Skip to content

Commit 818f649

Browse files
committed
Use wildcard in S3 bucket resource pattern for NAG suppression
1 parent fa27d13 commit 818f649

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

packages/cdk/nagSuppressions.ts

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -96,7 +96,7 @@ export const nagSuppressions = (stack: Stack) => {
9696
reason: "Bedrock Knowledge Base requires these permissions to access S3 documents and OpenSearch collection.",
9797
appliesTo: [
9898
"Action::bedrock:Delete*",
99-
"Resource::<StorageDocsBucketepsamDocsF25F63F1.Arn>/*",
99+
"Resource::<StorageDocsBucket*>/*",
100100
"Resource::arn:aws:bedrock:eu-west-2:undefined:knowledge-base/*",
101101
"Resource::arn:aws:bedrock:eu-west-2:591291862413:knowledge-base/*",
102102
"Resource::arn:aws:aoss:eu-west-2:undefined:collection/*",

0 commit comments

Comments
 (0)