@hulumi/policies@1.3.2

Pulumi CrossGuard policy packs for AWS, GitHub, Kubernetes, Cloudflare, and deployment governance. Includes HulumiHardeningPack, HulumiAwsOrgHardeningPack, state/backend/primitive/detection rules, GitHub packs, EKS packs, and platform governance. SLSA Bui

  • latest version

    2.0.3

  • latest non vulnerable version

  • first published

    3 months ago

  • latest version published

    7 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the @hulumi/policies package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Access Control Bypass

    @hulumi/policies is a Pulumi CrossGuard policy packs for AWS, GitHub, Kubernetes, Cloudflare, and deployment governance. Includes HulumiHardeningPack, HulumiAwsOrgHardeningPack, state/backend/primitive/detection rules, GitHub packs, EKS packs, and platform governance. SLSA Bui

    Affected versions of this package are vulnerable to Access Control Bypass through the exemption mechanism for raw S3 buckets in the hardening policy check. An attacker can deploy an unhardened S3 bucket without required security controls by pairing it with decoy sibling resources that reference a different bucket, causing the compliance check to pass incorrectly.

    How to fix Access Control Bypass?

    Upgrade @hulumi/policies to version 1.4.0 or higher.

    <1.4.0
    • H
    Incorrect Comparison

    @hulumi/policies is a Pulumi CrossGuard policy packs for AWS, GitHub, Kubernetes, Cloudflare, and deployment governance. Includes HulumiHardeningPack, HulumiAwsOrgHardeningPack, state/backend/primitive/detection rules, GitHub packs, EKS packs, and platform governance. SLSA Bui

    Affected versions of this package are vulnerable to Incorrect Comparison in the policy validation process. An attacker can bypass intended policy enforcement by configuring an IAM role to trust multiple OIDC providers, causing the validation to incorrectly skip checks for overly permissive wildcard conditions.

    How to fix Incorrect Comparison?

    Upgrade @hulumi/policies to version 1.4.0 or higher.

    <1.4.0
    • H
    Protection Mechanism Failure

    @hulumi/policies is a Pulumi CrossGuard policy packs for AWS, GitHub, Kubernetes, Cloudflare, and deployment governance. Includes HulumiHardeningPack, HulumiAwsOrgHardeningPack, state/backend/primitive/detection rules, GitHub packs, EKS packs, and platform governance. SLSA Bui

    Affected versions of this package are vulnerable to Protection Mechanism Failure through the URN parsing process. An attacker can bypass mandatory hardening checks by crafting a logical name containing trusted substrings, causing policy exemptions to be incorrectly applied.

    How to fix Protection Mechanism Failure?

    Upgrade @hulumi/policies to version 1.4.0 or higher.

    <1.4.0