Skip to content

bug(TF-SSM Session Transit Encryption Disabled): kmsKeyId not detected when content is built with jsonencode() #8103

Description

@bemban1996

Found a bug? You're welcome to GitHub Discussions

  • Please make sure to:
    • Describe in details what the problem is
    • Attach a log file with relevant data preferably in DEBUG level (--log-level=DEBUG)
    • Attach the scanned sample files, anonymize the data if the original file cannot be provided
    • When attaching files to the issue make sure they are properly formatted

Expected Behavior

The query SSM Session Transit Encryption Disabled (ce60cc6b-6831-4bd7-84a2-cc7f8ee71433) should not report a result when an aws_ssm_document of document_type = "Session" sets inputs.kmsKeyId, regardless of whether the content attribute is written as a heredoc/JSON string literal or produced by the jsonencode() function. Both are valid and idiomatic Terraform and produce identical documents at apply time.

(Which results are expected from KICS?)

Actual Behavior

(Formatted logs and samples helps us to better understand the issue)

please see my below attached code for your testing

sample code positive - KICS (SSM Session Transit Encryption Disabled).txt

Steps to Reproduce the Problem

(Command line arguments and flags used)

  1. step 1
  2. step 2
  3. step 3

Specifications

(N/A if not applicable)

  • Version:
  • Platform:
  • Subsystem:

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingcommunityCommunity contribution

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions