security-review/canary/infra/template.yaml
Adam Moussa 094a253c37
feat(canary): add anti-complacency recall-floor corpus + repo skip marker
Adds canary/ (the planted-vuln corpus from the local-only security-review-testbed,
answer-revealing comments stripped so it measures real detection) and canary-meta/
(KEY.md ground truth + CANARY_FLOOR=8, kept OUT of canary/ so detectors never read it).
One provider-pattern secret (sk_live_) was sanitized to a non-provider hardcoded key so
it stays a CWE-798 finding without tripping push protection.

Adds a root .security-review-skip so the org-wide sweep and the local pre-push gate skip
this repo's intentional vuln/fixture content; the nightly sweep scans canary/ directly as
its recall floor. 20 planted vulns (19 crit/high), 2 decoys, 3 traps.
2026-06-29 12:10:54 -04:00

46 lines
1.1 KiB
YAML

AWSTemplateFormatVersion: '2010-09-09'
Transform: AWS::Serverless-2016-10-31
Description: Payments service infrastructure.
Resources:
PaymentFn:
Type: AWS::Serverless::Function
Properties:
Runtime: python3.12
Handler: payment_handler.get_payment
Policies:
- Statement:
- Effect: Allow
Action: "*"
Resource: "*"
ReportsBucket:
Type: AWS::S3::Bucket
Properties:
BucketName: seahaven-payments-reports
PublicAccessBlockConfiguration:
BlockPublicAcls: false
BlockPublicPolicy: false
IgnorePublicAcls: false
RestrictPublicBuckets: false
AdminSG:
Type: AWS::EC2::SecurityGroup
Properties:
GroupDescription: payments admin
SecurityGroupIngress:
- IpProtocol: tcp
FromPort: 22
ToPort: 22
CidrIp: 0.0.0.0/0
WebSG:
Type: AWS::EC2::SecurityGroup
Properties:
GroupDescription: public web tier
SecurityGroupIngress:
- IpProtocol: tcp
FromPort: 443
ToPort: 443
CidrIp: 0.0.0.0/0