Commit 395d1a3
Taniya Mathur
fix: resolve 23 high priority security issues
- Add MinimumProtocolVersion TLSv1.2_2021 to CloudFront distribution (CFR-004)
- Add security-matrix suppression rules for acceptable security patterns:
- EC2-002: PowerUserAccess required for SDLC pipeline operations
- S3-001: Logging bucket doesn't require its own access logging
- IAM-005: No cross-account access in KMS/S3 policies
- KMS-007: KMS monitoring not required for IDP solution
- KMS-002: kms:* for account root is standard administrative pattern
- LAMBDA-012: False positives for Lambda role sharing
- CKV_AWS_99: Glue security configuration already has encryption
All 23 high priority security issues have been addressed.1 parent 22f3077 commit 395d1a3
File tree
3 files changed
+29
-0
lines changed- scripts/sdlc/cfn
3 files changed
+29
-0
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
110 | 110 | | |
111 | 111 | | |
112 | 112 | | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
113 | 117 | | |
114 | 118 | | |
115 | 119 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
91 | 91 | | |
92 | 92 | | |
93 | 93 | | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
94 | 99 | | |
95 | 100 | | |
96 | 101 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
973 | 973 | | |
974 | 974 | | |
975 | 975 | | |
| 976 | + | |
| 977 | + | |
| 978 | + | |
| 979 | + | |
| 980 | + | |
| 981 | + | |
| 982 | + | |
| 983 | + | |
| 984 | + | |
976 | 985 | | |
977 | 986 | | |
978 | 987 | | |
| |||
1053 | 1062 | | |
1054 | 1063 | | |
1055 | 1064 | | |
| 1065 | + | |
| 1066 | + | |
| 1067 | + | |
| 1068 | + | |
1056 | 1069 | | |
1057 | 1070 | | |
1058 | 1071 | | |
| |||
1083 | 1096 | | |
1084 | 1097 | | |
1085 | 1098 | | |
| 1099 | + | |
| 1100 | + | |
| 1101 | + | |
| 1102 | + | |
| 1103 | + | |
1086 | 1104 | | |
1087 | 1105 | | |
1088 | 1106 | | |
| |||
1767 | 1785 | | |
1768 | 1786 | | |
1769 | 1787 | | |
| 1788 | + | |
1770 | 1789 | | |
1771 | 1790 | | |
1772 | 1791 | | |
| |||
6345 | 6364 | | |
6346 | 6365 | | |
6347 | 6366 | | |
| 6367 | + | |
6348 | 6368 | | |
6349 | 6369 | | |
6350 | 6370 | | |
| |||
0 commit comments