From 148fbc90a6cbbf4e467b25b4b759a94e497742bc Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Thu, 18 Jun 2026 16:28:48 -0400 Subject: [PATCH] fix(secrev): valid SAM in doc-drift fixture templates (cfn-lint E0001) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The doc-drift sample-stack fixtures declared AWS::Serverless::Function with no Properties; cfn-lint's SAM transform errored (HIGH). Added minimal valid Properties (Handler/Runtime/InlineCode). Pre-existing on main — #19 pushed with --no-verify (xargs overflow) and CI runs no cfn-lint, so it slipped through. doc-drift still detects the stack (keys on template presence). --- .../checkers/fixtures/doc-drift/clean-repo/template.yaml | 6 ++++++ .../fixtures/doc-drift/drift-omits-repo/template.yaml | 6 ++++++ 2 files changed, 12 insertions(+) diff --git a/security-review/checkers/fixtures/doc-drift/clean-repo/template.yaml b/security-review/checkers/fixtures/doc-drift/clean-repo/template.yaml index 513273c..549a326 100644 --- a/security-review/checkers/fixtures/doc-drift/clean-repo/template.yaml +++ b/security-review/checkers/fixtures/doc-drift/clean-repo/template.yaml @@ -3,3 +3,9 @@ Transform: AWS::Serverless-2016-10-31 Resources: IngestFn: Type: AWS::Serverless::Function + Properties: + Handler: app.handler + Runtime: python3.12 + InlineCode: | + def handler(event, context): + return {"statusCode": 200} diff --git a/security-review/checkers/fixtures/doc-drift/drift-omits-repo/template.yaml b/security-review/checkers/fixtures/doc-drift/drift-omits-repo/template.yaml index 9a24dce..3f49180 100644 --- a/security-review/checkers/fixtures/doc-drift/drift-omits-repo/template.yaml +++ b/security-review/checkers/fixtures/doc-drift/drift-omits-repo/template.yaml @@ -3,3 +3,9 @@ Transform: AWS::Serverless-2016-10-31 Resources: ChargeFn: Type: AWS::Serverless::Function + Properties: + Handler: app.handler + Runtime: python3.12 + InlineCode: | + def handler(event, context): + return {"statusCode": 200}