Skip to content

Replay Talkdesk security demo - #18

Open
asarkar157 wants to merge 2 commits into
mainfrom
demo-replay/31820378906-manual
Open

asarkar157 wants to merge 2 commits into
mainfrom
demo-replay/31820378906-manual

Conversation

@asarkar157

Copy link
Copy Markdown
Contributor

This PR is deliberately closed after reset. Reopen it to start a fresh security-controls bootstrap run. The only change is a harmless replay marker, which the next reset will revert.

@asarkar157 asarkar157 added the demo-application Application PR eligible for secure delivery demo label Aug 14, 2026
@asarkar157

Copy link
Copy Markdown
Contributor Author

Reset complete. Reopen this PR to trigger the next demo run.

@asarkar157 asarkar157 closed this Aug 14, 2026
@asarkar157 asarkar157 reopened this Aug 14, 2026
@asarkar157

Copy link
Copy Markdown
Contributor Author

Restarting the security-control bootstrap after its post-merge continuation fix was deployed.

@asarkar157 asarkar157 closed this Aug 14, 2026
@asarkar157 asarkar157 reopened this Aug 14, 2026
@asarkar157

Copy link
Copy Markdown
Contributor Author

Security controls audit

  • Verified control commit on main: 2795fc7e494d36e6008e6858a2ad430840656d16
  • Installed destination: .github/workflows/security-gate.yml
  • Required status check: security-gate
  • Ruleset status: unavailable (the dedicated talkdesk-demo-security-gate ruleset was not created)
  • The branch will now be updated with the verified main control.

@asarkar157

asarkar157 commented Aug 14, 2026 •

Copy link
Copy Markdown
Contributor Author

Security gate: allowed

Blocking findings: None. The aggregate security-gate allowed this SHA; Gitleaks and Semgrep reported no findings or scan errors. Typecheck, build, dependency audit, 8 tests, and all 10 OPA policy tests passed.

Advisory Trivy IaC findings — infra/aws/main.tf:

  • AWS-0104 — Critical: unrestricted security-group egress. Restrict outbound CIDRs, ports, protocols, and destinations.
  • AWS-0053 — High: internet-exposed load balancer. Confirm public exposure is required; otherwise use an internal load balancer and restrict ingress.
  • AWS-0132 — High: S3 encryption does not use a customer-managed KMS key. Use SSE-KMS with a CMK where appropriate.
  • AWS-0164 — High, deduplicated across two subnets: default public-IP association. Disable automatic public IP assignment for private workloads; use controlled public subnets only where needed.

Evidence: Security gate run 31822956850. The deterministic gate conclusion remains allowed.

@asarkar157 asarkar157 closed this Aug 14, 2026
@asarkar157 asarkar157 reopened this Aug 14, 2026
@asarkar157

Copy link
Copy Markdown
Contributor Author

Security controls verified on main at 2795fc7e494d36e6008e6858a2ad430840656d16.

  • Installed destination: .github/workflows/security-gate.yml
  • Required status check: security-gate
  • Ruleset status: configured — talkdesk-demo-security-gate (ID 20861724) requires the strict security-gate check; asarkar157 has pull-request-only bypass access.
  • The branch will now be updated with main.

@asarkar157

Copy link
Copy Markdown
Contributor Author

Security-gate branch update could not be applied: GitHub returned 422 There are no new commits on the base branch while PR head remained 90b1bd0a7bfcbd241e6aa09d52f6a1dd19eab586. The PR is reported as behind main; no force-push was performed. Please reconcile the branch update before continuing.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

demo-application Application PR eligible for secure delivery demo

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant