Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(permissive role assumption): actions list handling #1869

Conversation

n4ch04
Copy link
Contributor

@n4ch04 n4ch04 commented Feb 9, 2023

Context

Check iam_no_custom_policy_permissive_role_assumption was returning false positives when Action section of the policy was not a list and included a * even if the service was not sts, e.g. s3:*

Description

Check explicit occurrences of * depending on the type of Action statement

License

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

@n4ch04 n4ch04 requested review from a team, drewkerrigan, toniblyx and jfagoagas February 9, 2023 09:00
@n4ch04 n4ch04 merged commit 5e9afdd into master Feb 9, 2023
@n4ch04 n4ch04 deleted the PRWLR-1510-bug-iam-no-custom-policy-permissive-role-assumption-false-positive-results branch February 9, 2023 09:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants