Skip to content

Commit 521995f

Browse files
committed
Update NAG suppression for SlackBot managed policy
1 parent eb9fa90 commit 521995f

File tree

1 file changed

+3
-2
lines changed

1 file changed

+3
-2
lines changed

packages/cdk/nagSuppressions.ts

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -127,16 +127,17 @@ export const nagSuppressions = (stack: Stack) => {
127127
// Suppress wildcard permissions for SlackBot managed policy
128128
safeAddNagSuppression(
129129
stack,
130-
"/EpsAssistMeStack/IamResources/SlackBotManagedPolicy/Resource",
130+
"/EpsAssistMeStack/Functions/SlackBotManagedPolicy/Resource",
131131
[
132132
{
133133
id: "AwsSolutions-IAM5",
134-
reason: "SlackBot Lambda needs access to all guardrails and functions for content filtering and self-invocation.",
134+
reason: "SlackBot Lambda needs access to all guardrails, knowledge bases, and functions for content filtering and self-invocation.",
135135
appliesTo: [
136136
"Resource::arn:aws:lambda:eu-west-2:undefined:function:*",
137137
"Resource::arn:aws:lambda:eu-west-2:591291862413:function:*",
138138
"Resource::arn:aws:bedrock:eu-west-2:undefined:guardrail/*",
139139
"Resource::arn:aws:bedrock:eu-west-2:591291862413:guardrail/*",
140+
"Resource::arn:aws:bedrock:eu-west-2:undefined:knowledge-base/*",
140141
"Resource::arn:aws:bedrock:eu-west-2:591291862413:knowledge-base/*"
141142
]
142143
}

0 commit comments

Comments
 (0)