Control: CodeBuild projects should not use an user controlled buildspec
Description
This control checks if buildspec.yml is used from a trusted source which user cant interfere with.
Usage
Run the control in your terminal:
powerpipe control run aws_compliance.control.codebuild_project_with_user_controlled_buildspecSnapshot and share results via Turbot Pipes:
powerpipe loginpowerpipe control run aws_compliance.control.codebuild_project_with_user_controlled_buildspec --shareSQL
This control uses a named query:
select  arn as resource,  case    when split_part(source ->> 'Buildspec', '.', -1) = 'yml' then 'alarm'    else 'ok'  end as status,  case    when split_part(source ->> 'Buildspec', '.', -1) = 'yml' then title || ' uses a user controlled buildspec.'    else title || ' does not uses a user controlled buildspec.'  end as reason    , region, account_idfrom  aws_codebuild_project;