We release patches for security vulnerabilities for the following versions:
| Version | Supported |
|---|---|
| 1.x.x | ✅ |
| < 1.0 | ❌ |
We take security vulnerabilities seriously. If you discover a security issue, please follow these steps:
Please do not open a public issue or disclose the vulnerability publicly until we have had a chance to address it.
Send a detailed report to the project maintainers via:
- GitHub Security Advisories (preferred)
- Email to the project maintainers
- Private message on GitHub
Your report should include:
- Description of the vulnerability
- Steps to reproduce the issue
- Potential impact
- Suggested fixes (if any)
- Your contact information
- 24 hours: Initial acknowledgment
- 72 hours: Preliminary assessment
- 7 days: Detailed response with timeline
- 30 days: Security patch release (target)
This module follows security best practices:
- Least Privilege: IAM roles and policies grant minimal required permissions
- Encryption: CloudWatch logs can be encrypted
- Resource Isolation: Proper resource naming and tagging
- Audit Logging: CloudWatch logging enabled by default
This project uses multiple security tools:
- tfsec: Terraform static analysis
- Checkov: Infrastructure as code scanning
- Trivy: Vulnerability and misconfiguration scanning
- Gitleaks: Secret detection in commits
- Dependency Review: GitHub dependency scanning
All pull requests are automatically scanned for:
- Terraform security misconfigurations
- Hardcoded secrets and credentials
- Vulnerable dependencies
- Infrastructure vulnerabilities
When using this module:
- IAM Permissions: Review and customize IAM policies for your use case
- Encryption: Enable encryption at rest and in transit where needed
- Secrets Management: Use AWS Secrets Manager or Parameter Store
- Resource Policies: Implement resource-based policies appropriately
- Monitoring: Enable CloudWatch alarms and AWS CloudTrail
- Store state in encrypted S3 buckets
- Enable versioning on state buckets
- Use DynamoDB for state locking
- Restrict access to state files
- Never commit state files to version control
module "secure_lambda" {
source = "./opentofu"
function_name = "secure-processor"
source_code_path = "lambda.zip"
# Use environment variables from Secrets Manager
environment_variables = {
SECRET_ARN = data.aws_secretsmanager_secret.example.arn
}
# Comprehensive tagging
tags = {
Environment = "production"
Compliance = "required"
DataClass = "confidential"
}
}The default Lambda execution role includes:
- CloudWatch Logs write permissions
- Event source read permissions (SQS, DynamoDB, Kinesis)
Recommendation: Extend the IAM policy for application-specific permissions.
By default, SQS queues use SSE (Server-Side Encryption) with AWS managed keys.
Recommendation: Use customer-managed KMS keys for sensitive data.
Failed messages are sent to a DLQ if configured.
Recommendation: Implement DLQ monitoring and alerting.
This module can help meet various compliance requirements:
- SOC 2: Audit logging, access controls
- HIPAA: Encryption, secure configuration
- PCI DSS: Network segmentation, monitoring
- GDPR: Data encryption, access controls
Note: Compliance is a shared responsibility. Review your specific requirements.
- Security patches are released as soon as possible
- Subscribe to GitHub releases for notifications
- Review CHANGELOG.md for security-related updates
- Update to the latest version regularly
- AWS Lambda Security Best Practices
- Terraform Security
- OWASP Serverless Top 10
- CIS AWS Foundations Benchmark
For security concerns, contact the maintainers via:
- GitHub Security Advisories
- Project issue tracker (for non-sensitive issues)
Thank you for helping keep this project secure!