{"_id":"@actsecurity/iam-simulate","_rev":"5-09ca1926a2e26dfdfb47c9e7f943e77a","name":"@actsecurity/iam-simulate","dist-tags":{"latest":"0.1.177"},"versions":{"0.1.173":{"name":"@actsecurity/iam-simulate","version":"0.1.173","keywords":["AWS","IAM"],"author":{"name":"David Kerber","email":"dave@cloudcopilot.io"},"license":"AGPL-3.0-or-later","_id":"@actsecurity/iam-simulate@0.1.173","maintainers":[{"name":"act-security-svc-user","email":"svc-user@act.security"},{"name":"daveatact","email":"david.kerber@act.security"},{"name":"elran.shefer","email":"elran.shefer@act.security"}],"homepage":"https://github.com/actsecurity/iam-simulate#readme","bugs":{"url":"https://github.com/actsecurity/iam-simulate/issues"},"dist":{"shasum":"e4ba7f7d9c91e0818c7ba42c2aa9effacc60ea53","tarball":"https://registry.npmjs.org/@actsecurity/iam-simulate/-/iam-simulate-0.1.173.tgz","fileCount":597,"integrity":"sha512-XdcvoUglxbiTOR9tEHovo1WOUx9LHz1HYFZcUHYpSD9KlBLn8yd88QEPx48P2VDj3x0cdPVaUHkQ0/oiyi277w==","signatures":[{"sig":"MEQCID59c1eHRUkJp1IgKkm5qqTM249RWNn2owqFUbQgxS9cAiA7zPN3HywFnO1IR6FGsWgVh75Cz1Z0rHQDDO2VfNt3Lg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1315999},"types":"dist/cjs/index.d.ts","exports":{".":{"import":"./dist/esm/index.js","require":"./dist/cjs/index.js"}},"gitHead":"35f783afe9bb74832018ef054fed14bb7a1dc82d","release":{"plugins":[["@semantic-release/commit-analyzer",{"releaseRules":[{"type":"feat","release":"patch"},{"type":"fix","release":"patch"},{"release":"patch","breaking":true},{"type":"*","release":"patch"}]}],"@semantic-release/release-notes-generator","@semantic-release/changelog",["@semantic-release/npm",{"npmPublish":true}],["@semantic-release/exec",{"successCmd":"echo published=true >> $GITHUB_OUTPUT && echo version=${nextRelease.version} >> $GITHUB_OUTPUT && echo package_name=$(node -p \"require('./package.json').name\") >> $GITHUB_OUTPUT"}],["@semantic-release/git",{"assets":["package.json","package-lock.json","CHANGELOG.md"],"message":"chore(release): ${nextRelease.version} [skip ci]"}],["@semantic-release/github",{"assets":[]}]],"branches":["main"]},"scripts":{"test":"npx vitest --run --coverage","build":"npx tsc -p tsconfig.cjs.json && npx tsc -p tsconfig.esm.json && ./postbuild.sh","clean":"rm -rf dist","format":"npx prettier --write src/","release":"npm run clean && npm run build && npm run test && npm run format-check && npm publish","format-check":"npx prettier --check src/"},"_npmUser":{"name":"daveatact","email":"david.kerber@act.security"},"prettier":"@actsecurity/prettier-config","repository":{"url":"git+https://github.com/actsecurity/iam-simulate.git","type":"git"},"_npmVersion":"11.17.0","description":"Simulate evaluation of AWS IAM policies","directories":{},"_nodeVersion":"26.5.0","dependencies":{"@actsecurity/iam-data":">=0.15.202511222 <1.0.0","@actsecurity/iam-utils":"^0.1.78","@actsecurity/iam-policy":"^0.1.89"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.0.18","typescript":"^5.5.4","@types/node":"^22.5.0","semantic-release":"^25.0.3","@vitest/coverage-v8":"^4.0.18","@semantic-release/git":"^10.0.1","@semantic-release/npm":"^13.1.4","@semantic-release/exec":"^7.1.0","@semantic-release/github":"^12.0.6","@semantic-release/changelog":"^6.0.3","@actsecurity/prettier-config":"^0.1.1","@semantic-release/commit-analyzer":"^13.0.1","@semantic-release/release-notes-generator":"^14.0.3"},"_npmOperationalInternal":{"tmp":"tmp/iam-simulate_0.1.173_1788244288235_0.17993469900984804","host":"s3://npm-registry-packages-npm-production"}},"0.1.174":{"name":"@actsecurity/iam-simulate","version":"0.1.174","keywords":["AWS","IAM"],"author":{"name":"David Kerber","email":"dave@cloudcopilot.io"},"license":"AGPL-3.0-or-later","_id":"@actsecurity/iam-simulate@0.1.174","maintainers":[{"name":"act-security-svc-user","email":"svc-user@act.security"},{"name":"daveatact","email":"david.kerber@act.security"},{"name":"elran.shefer","email":"elran.shefer@act.security"}],"homepage":"https://github.com/act-security-labs/iam-simulate#readme","bugs":{"url":"https://github.com/act-security-labs/iam-simulate/issues"},"dist":{"shasum":"5c65cfa5af45b0a8953d37c57781461d088933ec","tarball":"https://registry.npmjs.org/@actsecurity/iam-simulate/-/iam-simulate-0.1.174.tgz","fileCount":597,"integrity":"sha512-eKnwy9ywpkkVc4NPpzsP7bFF0hjlwhH1fT21Pe1rhBr0uN1kuREL8bgtH7kzUIEJINEy1PgOpSZakTZGvDz+JA==","signatures":[{"sig":"MEQCIHILJNknzBkrqxt6TM4RveAOeQLHjff8bUev3AGtE5PDAiAn40ojyBA/TmwgesmkH6/bCWp4VTwNW3+9kr0IdVhMrA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@actsecurity%2fiam-simulate@0.1.174","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1316034},"types":"dist/cjs/index.d.ts","exports":{".":{"import":"./dist/esm/index.js","require":"./dist/cjs/index.js"}},"gitHead":"b5b8bdac7f009989233f7bfc053d231365216933","release":{"plugins":[["@semantic-release/commit-analyzer",{"releaseRules":[{"type":"feat","release":"patch"},{"type":"fix","release":"patch"},{"release":"patch","breaking":true},{"type":"*","release":"patch"}]}],"@semantic-release/release-notes-generator","@semantic-release/changelog",["@semantic-release/npm",{"npmPublish":true}],["@semantic-release/exec",{"successCmd":"echo published=true >> $GITHUB_OUTPUT && echo version=${nextRelease.version} >> $GITHUB_OUTPUT && echo package_name=$(node -p \"require('./package.json').name\") >> $GITHUB_OUTPUT"}],["@semantic-release/git",{"assets":["package.json","package-lock.json","CHANGELOG.md"],"message":"chore(release): ${nextRelease.version} [skip ci]"}],["@semantic-release/github",{"assets":[]}]],"branches":["main"]},"scripts":{"test":"npx vitest --run --coverage","build":"npx tsc -p tsconfig.cjs.json && npx tsc -p tsconfig.esm.json && ./postbuild.sh","clean":"rm -rf dist","format":"npx prettier --write src/","release":"npm run clean && npm run build && npm run test && npm run format-check && npm publish","format-check":"npx prettier --check src/"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:d08abd7d-7a13-4cd1-a287-9927f5817248"}},"prettier":"@actsecurity/prettier-config","repository":{"url":"git+https://github.com/act-security-labs/iam-simulate.git","type":"git"},"_npmVersion":"11.19.1","description":"Simulate evaluation of AWS IAM policies","directories":{},"_nodeVersion":"26.8.1","dependencies":{"@actsecurity/iam-data":">=0.15.202511222 <1.0.0","@actsecurity/iam-utils":"^0.1.78","@actsecurity/iam-policy":"^0.1.89"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.0.18","typescript":"^5.5.4","@types/node":"^22.5.0","semantic-release":"^25.0.3","@vitest/coverage-v8":"^4.0.18","@semantic-release/git":"^10.0.1","@semantic-release/npm":"^13.1.4","@semantic-release/exec":"^7.1.0","@semantic-release/github":"^12.0.6","@semantic-release/changelog":"^6.0.3","@actsecurity/prettier-config":"^0.1.1","@semantic-release/commit-analyzer":"^13.0.1","@semantic-release/release-notes-generator":"^14.0.3"},"_npmOperationalInternal":{"tmp":"tmp/iam-simulate_0.1.174_1788274375414_0.713179835623478","host":"s3://npm-registry-packages-npm-production"}},"0.1.175":{"name":"@actsecurity/iam-simulate","version":"0.1.175","keywords":["AWS","IAM"],"author":{"name":"David Kerber","email":"dave@cloudcopilot.io"},"license":"AGPL-3.0-or-later","_id":"@actsecurity/iam-simulate@0.1.175","maintainers":[{"name":"act-security-svc-user","email":"svc-user@act.security"},{"name":"daveatact","email":"david.kerber@act.security"},{"name":"elran.shefer","email":"elran.shefer@act.security"}],"homepage":"https://github.com/act-security-labs/iam-simulate#readme","bugs":{"url":"https://github.com/act-security-labs/iam-simulate/issues"},"dist":{"shasum":"613af9439509d0d45fe34d1b73c1d3f384890b7d","tarball":"https://registry.npmjs.org/@actsecurity/iam-simulate/-/iam-simulate-0.1.175.tgz","fileCount":597,"integrity":"sha512-dNZQJ28HQ84urCiONhcT0Fwa5ZDFiERhNRQc/HOBSrI6Dw11e7NHvsIrogg5xmUWhVRhfwg6sMr2JDM2ysWRag==","signatures":[{"sig":"MEUCIG5a/97CSF8F424fM4QeDMvXyzJk3SWqO4+c58auLnU2AiEAp7s2museuIBHMtvPXMNDgJIfgovid8dhL1/m5MZu7tg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@actsecurity%2fiam-simulate@0.1.175","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1317698},"types":"dist/cjs/index.d.ts","exports":{".":{"import":"./dist/esm/index.js","require":"./dist/cjs/index.js"}},"gitHead":"e9480fd7a09af1a705762f90563fa755be955b35","release":{"plugins":[["@semantic-release/commit-analyzer",{"releaseRules":[{"type":"feat","release":"patch"},{"type":"fix","release":"patch"},{"release":"patch","breaking":true},{"type":"*","release":"patch"}]}],"@semantic-release/release-notes-generator","@semantic-release/changelog",["@semantic-release/npm",{"npmPublish":true}],["@semantic-release/exec",{"successCmd":"echo published=true >> $GITHUB_OUTPUT && echo version=${nextRelease.version} >> $GITHUB_OUTPUT && echo package_name=$(node -p \"require('./package.json').name\") >> $GITHUB_OUTPUT"}],["@semantic-release/git",{"assets":["package.json","package-lock.json","CHANGELOG.md"],"message":"chore(release): ${nextRelease.version} [skip ci]"}],["@semantic-release/github",{"assets":[]}]],"branches":["main"]},"scripts":{"test":"npx vitest --run --coverage","build":"npx tsc -p tsconfig.cjs.json && npx tsc -p tsconfig.esm.json && ./postbuild.sh","clean":"rm -rf dist","format":"npx prettier --write src/","release":"npm run clean && npm run build && npm run test && npm run format-check && npm publish","format-check":"npx prettier --check src/"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:d08abd7d-7a13-4cd1-a287-9927f5817248"}},"prettier":"@actsecurity/prettier-config","repository":{"url":"git+https://github.com/act-security-labs/iam-simulate.git","type":"git"},"_npmVersion":"11.19.1","description":"Simulate evaluation of AWS IAM policies","directories":{},"_nodeVersion":"26.8.1","dependencies":{"@actsecurity/iam-data":">=0.15.202511222 <1.0.0","@actsecurity/iam-utils":"^0.1.78","@actsecurity/iam-policy":"^0.1.89"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.0.18","typescript":"^5.5.4","@types/node":"^22.5.0","semantic-release":"^25.0.3","@vitest/coverage-v8":"^4.0.18","@semantic-release/git":"^10.0.1","@semantic-release/npm":"^13.1.4","@semantic-release/exec":"^7.1.0","@semantic-release/github":"^12.0.6","@semantic-release/changelog":"^6.0.3","@actsecurity/prettier-config":"^0.1.1","@semantic-release/commit-analyzer":"^13.0.1","@semantic-release/release-notes-generator":"^14.0.3"},"_npmOperationalInternal":{"tmp":"tmp/iam-simulate_0.1.175_1788770399812_0.8370251499840322","host":"s3://npm-registry-packages-npm-production"}},"0.1.176":{"name":"@actsecurity/iam-simulate","version":"0.1.176","keywords":["AWS","IAM"],"author":{"name":"David Kerber","email":"dave@cloudcopilot.io"},"license":"AGPL-3.0-or-later","_id":"@actsecurity/iam-simulate@0.1.176","maintainers":[{"name":"act-security-svc-user","email":"svc-user@act.security"},{"name":"daveatact","email":"david.kerber@act.security"},{"name":"elran.shefer","email":"elran.shefer@act.security"}],"homepage":"https://github.com/act-security-labs/iam-simulate#readme","bugs":{"url":"https://github.com/act-security-labs/iam-simulate/issues"},"dist":{"shasum":"1745e1a1c19d46f6daf3e932fe6d311e2d2a3a86","tarball":"https://registry.npmjs.org/@actsecurity/iam-simulate/-/iam-simulate-0.1.176.tgz","fileCount":597,"integrity":"sha512-oFgsgZ7ezOLm87XFO/T9l09h0bgPLJ1KIvTuU+Yk8BY4HM+b58nJfh/y9SgyDsYYfZuISLqkp3YM2+GGytahow==","signatures":[{"sig":"MEUCIQCxhj2mhGLYXga20JRYddxnRcIzJ13qKsSw9g84KeWegAIgVb2GyjLPvtN4MmoZrW3I/taUA8z/8i6oPCmz7NgTP48=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@actsecurity%2fiam-simulate@0.1.176","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1322445},"types":"dist/cjs/index.d.ts","exports":{".":{"import":"./dist/esm/index.js","require":"./dist/cjs/index.js"}},"gitHead":"4ce07ac7f5a3b9e5de580346372fbe608490fe92","release":{"plugins":[["@semantic-release/commit-analyzer",{"releaseRules":[{"type":"feat","release":"patch"},{"type":"fix","release":"patch"},{"release":"patch","breaking":true},{"type":"*","release":"patch"}]}],"@semantic-release/release-notes-generator","@semantic-release/changelog",["@semantic-release/npm",{"npmPublish":true}],["@semantic-release/exec",{"successCmd":"echo published=true >> $GITHUB_OUTPUT && echo version=${nextRelease.version} >> $GITHUB_OUTPUT && echo package_name=$(node -p \"require('./package.json').name\") >> $GITHUB_OUTPUT"}],["@semantic-release/git",{"assets":["package.json","package-lock.json","CHANGELOG.md"],"message":"chore(release): ${nextRelease.version} [skip ci]"}],["@semantic-release/github",{"assets":[]}]],"branches":["main"]},"scripts":{"test":"npx vitest --run --coverage","build":"npx tsc -p tsconfig.cjs.json && npx tsc -p tsconfig.esm.json && ./postbuild.sh","clean":"rm -rf dist","format":"npx prettier --write src/","release":"npm run clean && npm run build && npm run test && npm run format-check && npm publish","format-check":"npx prettier --check src/"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:d08abd7d-7a13-4cd1-a287-9927f5817248"}},"prettier":"@actsecurity/prettier-config","repository":{"url":"git+https://github.com/act-security-labs/iam-simulate.git","type":"git"},"_npmVersion":"11.19.1","description":"Simulate evaluation of AWS IAM policies","directories":{},"_nodeVersion":"26.8.1","dependencies":{"@actsecurity/iam-data":">=0.15.202511222 <1.0.0","@actsecurity/iam-utils":"^0.1.78","@actsecurity/iam-policy":"^0.1.89"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.0.18","typescript":"^5.5.4","@types/node":"^22.5.0","semantic-release":"^25.0.3","@vitest/coverage-v8":"^4.0.18","@semantic-release/git":"^10.0.1","@semantic-release/npm":"^13.1.4","@semantic-release/exec":"^7.1.0","@semantic-release/github":"^12.0.6","@semantic-release/changelog":"^6.0.3","@actsecurity/prettier-config":"^0.1.1","@semantic-release/commit-analyzer":"^13.0.1","@semantic-release/release-notes-generator":"^14.0.3"},"_npmOperationalInternal":{"tmp":"tmp/iam-simulate_0.1.176_1788978685275_0.78783832808323","host":"s3://npm-registry-packages-npm-production"}},"0.1.177":{"name":"@actsecurity/iam-simulate","version":"0.1.177","description":"Simulate evaluation of AWS IAM policies","repository":{"type":"git","url":"git+https://github.com/act-security-labs/iam-simulate.git"},"exports":{".":{"import":"./dist/esm/index.js","require":"./dist/cjs/index.js"}},"types":"dist/cjs/index.d.ts","scripts":{"build":"npx tsc -p tsconfig.cjs.json && npx tsc -p tsconfig.esm.json && ./postbuild.sh","clean":"rm -rf dist","test":"npx vitest --run --coverage","release":"npm run clean && npm run build && npm run test && npm run format-check && npm publish","format":"npx prettier --write src/","format-check":"npx prettier --check src/"},"keywords":["AWS","IAM"],"author":{"name":"David Kerber","email":"dave@cloudcopilot.io"},"license":"AGPL-3.0-or-later","bugs":{"url":"https://github.com/act-security-labs/iam-simulate/issues"},"homepage":"https://github.com/act-security-labs/iam-simulate#readme","devDependencies":{"@actsecurity/prettier-config":"^0.1.1","@semantic-release/changelog":"^6.0.3","@semantic-release/commit-analyzer":"^13.0.1","@semantic-release/exec":"^7.1.0","@semantic-release/git":"^10.0.1","@semantic-release/github":"^12.0.6","@semantic-release/npm":"^13.1.4","@semantic-release/release-notes-generator":"^14.0.3","@types/node":"^22.5.0","@vitest/coverage-v8":"^4.0.18","semantic-release":"^25.0.3","typescript":"^5.5.4","vitest":"^4.0.18"},"dependencies":{"@actsecurity/iam-data":">=0.15.202511222 <1.0.0","@actsecurity/iam-policy":"^0.1.89","@actsecurity/iam-utils":"^0.1.78"},"prettier":"@actsecurity/prettier-config","release":{"branches":["main"],"plugins":[["@semantic-release/commit-analyzer",{"releaseRules":[{"type":"feat","release":"patch"},{"type":"fix","release":"patch"},{"breaking":true,"release":"patch"},{"type":"*","release":"patch"}]}],"@semantic-release/release-notes-generator","@semantic-release/changelog",["@semantic-release/npm",{"npmPublish":true}],["@semantic-release/exec",{"successCmd":"echo published=true >> $GITHUB_OUTPUT && echo version=${nextRelease.version} >> $GITHUB_OUTPUT && echo package_name=$(node -p \"require('./package.json').name\") >> $GITHUB_OUTPUT"}],["@semantic-release/git",{"assets":["package.json","package-lock.json","CHANGELOG.md"],"message":"chore(release): ${nextRelease.version} [skip ci]"}],["@semantic-release/github",{"assets":[]}]]},"gitHead":"836416c35c11ac1a2ee92402bbcc2f2fa467d927","_id":"@actsecurity/iam-simulate@0.1.177","_nodeVersion":"26.8.1","_npmVersion":"11.19.1","dist":{"integrity":"sha512-aFsFXWO3HF9dLrX6gH/6zk4CO7ENaEoo9rIiM48fYgMCom8toiZ5e1XkphGghmZzO4g37BUvpItNiGg3VD0vdQ==","shasum":"fc9515b8553ee2315c59054782ed40b57cb48c65","tarball":"https://registry.npmjs.org/@actsecurity/iam-simulate/-/iam-simulate-0.1.177.tgz","fileCount":597,"unpackedSize":1337056,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@actsecurity%2fiam-simulate@0.1.177","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIAcIz5R23gKvecZi4BA/eeZBIKgk6ydSAIVHzhMVDRryAiEAnrcEO2/0uPqNcTtgyPV9V6owEszplRst29D1ukwQddM="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:d08abd7d-7a13-4cd1-a287-9927f5817248"}},"directories":{},"maintainers":[{"name":"act-security-svc-user","email":"svc-user@act.security"},{"name":"daveatact","email":"david.kerber@act.security"},{"name":"elran.shefer","email":"elran.shefer@act.security"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/iam-simulate_0.1.177_1789070825721_0.23855643557712036"},"_hasShrinkwrap":false}},"time":{"created":"2026-09-01T06:31:27.912Z","modified":"2026-09-10T20:07:06.219Z","0.1.173":"2026-09-01T06:31:28.395Z","0.1.174":"2026-09-01T14:52:55.550Z","0.1.175":"2026-09-07T08:39:59.956Z","0.1.176":"2026-09-09T18:31:25.411Z","0.1.177":"2026-09-10T20:07:05.858Z"},"bugs":{"url":"https://github.com/act-security-labs/iam-simulate/issues"},"author":{"name":"David Kerber","email":"dave@cloudcopilot.io"},"license":"AGPL-3.0-or-later","homepage":"https://github.com/act-security-labs/iam-simulate#readme","keywords":["AWS","IAM"],"repository":{"type":"git","url":"git+https://github.com/act-security-labs/iam-simulate.git"},"description":"Simulate evaluation of AWS IAM policies","maintainers":[{"name":"act-security-svc-user","email":"svc-user@act.security"},{"name":"daveatact","email":"david.kerber@act.security"},{"name":"elran.shefer","email":"elran.shefer@act.security"}],"readme":"# IAM Simulate\n\n[![NPM Version](https://img.shields.io/npm/v/@actsecurity/iam-simulate.svg?logo=nodedotjs)](https://www.npmjs.com/package/@actsecurity/iam-simulate) [![License: AGPL v3](https://img.shields.io/github/license/act-security-labs/iam-simulate)](LICENSE.txt) [![GuardDog](https://github.com/act-security-labs/iam-simulate/actions/workflows/guarddog.yml/badge.svg)](https://github.com/act-security-labs/iam-simulate/actions/workflows/guarddog.yml) [![Known Vulnerabilities](https://snyk.io/test/github/act-security-labs/iam-simulate/badge.svg?targetFile=package.json&style=flat-square)](https://snyk.io/test/github/act-security-labs/iam-simulate?targetFile=package.json)\n\nAn AWS IAM Simulator and Policy Tester built as a Node/Typescript library.\n\nThe simulator currently supports these features of AWS IAM\n\n### IAM Feature Support\n\n- Identity Policies\n- Resource Policies\n- Service Control Policies\n- Resource Control Policies\n- Permission Boundaries\n- All [AWS Condition Operators](https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_elements_condition_operators.html)\n- Same Account and Cross Account Requests\n- Custom trust behavior for IAM Trust Policies and KMS Key Policies\n\n### Request Validation\n\niam-simulate will automatically validate inputs including\n\n- IAM policies using [iam-policy](https://github.com/act-security-labs/iam-policy)\n- IAM Actions using [iam-data](https://github.com/act-security-labs/iam-data)\n- The resource ARN against allowed resource types for the action\n- The context keys allowed for the action/resource and their types.\n\nCurrently all [global condition keys](https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_condition-keys.html) are allowed for all requests which is not strictly true. More validation will be added in the future.\n\n### Explanation\n\niam-simulate will detail which statements were decisive in the final decision to allow or deny a request.\n\nIt will also return \"explains\" for each statement that was evaluated, detailing why that statement applied to the request or not.\n\n### Features Coming Soon\n\n- Session Policies\n- Validation of Global Condition Keys for each action\n- Automatically populating context keys from the request such as `aws:PrincipalServiceName`\n\n### Anonymous Requests\n\nUse `anonymousPrincipal` to simulate unsigned requests, such as public S3 object access granted by a bucket policy. Anonymous requests do not have identity policies, session policies, permission boundaries, or SCPs; those principal-side policy inputs are rejected by `runSimulation`.\n\n```typescript\nimport { anonymousPrincipal, runSimulation, type Simulation } from '@actsecurity/iam-simulate'\n\nconst simulation: Simulation = {\n  request: {\n    principal: anonymousPrincipal,\n    action: 's3:GetObject',\n    resource: {\n      resource: 'arn:aws:s3:::public-bucket/file.txt',\n      accountId: '123456789012'\n    },\n    contextVariables: {}\n  },\n  identityPolicies: [],\n  serviceControlPolicies: [],\n  resourceControlPolicies: [],\n  resourcePolicy: {\n    Version: '2012-10-17',\n    Statement: [\n      {\n        Effect: 'Allow',\n        Principal: '*',\n        Action: 's3:GetObject',\n        Resource: 'arn:aws:s3:::public-bucket/*'\n      }\n    ]\n  }\n}\n\nconst response = await runSimulation(simulation, {})\n```\n\n### S3 Block Public Access\n\nFor S3 requests, callers can provide the effective `RestrictPublicBuckets` setting with `additionalSettings.s3.blockPublicAccess`. iam-simulate does not fetch or determine this setting; provide `true` only when S3 Block Public Access should apply for the bucket/account being simulated.\n\n```typescript\nconst simulation: Simulation = {\n  // request and policies...\n  additionalSettings: {\n    s3: {\n      blockPublicAccess: true\n    }\n  }\n}\n```\n\nWhen enabled, public S3 bucket policies can block anonymous and cross-account access with `blockedBy: ['s3-bpa']`.\n\n## Installation\n\n```bash\nnpm install @actsecurity/iam-simulate\n```\n\n## Usage\n\n```typescript\nimport { runSimulation, type Simulation } from '@actsecurity/iam-simulate'\n\nconst simulation: Simulation = {\n  identityPolicies: [\n    {\n      name: 'userpolicy',\n      policy: {\n        Version: '2012-10-17',\n        Statement: [\n          {\n            Effect: 'Allow',\n            Action: ['s3:GetObject'],\n            Resource: ['arn:aws:s3:::mybucket/*']\n          }\n        ]\n      }\n    }\n  ],\n  serviceControlPolicies: [\n    {\n      orgIdentifier: 'ou-12345',\n      policies: [\n        {\n          name: 'AllowAll',\n          policy: {\n            Version: '2012-10-17',\n            Statement: [\n              {\n                Effect: 'Allow',\n                Action: '*',\n                Resource: '*'\n              }\n            ]\n          }\n        }\n      ]\n    }\n  ],\n  /*\n    The default RCP `RCPFullAWSAccess` is always applied implicitly and you do not need