan template, then ValidatePolicy and CheckNoNewAccess when this role
|
||||
# can be assumed.
|
||||
SeahavenOrgBaselinePolicyCheckRole:
|
||||
Type: AWS::IAM::Role
|
||||
Properties:
|
||||
|
|
@ -1399,7 +1405,9 @@ Resources:
|
|||
StringLike:
|
||||
token.actions.githubusercontent.com:sub:
|
||||
- !Sub repo:${GitHubOrg}/seahaven-org-baseline:ref:refs/heads/main
|
||||
- !Sub repo:${GitHubOrg}/seahaven-org-baseline:pull_request
|
||||
# use_immutable_subject is false, so pull_request tokens use
|
||||
# repo:ORG/seahaven-org-baseline:ref:refs/pull/N/merge.
|
||||
- !Sub repo:${GitHubOrg}/seahaven-org-baseline:ref:refs/pull/*
|
||||
Policies:
|
||||
- PolicyName: access-analyzer-policy-check
|
||||
PolicyDocument:
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue