aws-cloudformation / aws-cloudformation/cloudformation-guard

[Enhancement] Specific lines of violation or list of code snippets

Open
#580 1 comment 0 reactions 0 assignees View on GitHub
enhancement
Dominant language
Rust
Stars
1.4k
Forks
196
Avg merge
3d 6h
Merged PRs (30d)
5

Description

**Is your feature request related to a problem? Please describe.**

No

**Describe the solution you'd like**

I would like for the output to give me specific code and line number for the Action that is failing the CloudFormation guard check on an IAM role instead of just pointing me to the line the policy/role starts on.

**Describe alternatives you've considered**

The way it is now get the job done, but could just be more efficient for the end-user. I don't think there is any way to set up the rules so that it fails on a specific action rather than failing the whole managed policy.

**Additional context**

Add any other context or screenshots about the feature request here.

Contributor guide

Open the contributing guide

Research direction

No file or test is named in the issue. Start by tracing the existing CloudFormation Guard violation-reporting path for IAM roles and managed policies, then inspect how source locations are selected. Done means a failing action includes its specific code and line number rather than only the policy or role location.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust
Domain
infrastructure, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.