Closed mikegcoleman closed 8 months ago
Welcome @mikegcoleman! It looks like this is your first PR to falcosecurity/plugins 🎉
Hey @mikegcoleman
It looks like there're some yaml validation issues. Could you take a look at the failing tests and fix them, please?
For example https://github.com/falcosecurity/plugins/actions/runs/7414200888/job/20294145856?pr=392
@leogr fixed the formatting issues. took a note to run the yaml validator before submitting a PR next time :)
Comparing 77d72e0768f297e5a896ecf8678e1abeebfa15a9
with latest tag gcpaudit-0.2.2
Major changes:
GCP IAM serviceAccount key deleted
has been removedGCP IAM serviceAccount deleted
has been removedGCP IAM serviceAccount modified
has been removedGCP backendService deleted
has been removedGCP IAM serviceAccount created
has been removedGCP IAM serviceAccount key created
has been removedGCP IAM principle modified
has been removedGCP cloud function updated or deleted
has been removedGCP KMS updated or deleted
has been removedGCP Pub/Sub Subscriber modified
has been removedMinor changes:
gcpaudit
has been incrementedGCP IAM service account created
has been addedGCP cloud function modified
has been addedGCP KMS deleted
has been addedGCP IAM service account deleted
has been addedGCP IAM policy modified
has been addedGCP logging sink deleted
has been addedGCP Pub/Sub subscription deleted
has been addedGCP IAM service account modified
has been addedGCP cloud function deleted
has been addedGCP backend service deleted
has been addedGCP IAM service account key deleted
has been addedGCP KMS updated
has been addedGCP Pub/Sub subscription modified
has been addedGCP IAM service account key created
has been addedMajor changes:
- Rule
GCP IAM serviceAccount key deleted
has been removed- Rule
GCP IAM serviceAccount deleted
has been removed- Rule
GCP IAM serviceAccount modified
has been removed- Rule
GCP backendService deleted
has been removed- Rule
GCP IAM serviceAccount created
has been removed- Rule
GCP IAM serviceAccount key created
has been removed- Rule
GCP IAM principle modified
has been removed- Rule
GCP cloud function updated or deleted
has been removed- Rule
GCP KMS updated or deleted
has been removed- Rule
GCP Pub/Sub Subscriber modified
has been removed
Note for releasers: we can just bump the minor since the major is still 0
cc @LucaGuerra @Andreagit97 @jasondellaluce
[APPROVALNOTIFIER] This PR is APPROVED
This pull-request has been approved by: leogr, mikegcoleman
The full list of commands accepted by this bot can be found here.
The pull request process is described here
LGTM label has been added.
What type of PR is this?
/area plugins
There were some grammatical errors in the rules themselves. Also some rules output messages were wrong (e.g. it would say "an object was created" when the rule was for deletion). I also separated some rules into two rules - in particular I tried to create "delete" and "modify" rules separately since I think admins would prefer to have more specificity in their output.
Which issue(s) this PR fixes: Fixes #391
Special notes for your reviewer: