Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.
By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
[//]: # "
PR Title
Be aware that we use the title to create changelog automatically and therefore only allow specific prefixes
- break: to indicate a breaking change, this supersedes any of the types
- feat: to indicate new features or checks
- fix: to indicate a bugfix or handling of edge cases of existing checks
- docs: to indicate an update to our documentation
- chore: to indicate adjustments to workflow files or dependency updates
- platform: to indicate a change needed for the platform
Additionally a scope is needs to be added to the prefix, which indicates the targeted framework, in doubt choose 'general'.
#
Allowed prefixs:
ansible|argo|arm|azure|bicep|bitbucket|circleci|cloudformation|dockerfile|github|gha|gitlab|helm|kubernetes|kustomize|openapi|sast|sca|secrets|serverless|terraform|general|graph|terraform_plan|terraform_json
#
ex.
feat(terraform): add CKV_AWS_123 to ensure that VPC Endpoint Service is configured for Manual Acceptance
"
Description
We converted the check StorageSyncPublicAccessDisabled from TEerraform language to ARM so that it also works on resources that are defined in ARM.
Fixes # (issue)
Description
Ensure that Azure File Sync disables public network access
Fix
To address the issue, ensure that the Azure File Sync service is
configured to disable public network access. This can typically be done
by adjusting the configuration settings for Azure File Sync either
through the Azure Portal or using Azure CLI/PowerShell commands.
Specifically, you need to set the publicNetworkAccess property to Disabled
Checklist:
[x ] My code follows the style guidelines of this project
[ x] I have performed a self-review of my own code
[ ] I have commented my code, particularly in hard-to-understand areas
[ ] I have made corresponding changes to the documentation
[x ] I have added tests that prove my feature, policy, or fix is effective and works
[ x] New and existing tests pass locally with my changes
[ ] Any dependent changes have been merged and published in downstream modules
By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
[//]: # "
PR Title
"
Description
We converted the check StorageSyncPublicAccessDisabled from TEerraform language to ARM so that it also works on resources that are defined in ARM.
Fixes # (issue)
Description
Ensure that Azure File Sync disables public network access
Fix
To address the issue, ensure that the Azure File Sync service is configured to disable public network access. This can typically be done by adjusting the configuration settings for Azure File Sync either through the Azure Portal or using Azure CLI/PowerShell commands. Specifically, you need to set the publicNetworkAccess property to Disabled
Checklist: