{"_id":"@actsecurity/iam-truth","_rev":"4-2c3c5d32e2e31ac173abe42d6003a1bd","name":"@actsecurity/iam-truth","dist-tags":{"latest":"0.1.17"},"versions":{"0.1.14":{"name":"@actsecurity/iam-truth","version":"0.1.14","keywords":["AWS","IAM","policy","truth-table"],"author":{"name":"Act Security"},"license":"AGPL-3.0-or-later","_id":"@actsecurity/iam-truth@0.1.14","maintainers":[{"name":"act-security-svc-user","email":"svc-user@act.security"},{"name":"daveatact","email":"david.kerber@act.security"},{"name":"elran.shefer","email":"elran.shefer@act.security"}],"homepage":"https://github.com/act-security-labs/iam-truth#readme","bugs":{"url":"https://github.com/act-security-labs/iam-truth/issues"},"bin":{"iam-truth":"dist/esm/cli.js"},"dist":{"shasum":"77fc10a52ba86446dc45442fb30fb385ab0dce8f","tarball":"https://registry.npmjs.org/@actsecurity/iam-truth/-/iam-truth-0.1.14.tgz","fileCount":149,"integrity":"sha512-GjrRcZ8S6pcjOg4UQaCNi+CKz8hznbHfvbWeSmrb3Y8iZFBnFGE0nPM1cNf5efpcNfO0M+nK/Lnl7xubfM/meQ==","signatures":[{"sig":"MEQCIDR6xhtQZQGO4Sd3dLlxh7z6ZGPyd9aAPCWDGu6sfvcGAiAEt4q2wMKWorjfIaNo805H+a3n0cALJiX4IzME+JfgAA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":490910},"types":"dist/cjs/index.d.ts","exports":{".":{"import":"./dist/esm/index.js","require":"./dist/cjs/index.js"}},"gitHead":"e64e11495bc089bf6dfee722e2b09436ac60e88d","release":{"plugins":[["@semantic-release/commit-analyzer",{"releaseRules":[{"type":"feat","release":"patch"},{"type":"fix","release":"patch"},{"release":"patch","breaking":true},{"type":"*","release":"patch"}]}],"@semantic-release/release-notes-generator","@semantic-release/changelog",["@semantic-release/npm",{"npmPublish":true}],["@semantic-release/git",{"assets":["package.json","package-lock.json","CHANGELOG.md"],"message":"chore(release): ${nextRelease.version} [skip ci]"}],["@semantic-release/github",{"assets":[]}]],"branches":["main"]},"scripts":{"test":"npx vitest --run --coverage","build":"npx tsc -p tsconfig.cjs.json && npx tsc -p tsconfig.esm.json && ./postbuild.sh","clean":"rm -rf dist","format":"npx prettier --write src/","release":"npm install && npm run clean && npm run build && npm test && npm run format-check && npm publish","format-check":"npx prettier --check src/"},"_npmUser":{"name":"daveatact","email":"david.kerber@act.security"},"prettier":"@actsecurity/prettier-config","repository":{"url":"git+https://github.com/act-security-labs/iam-truth.git","type":"git"},"_npmVersion":"11.17.0","description":"Generate truth tables that explain AWS IAM policy behavior","directories":{},"_nodeVersion":"26.5.0","dependencies":{"@actsecurity/cli":"^0.2.46","@actsecurity/iam-data":">=0.20.202607211 <1.0.0","@actsecurity/iam-utils":"^0.1.79","@actsecurity/iam-expand":"^0.11.62","@actsecurity/iam-policy":"^0.1.89","@actsecurity/iam-simulate":"^0.1.168"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.0.18","typescript":"^5.5.4","@types/node":"^22.5.0","semantic-release":"^25.0.3","@vitest/coverage-v8":"^4.0.18","@semantic-release/git":"^10.0.1","@semantic-release/npm":"^13.1.4","@semantic-release/github":"^12.0.6","@semantic-release/changelog":"^6.0.3","@actsecurity/prettier-config":"^0.1.1","@semantic-release/commit-analyzer":"^13.0.1","@semantic-release/release-notes-generator":"^14.0.3"},"_npmOperationalInternal":{"tmp":"tmp/iam-truth_0.1.14_1788260586463_0.4015614954203408","host":"s3://npm-registry-packages-npm-production"}},"0.1.15":{"name":"@actsecurity/iam-truth","version":"0.1.15","keywords":["AWS","IAM","policy","truth-table"],"author":{"name":"Act Security"},"license":"AGPL-3.0-or-later","_id":"@actsecurity/iam-truth@0.1.15","maintainers":[{"name":"act-security-svc-user","email":"svc-user@act.security"},{"name":"daveatact","email":"david.kerber@act.security"},{"name":"elran.shefer","email":"elran.shefer@act.security"}],"homepage":"https://github.com/act-security-labs/iam-truth#readme","bugs":{"url":"https://github.com/act-security-labs/iam-truth/issues"},"bin":{"iam-truth":"dist/esm/cli.js"},"dist":{"shasum":"6d462b01866db727cfc7c1a8204c0d13f2e16c96","tarball":"https://registry.npmjs.org/@actsecurity/iam-truth/-/iam-truth-0.1.15.tgz","fileCount":149,"integrity":"sha512-Fx6AGmfGRoHgUBj2Jhe0FJ4XUXlj7kW8OIjAu9Wm7s0IqUuOYhDf+7JVWh7WlkREHRnnXwuYmQSvgnzsc+biNw==","signatures":[{"sig":"MEYCIQDzAJzWt0Zbc3K5giwqtPmN/tMiRuW0I88Ryuk+RfUehwIhAKB9r7vVJDQIWTnB6JyaFetReaX5Wc6UTaGe6Kv/Zz1y","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@actsecurity%2fiam-truth@0.1.15","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":490910},"types":"dist/cjs/index.d.ts","exports":{".":{"import":"./dist/esm/index.js","require":"./dist/cjs/index.js"}},"gitHead":"aa17f661945b69f9fe9903c488fdd6610c9f28a6","release":{"plugins":[["@semantic-release/commit-analyzer",{"releaseRules":[{"type":"feat","release":"patch"},{"type":"fix","release":"patch"},{"release":"patch","breaking":true},{"type":"*","release":"patch"}]}],"@semantic-release/release-notes-generator","@semantic-release/changelog",["@semantic-release/npm",{"npmPublish":true}],["@semantic-release/git",{"assets":["package.json","package-lock.json","CHANGELOG.md"],"message":"chore(release): ${nextRelease.version} [skip ci]"}],["@semantic-release/github",{"assets":[]}]],"branches":["main"]},"scripts":{"test":"npx vitest --run --coverage","build":"npx tsc -p tsconfig.cjs.json && npx tsc -p tsconfig.esm.json && ./postbuild.sh","clean":"rm -rf dist","format":"npx prettier --write src/","release":"npm install && npm run clean && npm run build && npm test && npm run format-check && npm publish","format-check":"npx prettier --check src/"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:d1e24c4c-d49d-4b56-adbf-9fddc7f0fa60"}},"prettier":"@actsecurity/prettier-config","repository":{"url":"git+https://github.com/act-security-labs/iam-truth.git","type":"git"},"_npmVersion":"11.19.1","description":"Generate truth tables that explain AWS IAM policy behavior","directories":{},"_nodeVersion":"26.8.1","dependencies":{"@actsecurity/cli":"^0.2.46","@actsecurity/iam-data":">=0.20.202607211 <1.0.0","@actsecurity/iam-utils":"^0.1.79","@actsecurity/iam-expand":"^0.11.62","@actsecurity/iam-policy":"^0.1.89","@actsecurity/iam-simulate":"^0.1.168"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.0.18","typescript":"^5.5.4","@types/node":"^22.5.0","semantic-release":"^25.0.3","@vitest/coverage-v8":"^4.0.18","@semantic-release/git":"^10.0.1","@semantic-release/npm":"^13.1.4","@semantic-release/github":"^12.0.6","@semantic-release/changelog":"^6.0.3","@actsecurity/prettier-config":"^0.1.1","@semantic-release/commit-analyzer":"^13.0.1","@semantic-release/release-notes-generator":"^14.0.3"},"_npmOperationalInternal":{"tmp":"tmp/iam-truth_0.1.15_1788260917494_0.2792795025699586","host":"s3://npm-registry-packages-npm-production"}},"0.1.16":{"name":"@actsecurity/iam-truth","version":"0.1.16","keywords":["AWS","IAM","policy","truth-table"],"author":{"name":"Act Security"},"license":"AGPL-3.0-or-later","_id":"@actsecurity/iam-truth@0.1.16","maintainers":[{"name":"act-security-svc-user","email":"svc-user@act.security"},{"name":"daveatact","email":"david.kerber@act.security"},{"name":"elran.shefer","email":"elran.shefer@act.security"}],"homepage":"https://github.com/act-security-labs/iam-truth#readme","bugs":{"url":"https://github.com/act-security-labs/iam-truth/issues"},"bin":{"iam-truth":"dist/esm/cli.js"},"dist":{"shasum":"189ab61617580ca7f4b5cebdac92861bbd176f2d","tarball":"https://registry.npmjs.org/@actsecurity/iam-truth/-/iam-truth-0.1.16.tgz","fileCount":149,"integrity":"sha512-lyd2yWDT1deV3jUfBdmgyeJQ8YSqSvwbElGxbh4oUUvZxo9xbvi+4CjXlJ6ZzAHoAvzQpPCpRUiE8crIAQAwTQ==","signatures":[{"sig":"MEQCICRx4etAitXXGtSZjiHQbmeZhQeEQLKsCODdOKyIH5ZaAiAVBlpUb2GD2ia8461nGqByYPW18qS8cZANVMhyZnIHXQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@actsecurity%2fiam-truth@0.1.16","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":490902},"types":"dist/cjs/index.d.ts","exports":{".":{"import":"./dist/esm/index.js","require":"./dist/cjs/index.js"}},"gitHead":"4e1429ee18047817f87fd8143726ee6d8fae6060","release":{"plugins":[["@semantic-release/commit-analyzer",{"releaseRules":[{"type":"feat","release":"patch"},{"type":"fix","release":"patch"},{"release":"patch","breaking":true},{"type":"*","release":"patch"}]}],"@semantic-release/release-notes-generator","@semantic-release/changelog",["@semantic-release/npm",{"npmPublish":true}],["@semantic-release/git",{"assets":["package.json","package-lock.json","CHANGELOG.md"],"message":"chore(release): ${nextRelease.version} [skip ci]"}],["@semantic-release/github",{"assets":[]}]],"branches":["main"]},"scripts":{"test":"npx vitest --run --coverage","build":"npx tsc -p tsconfig.cjs.json && npx tsc -p tsconfig.esm.json && ./postbuild.sh","clean":"rm -rf dist","format":"npx prettier --write src/","release":"npm install && npm run clean && npm run build && npm test && npm run format-check && npm publish","format-check":"npx prettier --check src/"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:d1e24c4c-d49d-4b56-adbf-9fddc7f0fa60"}},"prettier":"@actsecurity/prettier-config","repository":{"url":"git+https://github.com/act-security-labs/iam-truth.git","type":"git"},"_npmVersion":"11.19.1","description":"Generate truth tables that explain AWS IAM policy behavior","directories":{},"_nodeVersion":"26.8.1","dependencies":{"@actsecurity/cli":"^0.2.46","@actsecurity/iam-data":">=0.20.202607211 <1.0.0","@actsecurity/iam-utils":"^0.1.79","@actsecurity/iam-expand":"^0.11.62","@actsecurity/iam-policy":"^0.1.89","@actsecurity/iam-simulate":"^0.1.168"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.0.18","typescript":"^5.5.4","@types/node":"^22.5.0","semantic-release":"^25.0.3","@vitest/coverage-v8":"^4.0.18","@semantic-release/git":"^10.0.1","@semantic-release/npm":"^13.1.4","@semantic-release/github":"^12.0.6","@semantic-release/changelog":"^6.0.3","@actsecurity/prettier-config":"^0.1.1","@semantic-release/commit-analyzer":"^13.0.1","@semantic-release/release-notes-generator":"^14.0.3"},"_npmOperationalInternal":{"tmp":"tmp/iam-truth_0.1.16_1788274610468_0.6287911023231989","host":"s3://npm-registry-packages-npm-production"}},"0.1.17":{"name":"@actsecurity/iam-truth","version":"0.1.17","description":"Generate truth tables that explain AWS IAM policy behavior","repository":{"type":"git","url":"git+https://github.com/act-security-labs/iam-truth.git"},"exports":{".":{"import":"./dist/esm/index.js","require":"./dist/cjs/index.js"}},"types":"dist/cjs/index.d.ts","bin":{"iam-truth":"dist/esm/cli.js"},"scripts":{"build":"npx tsc -p tsconfig.cjs.json && npx tsc -p tsconfig.esm.json && ./postbuild.sh","clean":"rm -rf dist","test":"npx vitest --run --coverage","release":"npm install && npm run clean && npm run build && npm test && npm run format-check && npm publish","format":"npx prettier --write src/","format-check":"npx prettier --check src/"},"keywords":["AWS","IAM","policy","truth-table"],"author":{"name":"Act Security"},"license":"AGPL-3.0-or-later","bugs":{"url":"https://github.com/act-security-labs/iam-truth/issues"},"homepage":"https://github.com/act-security-labs/iam-truth#readme","dependencies":{"@actsecurity/cli":"^0.2.46","@actsecurity/iam-data":">=0.20.202607211 <1.0.0","@actsecurity/iam-expand":"^0.11.62","@actsecurity/iam-policy":"^0.1.89","@actsecurity/iam-simulate":"^0.1.168","@actsecurity/iam-utils":"^0.1.79"},"devDependencies":{"@actsecurity/prettier-config":"^0.1.1","@semantic-release/changelog":"^6.0.3","@semantic-release/commit-analyzer":"^13.0.1","@semantic-release/git":"^10.0.1","@semantic-release/github":"^12.0.6","@semantic-release/npm":"^13.1.4","@semantic-release/release-notes-generator":"^14.0.3","@types/node":"^22.5.0","@vitest/coverage-v8":"^4.0.18","semantic-release":"^25.0.3","typescript":"^5.5.4","vitest":"^4.0.18"},"prettier":"@actsecurity/prettier-config","release":{"branches":["main"],"plugins":[["@semantic-release/commit-analyzer",{"releaseRules":[{"type":"feat","release":"patch"},{"type":"fix","release":"patch"},{"breaking":true,"release":"patch"},{"type":"*","release":"patch"}]}],"@semantic-release/release-notes-generator","@semantic-release/changelog",["@semantic-release/npm",{"npmPublish":true}],["@semantic-release/git",{"assets":["package.json","package-lock.json","CHANGELOG.md"],"message":"chore(release): ${nextRelease.version} [skip ci]"}],["@semantic-release/github",{"assets":[]}]]},"gitHead":"cc6036bf86ed1e7fd46b4ded55948d6ee7b70cf2","_id":"@actsecurity/iam-truth@0.1.17","_nodeVersion":"26.8.1","_npmVersion":"11.19.1","dist":{"integrity":"sha512-4HOf19CXlBwq17ZYr2I0sjtNw45PfE7SO2Thw78BTdTh2n9UN25qrBZO0BPyrl2izMsN/9KM06knYJYsOHDq9w==","shasum":"ff2325e675cb89b9106735934d5651dc2a307d3d","tarball":"https://registry.npmjs.org/@actsecurity/iam-truth/-/iam-truth-0.1.17.tgz","fileCount":149,"unpackedSize":508261,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@actsecurity%2fiam-truth@0.1.17","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIEqTbOI/yz/G74kCsn/2Oo29Xaci9iwwI2L1ro81o3W5AiEAmCudyIUU0yIx6oohMW44VExP406lcqHo5HH929C+mv8="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:d1e24c4c-d49d-4b56-adbf-9fddc7f0fa60"}},"directories":{},"maintainers":[{"name":"act-security-svc-user","email":"svc-user@act.security"},{"name":"daveatact","email":"david.kerber@act.security"},{"name":"elran.shefer","email":"elran.shefer@act.security"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/iam-truth_0.1.17_1788982881866_0.26574020576453217"},"_hasShrinkwrap":false}},"time":{"created":"2026-09-01T11:03:06.218Z","modified":"2026-09-09T19:41:22.466Z","0.1.14":"2026-09-01T11:03:06.601Z","0.1.15":"2026-09-01T11:08:37.645Z","0.1.16":"2026-09-01T14:56:50.686Z","0.1.17":"2026-09-09T19:41:22.003Z"},"bugs":{"url":"https://github.com/act-security-labs/iam-truth/issues"},"author":{"name":"Act Security"},"license":"AGPL-3.0-or-later","homepage":"https://github.com/act-security-labs/iam-truth#readme","keywords":["AWS","IAM","policy","truth-table"],"repository":{"type":"git","url":"git+https://github.com/act-security-labs/iam-truth.git"},"description":"Generate truth tables that explain AWS IAM policy behavior","maintainers":[{"name":"act-security-svc-user","email":"svc-user@act.security"},{"name":"daveatact","email":"david.kerber@act.security"},{"name":"elran.shefer","email":"elran.shefer@act.security"}],"readme":"# @actsecurity/iam-truth\n\nGenerate JSON or Markdown truth tables that explain how a single AWS IAM policy behaves across representative scenarios.\n\n## Status\n\nInitial v1 scope supports SCP and RCP input with JSON and Markdown output.\n\n## CLI\n\n```sh\niam-truth --policy-type scp --file policy.json\niam-truth --policy-type rcp --file rcp.json --action s3:GetObject --resources arn:aws:s3:::example-bucket/example.txt\ncat policy.json | iam-truth --policy-type scp\n```\n\nOptional request overrides:\n\n```sh\niam-truth --policy-type scp --file policy.json --action s3:PutObject --resources '*' --principal arn:aws:iam::111111111111:role/TestRole\niam-truth --policy-type rcp --file rcp.json --action s3:GetObject --resources arn:aws:s3:::example-bucket/example.txt\n```\n\nTo test the same generated scenarios against more than one resource, provide multiple `--resources` values. Multiple resources multiply the output rows and add a `Resource` column before `Result`.\n\n```sh\niam-truth --policy-type scp --file policy.json --action s3:GetObject --resources arn:aws:s3:::example-bucket/first.txt arn:aws:s3:::example-bucket/second.txt\niam-truth --policy-type scp --file policy.json --action s3:GetObject --resources arn:aws:s3:::example-bucket/first.txt --resources arn:aws:s3:::example-bucket/second.txt\n```\n\nWhen simplification is enabled, the `Resource` column can collapse to `Any` when the row result is the same regardless of resource.\n\nResources that cannot be tested with the selected action are skipped and reported as validation diagnostics. If at least one resource is testable, iam-truth still returns rows for the testable resources and prints skipped-resource messages to stderr in the CLI.\n\nRCP support uses generated signed requests by default, but includes missing examples for principal context keys that can be absent in resource-side/anonymous request models. RCP resource-information keys such as `aws:ResourceAccount`, `aws:ResourceOrgID`, and `aws:ResourceOrgPaths` are generated according to AWS action-specific availability.\n\nBy default, multiple policy values for a single-valued condition key produce one representative matching row. To show one matching row for every policy value:\n\n```sh\niam-truth --policy-type scp --file policy.json --show-examples-for-all-policy-values\n```\n\nTo collapse redundant rows into summary rows that use `Any` for irrelevant generated values:\n\n```sh\niam-truth --policy-type scp --file policy.json --simplify\n```\n\nSimplified JSON rows use an object sentinel for any-value cells so real string values cannot collide with it:\n\n```json\n{ \"cellType\": \"any\", \"label\": \"Any\" }\n```\n\nSummary rows have `rowType: \"summary\"`, omit concrete `context`, and include `coveredRowCount` and `coveredRowIds`.\n\nGenerated request-context values are deterministic synthetic examples. User-provided policy condition values are preserved for matching rows, while non-matching and present-key examples use fake values shaped like the relevant IAM context key, such as sample account IDs, organization IDs, VPC IDs, regions, service principals, and tag values.\n\n## API\n\n```ts\nimport { generateTruthTables } from '@actsecurity/iam-truth'\n\nconst result = await generateTruthTables({\n  policy,\n  policyType: 'scp'\n})\n\nconst rcpResult = await generateTruthTables({\n  policy: rcpPolicy,\n  policyType: 'rcp',\n  request: {\n    action: 's3:GetObject',\n    resources: ['arn:aws:s3:::example-bucket/example.txt']\n  }\n})\n\nconst multiResourceResult = await generateTruthTables({\n  policy,\n  policyType: 'scp',\n  request: {\n    action: 's3:GetObject',\n    resources: ['arn:aws:s3:::example-bucket/first.txt', 'arn:aws:s3:::example-bucket/second.txt']\n  }\n})\n```\n\nSuccessful JSON tables include `testedResources`, the normalized resource list used for simulation, and `untestedResources`, any requested resources that were skipped because they are not supported by the selected action. A `Resource` column is included only when more than one resource was requested.\n\nIf no requested resources can be tested for the selected action, the API returns `resultType: 'noTestableResources'` with structured `untestedResources` and diagnostics.\n","readmeFilename":"README.md"}