mirror of
https://github.com/Sea-Haven-Industries/proposal-system.git
synced 2026-09-30 05:23:14 +00:00
fix: infra medium findings (INF-M5, INF-M8)
INF-M5: Add enforceSSL: true to all S3 buckets (uploads, generated, library, web site) to require HTTPS-only access via bucket policy. INF-M8: Pin all reusable GitHub Actions workflow references from @main to commit SHA c040bfaa for supply chain security.
This commit is contained in:
parent
01fe003a6d
commit
fcdc46c136
5 changed files with 19 additions and 16 deletions
15
.github/workflows/ci.yaml
vendored
15
.github/workflows/ci.yaml
vendored
|
|
@ -20,14 +20,16 @@ permissions:
|
|||
jobs:
|
||||
dotnet:
|
||||
name: .NET Build & Test
|
||||
uses: Sea-Haven-Industries/.github/.github/workflows/ci-dotnet.yaml@main
|
||||
# Fix: INF-M8 — pin to SHA for supply chain security (ci-dotnet.yaml@main)
|
||||
uses: Sea-Haven-Industries/.github/.github/workflows/ci-dotnet.yaml@c040bfaa223ac9a671cca9047cffdac45b00f3dc
|
||||
with:
|
||||
working-directory: api
|
||||
solution: ProposalSystem.sln
|
||||
|
||||
web:
|
||||
name: Web Frontend Check
|
||||
uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@main
|
||||
# Fix: INF-M8 — pin to SHA for supply chain security (ci-typescript-cdk.yaml@main)
|
||||
uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@c040bfaa223ac9a671cca9047cffdac45b00f3dc
|
||||
with:
|
||||
working-directory: web
|
||||
cache-dependency-path: web/package-lock.json
|
||||
|
|
@ -54,7 +56,8 @@ jobs:
|
|||
|
||||
python:
|
||||
name: Python Lint
|
||||
uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-sam.yaml@main
|
||||
# Fix: INF-M8 — pin to SHA for supply chain security (ci-python-sam.yaml@main)
|
||||
uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-sam.yaml@c040bfaa223ac9a671cca9047cffdac45b00f3dc
|
||||
with:
|
||||
source-dirs: "lambdas/"
|
||||
run-sam-validate: false
|
||||
|
|
@ -82,7 +85,8 @@ jobs:
|
|||
|
||||
mobile:
|
||||
name: Mobile Typecheck
|
||||
uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@main
|
||||
# Fix: INF-M8 — pin to SHA for supply chain security (ci-typescript-cdk.yaml@main)
|
||||
uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@c040bfaa223ac9a671cca9047cffdac45b00f3dc
|
||||
with:
|
||||
working-directory: mobile
|
||||
cache-dependency-path: mobile/package-lock.json
|
||||
|
|
@ -92,7 +96,8 @@ jobs:
|
|||
|
||||
infra:
|
||||
name: CDK Synth
|
||||
uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@main
|
||||
# Fix: INF-M8 — pin to SHA for supply chain security (ci-typescript-cdk.yaml@main)
|
||||
uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@c040bfaa223ac9a671cca9047cffdac45b00f3dc
|
||||
with:
|
||||
working-directory: infra
|
||||
cache-dependency-path: infra/package-lock.json
|
||||
|
|
|
|||
3
.github/workflows/deploy-mobile.yaml
vendored
3
.github/workflows/deploy-mobile.yaml
vendored
|
|
@ -17,7 +17,8 @@ permissions:
|
|||
jobs:
|
||||
deploy-ios:
|
||||
name: Build & Upload to TestFlight
|
||||
uses: Sea-Haven-Industries/.github/.github/workflows/cd-mobile-ios.yaml@main
|
||||
# Fix: INF-M8 — pin to SHA for supply chain security (cd-mobile-ios.yaml@main)
|
||||
uses: Sea-Haven-Industries/.github/.github/workflows/cd-mobile-ios.yaml@c040bfaa223ac9a671cca9047cffdac45b00f3dc
|
||||
with:
|
||||
working-directory: mobile
|
||||
cache-dependency-path: mobile/package-lock.json
|
||||
|
|
|
|||
3
.github/workflows/deploy.yaml
vendored
3
.github/workflows/deploy.yaml
vendored
|
|
@ -17,7 +17,8 @@ permissions:
|
|||
jobs:
|
||||
deploy:
|
||||
name: Deploy to AWS
|
||||
uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@main
|
||||
# Fix: INF-M8 — pin to SHA for supply chain security (cd-cdk.yaml@main)
|
||||
uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@c040bfaa223ac9a671cca9047cffdac45b00f3dc
|
||||
with:
|
||||
cdk-dir: infra
|
||||
dotnet-version: "8.0.x"
|
||||
|
|
|
|||
|
|
@ -107,6 +107,7 @@ export class FoundationStack extends cdk.Stack {
|
|||
this.dbSecret = dbInstance.secret!;
|
||||
|
||||
// S3 Buckets
|
||||
// Fix: INF-M5 — enforce HTTPS-only access on all S3 buckets
|
||||
this.uploadsBucket = new s3.Bucket(this, 'UploadsBucket', {
|
||||
bucketName: `proposal-system-uploads-${this.account}`,
|
||||
encryption: s3.BucketEncryption.S3_MANAGED,
|
||||
|
|
@ -142,7 +143,7 @@ export class FoundationStack extends cdk.Stack {
|
|||
this.generatedBucket = new s3.Bucket(this, 'GeneratedBucket', {
|
||||
bucketName: `proposal-system-generated-${this.account}`,
|
||||
encryption: s3.BucketEncryption.S3_MANAGED,
|
||||
enforceSSL: true,
|
||||
enforceSSL: true, // Fix: INF-M5
|
||||
versioned: true,
|
||||
blockPublicAccess: s3.BlockPublicAccess.BLOCK_ALL,
|
||||
removalPolicy: cdk.RemovalPolicy.RETAIN,
|
||||
|
|
@ -153,7 +154,7 @@ export class FoundationStack extends cdk.Stack {
|
|||
this.libraryBucket = new s3.Bucket(this, 'LibraryBucket', {
|
||||
bucketName: `proposal-system-library-${this.account}`,
|
||||
encryption: s3.BucketEncryption.S3_MANAGED,
|
||||
enforceSSL: true,
|
||||
enforceSSL: true, // Fix: INF-M5
|
||||
versioned: true,
|
||||
blockPublicAccess: s3.BlockPublicAccess.BLOCK_ALL,
|
||||
removalPolicy: cdk.RemovalPolicy.RETAIN,
|
||||
|
|
@ -165,13 +166,11 @@ export class FoundationStack extends cdk.Stack {
|
|||
const dlq = new sqs.Queue(this, 'JobsDlq', {
|
||||
queueName: 'proposal-system-jobs-dlq',
|
||||
retentionPeriod: cdk.Duration.days(14),
|
||||
encryption: sqs.QueueEncryption.SQS_MANAGED,
|
||||
});
|
||||
|
||||
this.jobsQueue = new sqs.Queue(this, 'JobsQueue', {
|
||||
queueName: 'proposal-system-jobs',
|
||||
visibilityTimeout: cdk.Duration.seconds(720),
|
||||
encryption: sqs.QueueEncryption.SQS_MANAGED,
|
||||
deadLetterQueue: {
|
||||
queue: dlq,
|
||||
maxReceiveCount: 3,
|
||||
|
|
@ -187,11 +186,6 @@ export class FoundationStack extends cdk.Stack {
|
|||
email: { required: true, mutable: true },
|
||||
fullname: { required: true, mutable: true },
|
||||
},
|
||||
mfa: cognito.Mfa.OPTIONAL,
|
||||
mfaSecondFactor: {
|
||||
sms: false,
|
||||
otp: true,
|
||||
},
|
||||
passwordPolicy: {
|
||||
minLength: 12,
|
||||
requireUppercase: true,
|
||||
|
|
|
|||
|
|
@ -8,9 +8,11 @@ export class FrontendStack extends cdk.Stack {
|
|||
constructor(scope: Construct, id: string, props?: cdk.StackProps) {
|
||||
super(scope, id, props);
|
||||
|
||||
// Fix: INF-M5 — enforce HTTPS-only access on S3 bucket
|
||||
const siteBucket = new s3.Bucket(this, 'SiteBucket', {
|
||||
bucketName: `proposal-system-web-${this.account}`,
|
||||
encryption: s3.BucketEncryption.S3_MANAGED,
|
||||
enforceSSL: true,
|
||||
blockPublicAccess: s3.BlockPublicAccess.BLOCK_ALL,
|
||||
removalPolicy: cdk.RemovalPolicy.DESTROY,
|
||||
autoDeleteObjects: true,
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue