aws-sagemaker-transform-job-environment

Batch-transform job environment variables are plaintext and may expose data-source credentials.

awscritical service: aws:sagemaker emits ContainsCredential

Where it sits

locationDescribeTransformJob.Environment
location kindenvironment_variable
data kindscredential password api_key access_key secret_key connection_string
emits edgeContainsCredential
serviceSageMaker (aws:sagemaker)

Collection recipe

access moderead_api
operationDescribeTransformJob
response pathEnvironment
encodingmap
params{"TransformJobName": "\u003cjob-name\u003e"}

Required permissions

sagemaker:DescribeTransformJob

References

move · open · esc close