Skip to content

Add Lambda Function URL evidence fixtures#1480

Open
jddark62 wants to merge 1 commit into
UnitOneAI:mainfrom
jddark62:improve/aws-lambda-url-fixtures-1477
Open

Add Lambda Function URL evidence fixtures#1480
jddark62 wants to merge 1 commit into
UnitOneAI:mainfrom
jddark62:improve/aws-lambda-url-fixtures-1477

Conversation

@jddark62

@jddark62 jddark62 commented Jun 6, 2026

Copy link
Copy Markdown

Summary

  • adds supplemental AWS-LAMBDA-URL-* evidence gates for Lambda Function URL discovery, auth type, resource policy, caller policy, execution-role blast radius, VPC/dependency caveats, alternate event sources, and audit/change monitoring
  • keeps Lambda Function URL findings outside the CIS AWS Foundations v3.0.0 denominator in a supplemental AWS service findings table
  • adds calibration fixtures covering benign IAM-authenticated CloudFront/OAC-style access, unauthenticated admin URL exposure, broad caller policy, VPC-as-private false positives, alternate trigger/audit gaps, and Not Evaluable missing policy exports

Validation

  • git diff --check
  • verified SKILL.md frontmatter fields
  • verified Markdown fence balance and ASCII-only content for changed files
  • parsed all 6 YAML fixture blocks
  • verified required markers for AWS-LAMBDA-URL-01 through AWS-LAMBDA-URL-09, InvokeFunctionUrl, authorization_type, function_url_auth_type, AWS_IAM, NONE, VPC, CloudTrail, Not Evaluable, aws_lambda_function_url, and AWS::Lambda::Url
  • verified AWS Lambda reference links returned HTTP 200
  • privacy scan passed for changed files

/claim #1477

Payment details can be coordinated privately after maintainer acceptance.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant