github Checkmarx/kics v1.5.12

latest releases: v2.0.1, v2.0.1-integrations, v2.0.0...
22 months ago

🚀 New features and improvements

feat(query): add new k8s rule to detect attach permission (RBAC) (#5491) by @Churro
feat(query): add query to check iam policy to invoke lambda (#5542) by @jplanckeel

🐛 Bug fixes

fix(query): add wafv2 to query incl. negative test (#5529) by @AlexEndris
fix(scan behavior): ignore broken synlink (#5533) by @liorj-orca
fix(keyExpectedValue): convert to a recommendation rather than a current status (#5574) (#5576) (#5575) by @liorj-orca
fix(keyExpectedValue): ansible-aws queries convert to a recommendation rather than a current status (#5589) by @liorj-orca
fix(keyExpectedValue): ansible-azure queries convert to a recommendation rather than a current status (#5590) by @liorj-orca
fix(keyExpectedValue): AzureResourceManager queries convert to a recommendation rather than a current status (#5592) by @liorj-orca
fix(keyExpectedValue): ansible-gcp queries convert to a recommendation rather than a current status (#5591) by @liorj-orca
fix(cloud provider flag): support alicloud in the cloud provider flag (#5561)
fix(query): add check for ALB use in Terraform AWS Security Query (#5593)

📦 Dependency updates bumps

build(deps): bump github.com/tdewolff/minify/v2 from 2.11.10 to 2.12.0 (#5523) (#5563) (#5582)
build(deps): bump github.com/hashicorp/hcl/v2 from 2.12.0 to 2.13.0 (#5524)
build(deps): bump github.com/aws/aws-sdk-go from 1.44.39 to 1.44.55 (#5525) (#5531) (#5538) (#5545) (#5548) (#5552) (#5557) (#5562) (#5566) (#5571) (#5581) (#5585) (#5595) (#5603)
build(deps): bump github.com/stretchr/testify from 1.7.4 to 1.8.0 (#5530) (#5544)
build(deps): bump github.com/emicklei/proto from 1.10.0 to 1.11.0 (#5549)
build(deps): bump github.com/open-policy-agent/opa from 0.41.0 to 0.42.2 (#5555) (#5572) (#5596)
build(deps): bump github.com/cheggaaa/pb/v3 from 3.0.8 to 3.1.0 (#5580)
build(deps): bump helm.sh/helm/v3 from 3.9.0 to 3.9.1 (#5597)

ci(deps): bump styfle/cancel-workflow-action from 0.9.1 to 0.10.0 (#5537)
ci(deps): bump golang from 1.18.3-alpine to 1.18.4-alpine (#5586)

Don't miss a new kics release

NewReleases is sending notifications on new releases.