Skip to content

Conversation

bridgecrew-dev[bot]
Copy link

Bridgecrew has created this PR to fix supply chain risks found in the files of this project.

Changes included in this PR:

  • /go.mod
  • /go.sum
  • /package.json
  • /package-lock.json
  • /package-files/yarn/package.json
  • /main.tf:aws_s3_bucket.data
  • /main.tf:aws_s3_bucket.data
  • /main.tf:aws_s3_bucket.data
  • /main.tf:aws_s3_bucket.data
  • /main.tf:aws_s3_bucket.data
  • /main.tf:aws_s3_bucket.data_science
  • /main.tf:aws_s3_bucket.data_science
  • /main.tf:aws_s3_bucket.financials
  • /main.tf:aws_s3_bucket.financials
  • /main.tf:aws_s3_bucket.financials
  • /main.tf:aws_s3_bucket.financials
  • /main.tf:aws_s3_bucket.logs
  • /main.tf:aws_s3_bucket.logs
  • /main.tf:aws_s3_bucket.operations
  • /main.tf:aws_s3_bucket.operations
  • /main.tf:aws_s3_bucket.operations

Below are the Policies fixed in this PR:

🌈 Policy ✨ Details
Ensure all data stored in the S3 bucket have versioning enabled View
Ensure that S3 bucket has cross-region replication enabled View
Packages scan found vulnerabilities View
Ensure that S3 buckets are encrypted with KMS by default View
S3 Bucket has an ACL defined which allows public READ access. View
Ensure the S3 bucket has access logging enabled View
Please check the changes in this PR to ensure they do not introduce conflicts to your project.

For more information:
View this repository's Supply Chain Graph👀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants