Skip to content

v3.114.0 - #2164

Merged
arielkr256 merged 6 commits into
mainfrom
develop
Aug 27, 2026
Merged

arielkr256 merged 6 commits into
mainfrom
develop

Conversation

@zaynahsmith-dasilva

Copy link
Copy Markdown
Contributor

Background

Changes

Testing

dependabot Bot and others added 5 commits August 5, 2026 06:13
… 6.2.3 (#2152)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…2160)

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
@zaynahsmith-dasilva
zaynahsmith-dasilva requested review from a team as code owners August 27, 2026 14:47
@cursor

cursor Bot commented Aug 27, 2026

Copy link
Copy Markdown

PR Summary

Cursor Bugbot is generating a summary for commit 61e64f5. Configure here.

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using default effort and found 3 potential issues.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 61e64f5. Configure here.

return True

created_at = resource.get("TimeCreated") or resource.get("InstanceCreateTime") or ""
return resource.get("StorageType") == "aurora" and created_at >= AURORA_DEFAULT_ENCRYPTION_DATE

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Date Does Not Prove Encryption

High Severity

created_at is treated as proof of Aurora encryption. Aurora clones, snapshots, or replicas from legacy unencrypted clusters can still remain unencrypted after the rollout date, so this can mark unencrypted resources compliant.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 61e64f5. Configure here.

return True

created_at = resource.get("TimeCreated") or resource.get("InstanceCreateTime") or ""
return resource.get("StorageType") == "aurora" and created_at >= AURORA_DEFAULT_ENCRYPTION_DATE

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I/O-Optimized Aurora Still Fails

Medium Severity

StorageType only matches aurora, so default-encrypted Aurora I/O-Optimized resources using aurora-iopt1 still fail when KmsKeyId is absent.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 61e64f5. Configure here.

# on the instance resource, so only Aurora instances created on/after this date are exempted
# below - older Aurora instances still require an explicit KmsKeyId to be considered compliant.
# Ref: https://aws.amazon.com/blogs/database/use-default-encryption-at-rest-for-new-amazon-aurora-clusters/ # pylint: disable=line-too-long
AURORA_DEFAULT_ENCRYPTION_DATE = "2026-02-17"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Aurora Cutover Date Is Early

Medium Severity

AURORA_DEFAULT_ENCRYPTION_DATE is one day early. Aurora default encryption applies to clusters created on or after 2026-02-18, so resources from 2026-02-17 can be marked compliant incorrectly.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 61e64f5. Configure here.

@arielkr256
arielkr256 enabled auto-merge August 27, 2026 16:51
@arielkr256
arielkr256 merged commit d3c03a4 into main Aug 27, 2026
19 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

3 participants