Skip to content

fix(cloud-security): ignore unused GovCloud session token#2820

Merged
tofikwest merged 2 commits into
mainfrom
fix/govcloud-session-token-ignore
May 11, 2026
Merged

fix(cloud-security): ignore unused GovCloud session token#2820
tofikwest merged 2 commits into
mainfrom
fix/govcloud-session-token-ignore

Conversation

@tofikwest
Copy link
Copy Markdown
Contributor

@tofikwest tofikwest commented May 11, 2026

Summary

  • Stop passing SECURITY_HUB_GOVCLOUD_SESSION_TOKEN into GovCloud STS credentials so placeholder values cannot invalidate long-lived IAM user keys.
  • Comment the optional session token in apps/api/.env.example to make the expected configuration clear.
  • Update the GovCloud credential helper test to cover placeholder session token values.

Co-authored-by: Cursor <cursoragent@cursor.com>
@vercel vercel Bot temporarily deployed to Preview – app May 11, 2026 19:44 Inactive
@vercel
Copy link
Copy Markdown

vercel Bot commented May 11, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
comp-framework-editor Ready Ready Preview, Comment May 11, 2026 7:46pm
2 Skipped Deployments
Project Deployment Actions Updated (UTC)
app Skipped Skipped May 11, 2026 7:46pm
portal Skipped Skipped May 11, 2026 7:46pm

Request Review

@vercel vercel Bot temporarily deployed to Preview – portal May 11, 2026 19:44 Inactive
Copy link
Copy Markdown
Contributor

@cubic-dev-ai cubic-dev-ai Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 3 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

@tofikwest tofikwest merged commit ff1f86d into main May 11, 2026
10 checks passed
@tofikwest tofikwest deleted the fix/govcloud-session-token-ignore branch May 11, 2026 19:46
@claudfuen
Copy link
Copy Markdown
Contributor

🎉 This PR is included in version 3.49.2 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants