Skip to content

Pipeline s3 bucket allows HTTP access #5389

@gabelton

Description

@gabelton

A recent pen test highlighted that the s3 bucket created after running copilot pipeline init didn't have SecureTransport: true in its configuration. Is this by design? Seems like the secure-by-default option would automatically set this to true, to prevent manipulation of data in transit.

Metadata

Metadata

Assignees

No one assigned

    Labels

    type/enhancementIssues that are improvements for existing features.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions