v3.114.0 - #2164
v3.114.0#2164
Conversation
… 6.2.3 (#2152) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
PR SummaryCursor Bugbot is generating a summary for commit 61e64f5. Configure here. |
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using default effort and found 3 potential issues.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 61e64f5. Configure here.
| return True | ||
|
|
||
| created_at = resource.get("TimeCreated") or resource.get("InstanceCreateTime") or "" | ||
| return resource.get("StorageType") == "aurora" and created_at >= AURORA_DEFAULT_ENCRYPTION_DATE |
There was a problem hiding this comment.
Date Does Not Prove Encryption
High Severity
created_at is treated as proof of Aurora encryption. Aurora clones, snapshots, or replicas from legacy unencrypted clusters can still remain unencrypted after the rollout date, so this can mark unencrypted resources compliant.
Reviewed by Cursor Bugbot for commit 61e64f5. Configure here.
| return True | ||
|
|
||
| created_at = resource.get("TimeCreated") or resource.get("InstanceCreateTime") or "" | ||
| return resource.get("StorageType") == "aurora" and created_at >= AURORA_DEFAULT_ENCRYPTION_DATE |
There was a problem hiding this comment.
I/O-Optimized Aurora Still Fails
Medium Severity
StorageType only matches aurora, so default-encrypted Aurora I/O-Optimized resources using aurora-iopt1 still fail when KmsKeyId is absent.
Reviewed by Cursor Bugbot for commit 61e64f5. Configure here.
| # on the instance resource, so only Aurora instances created on/after this date are exempted | ||
| # below - older Aurora instances still require an explicit KmsKeyId to be considered compliant. | ||
| # Ref: https://aws.amazon.com/blogs/database/use-default-encryption-at-rest-for-new-amazon-aurora-clusters/ # pylint: disable=line-too-long | ||
| AURORA_DEFAULT_ENCRYPTION_DATE = "2026-02-17" |
There was a problem hiding this comment.
Aurora Cutover Date Is Early
Medium Severity
AURORA_DEFAULT_ENCRYPTION_DATE is one day early. Aurora default encryption applies to clusters created on or after 2026-02-18, so resources from 2026-02-17 can be marked compliant incorrectly.
Reviewed by Cursor Bugbot for commit 61e64f5. Configure here.


Background
Changes
Testing