Skip to content

project

Stave

Stave is a policy-as-code engine that normalizes cloud and Kubernetes resources into typed assets and evaluates predicate-based controls against them.

Current stories

build1 publisher

Mastodon and Discourse write public-read S3 objects unless the deployer opts out

Stave flagged 47 security findings in the documented AWS defaults of Mastodon, Discourse and Chatwoot, according to a dev.to post. None of the three configures bucket encryption, access logging or Public Access Block, so whoever creates the bucket has to add them.

Publishers:dev.to

Reality

Evidence60
Adoption
Insufficient
Hype gap+25
Incentives
Insufficient
Confidence55