diff --git a/src/iam_sarif_report/checks.json b/src/iam_sarif_report/checks.json index 1459d3f..5606be5 100644 --- a/src/iam_sarif_report/checks.json +++ b/src/iam_sarif_report/checks.json @@ -711,7 +711,7 @@ "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/access-analyzer-reference-policy-checks.html#access-analyzer-reference-policy-checks-security-warning-string-like-operator-with-arn-condition-keys", "name": "StringLikeOperatorWithArnConditionKeys", "short_description": "AWS recommends that you use ARN operators instead of string operators when\ncomparing ARNs to ensure proper access restriction based on ARN condition\nvalues. Update the `StringLike` operator to the `ArnLike` operator in your\n`Condition` element whenever the specified key is used.", - "description": "AWS recommends that you use ARN operators instead of string operators when\ncomparing ARNs to ensure proper access restriction based on ARN condition\nvalues. Update the `StringLike` operator to the `ArnLike` operator in your\n`Condition` element whenever the specified key is used.\n\nThese AWS managed policies are exceptions to this security warning:\n\n * [AmazonSecurityLakeAdministrator](https://docs.aws.amazon.com/aws-managed-policy/latest/reference/AmazonSecurityLakeAdministrator.html)\n\n * [AWSCertificateManagerPrivateCAPrivilegedUser](https://docs.aws.amazon.com/aws-managed-policy/latest/reference/AWSCertificateManagerPrivateCAPrivilegedUser.html)\n\n * [AWSCertificateManagerPrivateCAUser](https://docs.aws.amazon.com/aws-managed-policy/latest/reference/AWSCertificateManagerPrivateCAUser.html)\n\n * [AWSCodeCommitFullAccess](https://docs.aws.amazon.com/aws-managed-policy/latest/reference/AWSCodeCommitFullAccess.html)\n\n * [AWSCodeCommitPowerUser](https://docs.aws.amazon.com/aws-managed-policy/latest/reference/AWSCodeCommitPowerUser.html)\n\n * [AWSCodeCommitReadOnly](https://docs.aws.amazon.com/aws-managed-policy/latest/reference/AWSCodeCommitReadOnly.html)\n\n * [AWSCodePipeline_FullAccess](https://docs.aws.amazon.com/aws-managed-policy/latest/reference/AWSCodePipeline_FullAccess.html)\n\n * [AWSCodePipeline_ReadOnlyAccess](https://docs.aws.amazon.com/aws-managed-policy/latest/reference/AWSCodePipeline_ReadOnlyAccess.html)\n\n * [AWSEC2CapacityReservationFleetRolePolicy](https://docs.aws.amazon.com/aws-managed-policy/latest/reference/AWSEC2CapacityReservationFleetRolePolicy.html)\n\n * [AWSLakeFormationCrossAccountManager](https://docs.aws.amazon.com/aws-managed-policy/latest/reference/AWSLakeFormationCrossAccountManager.html)\n\n * [AWSMarketplaceFullAccess](https://docs.aws.amazon.com/aws-managed-policy/latest/reference/AWSMarketplaceFullAccess.html)\n\n * [AWSMarketplaceImageBuildFullAccess](https://docs.aws.amazon.com/aws-managed-policy/latest/reference/AWSMarketplaceImageBuildFullAccess.html)\n\n * [AWSPrivateCAPrivilegedUser](https://docs.aws.amazon.com/aws-managed-policy/latest/reference/AWSPrivateCAPrivilegedUser.html)\n\n * [AWSPrivateCAUser](https://docs.aws.amazon.com/aws-managed-policy/latest/reference/AWSPrivateCAUser.html)\n\n * [S3UnlockBucketPolicy](https://docs.aws.amazon.com/aws-managed-policy/latest/reference/S3UnlockBucketPolicy.html)\n\n * [SecurityLakeResourceManagementServiceRolePolicy](https://docs.aws.amazon.com/aws-managed-policy/latest/reference/SecurityLakeResourceManagementServiceRolePolicy.html)\n\n * [SQSUnlockQueuePolicy](https://docs.aws.amazon.com/aws-managed-policy/latest/reference/SQSUnlockQueuePolicy.html)\n\n**Related terms**\n\n * [Amazon Resource Name (ARN) condition operators](https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_elements_condition_operators.html#Conditions_ARN)\n\n * [String condition operators](https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_elements_condition_operators.html#Conditions_String)\n\n * [AWS managed policies](https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_managed-vs-inline.html#aws-managed-policies)" + "description": "AWS recommends that you use ARN operators instead of string operators when\ncomparing ARNs to ensure proper access restriction based on ARN condition\nvalues. Update the `StringLike` operator to the `ArnLike` operator in your\n`Condition` element whenever the specified key is used.\n\nThese AWS managed policies are exceptions to this security warning:\n\n * [AmazonSecurityLakeAdministrator](https://docs.aws.amazon.com/aws-managed-policy/latest/reference/AmazonSecurityLakeAdministrator.html)\n\n * [AWSCertificateManagerPrivateCAPrivilegedUser](https://docs.aws.amazon.com/aws-managed-policy/latest/reference/AWSCertificateManagerPrivateCAPrivilegedUser.html)\n\n * [AWSCertificateManagerPrivateCAUser](https://docs.aws.amazon.com/aws-managed-policy/latest/reference/AWSCertificateManagerPrivateCAUser.html)\n\n * [AWSCodePipeline_FullAccess](https://docs.aws.amazon.com/aws-managed-policy/latest/reference/AWSCodePipeline_FullAccess.html)\n\n * [AWSCodePipeline_ReadOnlyAccess](https://docs.aws.amazon.com/aws-managed-policy/latest/reference/AWSCodePipeline_ReadOnlyAccess.html)\n\n * [AWSEC2CapacityReservationFleetRolePolicy](https://docs.aws.amazon.com/aws-managed-policy/latest/reference/AWSEC2CapacityReservationFleetRolePolicy.html)\n\n * [AWSLakeFormationCrossAccountManager](https://docs.aws.amazon.com/aws-managed-policy/latest/reference/AWSLakeFormationCrossAccountManager.html)\n\n * [AWSMarketplaceFullAccess](https://docs.aws.amazon.com/aws-managed-policy/latest/reference/AWSMarketplaceFullAccess.html)\n\n * [AWSMarketplaceImageBuildFullAccess](https://docs.aws.amazon.com/aws-managed-policy/latest/reference/AWSMarketplaceImageBuildFullAccess.html)\n\n * [AWSPrivateCAPrivilegedUser](https://docs.aws.amazon.com/aws-managed-policy/latest/reference/AWSPrivateCAPrivilegedUser.html)\n\n * [AWSPrivateCAUser](https://docs.aws.amazon.com/aws-managed-policy/latest/reference/AWSPrivateCAUser.html)\n\n * [S3UnlockBucketPolicy](https://docs.aws.amazon.com/aws-managed-policy/latest/reference/S3UnlockBucketPolicy.html)\n\n * [SecurityLakeResourceManagementServiceRolePolicy](https://docs.aws.amazon.com/aws-managed-policy/latest/reference/SecurityLakeResourceManagementServiceRolePolicy.html)\n\n * [SQSUnlockQueuePolicy](https://docs.aws.amazon.com/aws-managed-policy/latest/reference/SQSUnlockQueuePolicy.html)\n\n**Related terms**\n\n * [Amazon Resource Name (ARN) condition operators](https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_elements_condition_operators.html#Conditions_ARN)\n\n * [String condition operators](https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_elements_condition_operators.html#Conditions_String)\n\n * [AWS managed policies](https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_managed-vs-inline.html#aws-managed-policies)" }, "suggestion_empty_array_action": { "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/access-analyzer-reference-policy-checks.html#access-analyzer-reference-policy-checks-suggestion-empty-array-action",