Possible new rule for Tfsec #1145
jdsmithit
started this conversation in
Developement
Replies: 1 comment
-
This is now a rule 👍 See https://aquasecurity.github.io/tfsec/v0.61.3/checks/aws/iam/no-policy-wildcards/ |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Looking briefly at Tfsec I have noticed it allows you to assign 'resources = ["*"]' in the statement block, How does everyone feel about this being flagged as a security issue? I believe this goes against the principle of least privilege and assigning to more resources than should be needed?
Beta Was this translation helpful? Give feedback.
All reactions