Automated AWS compliance guardrails using Service Control Policies and CloudFormation. Controls enforce audit log protection, encryption at rest, boundary protection, and least functionality, mapped to CJIS Security Policy v6.0, FedRAMP High baseline, and NIST 800-53 Rev. 5.
active 2026-03-08 → 2026-07-22 (UTC)
Activity over time
Daily event counts in the loaded window
Line chart, 137 days from 2026-03-08 to 2026-07-22. Pushes: 14 total, peak 3 in a day. Pull requests: 11 total, peak 4 in a day. Issues: 26 total, peak 10 in a day. Comments: 3 total, peak 2 in a day. Stars: 0 total, peak 0 in a day.
- Pushes
- Pull requests
- Issues
- Comments
- Stars
Stars, PRs, issues and forks are under-captured in the later part of this window. GH Archive progressively stopped capturing non-push events during 2026 — −95% or worse by the end of the window. Every series here except Pushes fades for that reason, so a decline above reflects the archive, not this repository. Pushes stay reliable throughout, so read them, and the contributor counts derived from them, as the real signal. Data health has the measurements.
Top contributors
Pushes, PRs, issues, reviews and comments — stars and forks excluded, so this is contribution rather than popularity
| Contributor | Contributions | Pushes | PRs | Comments |
|---|---|---|---|---|
| 0xBahalaNa | 51 | 14 | 11 | 0 |
| linear[bot] | 3 | 0 | 0 | 3 |
Recent activity
Latest issues, pull requests and releases
- Issue#320xBahalaNa2026-06-16 01:52docs: SCP scp-require-s3-encryption interaction with Layer 4 Config delivery in UseExisting mode
- Pull request#370xBahalaNa2026-06-10 00:48
- Pull request#370xBahalaNa2026-06-10 00:48
- Issue#310xBahalaNa2026-05-27 21:20feat: extend compliance/layer/project tag triple from Layer 1 to Layers 2-5
- Issue#200xBahalaNa2026-05-27 21:14feat: lockdown carve-out ergonomics (case-tolerant + multi-role)
- Issue#330xBahalaNa2026-05-27 20:11feat: Config bucket policy admin role parallel to BucketPolicyAdminRole
- Pull request#280xBahalaNa2026-05-27 16:51
- Issue comment#27linear[bot]2026-05-27 12:54docs: Layer 2 deploy-principal + bucket-policy lockdown recovery scenario
- Pull request#270xBahalaNa2026-05-27 12:54
- Issue#250xBahalaNa2026-05-27 04:52feat: export BucketPolicyAdminBoundaryArn for cross-stack consumers
- Issue#230xBahalaNa2026-05-27 04:51feat: anchor boundary Deny ARNs to prevent Path/ManagedPolicyName drift
- Issue#230xBahalaNa2026-05-27 04:51feat: anchor boundary Deny ARNs to prevent Path/ManagedPolicyName drift
- Issue#230xBahalaNa2026-05-27 04:51feat: anchor boundary Deny ARNs to prevent Path/ManagedPolicyName drift
- Issue#230xBahalaNa2026-05-27 04:51feat: anchor boundary Deny ARNs to prevent Path/ManagedPolicyName drift
- Issue comment#22linear[bot]2026-05-27 04:51feat: close sibling-role escalation via iam:CreatePolicy + PutRolePermissionsBoundary on un-listed roles
- Pull request#210xBahalaNa2026-05-27 04:50
- Pull request#160xBahalaNa2026-05-24 23:42
- Pull request#160xBahalaNa2026-05-24 23:42
- Pull request#160xBahalaNa2026-05-24 23:42
- Pull request#160xBahalaNa2026-05-24 23:42
- Issue comment#15linear[bot]2026-05-24 20:08feat: Layer 5 — GuardDuty + EventBridge + SNS + Security Hub (NIST 800-53)
- Pull request#140xBahalaNa2026-05-23 21:38
- Issue#100xBahalaNa2026-05-14 00:41Separate retention parameters for CloudTrail vs VPC Flow Logs
- Issue#40xBahalaNa2026-04-01 00:27#4: Deploy KMS CMK with service-level encryption defaults
- Issue#30xBahalaNa2026-04-01 00:27#3: Enforce IAM baseline and organization guardrails
Totals cover only the window loaded into ClickHouse and count events, not GitHub's lifetime totals — 0 stars here means stars gained during the window, not the repo's star count.