IA Squad
SearchPT
js · @hulumi/policiesCritical

@hulumi/policies: AWS IAM trust policy multi-provider detection fix

AWS IAM trust policies listing multiple federated identity providers (e.

11 Jun 2026Read 1 minSeverity: act now

What changed

AWS IAM trust policies listing multiple federated identity providers (e.g., GitHub Actions OIDC and Google OIDC) were not correctly recognized by G_OIDC_1 and G_OIDC_2 policy rules. The providers list was coerced into a single comma-joined string, causing the matcher to miss the GitHub OIDC ARN. This allowed wildcard sub: conditions to pass undetected.

Who it affects

Users of @hulumi/policies < 1.4.0 who use HulumiHardeningPack or HulumiGithubHardeningPack and have IAM roles with multiple federated identity providers in the trust policy.

What to do today

Upgrade to @hulumi/[email protected] immediately.

The trail
Collected Audited Written Published