mirror of
https://github.com/Sea-Haven-Industries/sh-openswe-traces.git
synced 2026-09-30 04:33:14 +00:00
chore(security): add repo-local suppressions for adjudicated IAM FPs (#3)
Some checks failed
Deploy / deploy (push) Has been cancelled
Some checks failed
Deploy / deploy (push) Has been cancelled
Moves proof-or-kill-verified checkov false positives on bootstrap.yaml ExecRole (CFN-only role, ARN-scoped IAM-user actions gated by an explicit anti-escalation Deny; KMS CreateKey Resource:* inherent to key creation) from machine-level to a tracked repo-local .security-review/suppressions.json so the Open SWE daily-report automation resolves them. Machine-level copy retained until merge.
This commit is contained in:
parent
6e9749fe07
commit
dbd41bb52c
1 changed files with 12 additions and 0 deletions
12
.security-review/suppressions.json
Normal file
12
.security-review/suppressions.json
Normal file
|
|
@ -0,0 +1,12 @@
|
|||
{
|
||||
"suppressions": [
|
||||
{
|
||||
"id": "checkov-CKV_AWS_109-13",
|
||||
"justification": "False positive. bootstrap.yaml ExecRole (line 13) is a CloudFormation execution role assumable ONLY by cloudformation.amazonaws.com and gated by aws:SourceAccount == this account. CKV_AWS_109 fires on the IAM user actions (iam:CreateUser/PutUserPolicy in the ExportUser block), but those are ARN-scoped to arn:aws:iam::${AWS::AccountId}:user/sh-openswe-traces-* (not Resource:*), AND the explicit DenyUserCredentialAndEscalation block denies CreateAccessKey/CreateLoginProfile/UpdateLoginProfile/AttachUserPolicy/CreateServiceSpecificCredential and boundary tampering, so any created user is credential-inert. No privesc path. iam:PassRole is conditioned to cloudformation.amazonaws.com. Verified proof-or-kill 2026-07-13."
|
||||
},
|
||||
{
|
||||
"id": "checkov-CKV_AWS_111-13",
|
||||
"justification": "False positive. Same ExecRole. CKV_AWS_111 (write without constraint on Resource:*) fires on the KMS block (kms:CreateKey/CreateAlias), which is inherent to key creation — not-yet-existent keys cannot be ARN-scoped — with blast radius bounded to this stack's deploys. The other Resource:* statement is a Deny (flagging a Deny as over-permissive is nonsensical). CFN-only assumable, SourceAccount-conditioned. Verified proof-or-kill 2026-07-13."
|
||||
}
|
||||
]
|
||||
}
|
||||
Loading…
Add table
Reference in a new issue