aquasecurity / aquasecurity/cloudsploit
Propose to include AWS role to ensure credentials are not exposed for running the scans
Open
- Dominant language
- JavaScript
- Stars
- 3.8k
- Forks
- 751
- Avg merge
- 11d 9h
- Merged PRs (30d)
- 3
Description
An AWS role can be passed as a command line parameter (for STS assume role) to scan an account without creating/exposing access keys. It should not be a major code change and I can contribute if you are okay with it.
Contributor guide
Research direction
Start by tracing how the command-line scan parameters receive AWS credentials and review the existing AWS authentication flow for an STS assume-role option. Done means an AWS role can be supplied without creating or exposing access keys and the scan can run against the target account.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- aws, javascript
- Domain
- cloud, security
- Issue type
- Feature
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100