Skip to content

Improve IaC Pulumi and Bicep secret evidence gates#1368

Open
danyili2632 wants to merge 1 commit into
UnitOneAI:mainfrom
danyili2632:improve/iac-pulumi-bicep-secret-evidence
Open

Improve IaC Pulumi and Bicep secret evidence gates#1368
danyili2632 wants to merge 1 commit into
UnitOneAI:mainfrom
danyili2632:improve/iac-pulumi-bicep-secret-evidence

Conversation

@danyili2632
Copy link
Copy Markdown

Summary

  • addresses [REVIEW] iac-security: add Pulumi and Bicep evidence gates #1116 by adding Pulumi- and Bicep-specific secret evidence gates to iac-security
  • distinguishes safe Pulumi secret-tainted values from plaintext config reads, callback/log leakage, unsafe stack outputs, and weak secrets-provider posture
  • distinguishes safe Bicep @secure() parameters from plaintext secure inputs, list*() output leakage, module/script re-exposure, and deployment-history exposure
  • updates the report template with evidence-origin fields and Pulumi/Bicep posture summary fields

Validation

  • git diff --check
  • verified required markers for Pulumi secret-taint review, Python/TypeScript examples, Bicep secure inputs, list* output leakage, evidence-origin reporting, and output summary fields
  • verified Markdown fence counts are balanced

Bounty

  • Target tier: Improver Moderate ($100) if accepted
  • Preferred payment method: crypto, Base USDC 0x6CBF4b5cb88b8C2B7af776Bc2B073163B5d3C08A

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant