jinugasachio / terraform-workspace-type

0 stars 0 forks source link

Update dependency aquasecurity/tfsec to v1.28.10 #89

Open renovate[bot] opened 2 years ago

renovate[bot] commented 2 years ago

This PR contains the following updates:

Package Update Change
aquasecurity/tfsec minor v1.15.4 -> v1.28.10

Release Notes

aquasecurity/tfsec (aquasecurity/tfsec) ### [`v1.28.10`](https://togithub.com/aquasecurity/tfsec/releases/tag/v1.28.10) [Compare Source](https://togithub.com/aquasecurity/tfsec/compare/v1.28.9...v1.28.10) ##### What's Changed - Goreleaser update by [@​simar7](https://togithub.com/simar7) in [https://github.com/aquasecurity/tfsec/pull/2149](https://togithub.com/aquasecurity/tfsec/pull/2149) **Full Changelog**: https://github.com/aquasecurity/tfsec/compare/v1.28.8...v1.28.10 ### [`v1.28.9`](https://togithub.com/aquasecurity/tfsec/releases/tag/v1.28.9) [Compare Source](https://togithub.com/aquasecurity/tfsec/compare/v1.28.8...v1.28.9) #### What's Changed - Goreleaser update by [@​simar7](https://togithub.com/simar7) in [https://github.com/aquasecurity/tfsec/pull/2149](https://togithub.com/aquasecurity/tfsec/pull/2149) **Full Changelog**: https://github.com/aquasecurity/tfsec/compare/v1.28.8...v1.28.9 ### [`v1.28.8`](https://togithub.com/aquasecurity/tfsec/releases/tag/v1.28.8) [Compare Source](https://togithub.com/aquasecurity/tfsec/compare/v1.28.7...v1.28.8) #### What's Changed - chore(deps): Fix goreleaser to use pinned version by [@​simar7](https://togithub.com/simar7) in [https://github.com/aquasecurity/tfsec/pull/2148](https://togithub.com/aquasecurity/tfsec/pull/2148) **Full Changelog**: https://github.com/aquasecurity/tfsec/compare/v1.28.7...v1.28.8 ### [`v1.28.7`](https://togithub.com/aquasecurity/tfsec/releases/tag/v1.28.7) [Compare Source](https://togithub.com/aquasecurity/tfsec/compare/v1.28.6...v1.28.7) #### What's Changed - fix: typo by [@​testwill](https://togithub.com/testwill) in [https://github.com/aquasecurity/tfsec/pull/2110](https://togithub.com/aquasecurity/tfsec/pull/2110) - Bumped Go-Getter due High Vulnerability CVE-2024-6257 by [@​jdesouza](https://togithub.com/jdesouza) in [https://github.com/aquasecurity/tfsec/pull/2145](https://togithub.com/aquasecurity/tfsec/pull/2145) - chore(deps): bump golang.org/x/net from 0.19.0 to 0.23.0 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/aquasecurity/tfsec/pull/2146](https://togithub.com/aquasecurity/tfsec/pull/2146) - chore(deps): bump google.golang.org/protobuf from 1.30.0 to 1.33.0 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/aquasecurity/tfsec/pull/2147](https://togithub.com/aquasecurity/tfsec/pull/2147) #### New Contributors - [@​testwill](https://togithub.com/testwill) made their first contribution in [https://github.com/aquasecurity/tfsec/pull/2110](https://togithub.com/aquasecurity/tfsec/pull/2110) **Full Changelog**: https://github.com/aquasecurity/tfsec/compare/v1.28.6...v1.28.7 ### [`v1.28.6`](https://togithub.com/aquasecurity/tfsec/releases/tag/v1.28.6) [Compare Source](https://togithub.com/aquasecurity/tfsec/compare/v1.28.5...v1.28.6) ##### What's Changed - Bumped hashicorp/go-getter due Critical Vulnerability by [@​jdesouza](https://togithub.com/jdesouza) in [https://github.com/aquasecurity/tfsec/pull/2144](https://togithub.com/aquasecurity/tfsec/pull/2144) ##### New Contributors - [@​jdesouza](https://togithub.com/jdesouza) made their first contribution in [https://github.com/aquasecurity/tfsec/pull/2144](https://togithub.com/aquasecurity/tfsec/pull/2144) **Full Changelog**: https://github.com/aquasecurity/tfsec/compare/v1.28.5...v1.28.6 ### [`v1.28.5`](https://togithub.com/aquasecurity/tfsec/releases/tag/v1.28.5) [Compare Source](https://togithub.com/aquasecurity/tfsec/compare/v1.28.4...v1.28.5) ##### What's Changed - Create auto-close-issues.yml by [@​simar7](https://togithub.com/simar7) in [https://github.com/aquasecurity/tfsec/pull/2104](https://togithub.com/aquasecurity/tfsec/pull/2104) - chore(deps): bump github.com/go-git/go-git/v5 from 5.5.2 to 5.11.0 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/aquasecurity/tfsec/pull/2131](https://togithub.com/aquasecurity/tfsec/pull/2131) - chore(deps): bump google.golang.org/grpc from 1.52.0 to 1.56.3 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/aquasecurity/tfsec/pull/2132](https://togithub.com/aquasecurity/tfsec/pull/2132) - chore(deps): bump golang.org/x/crypto from 0.16.0 to 0.17.0 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/aquasecurity/tfsec/pull/2133](https://togithub.com/aquasecurity/tfsec/pull/2133) - chore(deps): bump github.com/cloudflare/circl from 1.3.3 to 1.3.7 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/aquasecurity/tfsec/pull/2134](https://togithub.com/aquasecurity/tfsec/pull/2134) **Full Changelog**: https://github.com/aquasecurity/tfsec/compare/v1.28.4...v1.28.5 ### [`v1.28.4`](https://togithub.com/aquasecurity/tfsec/releases/tag/v1.28.4) [Compare Source](https://togithub.com/aquasecurity/tfsec/compare/v1.28.3...v1.28.4) ##### What's Changed - chore(ci): Update docs generation runner by [@​simar7](https://togithub.com/simar7) in [https://github.com/aquasecurity/tfsec/pull/2101](https://togithub.com/aquasecurity/tfsec/pull/2101) **Full Changelog**: https://github.com/aquasecurity/tfsec/compare/v1.28.3...v1.28.4 ### [`v1.28.3`](https://togithub.com/aquasecurity/tfsec/releases/tag/v1.28.3) [Compare Source](https://togithub.com/aquasecurity/tfsec/compare/v1.28.2...v1.28.3) ##### What's Changed - Print the transition message as standard error by [@​yu-iskw](https://togithub.com/yu-iskw) in [https://github.com/aquasecurity/tfsec/pull/2099](https://togithub.com/aquasecurity/tfsec/pull/2099) - chore(ci): Fix CI issues by [@​simar7](https://togithub.com/simar7) in [https://github.com/aquasecurity/tfsec/pull/2100](https://togithub.com/aquasecurity/tfsec/pull/2100) ##### New Contributors - [@​yu-iskw](https://togithub.com/yu-iskw) made their first contribution in [https://github.com/aquasecurity/tfsec/pull/2099](https://togithub.com/aquasecurity/tfsec/pull/2099) **Full Changelog**: https://github.com/aquasecurity/tfsec/compare/v1.28.2...v1.28.3 ### [`v1.28.2`](https://togithub.com/aquasecurity/tfsec/releases/tag/v1.28.2) [Compare Source](https://togithub.com/aquasecurity/tfsec/compare/v1.28.1...v1.28.2) ##### What's Changed - chore(deps): bump github.com/stretchr/testify from 1.8.0 to 1.8.1 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/aquasecurity/tfsec/pull/1930](https://togithub.com/aquasecurity/tfsec/pull/1930) - Set github stale bot message "days" to its config by [@​nitrocode](https://togithub.com/nitrocode) in [https://github.com/aquasecurity/tfsec/pull/1963](https://togithub.com/aquasecurity/tfsec/pull/1963) - Fix table in usage.md by [@​Eforen](https://togithub.com/Eforen) in [https://github.com/aquasecurity/tfsec/pull/1922](https://togithub.com/aquasecurity/tfsec/pull/1922) - chore(deps): bump github.com/spf13/cobra from 1.6.0 to 1.6.1 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/aquasecurity/tfsec/pull/1933](https://togithub.com/aquasecurity/tfsec/pull/1933) - Update snapshot-release.yml by [@​owenrumney](https://togithub.com/owenrumney) in [https://github.com/aquasecurity/tfsec/pull/1971](https://togithub.com/aquasecurity/tfsec/pull/1971) - chore(deps): bump crazy-max/ghaction-import-gpg from 5.1.0 to 5.2.0 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/aquasecurity/tfsec/pull/1928](https://togithub.com/aquasecurity/tfsec/pull/1928) - chore(deps): bump goreleaser/goreleaser-action from 3 to 4 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/aquasecurity/tfsec/pull/1964](https://togithub.com/aquasecurity/tfsec/pull/1964) - chore(deps): bump github.com/liamg/memoryfs from 1.4.3 to 1.5.0 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/aquasecurity/tfsec/pull/1944](https://togithub.com/aquasecurity/tfsec/pull/1944) - chore(deps): bump github.com/aquasecurity/defsec from 0.82.2 to 0.82.6 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/aquasecurity/tfsec/pull/1951](https://togithub.com/aquasecurity/tfsec/pull/1951) - Update snapshot-release.yml by [@​owenrumney](https://togithub.com/owenrumney) in [https://github.com/aquasecurity/tfsec/pull/1973](https://togithub.com/aquasecurity/tfsec/pull/1973) - chore(deps): bump golangci/golangci-lint-action from 3.2.0 to 3.3.1 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/aquasecurity/tfsec/pull/1947](https://togithub.com/aquasecurity/tfsec/pull/1947) - chore(deps): bump actions/stale from 6 to 7 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/aquasecurity/tfsec/pull/1968](https://togithub.com/aquasecurity/tfsec/pull/1968) - docs: Add Trivy migration guide by [@​simar7](https://togithub.com/simar7) in [https://github.com/aquasecurity/tfsec/pull/1961](https://togithub.com/aquasecurity/tfsec/pull/1961) - chore(deps): bump golangci/golangci-lint-action from 3.3.1 to 3.4.0 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/aquasecurity/tfsec/pull/1981](https://togithub.com/aquasecurity/tfsec/pull/1981) - chore(deps): bump github.com/liamg/memoryfs from 1.5.0 to 1.6.0 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/aquasecurity/tfsec/pull/1984](https://togithub.com/aquasecurity/tfsec/pull/1984) - Update golangci-lint.yml by [@​giorod3](https://togithub.com/giorod3) in [https://github.com/aquasecurity/tfsec/pull/2009](https://togithub.com/aquasecurity/tfsec/pull/2009) - bump go to version 1.19 by [@​simar7](https://togithub.com/simar7) in [https://github.com/aquasecurity/tfsec/pull/2013](https://togithub.com/aquasecurity/tfsec/pull/2013) - chore(deps): bump github.com/aquasecurity/defsec from 0.82.6 to 0.84.1 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/aquasecurity/tfsec/pull/2008](https://togithub.com/aquasecurity/tfsec/pull/2008) - chore(deps): bump alpine from 3.16.0 to 3.17.2 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/aquasecurity/tfsec/pull/1998](https://togithub.com/aquasecurity/tfsec/pull/1998) - fix typo of drop-invalid-headers doc by [@​tk3fftk](https://togithub.com/tk3fftk) in [https://github.com/aquasecurity/tfsec/pull/1976](https://togithub.com/aquasecurity/tfsec/pull/1976) - chore(deps): bump github/issue-labeler from 2.5 to 3.0 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/aquasecurity/tfsec/pull/1989](https://togithub.com/aquasecurity/tfsec/pull/1989) - fix: sha256 command by [@​aiell0](https://togithub.com/aiell0) in [https://github.com/aquasecurity/tfsec/pull/1987](https://togithub.com/aquasecurity/tfsec/pull/1987) - feat(config): use spf13/viper to read config from env vars by [@​nitrocode](https://togithub.com/nitrocode) in [https://github.com/aquasecurity/tfsec/pull/1990](https://togithub.com/aquasecurity/tfsec/pull/1990) - docs: Trivy callout and migration guide added by [@​AnaisUrlichs](https://togithub.com/AnaisUrlichs) in [https://github.com/aquasecurity/tfsec/pull/2021](https://togithub.com/aquasecurity/tfsec/pull/2021) - feat: Add a transition message by [@​simar7](https://togithub.com/simar7) in [https://github.com/aquasecurity/tfsec/pull/2067](https://togithub.com/aquasecurity/tfsec/pull/2067) - docs: README tfsec to trivy migration callout by [@​AnaisUrlichs](https://togithub.com/AnaisUrlichs) in [https://github.com/aquasecurity/tfsec/pull/2020](https://togithub.com/aquasecurity/tfsec/pull/2020) - chore(deps): bump github.com/cloudflare/circl from 1.1.0 to 1.3.3 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/aquasecurity/tfsec/pull/2055](https://togithub.com/aquasecurity/tfsec/pull/2055) ##### New Contributors - [@​nitrocode](https://togithub.com/nitrocode) made their first contribution in [https://github.com/aquasecurity/tfsec/pull/1963](https://togithub.com/aquasecurity/tfsec/pull/1963) - [@​Eforen](https://togithub.com/Eforen) made their first contribution in [https://github.com/aquasecurity/tfsec/pull/1922](https://togithub.com/aquasecurity/tfsec/pull/1922) - [@​giorod3](https://togithub.com/giorod3) made their first contribution in [https://github.com/aquasecurity/tfsec/pull/2009](https://togithub.com/aquasecurity/tfsec/pull/2009) - [@​aiell0](https://togithub.com/aiell0) made their first contribution in [https://github.com/aquasecurity/tfsec/pull/1987](https://togithub.com/aquasecurity/tfsec/pull/1987) - [@​AnaisUrlichs](https://togithub.com/AnaisUrlichs) made their first contribution in [https://github.com/aquasecurity/tfsec/pull/2021](https://togithub.com/aquasecurity/tfsec/pull/2021) **Full Changelog**: https://github.com/aquasecurity/tfsec/compare/v1.28.1...v1.28.2 ### [`v1.28.1`](https://togithub.com/aquasecurity/tfsec/releases/tag/v1.28.1) [Compare Source](https://togithub.com/aquasecurity/tfsec/compare/v1.28.0...v1.28.1) #### What's Changed - chore(deps): bump github.com/liamg/memoryfs from 1.4.2 to 1.4.3 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/aquasecurity/tfsec/pull/1893](https://togithub.com/aquasecurity/tfsec/pull/1893) - chore(deps): bump actions/stale from 5 to 6 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/aquasecurity/tfsec/pull/1910](https://togithub.com/aquasecurity/tfsec/pull/1910) - chore(deps): bump github.com/AlecAivazis/survey/v2 from 2.3.5 to 2.3.6 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/aquasecurity/tfsec/pull/1891](https://togithub.com/aquasecurity/tfsec/pull/1891) - chore: Update defsec to v0.82.2 by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/tfsec/pull/1932](https://togithub.com/aquasecurity/tfsec/pull/1932) **Full Changelog**: https://github.com/aquasecurity/tfsec/compare/v1.28.0...v1.28.1 ### [`v1.28.0`](https://togithub.com/aquasecurity/tfsec/releases/tag/v1.28.0) [Compare Source](https://togithub.com/aquasecurity/tfsec/compare/v1.27.6...v1.28.0) #### What's Changed - Add missing docs from recent additions to defsec by [@​reedloden](https://togithub.com/reedloden) in [https://github.com/aquasecurity/tfsec/pull/1884](https://togithub.com/aquasecurity/tfsec/pull/1884) - fix wrong code block by [@​dawez](https://togithub.com/dawez) in [https://github.com/aquasecurity/tfsec/pull/1883](https://togithub.com/aquasecurity/tfsec/pull/1883) - feat: support exclude expiry in config by [@​owenrumney](https://togithub.com/owenrumney) in [https://github.com/aquasecurity/tfsec/pull/1897](https://togithub.com/aquasecurity/tfsec/pull/1897) - feat: support optional provider and service name in custom checks by [@​owenrumney](https://togithub.com/owenrumney) in [https://github.com/aquasecurity/tfsec/pull/1899](https://togithub.com/aquasecurity/tfsec/pull/1899) - fix: Ensure rego input is properly filled for nested slices by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/defsec/pull/952](https://togithub.com/aquasecurity/defsec/pull/952) - fix: Readd policy wildcards rule to default framework by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/defsec/pull/954](https://togithub.com/aquasecurity/defsec/pull/954) - feat: add OnlyContains helper function by [@​owenrumney](https://togithub.com/owenrumney) in [https://github.com/aquasecurity/defsec/pull/953](https://togithub.com/aquasecurity/defsec/pull/953) **Full Changelog**: https://github.com/aquasecurity/tfsec/compare/v1.27.6...v1.28.0 ### [`v1.27.6`](https://togithub.com/aquasecurity/tfsec/releases/tag/v1.27.6) [Compare Source](https://togithub.com/aquasecurity/tfsec/compare/v1.27.5...v1.27.6) #### What's Changed - docs: Add module ignore documentation by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/tfsec/pull/1875](https://togithub.com/aquasecurity/tfsec/pull/1875) - build: Speed up caching and tidy actions build by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/tfsec/pull/1876](https://togithub.com/aquasecurity/tfsec/pull/1876) - fix: Use `mktemp` instead of `/tmp` to securely manage temporary directories by [@​reedloden](https://togithub.com/reedloden) in [https://github.com/aquasecurity/tfsec/pull/1870](https://togithub.com/aquasecurity/tfsec/pull/1870) - chore: Update defsec to v0.73.0 by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/tfsec/pull/1877](https://togithub.com/aquasecurity/tfsec/pull/1877) #### New Contributors - [@​reedloden](https://togithub.com/reedloden) made their first contribution in [https://github.com/aquasecurity/tfsec/pull/1870](https://togithub.com/aquasecurity/tfsec/pull/1870) **Full Changelog**: https://github.com/aquasecurity/tfsec/compare/v1.27.5...v1.27.6 ### [`v1.27.5`](https://togithub.com/aquasecurity/tfsec/releases/tag/v1.27.5) [Compare Source](https://togithub.com/aquasecurity/tfsec/compare/v1.27.4...v1.27.5) #### What's Changed - fix: Resolve S3 regressions by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/tfsec/pull/1867](https://togithub.com/aquasecurity/tfsec/pull/1867) **Full Changelog**: https://github.com/aquasecurity/tfsec/compare/v1.27.4...v1.27.5 ### [`v1.27.4`](https://togithub.com/aquasecurity/tfsec/releases/tag/v1.27.4) [Compare Source](https://togithub.com/aquasecurity/tfsec/compare/v1.27.3...v1.27.4) #### What's Changed - fix: panic in sqs adapter by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/tfsec/pull/1866](https://togithub.com/aquasecurity/tfsec/pull/1866) **Full Changelog**: https://github.com/aquasecurity/tfsec/compare/v1.27.3...v1.27.4 ### [`v1.27.3`](https://togithub.com/aquasecurity/tfsec/releases/tag/v1.27.3) [Compare Source](https://togithub.com/aquasecurity/tfsec/compare/v1.27.2...v1.27.3) #### What's Changed - fix: Fix s3 public access block linking