mirror of
https://github.com/Sea-Haven-Industries/security-review.git
synced 2026-09-30 08:03:17 +00:00
Adds canary/ (the planted-vuln corpus from the local-only security-review-testbed, answer-revealing comments stripped so it measures real detection) and canary-meta/ (KEY.md ground truth + CANARY_FLOOR=8, kept OUT of canary/ so detectors never read it). One provider-pattern secret (sk_live_) was sanitized to a non-provider hardcoded key so it stays a CWE-798 finding without tripping push protection. Adds a root .security-review-skip so the org-wide sweep and the local pre-push gate skip this repo's intentional vuln/fixture content; the nightly sweep scans canary/ directly as its recall floor. 20 planted vulns (19 crit/high), 2 decoys, 3 traps.
46 lines
1.1 KiB
YAML
46 lines
1.1 KiB
YAML
AWSTemplateFormatVersion: '2010-09-09'
|
|
Transform: AWS::Serverless-2016-10-31
|
|
Description: Payments service infrastructure.
|
|
|
|
Resources:
|
|
|
|
PaymentFn:
|
|
Type: AWS::Serverless::Function
|
|
Properties:
|
|
Runtime: python3.12
|
|
Handler: payment_handler.get_payment
|
|
Policies:
|
|
- Statement:
|
|
- Effect: Allow
|
|
Action: "*"
|
|
Resource: "*"
|
|
|
|
ReportsBucket:
|
|
Type: AWS::S3::Bucket
|
|
Properties:
|
|
BucketName: seahaven-payments-reports
|
|
PublicAccessBlockConfiguration:
|
|
BlockPublicAcls: false
|
|
BlockPublicPolicy: false
|
|
IgnorePublicAcls: false
|
|
RestrictPublicBuckets: false
|
|
|
|
AdminSG:
|
|
Type: AWS::EC2::SecurityGroup
|
|
Properties:
|
|
GroupDescription: payments admin
|
|
SecurityGroupIngress:
|
|
- IpProtocol: tcp
|
|
FromPort: 22
|
|
ToPort: 22
|
|
CidrIp: 0.0.0.0/0
|
|
|
|
WebSG:
|
|
Type: AWS::EC2::SecurityGroup
|
|
Properties:
|
|
GroupDescription: public web tier
|
|
SecurityGroupIngress:
|
|
- IpProtocol: tcp
|
|
FromPort: 443
|
|
ToPort: 443
|
|
CidrIp: 0.0.0.0/0
|