Skip to content

Refresh secure delivery demo status copy - #6

Open
asarkar157 wants to merge 2 commits into
mainfrom
demo/application-rerun-advisory-trivy
Open

Refresh secure delivery demo status copy#6
asarkar157 wants to merge 2 commits into
mainfrom
demo/application-rerun-advisory-trivy

Conversation

@asarkar157

Copy link
Copy Markdown
Contributor

Fresh application PR for the advisory-Trivy security-controls rerun. The application code change is intentionally small and awaits human approval after controls and scans complete.

@asarkar157 asarkar157 added the demo-application Application PR eligible for secure delivery demo label Aug 14, 2026
@asarkar157 asarkar157 closed this Aug 14, 2026
@asarkar157 asarkar157 reopened this Aug 14, 2026
@asarkar157 asarkar157 closed this Aug 14, 2026
@asarkar157 asarkar157 reopened this Aug 14, 2026
@asarkar157 asarkar157 closed this Aug 14, 2026
@asarkar157 asarkar157 reopened this Aug 14, 2026
@asarkar157 asarkar157 closed this Aug 14, 2026
@asarkar157 asarkar157 reopened this Aug 14, 2026
@asarkar157

Copy link
Copy Markdown
Contributor Author

@/tmp/pr6-security-comment.md

@asarkar157 asarkar157 closed this Aug 14, 2026
@asarkar157 asarkar157 reopened this Aug 14, 2026
@asarkar157

Copy link
Copy Markdown
Contributor Author

Security controls were already present on main at d91cfb2fcb087ab8262a12895109ce77bffca4e6; no controls PR was created or merged.

Installed destination: .github/workflows/security-gate.yml (40deab4a078437f0a3e46d47d154248c6c715b44).

The security-gate required status check is enforced by the active talkdesk-demo-security-gate ruleset (ID 20855572). asarkar157 has pull-request-only bypass. The branch will now be updated.

@asarkar157 asarkar157 closed this Aug 14, 2026
@asarkar157 asarkar157 reopened this Aug 14, 2026
@asarkar157

Copy link
Copy Markdown
Contributor Author

Security review — gate allowed

Blocking: None. Gitleaks, Semgrep, tests, policies, and security-gate succeeded; required artifacts were present. No secrets, Semgrep findings, or dependency CVEs were reported.

Advisory Trivy IaC findings (infra/aws/main.tf; Trivy succeeded):

  • AWS-0104 Criticalaws_security_group.ec2: restrict egress CIDR ranges.
  • AWS-0053 Highaws_lb.demo: use an internal load balancer when public exposure is unnecessary.
  • AWS-0132 Highaws_s3_bucket_server_side_encryption_configuration.evidence: use SSE-KMS with a customer-managed key.
  • AWS-0164 Highaws_subnet.public[0], aws_subnet.public[1]: disable public IP assignment where not required.

Next: remediate the advisory infrastructure findings as appropriate. Security gate run · Gitleaks artifact · Semgrep artifact · Trivy artifact · Gate artifact

@asarkar157

Copy link
Copy Markdown
Contributor Author

@/tmp/pr6-security-comment.md

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

demo-application Application PR eligible for secure delivery demo

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant