mirror of
https://github.com/tiennm99/miti99bot.git
synced 2026-06-08 18:16:54 +00:00
efe79be9ac
Captures the 2026-05-18 security review session output: - plans/reports/code-reviewer-260518-1019-security-aws-infra.md - plans/reports/code-reviewer-260518-1019-security-go-app.md - plans/reports/researcher-260518-1019-security-dependencies.md - docs/deploy-aws-free-tier-guide.md (adds free-tier hard rule + accepted security trade-offs as project standards) Plan for the two HIGH-severity findings (F1, F2) targeting github-deploy-miti99bot OIDC role: plans/260518-1019-iam-least-privilege/. Plan was red-team-reviewed (15 findings applied) and validate-interviewed (4 decisions recorded). Zero unresolved contradictions. Implementation not yet started; phase 1 is standalone and lowest risk. Other audit findings (F3 CORS, F4 root handler, F5-F16) deferred to future commits; rationale in audit report.