Skip to content

Commit c604b70

Browse files
authored
fix: Flipped condition on secrets manager policy (#13862)
for issue #13773
1 parent 76c21fb commit c604b70

2 files changed

Lines changed: 4 additions & 4 deletions

File tree

plugins/source/aws/policies/queries/secretsmanager/remove_unused_secrets_manager_secrets.sql

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ select
77
account_id,
88
arn as resource_id,
99
case when
10-
(last_accessed_date is null and created_date > now() - INTERVAL '90 days')
11-
or (last_accessed_date is not null and last_accessed_date > now() - INTERVAL '90 days')
10+
(last_accessed_date is null and created_date < now() - INTERVAL '90 days')
11+
or (last_accessed_date is not null and last_accessed_date < now() - INTERVAL '90 days')
1212
then 'fail' else 'pass' end as status
1313
from aws_secretsmanager_secrets

website/tables/aws/aws_secretsmanager_secrets.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -53,11 +53,11 @@ SELECT
5353
CASE
5454
WHEN (
5555
last_accessed_date IS NULL
56-
AND created_date > now() - '90 days'::INTERVAL
56+
AND created_date < now() - '90 days'::INTERVAL
5757
)
5858
OR (
5959
last_accessed_date IS NOT NULL
60-
AND last_accessed_date > now() - '90 days'::INTERVAL
60+
AND last_accessed_date < now() - '90 days'::INTERVAL
6161
)
6262
THEN 'fail'
6363
ELSE 'pass'

0 commit comments

Comments
 (0)