to include it here. https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_rcps_examples.html#example-rcp-full-aws-access\n  */\n  resourceControlPolicies: [\n    {\n      orgIdentifier: 'o-123456789012',\n      policies: [\n        {\n          name: 'EnforceSecureTransport',\n          policy: {\n            Version: '2012-10-17',\n            Statement: [\n              {\n                Sid: 'EnforceSecureTransport',\n                Effect: 'Deny',\n                Principal: '*',\n                Action: ['sts:*', 's3:*', 'sqs:*', 'secretsmanager:*', 'kms:*'],\n                Resource: '*',\n                Condition: {\n                  BoolIfExists: {\n                    'aws:SecureTransport': 'false'\n                  }\n                }\n              }\n            ]\n          }\n        }\n      ]\n    }\n  ],\n  resourcePolicy: {\n    Version: '2012-10-17',\n    Statement: [\n      {\n        Effect: 'Allow',\n        Action: ['s3:GetObject'],\n        Resource: ['arn:aws:s3:::mybucket/*'],\n        Principal: 'aws:arn:iam::123456789012:root',\n        Condition: {\n          StringEquals: {\n            'aws:PrincipalOrgID': 'o-123456789012'\n          }\n        }\n      }\n    ]\n  },\n  request: {\n    action: 's3:GetObject',\n    principal: 'arn:aws:iam::123456789012:user/username',\n    resource: {\n      accountId: '123456789012',\n      resource: 'arn:aws:s3:::mybucket/file.txt'\n    },\n    contextVariables: {\n      'aws:PrincipalOrgID': 'o-123456789012'\n    }\n  }\n}\n\n`runSimulation` returns a discriminated union with `resultType`:\n\n- `resultType: 'error'` includes `errors` and no simulation results.\n- `resultType: 'single'` includes `overallResult` and a single `result`.\n- `resultType: 'wildcard'` includes `overallResult` and `results` for each matching pattern.\n\nconst response = await runSimulation(simulation, {})\n//Check for validation errors (errors are returned at the response level):\nif (response.resultType === 'error') {\n  console.log(response.errors.message)\n  console.log(JSON.stringify(response.errors, null, 2))\n}\n\n//The simulation ran successfully\nif (response.resultType === 'single') {\n  const result = response.result\n  console.log(response.overallResult) // 'Allowed', 'ExplicitlyDenied', or 'ImplicitlyDenied'\n  console.log(result.analysis?.result)\n\n  //Output the identity statements that allowed the request\n  const identityAllowExplains =\n    result?.analysis?.identityAnalysis?.allowStatements.map((s) => s.explain) || []\n  //Show which statements applied and exactly how.\n  for (const explain of identityAllowExplains) {\n    console.log(explain)\n  }\n}\n\nif (response.resultType === 'wildcard') {\n  console.log(response.overallResult)\n  for (const result of response.results) {\n    console.log(result.resourcePattern, result.analysis?.result)\n  }\n}\n```\n\nThis would output an explain that shows how the identity statement was evaluated:\n\n```javascript\n{\n  effect: 'Allow',\n  identifier: '1',\n  matches: true,\n  actionMatch: true,\n  principalMatch: 'Match',\n  resourceMatch: true,\n  conditionMatch: true,\n  resources: [\n    {\n      resource: 'arn:aws:s3:::mybucket/*',\n      matches: true,\n    }\n  ],\n  actions: [ { action: 's3:GetObject', matches: true } ],\n}\n```\n","readmeFilename":"README.md"}