What's Changed
- feat(query): implements "Beta - Azure Container Registry With Broad Permissions" by @cx-andre-pereira in #7880
- feat(query): implements "Beta - Storage Account Without CMK" by @cx-andre-pereira in #7874
- feat(queries): implemented queries that checks if the tls encryption version is set to '1.2' or higher for terrraform/azure by @cx-ricardo-jesus in #7852
- feat(query): implements "Beta - AKS Without Audit Logs" by @cx-andre-pereira in #7883
- refactor(similarityID): the transition type in the transition yaml files similarityID from 2 to 1 in beta queries by @cx-ricardo-jesus in #7952
- feat(query): implemented query that checks if alpha clusters are enabled for google kubernetes engine cluster by @cx-ricardo-jesus in #7881
- fix(query): added missing check for 'clone' field in "google_sql_database_instance" beta queries by @cx-andre-pereira in #7910
- feat(query): implements "Beta - Cluster Without Network Policy Support" by @cx-andre-pereira in #7907
- fix(vulnerabilities): upgrade OPA to v1.12.3 by @cx-rui-araujo in #7958
- feat(query): implemented query that ensures that gke version management is automated using release channels by @cx-ricardo-jesus in #7885
- fix(query): directly covered the cases where vhd_containers is defined on the azurerm_virtual_machine_scale_set_resource by @cx-ricardo-jesus in #7923
- feat(queries): implemented queries to check if managed identity is not enabled by @cx-ricardo-jesus in #7863
- fix(analyzer): add unwanted channel drain before done channel returns for correct line count by @cx-artur-ribeiro in #7942
- fix(bug): improve helm scanning for empty files and duplicated results by @cx-miguel-dasilva in #7937
- fix(queries): fixed results on queries that had unhandled %s by @cx-ricardo-jesus in #7950
- fix(queries): fix policy evaluation when scanning Terraform plan vs HCL files by @cx-artur-ribeiro in #7926
- fix(queries): fix policy evaluation when scanning Terraform plan vs HCL files - phase2 by @cx-artur-ribeiro in #7927
- fix(query): fixed results to mention correct resource type in secret without expiration date query by @cx-ricardo-jesus in #7954
- feat(query): implemented query that ensures that integrity monitoring for Shielded GKE Nodes is enabled by @cx-ricardo-jesus in #7886
- feat(query): implemented query that ensures that kubernetes web ui is disabled (field deprecated) by @cx-ricardo-jesus in #7879
- fix(loglevel): update log level from error to warn on analyzer by @cx-artur-ribeiro in #7970
- fix(query): add supports for Microsoft.Web/sites/config on Web App Not Using TLS Last Version for AzureResourceManager by @cx-ricardo-jesus in #7928
- fix(queries): better interpreter for gcp queries by @cx-andre-pereira in #7912
- docs(queries): update queries catalog by @kicsbot in #7945
- docs(kicsbot): preparing for release 2.1.20 by @kicsbot in #7983
Full Changelog: v2.1.19...v2.1.20