aws-codebuild-project-inline-buildspec

Inline buildspec YAML and command strings can contain hard-coded credentials.

awscritical service: aws:codebuild emits ContainsCredential

Where it sits

locationBatchGetProjects.projects[].source.buildspec / projects[].secondarySources[].buildspec
location kindtemplate_document
data kindssource_code_secret credential password api_key connection_string
emits edgeContainsCredential
serviceCodeBuild (aws:codebuild)

Collection recipe

access moderead_api
operationBatchGetProjects
response pathprojects[].source.buildspec / projects[].secondarySources[].buildspec
encodingyaml
params{"names": ["\u003cproject-name\u003e"]}

Required permissions

codebuild:BatchGetProjects

References

move · open · esc close