IA Squad
SearchPT
js · @hulumi/policiesCritical

@hulumi/policies <1.4.0: HULUMI-H5 exemption validation bypass

HULUMI-H5 policy in @hulumi/policies <1.

11 Jun 2026Read 1 minSeverity: act now

What changed

HULUMI-H5 policy in @hulumi/policies <1.4.0 only checked sibling resource types, not that they applied to the exempted bucket. Fixed in 1.4.0 by requiring sibling to share the same parent SecureBucket instance and reference the exempted bucket explicitly.

Who it affects

Consumers using HulumiHardeningPack with @hulumi/policies <1.4.0 who rely on the SecureBucket exemption for raw S3 buckets.

What to do today

Upgrade to @hulumi/[email protected] immediately to ensure HULUMI-H5 correctly validates sibling hardening resources apply to the exempted bucket.

The trail
Collected Audited Written Published