From bab8e2b95dababc4884097c97c494d62a969c306 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Tue, 22 Sep 2026 15:32:17 -0400 Subject: [PATCH] chore(security): retarget githubdeploy Checkov suppression The OIDC dual-claim edit shifted CKV_AWS_111 from line 40 to 49. Permissions are unchanged. --- .security-review/suppressions.json | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.security-review/suppressions.json b/.security-review/suppressions.json index 4d878ff..3410db8 100644 --- a/.security-review/suppressions.json +++ b/.security-review/suppressions.json @@ -9,8 +9,8 @@ "justification": "The meals API ALB is the CloudFront HTTP origin for orders.seahaven.com. TLS and WAF terminate at CloudFront. Restricting the security group to the CloudFront managed prefix list would block GitHub-hosted weekly-menu HMAC publish, which must call the origin with X-Meals-Publish-Key. Application gates are HMAC on /api/publish, Cognito or Google Bearer on admin, and public submit only. Accepted as the HTTP-origin design for PLAT-215; TLS on the ALB is a follow-up." }, { - "id": "checkov-CKV_AWS_111-40", - "justification": "githubdeploy-meal-order-manager needs ecr:GetAuthorizationToken and ecs:RegisterTaskDefinition, both of which AWS documents as Resource *. Trust is pinned to environment:dev or environment:prod, job_workflow_ref on org cd-hcp-fargate.yaml@*, and workflow_ref on the thin deploy-api.yaml caller at refs/heads/main or refs/tags/v*. iam:PassRole is limited to the ECS task and execution roles. ECR push and SSM parameter reads are already resource-scoped." + "id": "checkov-CKV_AWS_111-49", + "justification": "LINE SHIFT ONLY: the OIDC dual-claim change adds a workflow_ref condition and retargets job_workflow_ref, shifting github_deploy from 40 to 49. The permission document is unchanged. Original justification: githubdeploy-meal-order-manager needs ecr:GetAuthorizationToken and ecs:RegisterTaskDefinition, both of which AWS documents as Resource *. Trust is pinned to environment:dev or environment:prod, job_workflow_ref on org cd-hcp-fargate.yaml@*, and workflow_ref on the thin deploy-api.yaml caller at refs/heads/main or refs/tags/v*. iam:PassRole is limited to the ECS task and execution roles. ECR push and SSM parameter reads are already resource-scoped." } ] }