aws / aws/serverless-application-model
SAM Policy templates have outdated policies and they fail with cfn-lint
- Dominant language
- Python
- Stars
- 9.6k
- Forks
- 2.5k
- Avg merge
- 1d 11h
- Merged PRs (30d)
- 7
Description
### Description
SAM Policy templates have outdated policies and they fail with cfn-lint (version 1.30.0) The reason of failure is rule W3037.
Example: The SQSPollerPolicy:
```
"Statement": [
{
"Effect": "Allow",
"Action": [
"sqs:ChangeMessageVisibility",
"sqs:ChangeMessageVisibilityBatch",
"sqs:DeleteMessage",
"sqs:DeleteMessageBatch",
"sqs:GetQueueAttributes",
"sqs:ReceiveMessage"
],
"Resource": {
"Fn::Sub": [
"arn:${AWS::Partition}:sqs:${AWS::Region}:${AWS::AccountId}:${queueName}",
{
"queueName": {
"Ref": "QueueName"
}
}
]
}
}
]
```
### Steps to reproduce
use the following in a CFN template
```
SQSReader
Type: AWS::Serverless::Function
Properties:
CodeUri: ./thecode
Description: Parses Pulse events and writes them in the Staging bucket
Events:
TheQueue:
Type: SQS
Properties:
BatchSize: 10
Enabled: True
MaximumBatchingWindowInSeconds: 60
Queue: !GetAtt TheQueue.Arn
ScalingConfig:
MaximumConcurrency: 4
Handler: SomeClass:handleRequest
Policies:
- SQSPollerPolicy:
QueueName: !GetAtt PulseEventsStreamQueue.QueueName
Tracing: Active
```
### Observed result
The policy template has rights that no longer exist
### Expected result
A valid policy
### Additional environment details
1. OS: Linux
2. If using the [SAM CLI](https://github.com/aws/aws-sam-cli), `sam --version`:
3. AWS region: eu-west-1
Contributor guide
Assessment
This issue has not been assessed yet.