SDK
🐞 Fixed
s3_bucket_shadow_resource_vulnerabilityno longer emits a tautologicalPASSfinding for every bucket; a finding is now produced only when the bucket name matches one of the predictable service patterns (Glue, SageMaker, EMR, CodeStar) (#11220)sqlserver_tde_encrypted_with_cmkcheck for Azure provider no longer reports a falseFAILfor SQL Servers whose user databases are correctly encrypted with a customer-managed key, by excluding the systemmasterdatabase (always reports TDEDisabledand is not customer-controllable) from the TDE evaluation (#11233)