github kubescape/regolibrary v1.0.195
Release v1.0.195

latest releases: v2, v2.0.11, v2.0.11-rc.1...
2 years ago

List of changes

1. Added new "Attack Track" definitions

We have 3 attack tracks:

  1. Container
  2. Kube API
  3. Node

Attack tracks will be published as an artifact in the release (similar to frameworks).
Export python script was updated accordingly.

2. Existing controls were updated with attack track information

A control is associated to specific step(s) in an attack track. (attackTracks attribute)
A control can be associated with different tags (controlTypeTags attribute)

Base score is also updated for some controls.

3. Removed duplications - consolidated export.py and export-dev.py

4. Controls were marked inactive

  • Application exploit (RCE)
  • Bash/cmd inside container
  • Vulnerable application
  • Access tiller endpoint

5. "Resource policies" control renamed to "Resource limits"

Don't miss a new regolibrary release

NewReleases is sending notifications on new releases.