Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

integrations v1.5.12 updated #5631

Merged
merged 321 commits into from
Jul 21, 2022
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
321 commits
Select commit Hold shift + click to select a range
3478587
fix(filesystem): GetExcludedPaths (#5288)
rafaela-soares May 2, 2022
1b5a6b9
docs: preparing for release 1.5.7 (#5289)
kicsbot May 2, 2022
fd4160f
build(deps): bump github.com/aws/aws-sdk-go from 1.44.4 to 1.44.5 (#5…
dependabot[bot] May 3, 2022
0d7a3cd
build(deps): bump github.com/aws/aws-sdk-go from 1.44.5 to 1.44.6 (#5…
dependabot[bot] May 4, 2022
d332f8b
docs(kicsbot): update images digest (#5300)
kicsbot May 4, 2022
6b42599
update Network ACL With Unrestricted Access To RDP (#5296)
cxMiguelSilva May 4, 2022
d2196e9
update(query): Update category and severities according with issue 52…
cxMiguelSilva May 4, 2022
c2993ec
Add community tag to new issues by default
kaplanlior May 4, 2022
d5032f4
build(deps): bump github.com/aws/aws-sdk-go from 1.44.6 to 1.44.7 (#5…
dependabot[bot] May 5, 2022
72ad390
docs(kicsbot): update images digest (#5302)
kicsbot May 5, 2022
3e358e6
feat(query): add new k8s rule to detect port-forwarding into containe…
Churro May 5, 2022
cfba9a8
feat(query): add new k8s rule to detect account impersonation (RBAC) …
Churro May 5, 2022
9baf524
feat(query): add new k8s rule to detect bind or escalate permissions …
Churro May 5, 2022
8fa646c
feat(query): add new k8s rule to detect exec permissions (RBAC) (#5286)
Churro May 5, 2022
ca12c85
update installation options and notes (#5293)
konstruktoid May 5, 2022
ea1d7dd
update Missing Flag From Dnf Install (#5310)
cxMiguelSilva May 5, 2022
cabd053
removed results report formats list from docs (#5308)
joaorufi May 5, 2022
2e22fea
ci(deps): bump docker/build-push-action from 2.10.0 to 3.0.0 (#5316)
dependabot[bot] May 6, 2022
6d3f34c
ci(deps): bump docker/login-action from 1.14.1 to 2.0.0 (#5317)
dependabot[bot] May 6, 2022
a16d514
build(deps): bump github.com/aws/aws-sdk-go from 1.44.7 to 1.44.8 (#5…
dependabot[bot] May 6, 2022
d5a2d15
update(query): StatefulSet Without Service Name for Kubernetes (#5303)
cxMiguelSilva May 6, 2022
75352a3
update(query): Remote Desktop Port Open To Internet and HTTP Port Ope…
cxMiguelSilva May 6, 2022
3955d59
delete check for incorrect default (#5314)
cxMiguelSilva May 6, 2022
c7a6473
doc: fix syntax (#5309)
nv35 May 6, 2022
b374fc3
ci(deps): bump docker/setup-qemu-action from 1 to 2 (#5315)
dependabot[bot] May 6, 2022
2af799b
build(deps): bump github.com/aws/aws-sdk-go from 1.44.8 to 1.44.9 (#5…
dependabot[bot] May 9, 2022
6f5c8c8
build(deps): bump github.com/moby/buildkit from 0.10.2 to 0.10.3 (#5324)
dependabot[bot] May 9, 2022
5a85316
fix(query): adjusted severity rating and added searchLine in rbac_wil…
Churro May 9, 2022
440baab
update(query): Audit Policy Not Cover Key Security Concerns for Kuber…
cxMiguelSilva May 9, 2022
8dbe997
update(queries): Add check for traffic direction in port queries in s…
cxMiguelSilva May 9, 2022
fc9b5ee
build(deps): bump github.com/aws/aws-sdk-go from 1.44.9 to 1.44.10 (#…
dependabot[bot] May 10, 2022
eb40b4c
build(deps): bump github.com/aws/aws-sdk-go from 1.44.10 to 1.44.11 (…
dependabot[bot] May 11, 2022
2d248b3
build(deps): bump github.com/johnfercher/maroto from 0.36.1 to 0.37.0…
dependabot[bot] May 11, 2022
5a8b565
ci(deps): bump golang from 1.18.1-alpine to 1.18.2-alpine (#5332)
dependabot[bot] May 11, 2022
fa760f4
docs(kicsbot): update images digest (#5311)
kicsbot May 11, 2022
172ee5a
fix(password and secrets): improve performance (#5334)
rafaela-soares May 11, 2022
0377df7
fix(cpu): fixed number of cpus available info (#5321)
joaorufi May 11, 2022
12b5e0d
fix(samples): k8s queries (#5322)
rafaela-soares May 11, 2022
38bb9f3
docs: preparing for release 1.5.8 (#5336)
kicsbot May 11, 2022
6b290f1
ci(deps): bump golangci/golangci-lint-action from 3.1.0 to 3.2.0 (#5339)
dependabot[bot] May 12, 2022
8b6de6a
build(deps): bump mvdan.cc/sh/v3 from 3.4.3 to 3.5.0 (#5341)
dependabot[bot] May 12, 2022
985aa68
docs(kicsbot): update images digest (#5342)
kicsbot May 12, 2022
1d4f699
build(deps): bump github.com/aws/aws-sdk-go from 1.44.11 to 1.44.12 (…
dependabot[bot] May 12, 2022
2be0f04
build(deps): bump github.com/aws/aws-sdk-go from 1.44.12 to 1.44.13 (…
dependabot[bot] May 13, 2022
73996ca
docs(kicsbot): update images digest (#5346)
kicsbot May 13, 2022
20bc754
build(deps): bump github.com/aws/aws-sdk-go from 1.44.13 to 1.44.14 (…
dependabot[bot] May 16, 2022
213e2d9
docs(kicsbot): update images digest (#5351)
kicsbot May 16, 2022
75251d6
build(go): bump golang version to 1.18 (#5348)
cx-joao-reigota May 16, 2022
de69e34
build(deps): bump github.com/aws/aws-sdk-go from 1.44.14 to 1.44.15 (…
dependabot[bot] May 17, 2022
6ee1a14
docs(kicsbot): update images digest (#5354)
kicsbot May 17, 2022
b372952
build(deps): bump github.com/aws/aws-sdk-go from 1.44.15 to 1.44.16 (…
dependabot[bot] May 18, 2022
8278b60
docs(kicsbot): update images digest (#5367)
kicsbot May 18, 2022
4550b13
build(deps): bump github.com/hashicorp/go-getter from 1.5.11 to 1.6.0…
dependabot[bot] May 19, 2022
0bfaf3b
build(deps): bump github.com/aws/aws-sdk-go from 1.44.16 to 1.44.17 (…
dependabot[bot] May 19, 2022
6563d92
build(deps): bump helm.sh/helm/v3 from 3.8.2 to 3.9.0 (#5374)
dependabot[bot] May 19, 2022
e21eac4
docs(kicsbot): update images digest (#5375)
kicsbot May 19, 2022
ba6dbe0
build(deps): bump github.com/aws/aws-sdk-go from 1.44.17 to 1.44.18 (…
dependabot[bot] May 20, 2022
9a9a790
build(deps): bump github.com/hashicorp/go-getter from 1.6.0 to 1.6.1 …
dependabot[bot] May 20, 2022
2528a72
docs(kicsbot): update images digest (#5379)
kicsbot May 20, 2022
7ed9844
add support to .crt file (#5360)
cxMiguelSilva May 20, 2022
cfbdfbd
fix(query): Changed severity of Memcached Disabled query (#5349)
joaorufi May 20, 2022
ff092cf
fix function (#5343)
joaorufi May 20, 2022
231d98c
fix(vulnerability builder): fixed and improved DefaultVulnerabilityBu…
rafaela-soares May 20, 2022
15f5f5d
build(deps): bump github.com/aws/aws-sdk-go from 1.44.18 to 1.44.19 (…
dependabot[bot] May 23, 2022
d051375
docs(kicsbot): update images digest (#5382)
kicsbot May 23, 2022
1a4c2c3
feat(query): added Default KMS Key Usage query for CloudFormation (#5…
joaorufi May 23, 2022
c283b2d
feat(query): CNI Plugin Does Not Support Network Policies for Kuberne…
cxMiguelSilva May 23, 2022
bf62ac7
feat(query): Ensure Administrative Boundaries Between Resources for K…
cxMiguelSilva May 23, 2022
af34083
update(kics): reduced the number of code files (#5325)
rafaela-soares May 23, 2022
3666f8a
fix(cpu): fix number cpus macos (#5371)
joaorufi May 23, 2022
28537be
ci(deps): bump goreleaser/goreleaser-action from 2.9.1 to 3.0.0 (#5390)
dependabot[bot] May 24, 2022
e0838c6
build(deps): bump mvdan.cc/sh/v3 from 3.5.0 to 3.5.1 (#5391)
dependabot[bot] May 24, 2022
eb0b7e4
build(deps): bump github.com/tdewolff/minify/v2 from 2.11.2 to 2.11.5…
dependabot[bot] May 24, 2022
5b6631e
build(deps): bump github.com/aws/aws-sdk-go from 1.44.19 to 1.44.20 (…
dependabot[bot] May 24, 2022
422ec7d
ci(deps): bump alpine from 3.15.4 to 3.16.0 (#5394)
dependabot[bot] May 24, 2022
499bca2
fix(ci): fixed access to CIFlag (#5395)
rafaela-soares May 24, 2022
bc5fb99
feat(result): added resourceType and resourceName to Kubernetes queri…
rafaela-soares May 24, 2022
f4ed3d0
feat(result): added resourceType and resourceName to Azure Resource M…
rafaela-soares May 24, 2022
b1c5ad2
fix(query): fix/cmk rotation disabled on terraform asymmetric key cre…
LupovichRan May 24, 2022
fb12798
update(query): Ensure Administrative Boundaries (#5388)
cxMiguelSilva May 24, 2022
2134994
docs(kicsbot): update github-action image digest (#5359)
kicsbot May 24, 2022
830be5d
feat(result): added resourceType and resourceName to Google Deploymen…
rafaela-soares May 24, 2022
ff00ceb
feat(result): added resourceType and resourceName to Ansible queries …
rafaela-soares May 24, 2022
aad61f2
build(deps): bump github.com/aws/aws-sdk-go from 1.44.20 to 1.44.21 (…
dependabot[bot] May 25, 2022
9c36d5a
feat(resolver): added openapi file resolver for json and yaml parsers…
cx-joao-reigota May 25, 2022
a10268f
docs(kicsbot): update images digest (#5386)
kicsbot May 25, 2022
2b61225
update(resolver): implemented limit in resolver to 50 files (#5398)
cx-joao-reigota May 25, 2022
39778e8
fix(resolver): fixed issue with searchLine (#5399)
cx-joao-reigota May 25, 2022
3ace1f4
fix(helm): fixed helm filepath bug introduced by resolver (#5400)
cx-joao-reigota May 25, 2022
8dab4f0
docs: preparing for release 1.5.9 (#5401)
kicsbot May 25, 2022
c9533f4
build(deps): bump github.com/aws/aws-sdk-go from 1.44.21 to 1.44.22 (…
dependabot[bot] May 26, 2022
3ab8388
build(deps): bump github.com/hashicorp/terraform-json (#5405)
dependabot[bot] May 26, 2022
ede5d25
docs(kicsbot): update images digest (#5406)
kicsbot May 26, 2022
ffd44ad
build(deps): bump github.com/aws/aws-sdk-go from 1.44.22 to 1.44.23 (…
dependabot[bot] May 27, 2022
d83fe11
build(deps): bump github.com/spf13/viper from 1.11.0 to 1.12.0 (#5410)
dependabot[bot] May 27, 2022
b753e9b
docs(kicsbot): update images digest (#5411)
kicsbot May 27, 2022
9dc940b
docs(kicsbot): update images digest (#5416)
kicsbot May 30, 2022
bf9162c
build(deps): bump github.com/aws/aws-sdk-go from 1.44.23 to 1.44.24 (…
dependabot[bot] May 30, 2022
2565134
build(deps): bump gopkg.in/yaml.v3 from 3.0.0 to 3.0.1 (#5413)
dependabot[bot] May 30, 2022
2ac9637
build(deps): bump github.com/tdewolff/minify/v2 from 2.11.5 to 2.11.7…
dependabot[bot] May 31, 2022
92f459d
docs(kicsbot): update images digest (#5421)
kicsbot May 31, 2022
d7fc24f
build(deps): bump github.com/aws/aws-sdk-go from 1.44.24 to 1.44.25 (…
dependabot[bot] Jun 1, 2022
0dc8d81
docs(kicsbot): update images digest (#5426)
kicsbot Jun 1, 2022
86319d6
Update metadata.json (#5424)
ramprasathasokan Jun 1, 2022
60c6251
ci(deps): bump golang from 1.18.2-alpine to 1.18.3-alpine (#5430)
dependabot[bot] Jun 2, 2022
75a24d3
build(deps): bump github.com/aws/aws-sdk-go from 1.44.25 to 1.44.26 (…
dependabot[bot] Jun 2, 2022
31e1300
docs(kicsbot): update images digest (#5428)
kicsbot Jun 2, 2022
138a7f1
feat(query): added "App Service Without Latest PHP Version" query for…
cxAndreFelicidade Jun 2, 2022
9970ebe
build(deps): bump github.com/open-policy-agent/opa from 0.40.0 to 0.4…
dependabot[bot] Jun 3, 2022
1e38e44
build(deps): bump github.com/aws/aws-sdk-go from 1.44.26 to 1.44.27 (…
dependabot[bot] Jun 3, 2022
c993b95
build(deps): bump github.com/tdewolff/minify/v2 from 2.11.7 to 2.11.8…
dependabot[bot] Jun 6, 2022
e3cbbc5
added -t flag on docker run command (#5434)
joaorufi Jun 6, 2022
122fa25
added 256 color to Dockerfile (#5427)
rafaela-soares Jun 6, 2022
c84e0c3
update(report): improved report message (#5418)
rafaela-soares Jun 6, 2022
2d90888
fix(analyzer): fixed Dockerfile analyzer approach (#5407)
rafaela-soares Jun 6, 2022
2d347ee
update(queries): updated S3 Bucket queries for Terraform (#4872)
rafaela-soares Jun 6, 2022
7977e7c
update(bom): updated AWS BOM S3 Bucket (#4873)
rafaela-soares Jun 6, 2022
f423529
fix(inspector): fix timeout secrets inspector (#5419)
joaorufi Jun 6, 2022
6f72dcc
feat(filesystem): double star support to exclude folders (#5408)
joaorufi Jun 6, 2022
bb6841f
docs(kicsbot): update images digest (#5432)
kicsbot Jun 6, 2022
b7caba6
docs(kicsbot): update github-action image digest (#5440)
kicsbot Jun 6, 2022
d5dd1f3
fixed queries (#5441)
rafaela-soares Jun 6, 2022
9d89255
fix(query): s3 bucket policy accepts http requests (#5415)
LupovichRan Jun 6, 2022
417e0ea
feat(query): added "Role Definition Allows Custom Role Creation" quer…
cosmicgirl97 Jun 6, 2022
0be47c5
fixed function check_schemes of openapi lib (#5433)
rafaela-soares Jun 6, 2022
8d06099
support child modules in the tfplan payload (#5422)
rafaela-soares Jun 6, 2022
cb69f65
docs(kicsbot): update images digest (#5442)
kicsbot Jun 7, 2022
df85a0e
build(deps): bump github.com/stretchr/testify from 1.7.1 to 1.7.2 (#5…
dependabot[bot] Jun 7, 2022
a7e5dcb
build(deps): bump github.com/aws/aws-sdk-go from 1.44.27 to 1.44.28 (…
dependabot[bot] Jun 7, 2022
d393cfa
build(deps): bump github.com/tdewolff/minify/v2 from 2.11.8 to 2.11.9…
dependabot[bot] Jun 7, 2022
7205c12
build(deps): bump github.com/aws/aws-sdk-go from 1.44.28 to 1.44.29 (…
dependabot[bot] Jun 8, 2022
7cadf69
docs(kicsbot): update images digest (#5450)
kicsbot Jun 8, 2022
299d9a7
fix(queries): align descriptionText to similar queries across differe…
roi-orca Jun 8, 2022
8455700
added mutex (#5429)
joaorufi Jun 8, 2022
f398dff
feat(result): added resourceType and resourceName to CloudFormation q…
rafaela-soares Jun 8, 2022
20a0028
docs(queries): update queries catalog (#5451)
kicsbot Jun 8, 2022
cd24fef
feat(result): added resourceType and resourceName to Terraform querie…
rafaela-soares Jun 8, 2022
26b653b
docs(queries): update queries catalog (#5454)
kicsbot Jun 8, 2022
583aeb7
docs: preparing for release 1.5.10 (#5455)
kicsbot Jun 8, 2022
49e8fe5
build(deps): bump github.com/gookit/color from 1.5.0 to 1.5.1 (#5469)
dependabot[bot] Jun 13, 2022
c4110da
build(deps): bump github.com/aws/aws-sdk-go from 1.44.29 to 1.44.32 (…
dependabot[bot] Jun 13, 2022
d797e13
docs(kicsbot): update images digest (#5464)
kicsbot Jun 13, 2022
46a5591
build(deps): bump golang.org/x/tools from 0.1.10 to 0.1.11 (#5467)
dependabot[bot] Jun 13, 2022
61fb4d0
ci(deps): bump actions/setup-python from 3 to 4 (#5462)
dependabot[bot] Jun 13, 2022
bce876d
fix(queries): align descriptionText to similar queries across differe…
roi-orca Jun 13, 2022
dfbf53c
docs(kicsbot): update images digest (#5471)
kicsbot Jun 14, 2022
51f2e5f
build(deps): bump github.com/aws/aws-sdk-go from 1.44.32 to 1.44.33 (…
dependabot[bot] Jun 14, 2022
b0878fd
build(deps): bump github.com/hashicorp/go-getter from 1.6.1 to 1.6.2 …
dependabot[bot] Jun 14, 2022
7ba5f12
docs(kicsbot): update github-action image digest (#5474)
kicsbot Jun 14, 2022
e7fd749
build(deps): bump github.com/tdewolff/minify/v2 from 2.11.9 to 2.11.1…
dependabot[bot] Jun 15, 2022
3330636
build(deps): bump github.com/aws/aws-sdk-go from 1.44.33 to 1.44.34 (…
dependabot[bot] Jun 15, 2022
07a8bdf
docs(kicsbot): update images digest (#5485)
kicsbot Jun 20, 2022
41953d3
build(deps): bump github.com/aws/aws-sdk-go from 1.44.34 to 1.44.37 (…
dependabot[bot] Jun 20, 2022
ec3496e
fix(query): uncomment cloud formation's test sample (#5320)
lipeavelar Jun 20, 2022
3ed1506
added branching process for major versions (#5479)
rafaela-soares Jun 20, 2022
b92b481
Update sync_major_release.yaml (#5497)
rafaela-soares Jun 20, 2022
12ad5cb
build(deps): bump github.com/aws/aws-sdk-go from 1.44.37 to 1.44.38 (…
dependabot[bot] Jun 21, 2022
bb4eb62
build(deps): bump github.com/stretchr/testify from 1.7.2 to 1.7.4 (#5…
dependabot[bot] Jun 21, 2022
3ab1ca4
docs(kicsbot): update images digest (#5500)
kicsbot Jun 21, 2022
af958ea
update(query): improved "Resource Not Using Tags" description (#5483)
rafaela-soares Jun 21, 2022
af2c63a
fix(secrets inspector): added mutex to lock addVulnerability (#5503)
rafaela-soares Jun 21, 2022
6c18f4c
docs(queries): update queries catalog (#5501)
kicsbot Jun 21, 2022
cd8dca1
build(deps): bump github.com/spf13/cobra from 1.4.0 to 1.5.0 (#5507)
dependabot[bot] Jun 22, 2022
eb70ded
build(deps): bump github.com/aws/aws-sdk-go from 1.44.38 to 1.44.39 (…
dependabot[bot] Jun 22, 2022
d47a92a
docs(kicsbot): update images digest (#5509)
kicsbot Jun 22, 2022
4552d3e
fix(analyzer): discard possible Dockerfile when they are not actually…
rafaela-soares Jun 22, 2022
03f43c6
update(dockerfile): fix CVE-2022-1586 and CVE-2022-29810 (#5492)
rafaela-soares Jun 22, 2022
5fe2e7c
fix(resolver): exclude resolve path call for the same path reference …
rafaela-soares Jun 22, 2022
2343a0f
docs: preparing for release 1.5.11 (#5515)
kicsbot Jun 22, 2022
321064a
build(deps): bump github.com/tdewolff/minify/v2 from 2.11.10 to 2.11.…
dependabot[bot] Jun 23, 2022
7979aa9
build(deps): bump github.com/hashicorp/hcl/v2 from 2.12.0 to 2.13.0 (…
dependabot[bot] Jun 23, 2022
8a7fc2a
build(deps): bump github.com/aws/aws-sdk-go from 1.44.39 to 1.44.40 (…
dependabot[bot] Jun 23, 2022
2c3d197
docs(kicsbot): update images digest (#5526)
kicsbot Jun 23, 2022
c3758f0
build(deps): bump github.com/stretchr/testify from 1.7.4 to 1.7.5 (#5…
dependabot[bot] Jun 27, 2022
b9ef2dc
build(deps): bump github.com/aws/aws-sdk-go from 1.44.40 to 1.44.42 (…
dependabot[bot] Jun 27, 2022
f91d294
docs(kicsbot): update images digest (#5528)
kicsbot Jun 27, 2022
0a3b222
feat(query): add new k8s rule to detect attach permission (RBAC) (#5491)
Churro Jun 27, 2022
7eae846
docs(kicsbot): update images digest (#5535)
kicsbot Jun 28, 2022
f65d2b6
ci(deps): bump styfle/cancel-workflow-action from 0.9.1 to 0.10.0 (#5…
dependabot[bot] Jun 28, 2022
4cec726
build(deps): bump github.com/aws/aws-sdk-go from 1.44.42 to 1.44.43 (…
dependabot[bot] Jun 28, 2022
d0e2350
Add wafv2 to query incl. negative test (#5529)
AlexEndris Jun 30, 2022
c3c2a79
docs(kicsbot): update images digest (#5541)
kicsbot Jun 30, 2022
e50ce90
build(deps): bump github.com/stretchr/testify from 1.7.5 to 1.8.0 (#5…
dependabot[bot] Jun 30, 2022
f8e601a
build(deps): bump github.com/aws/aws-sdk-go from 1.44.43 to 1.44.45 (…
dependabot[bot] Jun 30, 2022
27009c3
fix(scan behavior): ignore broken synlink (#5533)
liorj-orca Jun 30, 2022
0c35555
build(deps): bump github.com/aws/aws-sdk-go from 1.44.45 to 1.44.46 (…
dependabot[bot] Jul 1, 2022
d579cc9
build(deps): bump github.com/emicklei/proto from 1.10.0 to 1.11.0 (#5…
dependabot[bot] Jul 1, 2022
052994a
docs(kicsbot): update images digest (#5550)
kicsbot Jul 1, 2022
16506e6
build(deps): bump github.com/aws/aws-sdk-go from 1.44.46 to 1.44.47 (…
dependabot[bot] Jul 4, 2022
2b586d5
docs(kicsbot): update images digest (#5553)
kicsbot Jul 4, 2022
fe231e4
build(deps): bump github.com/open-policy-agent/opa from 0.41.0 to 0.4…
dependabot[bot] Jul 5, 2022
f74d47d
docs(kicsbot): update images digest (#5556)
kicsbot Jul 5, 2022
c9a73dc
build(deps): bump github.com/aws/aws-sdk-go from 1.44.47 to 1.44.48 (…
dependabot[bot] Jul 6, 2022
c129eb3
docs(kicsbot): update images digest (#5558)
kicsbot Jul 6, 2022
2f03f19
build(deps): bump github.com/aws/aws-sdk-go from 1.44.48 to 1.44.49 (…
dependabot[bot] Jul 7, 2022
3a9a673
build(deps): bump github.com/tdewolff/minify/v2 from 2.11.11 to 2.11.…
dependabot[bot] Jul 7, 2022
4517cbb
docs(kicsbot): update images digest (#5564)
kicsbot Jul 7, 2022
15ef9bc
build(deps): bump github.com/aws/aws-sdk-go from 1.44.49 to 1.44.50 (…
dependabot[bot] Jul 8, 2022
69298d4
docs(kicsbot): update images digest (#5567)
kicsbot Jul 8, 2022
a930f32
build(deps): bump github.com/aws/aws-sdk-go from 1.44.50 to 1.44.51 (…
dependabot[bot] Jul 11, 2022
b5b8d6d
build(deps): bump github.com/open-policy-agent/opa from 0.42.0 to 0.4…
dependabot[bot] Jul 11, 2022
9e04f40
docs(kicsbot): update images digest (#5573)
kicsbot Jul 11, 2022
f3d5f40
feat(rego): add query to check iam policy to invoke lambda (#5542)
jplanckeel Jul 11, 2022
147cf5e
fix(keyExpectedValue): convert to a recommendation rather than a curr…
liorj-orca Jul 11, 2022
d992b8a
docs(queries): update queries catalog (#5577)
kicsbot Jul 11, 2022
77fa241
fix(keyExpectedValue): convert to a recommendation rather than a cur…
liorj-orca Jul 11, 2022
a725fe5
build(deps): bump github.com/cheggaaa/pb/v3 from 3.0.8 to 3.1.0 (#5580)
dependabot[bot] Jul 12, 2022
548068c
build(deps): bump github.com/tdewolff/minify/v2 from 2.11.12 to 2.12.…
dependabot[bot] Jul 12, 2022
565f073
docs(kicsbot): update images digest (#5583)
kicsbot Jul 12, 2022
0d4daf5
build(deps): bump github.com/aws/aws-sdk-go from 1.44.51 to 1.44.52 (…
dependabot[bot] Jul 12, 2022
207bcf3
fix(keyExpectedValue): convert to a recommendation rather than a cur…
liorj-orca Jul 12, 2022
b40e888
build(deps): bump github.com/aws/aws-sdk-go from 1.44.52 to 1.44.53 (…
dependabot[bot] Jul 13, 2022
f9605f9
docs(kicsbot): update images digest (#5587)
kicsbot Jul 13, 2022
04160b4
ci(deps): bump golang from 1.18.3-alpine to 1.18.4-alpine (#5586)
dependabot[bot] Jul 13, 2022
8e7caaf
fix(keyExpectedValue): ansible-aws queries convert to a recommendatio…
liorj-orca Jul 13, 2022
e813f46
fix(keyExpectedValue): ansible-azure queries convert to a recommendat…
liorj-orca Jul 13, 2022
59f5063
fix(keyExpectedValue): AzureResourceManager queries convert to a reco…
liorj-orca Jul 13, 2022
345f5b8
fix(cloud provider flag): support alicloud in the cloud provider flag…
rafaela-soares Jul 13, 2022
b61dbe4
fix(keyExpectedValue): ansible-gcp queries convert to a recommendatio…
liorj-orca Jul 13, 2022
661e90a
build(deps): bump github.com/aws/aws-sdk-go from 1.44.53 to 1.44.54 (…
dependabot[bot] Jul 14, 2022
fcb7fb4
build(deps): bump github.com/open-policy-agent/opa from 0.42.1 to 0.4…
dependabot[bot] Jul 14, 2022
3c6a2c9
build(deps): bump helm.sh/helm/v3 from 3.9.0 to 3.9.1 (#5597)
dependabot[bot] Jul 14, 2022
3569bd6
docs(kicsbot): update images digest (#5598)
kicsbot Jul 14, 2022
8ac8b66
feat(cli & engine): kics auto remediation support (#5570)
rafaela-soares Jul 14, 2022
55aefaa
fix(query): add check for ALB use in Terraform AWS Security Query (#5…
cxMiguelSilva Jul 14, 2022
6e86b67
feat(auto_remediation): add auto remediation for Terraform AWS Querie…
cxMiguelSilva Jul 14, 2022
bc87c6b
feat(kics_ar): add remediation for terraform alicloud security querie…
cxMiguelSilva Jul 14, 2022
d1a4632
feat(kics_ar): add kics_auto_remediation terraform azure security que…
cxMiguelSilva Jul 15, 2022
1d591b0
docs(kicsbot): update images digest (#5604)
kicsbot Jul 15, 2022
a686091
build(deps): bump github.com/aws/aws-sdk-go from 1.44.54 to 1.44.55 (…
dependabot[bot] Jul 15, 2022
41607be
feat(kics_ar): add kics_auto_remediation for terraform gcp securtiy q…
cxMiguelSilva Jul 15, 2022
60b2869
feat(kics_ar): add kics_auto_remediation for terraform kubernetes sec…
cxMiguelSilva Jul 15, 2022
eb8abf1
reverting go routine
rafaela-soares Jul 15, 2022
cf023ce
Merge pull request #5608 from Checkmarx/fix/kics_ar
cxMiguelSilva Jul 15, 2022
902fa7b
docs: preparing for release 1.5.12 (#5610)
kicsbot Jul 15, 2022
f0cb54c
build(deps): bump github.com/aws/aws-sdk-go from 1.44.55 to 1.44.56 (…
dependabot[bot] Jul 18, 2022
7e8b65d
docs(kicsbot): update images digest (#5614)
kicsbot Jul 18, 2022
046d671
build(deps): bump github.com/aws/aws-sdk-go from 1.44.56 to 1.44.57 (…
dependabot[bot] Jul 19, 2022
f3fa073
ci(deps): bump alpine from 3.16.0 to 3.16.1 (#5618)
dependabot[bot] Jul 19, 2022
5364536
docs(kicsbot): update images digest (#5619)
kicsbot Jul 19, 2022
a8e7a61
docs(kicsbot): update github-action image digest (#5620)
kicsbot Jul 19, 2022
cfe61ad
ci(deps): bump docker/build-push-action from 3.0.0 to 3.1.0 (#5623)
dependabot[bot] Jul 20, 2022
fe4b1d2
build(deps): bump github.com/aws/aws-sdk-go from 1.44.57 to 1.44.58 (…
dependabot[bot] Jul 20, 2022
278acb1
docs(kicsbot): update images digest (#5625)
kicsbot Jul 20, 2022
6982566
build(deps): bump github.com/BurntSushi/toml from 1.1.0 to 1.2.0 (#5627)
dependabot[bot] Jul 21, 2022
e6e101a
build(deps): bump github.com/aws/aws-sdk-go from 1.44.58 to 1.44.59 (…
dependabot[bot] Jul 21, 2022
20c1b63
docs(kicsbot): update images digest (#5629)
kicsbot Jul 21, 2022
0ac33a5
fix(detector): fixed memory leak (#5626)
rafaela-soares Jul 21, 2022
16f8b86
Merge branch 'master' into integrations_v1.5.12_updated
rafaela-soares Jul 21, 2022
87a5fa9
correcting dockercompose-queries.md
rafaela-soares Jul 21, 2022
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/go-ci-integration.yml
Original file line number Diff line number Diff line change
Expand Up @@ -32,7 +32,7 @@ jobs:
run: echo "GITHUB_SHA_SHORT=$(echo $GITHUB_SHA | cut -c 1-8)" >> $GITHUB_ENV
- name: Build
id: docker_build
uses: docker/build-push-action@v3.0.0
uses: docker/build-push-action@v3.1.0
with:
load: true
context: ./
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/go-e2e.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -55,7 +55,7 @@ jobs:
run: echo "GITHUB_SHA_SHORT=$(echo $GITHUB_SHA | cut -c 1-8)" >> $GITHUB_ENV
- name: Build
id: docker_build
uses: docker/build-push-action@v3.0.0
uses: docker/build-push-action@v3.1.0
with:
load: true
context: ./
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/go-generate-antlr-parser.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ jobs:
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v1
- name: Build ANTLR image
uses: docker/build-push-action@v3.0.0
uses: docker/build-push-action@v3.1.0
id: build_antlr_image
with:
context: .
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/release-apispec.yml
Original file line number Diff line number Diff line change
Expand Up @@ -137,7 +137,7 @@ jobs:
password: ${{ secrets.DOCKER_PASSWORD }}
- name: Push alpine to Docker Hub
id: build_alpine
uses: docker/build-push-action@v3.0.0
uses: docker/build-push-action@v3.1.0
with:
context: .
push: true
Expand All @@ -150,7 +150,7 @@ jobs:
APISCANNER="true"
- name: Build and push debian to Docker Hub
id: build_debian
uses: docker/build-push-action@v3.0.0
uses: docker/build-push-action@v3.1.0
with:
context: .
file: ./docker/Dockerfile.apispec.debian
Expand Down
6 changes: 3 additions & 3 deletions .github/workflows/release-dkr-image-for-tag.yml
Original file line number Diff line number Diff line change
Expand Up @@ -69,7 +69,7 @@ jobs:
username: ${{ secrets.DOCKER_USERNAME }}
password: ${{ secrets.DOCKER_PASSWORD }}
- name: Push alpine to Docker Hub
uses: docker/build-push-action@v3.0.0
uses: docker/build-push-action@v3.1.0
with:
context: .
push: true
Expand All @@ -83,7 +83,7 @@ jobs:
- name: Push debian to Docker Hub
if: ${{ hashFiles('./docker/Dockerfile.debian') }} != ""
id: build_debian
uses: docker/build-push-action@v3.0.0
uses: docker/build-push-action@v3.1.0
with:
context: .
file: ./docker/Dockerfile.debian
Expand All @@ -98,7 +98,7 @@ jobs:
- name: Push ubi8 to Docker Hub
if: ${{ hashFiles('./docker/Dockerfile.ubi8') }} != ""
id: build_ubi8
uses: docker/build-push-action@v3.0.0
uses: docker/build-push-action@v3.1.0
with:
context: .
file: ./docker/Dockerfile.ubi8
Expand Down
6 changes: 3 additions & 3 deletions .github/workflows/release-dkr-image.yml
Original file line number Diff line number Diff line change
Expand Up @@ -48,7 +48,7 @@ jobs:
username: ${{ secrets.DOCKER_USERNAME }}
password: ${{ secrets.DOCKER_PASSWORD }}
- name: Push alpine to Docker Hub
uses: docker/build-push-action@v3.0.0
uses: docker/build-push-action@v3.1.0
id: build_alpine
with:
context: .
Expand All @@ -62,7 +62,7 @@ jobs:
DESCRIPTIONS_URL=${{ secrets.DESCRIPTIONS_URL }}
- name: Build and push debian to Docker Hub
id: build_debian
uses: docker/build-push-action@v3.0.0
uses: docker/build-push-action@v3.1.0
with:
context: .
file: ./docker/Dockerfile.debian
Expand All @@ -76,7 +76,7 @@ jobs:
DESCRIPTIONS_URL=${{ secrets.DESCRIPTIONS_URL }}
- name: Build and push ubi8 to Docker Hub
id: build_ubi8
uses: docker/build-push-action@v3.0.0
uses: docker/build-push-action@v3.1.0
with:
context: .
file: ./docker/Dockerfile.ubi8
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/release-docker-github-actions.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -33,7 +33,7 @@ jobs:
username: ${{ secrets.DOCKER_USERNAME }}
password: ${{ secrets.DOCKER_PASSWORD }}
- name: Push Github Action Image to Docker Hub
uses: docker/build-push-action@v3.0.0
uses: docker/build-push-action@v3.1.0
id: build_gh_action
with:
context: .
Expand Down
6 changes: 3 additions & 3 deletions .github/workflows/release-nightly.yml
Original file line number Diff line number Diff line change
Expand Up @@ -160,7 +160,7 @@ jobs:
password: ${{ secrets.DOCKER_PASSWORD }}
- name: Push alpine to Docker Hub
id: build_alpine
uses: docker/build-push-action@v3.0.0
uses: docker/build-push-action@v3.1.0
with:
context: .
push: true
Expand All @@ -172,7 +172,7 @@ jobs:
DESCRIPTIONS_URL=${{ secrets.DESCRIPTIONS_URL }}
- name: Build and push debian to Docker Hub
id: build_debian
uses: docker/build-push-action@v3.0.0
uses: docker/build-push-action@v3.1.0
with:
context: .
file: ./docker/Dockerfile.debian
Expand All @@ -185,7 +185,7 @@ jobs:
DESCRIPTIONS_URL=${{ secrets.DESCRIPTIONS_URL }}
- name: Build and push ubi8 to Docker Hub
id: build_ubi8
uses: docker/build-push-action@v3.0.0
uses: docker/build-push-action@v3.1.0
with:
context: .
file: ./docker/Dockerfile.ubi8
Expand Down
2 changes: 1 addition & 1 deletion Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -33,7 +33,7 @@ HEALTHCHECK CMD wget -q --method=HEAD localhost/system-status.txt
# Runtime image
# Ignore no User Cmd since KICS container is stopped afer scan
# kics-scan ignore-line
FROM alpine:3.16.0
FROM alpine:3.16.1

ENV TERM xterm-256color

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,6 @@ subjects:
name: bob
apiGroup: rbac.authorization.k8s.io
roleRef:
kind: Role
kind: Role
name: allow-attach-neg
apiGroup: ""
Original file line number Diff line number Diff line change
Expand Up @@ -13,9 +13,12 @@ CxPolicy[result] {
"resourceType": "aws_api_gateway_rest_api",
"resourceName": tf_lib.get_resource_name(resource, name),
"searchKey": sprintf("aws_api_gateway_rest_api[%s]", [name]),
"searchLine": commonLib.build_search_line(["resource", "aws_api_gateway_rest_api", name], []),
"issueType": "MissingAttribute",
"keyExpectedValue": "Attribute 'minimum_compression_size' to be set and have a value greater than -1 and smaller than 10485760",
"keyActualValue": "Attribute 'minimum_compression_size' is undefined",
"remediation": "minimum_compression_size = 0",
"remediationType": "addition",
}
}

Expand All @@ -29,8 +32,14 @@ CxPolicy[result] {
"resourceType": "aws_api_gateway_rest_api",
"resourceName": tf_lib.get_resource_name(resource, name),
"searchKey": sprintf("aws_api_gateway_rest_api[%s].minimum_compression_size", [name]),
"searchLine": commonLib.build_search_line(["resource", "aws_api_gateway_rest_api", name, "minimum_compression_size"], []),
"issueType": "IncorrectValue",
"keyExpectedValue": "Attribute 'minimum_compression_size' to be greater than -1 and smaller than 10485760",
"keyActualValue": sprintf("Attribute 'minimum_compression_size' is %d", [resource.minimum_compression_size]),
"remediation": json.marshal({
"before": sprintf("%d", [resource.minimum_compression_size]),
"after": "0"
}),
"remediationType": "replacement",
}
}
1 change: 1 addition & 0 deletions docs/docker/digests.csv
Original file line number Diff line number Diff line change
Expand Up @@ -79,3 +79,4 @@ v1.5.6-gh-actions,sha256:f0232875171f3ef272ed3374a4f4e649fcddc9cc4fea3825d6ff103
v1.5.8-gh-actions,sha256:61a2d50c83f15acbcf536f56bebc114ba19eecfe5a356580ed931c4a01f341fd
v1.5.9-gh-actions,sha256:015eebbaeb31e8a9ea0909df089bed06442d8aabe60ac3e6afcdc00c269c0f41
v1.5.10-gh-actions,sha256:78199d59ab734071f32746d84ff0443b9a9dd6088bd9e335bfb7867964f2223b
v1.5.12-gh-actions,sha256:e3172e976f6be1885dfd6164a181ad2d9b824b6baab3b32e0b0b957b394fe1eb
1 change: 1 addition & 0 deletions docs/docker/digests.md
Original file line number Diff line number Diff line change
Expand Up @@ -80,3 +80,4 @@ v1.5.6-gh-actions | sha256:f0232875171f3ef272ed3374a4f4e649fcddc9cc4fea3825d6
v1.5.8-gh-actions | sha256:61a2d50c83f15acbcf536f56bebc114ba19eecfe5a356580ed931c4a01f341fd
v1.5.9-gh-actions | sha256:015eebbaeb31e8a9ea0909df089bed06442d8aabe60ac3e6afcdc00c269c0f41
v1.5.10-gh-actions | sha256:78199d59ab734071f32746d84ff0443b9a9dd6088bd9e335bfb7867964f2223b
v1.5.12-gh-actions | sha256:e3172e976f6be1885dfd6164a181ad2d9b824b6baab3b32e0b0b957b394fe1eb
16 changes: 16 additions & 0 deletions docs/docker/nightly.csv
Original file line number Diff line number Diff line change
Expand Up @@ -421,3 +421,19 @@ scratch,bc87c6bf,2022-07-15,sha256:180ae2bd2b8b27f13f716a5f645f602b8ee93fa31a079
alpine,bc87c6bf,2022-07-15,sha256:180ae2bd2b8b27f13f716a5f645f602b8ee93fa31a07969d52e8de2046441fd7
debian,bc87c6bf,2022-07-15,sha256:85b899a8ccbc3260b50239ca84a375087bbc57352c8b5dbd38efbb23118c2f5c
ubi8,bc87c6bf,2022-07-15,sha256:1263b8496e10a4914efc1c09b8c9b10b8cb39eaced03e207891b58088914ee29
scratch,902fa7bb,2022-07-18,sha256:890cc5f3730e8a58db1a9e8984285fd100f534e549a735a3984024b9ec3e8473
alpine,902fa7bb,2022-07-18,sha256:890cc5f3730e8a58db1a9e8984285fd100f534e549a735a3984024b9ec3e8473
debian,902fa7bb,2022-07-18,sha256:4526282f445316fe1615aa98414d604828d9af9e3741bd85c9e00ddc3fe5f4cf
ubi8,902fa7bb,2022-07-18,sha256:4b1935952706a5ccfbdd12378377f91d02b201d584f193ddbc89eb103fd9b8dd
scratch,7e8b65d9,2022-07-19,sha256:846a9fafb7cf2e9b95ae2e8ff611b81aec79c0ff37860270ed63635ba637a995
alpine,7e8b65d9,2022-07-19,sha256:846a9fafb7cf2e9b95ae2e8ff611b81aec79c0ff37860270ed63635ba637a995
debian,7e8b65d9,2022-07-19,sha256:8a87129603cd5e6e1ff9d655e2cf33405354d7e1bb759a0440be21b07f2235ca
ubi8,7e8b65d9,2022-07-19,sha256:fff30708f3809a04b3839a32a4cb4d267bace0cb30f6b0c77e38bb75640f3e8a
scratch,a8e7a611,2022-07-20,sha256:aa0db1182f560bb29d1afbaf8d0ca5e0779e8543d603110792bce24a19e706f6
alpine,a8e7a611,2022-07-20,sha256:aa0db1182f560bb29d1afbaf8d0ca5e0779e8543d603110792bce24a19e706f6
debian,a8e7a611,2022-07-20,sha256:0f2d0cf342f1df566800e286c4c926353a6b60b8355e0dcb460a839156c8e187
ubi8,a8e7a611,2022-07-20,sha256:6398049c8978b03454ff5d190cb358dd1f262871f879c368ec2271ba38c61246
scratch,278acb19,2022-07-21,sha256:027f5bbe9521c315060bc1a9198c911163cf155d68a31cfdca45e52e2a616979
alpine,278acb19,2022-07-21,sha256:027f5bbe9521c315060bc1a9198c911163cf155d68a31cfdca45e52e2a616979
debian,278acb19,2022-07-21,sha256:22c026a49665bf94751cc69a71d1d6e78af9cc3e6d1e301fe17b3b82e3b2d12a
ubi8,278acb19,2022-07-21,sha256:a9d3bb91a83a79af4f33006f521f73163a64036d3ea681e1c3f07d319cefd194
16 changes: 16 additions & 0 deletions docs/docker/nightly.md
Original file line number Diff line number Diff line change
Expand Up @@ -422,3 +422,19 @@ scratch | bc87c6bf | 2022-07-15 | sha256:180ae2bd2b8b27f13f716a5f645f602b8
alpine | bc87c6bf | 2022-07-15 | sha256:180ae2bd2b8b27f13f716a5f645f602b8ee93fa31a07969d52e8de2046441fd7
debian | bc87c6bf | 2022-07-15 | sha256:85b899a8ccbc3260b50239ca84a375087bbc57352c8b5dbd38efbb23118c2f5c
ubi8 | bc87c6bf | 2022-07-15 | sha256:1263b8496e10a4914efc1c09b8c9b10b8cb39eaced03e207891b58088914ee29
scratch | 902fa7bb | 2022-07-18 | sha256:890cc5f3730e8a58db1a9e8984285fd100f534e549a735a3984024b9ec3e8473
alpine | 902fa7bb | 2022-07-18 | sha256:890cc5f3730e8a58db1a9e8984285fd100f534e549a735a3984024b9ec3e8473
debian | 902fa7bb | 2022-07-18 | sha256:4526282f445316fe1615aa98414d604828d9af9e3741bd85c9e00ddc3fe5f4cf
ubi8 | 902fa7bb | 2022-07-18 | sha256:4b1935952706a5ccfbdd12378377f91d02b201d584f193ddbc89eb103fd9b8dd
scratch | 7e8b65d9 | 2022-07-19 | sha256:846a9fafb7cf2e9b95ae2e8ff611b81aec79c0ff37860270ed63635ba637a995
alpine | 7e8b65d9 | 2022-07-19 | sha256:846a9fafb7cf2e9b95ae2e8ff611b81aec79c0ff37860270ed63635ba637a995
debian | 7e8b65d9 | 2022-07-19 | sha256:8a87129603cd5e6e1ff9d655e2cf33405354d7e1bb759a0440be21b07f2235ca
ubi8 | 7e8b65d9 | 2022-07-19 | sha256:fff30708f3809a04b3839a32a4cb4d267bace0cb30f6b0c77e38bb75640f3e8a
scratch | a8e7a611 | 2022-07-20 | sha256:aa0db1182f560bb29d1afbaf8d0ca5e0779e8543d603110792bce24a19e706f6
alpine | a8e7a611 | 2022-07-20 | sha256:aa0db1182f560bb29d1afbaf8d0ca5e0779e8543d603110792bce24a19e706f6
debian | a8e7a611 | 2022-07-20 | sha256:0f2d0cf342f1df566800e286c4c926353a6b60b8355e0dcb460a839156c8e187
ubi8 | a8e7a611 | 2022-07-20 | sha256:6398049c8978b03454ff5d190cb358dd1f262871f879c368ec2271ba38c61246
scratch | 278acb19 | 2022-07-21 | sha256:027f5bbe9521c315060bc1a9198c911163cf155d68a31cfdca45e52e2a616979
alpine | 278acb19 | 2022-07-21 | sha256:027f5bbe9521c315060bc1a9198c911163cf155d68a31cfdca45e52e2a616979
debian | 278acb19 | 2022-07-21 | sha256:22c026a49665bf94751cc69a71d1d6e78af9cc3e6d1e301fe17b3b82e3b2d12a
ubi8 | 278acb19 | 2022-07-21 | sha256:a9d3bb91a83a79af4f33006f521f73163a64036d3ea681e1c3f07d319cefd194
Loading