Skip to content

[codex] Add full-pipeline verdict regressions#65

Merged
InfoSecHack merged 1 commit into
mainfrom
codex/full-pipeline-verdict-regressions
Jun 5, 2026
Merged

[codex] Add full-pipeline verdict regressions#65
InfoSecHack merged 1 commit into
mainfrom
codex/full-pipeline-verdict-regressions

Conversation

@InfoSecHack
Copy link
Copy Markdown
Owner

Summary

  • Adds hermetic integration regressions built from pipeline-shaped AccountData / OrgData inputs.
  • Covers PassRole Lambda iam:PassedToService glob handling, cross-account trust SCP filtering, dangling S3 bucket demotion, SCP source-account scoping, and frozen-artifact replay parity.
  • Keeps the slice tests-only: no live AWS, Terraform, benchmark semantic changes, scores, or production claims.

Validation

  • python -m pytest -q tests/integration/test_full_pipeline_reasoner_verdicts.py → 6 passed
  • python -m pytest -q tests/test_passrole_lambda_reasoner.py tests/test_passrole_ecs_reasoner.py tests/test_cross_account_reasoner.py tests/test_s3_bucket_takeover_reasoner.py tests/test_scp_binder.py → 175 passed
  • ./scripts/check.sh → passed
  • ./scripts/test_fast.sh → 2005 passed
  • git diff --check → passed
  • account/ARN hygiene scans → clean
  • Terraform/raw artifact scan → clean

@InfoSecHack InfoSecHack marked this pull request as ready for review June 5, 2026 20:33
@InfoSecHack InfoSecHack merged commit a67ff8c into main Jun 5, 2026
6 checks passed
@InfoSecHack InfoSecHack deleted the codex/full-pipeline-verdict-regressions branch June 5, 2026 20:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant