DEFAULT_BUILD_POLICIES: PolicyStatement[] = ...

Default policy for the CodeBuild role generated. It allows look-ups, including access to AWS Secrets Manager. Not recommended for production. For production use case, CodeBuild policies must be restricted to particular resources. Outbound access from the build should be controlled by ACL.