Skip to content

Too open permissions on Static example #6

@midN

Description

@midN

Hey,

You've got this line:
https://github.com/stelligent/devops-essentials/blob/master/samples/static/pipeline.yml#L125-L130

Allowing pretty much any S3 action.
While above you have some lines to allow Get only actions + Put action only on specific buckets:
https://github.com/stelligent/devops-essentials/blob/master/samples/static/pipeline.yml#L114-L124

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions