aws-glue-job-default-arguments

Glue job argument maps are plaintext and commonly carry --password, --token, or connection values.

awscritical service: aws:glue emits ContainsCredential

Where it sits

locationGetJob.Job.DefaultArguments / NonOverridableArguments
location kindenvironment_variable
data kindscredential password api_key access_key secret_key connection_string
emits edgeContainsCredential
serviceGlue (aws:glue)

Collection recipe

access moderead_api
operationGetJob
response pathJob.{DefaultArguments,NonOverridableArguments}
encodingmap
params{"JobName": "\u003cjob-name\u003e"}

Required permissions

glue:GetJob

References

move · open · esc close