by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/tfsec/pull/1865](https://togithub.com/aquasecurity/tfsec/pull/1865) **Full Changelog**: https://github.com/aquasecurity/tfsec/compare/v1.27.2...v1.27.3 ### [`v1.27.2`](https://togithub.com/aquasecurity/tfsec/releases/tag/v1.27.2) [Compare Source](https://togithub.com/aquasecurity/tfsec/compare/v1.27.1...v1.27.2) #### What's Changed - misc: automate the installation of tfsec on linux by [@​dawez](https://togithub.com/dawez) in [https://github.com/aquasecurity/tfsec/pull/1847](https://togithub.com/aquasecurity/tfsec/pull/1847) - chore(deps): bump crazy-max/ghaction-import-gpg from 5.0.0 to 5.1.0 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/aquasecurity/tfsec/pull/1837](https://togithub.com/aquasecurity/tfsec/pull/1837) - chore(deps): Update defsec to fix IAM ignores by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/tfsec/pull/1853](https://togithub.com/aquasecurity/tfsec/pull/1853) - fix: Fix build script by [@​owenrumney](https://togithub.com/owenrumney) in [https://github.com/aquasecurity/tfsec/pull/1856](https://togithub.com/aquasecurity/tfsec/pull/1856) - chore(deps): update defsec to v0.71.11 by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/tfsec/pull/1858](https://togithub.com/aquasecurity/tfsec/pull/1858) - chore(deps): update defsec to v0.72.0 by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/tfsec/pull/1861](https://togithub.com/aquasecurity/tfsec/pull/1861) #### New Contributors - [@​dawez](https://togithub.com/dawez) made their first contribution in [https://github.com/aquasecurity/tfsec/pull/1847](https://togithub.com/aquasecurity/tfsec/pull/1847) **Full Changelog**: https://github.com/aquasecurity/tfsec/compare/v1.27.1...v1.27.2 ### [`v1.27.1`](https://togithub.com/aquasecurity/tfsec/releases/tag/v1.27.1) [Compare Source](https://togithub.com/aquasecurity/tfsec/compare/v1.27.0...v1.27.1) #### What's Changed - chore: bump defsec by [@​owenrumney](https://togithub.com/owenrumney) in [https://github.com/aquasecurity/tfsec/pull/1843](https://togithub.com/aquasecurity/tfsec/pull/1843) **Full Changelog**: https://github.com/aquasecurity/tfsec/compare/v1.27.0...v1.27.1 ### [`v1.27.0`](https://togithub.com/aquasecurity/tfsec/releases/tag/v1.27.0) [Compare Source](https://togithub.com/aquasecurity/tfsec/compare/v1.26.3...v1.27.0) #### What's Changed - chore(deps): bump github.com/aquasecurity/defsec from 0.68.8 to 0.68.9 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/aquasecurity/tfsec/pull/1827](https://togithub.com/aquasecurity/tfsec/pull/1827) - fix tiny typo by [@​tk3fftk](https://togithub.com/tk3fftk) in [https://github.com/aquasecurity/tfsec/pull/1833](https://togithub.com/aquasecurity/tfsec/pull/1833) - chore(deps): bump github.com/aquasecurity/defsec from 0.68.9 to 0.68.10 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/aquasecurity/tfsec/pull/1831](https://togithub.com/aquasecurity/tfsec/pull/1831) - fix: output statistics in lovely, markdown or json format ([#​1790](https://togithub.com/aquasecurity/tfsec/issues/1790)) by [@​amandahla](https://togithub.com/amandahla) in [https://github.com/aquasecurity/tfsec/pull/1840](https://togithub.com/aquasecurity/tfsec/pull/1840) - feat: Add exclude-ignores flag and --config-file attribute by [@​alexandrupopafc](https://togithub.com/alexandrupopafc) in [https://github.com/aquasecurity/tfsec/pull/1839](https://togithub.com/aquasecurity/tfsec/pull/1839) #### New Contributors - [@​tk3fftk](https://togithub.com/tk3fftk) made their first contribution in [https://github.com/aquasecurity/tfsec/pull/1833](https://togithub.com/aquasecurity/tfsec/pull/1833) - [@​amandahla](https://togithub.com/amandahla) made their first contribution in [https://github.com/aquasecurity/tfsec/pull/1840](https://togithub.com/aquasecurity/tfsec/pull/1840) - [@​alexandrupopafc](https://togithub.com/alexandrupopafc) made their first contribution in [https://github.com/aquasecurity/tfsec/pull/1839](https://togithub.com/aquasecurity/tfsec/pull/1839) **Full Changelog**: https://github.com/aquasecurity/tfsec/compare/v1.26.3...v1.27.0 ### [`v1.26.3`](https://togithub.com/aquasecurity/tfsec/releases/tag/v1.26.3) [Compare Source](https://togithub.com/aquasecurity/tfsec/compare/v1.26.2...v1.26.3) #### What's Changed - GitHub Action link correction by [@​mencarellic](https://togithub.com/mencarellic) in [https://github.com/aquasecurity/tfsec/pull/1801](https://togithub.com/aquasecurity/tfsec/pull/1801) - chore(deps): bump github.com/stretchr/testify from 1.7.2 to 1.8.0 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/aquasecurity/tfsec/pull/1817](https://togithub.com/aquasecurity/tfsec/pull/1817) - chore(deps): bump github.com/hashicorp/go-version from 1.5.0 to 1.6.0 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/aquasecurity/tfsec/pull/1816](https://togithub.com/aquasecurity/tfsec/pull/1816) - chore(deps): bump github.com/spf13/cobra from 1.4.0 to 1.5.0 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/aquasecurity/tfsec/pull/1808](https://togithub.com/aquasecurity/tfsec/pull/1808) - chore(deps): bump github.com/owenrumney/go-sarif/v2 from 2.1.1 to 2.1.2 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/aquasecurity/tfsec/pull/1806](https://togithub.com/aquasecurity/tfsec/pull/1806) - fix: Fix bad use of AsNumber by [@​owenrumney](https://togithub.com/owenrumney) in [https://github.com/aquasecurity/tfsec/pull/1824](https://togithub.com/aquasecurity/tfsec/pull/1824) #### New Contributors - [@​mencarellic](https://togithub.com/mencarellic) made their first contribution in [https://github.com/aquasecurity/tfsec/pull/1801](https://togithub.com/aquasecurity/tfsec/pull/1801) **Full Changelog**: https://github.com/aquasecurity/tfsec/compare/v1.26.2...v1.26.3 ### [`v1.26.2`](https://togithub.com/aquasecurity/tfsec/releases/tag/v1.26.2) [Compare Source](https://togithub.com/aquasecurity/tfsec/compare/v1.26.1...v1.26.2) #### What's Changed - fix: fix public block linking by [@​owenrumney](https://togithub.com/owenrumney) in [https://github.com/aquasecurity/tfsec/pull/1821](https://togithub.com/aquasecurity/tfsec/pull/1821) **Full Changelog**: https://github.com/aquasecurity/tfsec/compare/v1.26.1...v1.26.2 ### [`v1.26.1`](https://togithub.com/aquasecurity/tfsec/releases/tag/v1.26.1) [Compare Source](https://togithub.com/aquasecurity/tfsec/compare/v1.26.0...v1.26.1) #### What's Changed - fix: prefer tfsec-bin AUR package by [@​greut](https://togithub.com/greut) in [https://github.com/aquasecurity/tfsec/pull/1798](https://togithub.com/aquasecurity/tfsec/pull/1798) - fix: Treat numbers in string attributes as numbers if required by [@​owenrumney](https://togithub.com/owenrumney) in [https://github.com/aquasecurity/tfsec/pull/1820](https://togithub.com/aquasecurity/tfsec/pull/1820) **Full Changelog**: https://github.com/aquasecurity/tfsec/compare/v1.26.0...v1.26.1 ### [`v1.26.0`](https://togithub.com/aquasecurity/tfsec/releases/tag/v1.26.0) [Compare Source](https://togithub.com/aquasecurity/tfsec/compare/v1.25.1...v1.26.0) #### What's Changed - feat: Improve markdown/html output by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/tfsec/pull/1795](https://togithub.com/aquasecurity/tfsec/pull/1795) - chore: Update defsec to v0.68.2 by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/tfsec/pull/1796](https://togithub.com/aquasecurity/tfsec/pull/1796) **Full Changelog**: https://github.com/aquasecurity/tfsec/compare/v1.25.1...v1.26.0 ### [`v1.25.1`](https://togithub.com/aquasecurity/tfsec/releases/tag/v1.25.1) [Compare Source](https://togithub.com/aquasecurity/tfsec/compare/v1.25.0...v1.25.1) #### What's Changed - fix: Non-CGO builds by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/tfsec/pull/1794](https://togithub.com/aquasecurity/tfsec/pull/1794) **Full Changelog**: https://github.com/aquasecurity/tfsec/compare/v1.25.0...v1.25.1 ### [`v1.25.0`](https://togithub.com/aquasecurity/tfsec/releases/tag/v1.25.0) [Compare Source](https://togithub.com/aquasecurity/tfsec/compare/v1.24.4...v1.25.0) #### What's Changed - chore(deps): bump github.com/AlecAivazis/survey/v2 from 2.3.4 to 2.3.5 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/aquasecurity/tfsec/pull/1785](https://togithub.com/aquasecurity/tfsec/pull/1785) - chore(deps): bump actions/setup-python from 3 to 4 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/aquasecurity/tfsec/pull/1784](https://togithub.com/aquasecurity/tfsec/pull/1784) - chore(deps): bump docker/setup-qemu-action from 1 to 2 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/aquasecurity/tfsec/pull/1783](https://togithub.com/aquasecurity/tfsec/pull/1783) - feat: Added sys info and extra debug logging via newer defsec by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/tfsec/pull/1793](https://togithub.com/aquasecurity/tfsec/pull/1793) - fix: Fix incorrect module/project directory being used when symlinks are encountered within a module (via defsec) **Full Changelog**: https://github.com/aquasecurity/tfsec/compare/v1.24.4...v1.25.0 ### [`v1.24.4`](https://togithub.com/aquasecurity/tfsec/releases/tag/v1.24.4) [Compare Source](https://togithub.com/aquasecurity/tfsec/compare/v1.24.3...v1.24.4) **Full Changelog**: https://github.com/aquasecurity/tfsec/compare/v1.24.3...v1.24.4 ### [`v1.24.3`](https://togithub.com/aquasecurity/tfsec/releases/tag/v1.24.3) [Compare Source](https://togithub.com/aquasecurity/tfsec/compare/v1.24.1...v1.24.3) #### What's Changed - fix: Fix docs generation by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/tfsec/pull/1788](https://togithub.com/aquasecurity/tfsec/pull/1788) - fix: Fix mkdocs insiders version by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/tfsec/pull/1789](https://togithub.com/aquasecurity/tfsec/pull/1789) **Full Changelog**: https://github.com/aquasecurity/tfsec/compare/v1.24.1...v1.24.3 ### [`v1.24.1`](https://togithub.com/aquasecurity/tfsec/releases/tag/v1.24.1) [Compare Source](https://togithub.com/aquasecurity/tfsec/compare/v1.24.0...v1.24.1) #### What's Changed - fix: Fix module handling via update to defsec v0.65.0 by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/tfsec/pull/1787](https://togithub.com/aquasecurity/tfsec/pull/1787) **Full Changelog**: https://github.com/aquasecurity/tfsec/compare/v1.24.0...v1.24.1 ### [`v1.24.0`](https://togithub.com/aquasecurity/tfsec/releases/tag/v1.24.0) [Compare Source](https://togithub.com/aquasecurity/tfsec/compare/v1.23.3...v1.24.0) #### What's Changed - feat: Add markdown and html output formats by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/tfsec/pull/1782](https://togithub.com/aquasecurity/tfsec/pull/1782) **Full Changelog**: https://github.com/aquasecurity/tfsec/compare/v1.23.3...v1.24.0 ### [`v1.23.3`](https://togithub.com/aquasecurity/tfsec/releases/tag/v1.23.3) [Compare Source](https://togithub.com/aquasecurity/tfsec/compare/v1.23.2...v1.23.3) Fixing the docker build - putting tfsec in the correct location for execution **Full Changelog**: https://github.com/aquasecurity/tfsec/compare/v1.23.2...v1.23.3 ### [`v1.23.2`](https://togithub.com/aquasecurity/tfsec/releases/tag/v1.23.2) [Compare Source](https://togithub.com/aquasecurity/tfsec/compare/v1.22.1...v1.23.2) #### What's Changed - chore(deps): bump github.com/stretchr/testify from 1.7.1 to 1.7.2 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/aquasecurity/tfsec/pull/1770](https://togithub.com/aquasecurity/tfsec/pull/1770) - feat: Install git on the CI Docker by [@​owenrumney](https://togithub.com/owenrumney) in [https://github.com/aquasecurity/tfsec/pull/1772](https://togithub.com/aquasecurity/tfsec/pull/1772) - feat: download config from remote location with config-file-url by [@​owenrumney](https://togithub.com/owenrumney) in [https://github.com/aquasecurity/tfsec/pull/1774](https://togithub.com/aquasecurity/tfsec/pull/1774) - fix: add git to Docker file so it can download modules by [@​owenrumney](https://togithub.com/owenrumney) in [https://github.com/aquasecurity/tfsec/pull/1777](https://togithub.com/aquasecurity/tfsec/pull/1777) - feat: add support for using custom check file from remote location by [@​owenrumney](https://togithub.com/owenrumney) in [https://github.com/aquasecurity/tfsec/pull/1776](https://togithub.com/aquasecurity/tfsec/pull/1776) - chore(deps): Bump the defsec version by [@​owenrumney](https://togithub.com/owenrumney) in [https://github.com/aquasecurity/tfsec/pull/1778](https://togithub.com/aquasecurity/tfsec/pull/1778) - fix: docker build by [@​owenrumney](https://togithub.com/owenrumney) in [https://github.com/aquasecurity/tfsec/pull/1781](https://togithub.com/aquasecurity/tfsec/pull/1781) **Full Changelog**: https://github.com/aquasecurity/tfsec/compare/v1.22.1...v1.23.2 ### [`v1.22.1`](https://togithub.com/aquasecurity/tfsec/releases/tag/v1.22.1) [Compare Source](https://togithub.com/aquasecurity/tfsec/compare/v1.22.0...v1.22.1) #### What's Changed - fix: infer no-code when concise by [@​owenrumney](https://togithub.com/owenrumney) in [https://github.com/aquasecurity/tfsec/pull/1764](https://togithub.com/aquasecurity/tfsec/pull/1764) - chore(deps): Update defsec to v0.62.0 