Skip to content

fix(queries): correct mismatched expected/actual values across 22 queries - #8120

Merged
cx-artur-ribeiro merged 11 commits into
masterfrom
fix_queries_expected_actual_values
Oct 6, 2026
Merged

cx-artur-ribeiro merged 11 commits into
masterfrom
fix_queries_expected_actual_values

Conversation

@cx-artur-ribeiro

@cx-artur-ribeiro cx-artur-ribeiro commented Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

Reason for Proposed Changes

  • An audit of the query catalog found 22 queries where keyExpectedValue and/or keyActualValue were reversed, identical, or repeated a recommendation instead of describing the detected state, making findings confusing or misleading to users.

Proposed Changes

  • Fixed reversed expected/actual values in 5 queries: api_gateway_without_security_policy, sql_server_ingress_from_any_ip, iam_policy_on_user, iam_managed_policy_applied_to_a_user, and the two provisioner branches of ec2_instance_using_api_keys.
  • Fixed the same systemic reversal across 8 copied secret-exposure queries (Amplify, DocDB, DMS, Directory Service), and fixed a copy/paste bug in amplify_app_oauth_token_exposed where messages referenced BasicAuthConfig.Password instead of OauthToken.
  • Fixed security_requirement_object_with_wrong_scopes, which had identical expected and actual text.
  • Fixed 7 queries where keyActualValue repeated a recommendation instead of reporting the detected state: missing_version_specification_in_dnf_install, the 3 API Gateway usage-plan/access-log association queries, and the 3 ecs_service_without_running_tasks variants, and fixed a %&s format typo in the Ansible ECS query.
  • Fixed misleading actual-value phrasing in email_notifications_set_off.

I submit this contribution under the Apache-2.0 license.

@cx-artur-ribeiro cx-artur-ribeiro self-assigned this Sep 14, 2026
@cx-artur-ribeiro
cx-artur-ribeiro requested a review from a team September 14, 2026 07:48
@stepsecurity-app

stepsecurity-app Bot commented Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

✅ Resolved — a later workflow run passed this policy check.

Original alert (resolved)

Security Policy Alert: Actions Policy Violation

This workflow run has been blocked by StepSecurity's actions policy.

Disallowed Actions:

  • lots0logs/gh-action-get-changed-files@6cb5164a823dbf3318b7c8032a333b4b7ed425b2

To fix this issue, please modify the workflow to use only allowed actions. Contact your organization administrator to request changes to the allowed actions list if needed.

For more information, see StepSecurity's Actions Policy documentation.

@stepsecurity-app

stepsecurity-app Bot commented Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

✅ Resolved — a later workflow run passed this policy check.

Original alert (resolved)

Security Policy Alert: Secret Policy Violation

This workflow run has been blocked by StepSecurity's secrets policy because it accesses secrets and the workflow file differs from the default branch.

Secret references detected:

  • secrets.ECHO_LIBRARIES_ACCESS_KEY at line 31

To approve this workflow, please add the workflows-approved label to this PR.

Note: The label must be added by someone other than the PR author (cx-artur-ribeiro) or automation bots to ensure proper security review.

After the label is added, you can re-run the blocked workflow to proceed.

This workflow will be automatically approved once merged into the default branch.

For more information, see StepSecurity's Secret Exfiltration Policy documentation.

@cx-andre-pereira cx-andre-pereira left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@cx-andre-pereira cx-andre-pereira left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

Comment thread .github/workflows/validate-cfn-samples.yml
@cx-artur-ribeiro
cx-artur-ribeiro merged commit 438db3b into master Oct 6, 2026
39 of 42 checks passed
@cx-artur-ribeiro
cx-artur-ribeiro deleted the fix_queries_expected_actual_values branch October 6, 2026 09:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants