js · @hulumi/policiesCritical
@hulumi/policies <1.4.0: HULUMI-H5 exemption validation bypass
HULUMI-H5 policy in @hulumi/policies <1.
What changed
HULUMI-H5 policy in @hulumi/policies <1.4.0 only checked sibling resource types, not that they applied to the exempted bucket. Fixed in 1.4.0 by requiring sibling to share the same parent SecureBucket instance and reference the exempted bucket explicitly.
Who it affects
Consumers using HulumiHardeningPack with @hulumi/policies <1.4.0 who rely on the SecureBucket exemption for raw S3 buckets.
What to do today
Upgrade to @hulumi/[email protected] immediately to ensure HULUMI-H5 correctly validates sibling hardening resources apply to the exempted bucket.
The trail
Collected→
Audited→
Written→
Published