Skip to content

chore: scope down default permissions#5423

Merged
mergify[bot] merged 2 commits intoaws:mainlinefrom
huanjani:sec-ops
Oct 31, 2023
Merged

chore: scope down default permissions#5423
mergify[bot] merged 2 commits intoaws:mainlinefrom
huanjani:sec-ops

Conversation

@huanjani
Copy link
Copy Markdown
Contributor

@huanjani huanjani commented Oct 27, 2023

This disallows the Task Role and Instance Role from assuming Copilot-tagged roles (like EnvManager Role), and scopes down permissions of the CFN Execution Role].

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the Apache 2.0 License.

@huanjani huanjani requested a review from a team as a code owner October 27, 2023 22:26
@huanjani huanjani requested review from iamhopaul123 and removed request for a team October 27, 2023 22:26
@huanjani huanjani marked this pull request as draft October 27, 2023 22:26
@github-actions
Copy link
Copy Markdown

github-actions Bot commented Oct 27, 2023

🍕 Here are the new binary sizes!

Name New size (kiB) size (kiB) Delta (%)
macOS (amd) 52208 51976 +0.45
macOS (arm) 53064 52812 +0.48
linux (amd) 45924 45716 +0.45
linux (arm) 45252 45060 +0.43
windows (amd) 43368 43168 +0.46

@codecov-commenter
Copy link
Copy Markdown

codecov-commenter commented Oct 27, 2023

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 69.91%. Comparing base (c30e076) to head (0b99b00).
⚠️ Report is 212 commits behind head on mainline.

Additional details and impacted files
@@            Coverage Diff            @@
##           mainline    #5423   +/-   ##
=========================================
  Coverage     69.91%   69.91%           
=========================================
  Files           299      299           
  Lines         45484    45484           
  Branches        295      295           
=========================================
  Hits          31799    31799           
  Misses        12140    12140           
  Partials       1545     1545           

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@huanjani huanjani marked this pull request as ready for review October 30, 2023 19:07
@mergify mergify Bot merged commit cce61ba into aws:mainline Oct 31, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Archived in project

Development

Successfully merging this pull request may close these issues.

5 participants