cloudsploit icon indicating copy to clipboard operation
cloudsploit copied to clipboard

CloudResourceManager plugins always return status OK regardless of policies configuration

Open nuhasha opened this issue 2 years ago • 1 comments

CloudResourceManager plugins don’t behave as expected in all test cases, it always give scan result OK but the reason is not accurate, as it indicates: No organization policies found which is not the case, as org policy is setup and the expected outcome here is OK because Org policy is enforced.

another example on disableAutomaticIAMGrants Plugin, change the environment setup, by not enforcing disableAutomaticIAMGrants , in this case, plugin must give fail result, for the reason disableAutomaticIAMGrants is not enforced, but again we get same OK result for reason, "No organization policies found"

nuhasha avatar Apr 28 '23 16:04 nuhasha

can I work on this?

NextThread avatar Aug 12 '23 18:08 NextThread