github Checkmarx/kics v2.1.20

10 hours ago

What's Changed

  • feat(query): implements "Beta - Azure Container Registry With Broad Permissions" by @cx-andre-pereira in #7880
  • feat(query): implements "Beta - Storage Account Without CMK" by @cx-andre-pereira in #7874
  • feat(queries): implemented queries that checks if the tls encryption version is set to '1.2' or higher for terrraform/azure by @cx-ricardo-jesus in #7852
  • feat(query): implements "Beta - AKS Without Audit Logs" by @cx-andre-pereira in #7883
  • refactor(similarityID): the transition type in the transition yaml files similarityID from 2 to 1 in beta queries by @cx-ricardo-jesus in #7952
  • feat(query): implemented query that checks if alpha clusters are enabled for google kubernetes engine cluster by @cx-ricardo-jesus in #7881
  • fix(query): added missing check for 'clone' field in "google_sql_database_instance" beta queries by @cx-andre-pereira in #7910
  • feat(query): implements "Beta - Cluster Without Network Policy Support" by @cx-andre-pereira in #7907
  • fix(vulnerabilities): upgrade OPA to v1.12.3 by @cx-rui-araujo in #7958
  • feat(query): implemented query that ensures that gke version management is automated using release channels by @cx-ricardo-jesus in #7885
  • fix(query): directly covered the cases where vhd_containers is defined on the azurerm_virtual_machine_scale_set_resource by @cx-ricardo-jesus in #7923
  • feat(queries): implemented queries to check if managed identity is not enabled by @cx-ricardo-jesus in #7863
  • fix(analyzer): add unwanted channel drain before done channel returns for correct line count by @cx-artur-ribeiro in #7942
  • fix(bug): improve helm scanning for empty files and duplicated results by @cx-miguel-dasilva in #7937
  • fix(queries): fixed results on queries that had unhandled %s by @cx-ricardo-jesus in #7950
  • fix(queries): fix policy evaluation when scanning Terraform plan vs HCL files by @cx-artur-ribeiro in #7926
  • fix(queries): fix policy evaluation when scanning Terraform plan vs HCL files - phase2 by @cx-artur-ribeiro in #7927
  • fix(query): fixed results to mention correct resource type in secret without expiration date query by @cx-ricardo-jesus in #7954
  • feat(query): implemented query that ensures that integrity monitoring for Shielded GKE Nodes is enabled by @cx-ricardo-jesus in #7886
  • feat(query): implemented query that ensures that kubernetes web ui is disabled (field deprecated) by @cx-ricardo-jesus in #7879
  • fix(loglevel): update log level from error to warn on analyzer by @cx-artur-ribeiro in #7970
  • fix(query): add supports for Microsoft.Web/sites/config on Web App Not Using TLS Last Version for AzureResourceManager by @cx-ricardo-jesus in #7928
  • fix(queries): better interpreter for gcp queries by @cx-andre-pereira in #7912
  • docs(queries): update queries catalog by @kicsbot in #7945
  • docs(kicsbot): preparing for release 2.1.20 by @kicsbot in #7983

Full Changelog: v2.1.19...v2.1.20

Don't miss a new kics release

NewReleases is sending notifications on new releases.