by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/tfsec/pull/1768](https://togithub.com/aquasecurity/tfsec/pull/1768) ##### Changes in defsec v0.62.0 - feat(Dockerfile): Add support for 'Containerfile' detection as required by trivy/fanal by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/defsec/pull/660](https://togithub.com/aquasecurity/defsec/pull/660) - chore(deps): bump github.com/open-policy-agent/opa from 0.40.0 to 0.41.0 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/aquasecurity/defsec/pull/659](https://togithub.com/aquasecurity/defsec/pull/659) - chore(deps): bump gopkg.in/yaml.v3 from 3.0.0 to 3.0.1 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/aquasecurity/defsec/pull/658](https://togithub.com/aquasecurity/defsec/pull/658) - fix: Fix GKE cluster node config when non-default node-pool is used by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/defsec/pull/662](https://togithub.com/aquasecurity/defsec/pull/662) - fix: Fix no-auto-mount-service-token recommended action by [@​kajogo777](https://togithub.com/kajogo777) in [https://github.com/aquasecurity/defsec/pull/654](https://togithub.com/aquasecurity/defsec/pull/654) - fix: Fix unresolved string slice behaviour by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/defsec/pull/664](https://togithub.com/aquasecurity/defsec/pull/664) **Full Changelog**: https://github.com/aquasecurity/tfsec/compare/v1.22.0...v1.22.1 ### [`v1.22.0`](https://togithub.com/aquasecurity/tfsec/releases/tag/v1.22.0) [Compare Source](https://togithub.com/aquasecurity/tfsec/compare/v1.21.2...v1.22.0) #### What's Changed - chore(deps): bump github.com/hashicorp/go-version from 1.4.0 to 1.5.0 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/aquasecurity/tfsec/pull/1750](https://togithub.com/aquasecurity/tfsec/pull/1750) - fix: remove broken git submodule reference by [@​smelchior](https://togithub.com/smelchior) in [https://github.com/aquasecurity/tfsec/pull/1751](https://togithub.com/aquasecurity/tfsec/pull/1751) - chore(deps): bump goreleaser/goreleaser-action from 2 to 3 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/aquasecurity/tfsec/pull/1748](https://togithub.com/aquasecurity/tfsec/pull/1748) - chore(deps): bump alpine from 3.15 to 3.16.0 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/aquasecurity/tfsec/pull/1747](https://togithub.com/aquasecurity/tfsec/pull/1747) - chore(deps): bump github.com/aquasecurity/defsec from 0.57.8 to 0.59.0 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/aquasecurity/tfsec/pull/1749](https://togithub.com/aquasecurity/tfsec/pull/1749) - chore(deps): Update defsec to v0.60.0 by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/tfsec/pull/1758](https://togithub.com/aquasecurity/tfsec/pull/1758) - fix: Update defsec to fix unknown value error in reference by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/tfsec/pull/1759](https://togithub.com/aquasecurity/tfsec/pull/1759) - chore(deps): bump crazy-max/ghaction-import-gpg from 4.4.0 to 5.0.0 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/aquasecurity/tfsec/pull/1755](https://togithub.com/aquasecurity/tfsec/pull/1755) - feat: add glob support to exclude paths by [@​owenrumney](https://togithub.com/owenrumney) in [https://github.com/aquasecurity/tfsec/pull/1760](https://togithub.com/aquasecurity/tfsec/pull/1760) - feat: add no code option by [@​owenrumney](https://togithub.com/owenrumney) in [https://github.com/aquasecurity/tfsec/pull/1762](https://togithub.com/aquasecurity/tfsec/pull/1762) - fix(modules): Fix edge case causing infinite loop when resolving nested modules by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/tfsec/pull/1761](https://togithub.com/aquasecurity/tfsec/pull/1761) - chore(deps): bump defsec by [@​owenrumney](https://togithub.com/owenrumney) in [https://github.com/aquasecurity/tfsec/pull/1763](https://togithub.com/aquasecurity/tfsec/pull/1763) #### Defsec Updates - feat: split out DAX cluster and DynamoDB Table (https://github.com/aquasecurity/defsec#/defsec#653) (Owen Rumney) - feat: support managed encryption for sqs (https://github.com/aquasecurity/defsec#/defsec#651) (Owen Rumney) - feat: support for AWS EMR security configuration (https://github.com/aquasecurity/defsec#/defsec#643) (brandon-maxar) - fix(terraform): Properly support relative paths in remote modules (https://github.com/aquasecurity/defsec#/defsec#649) (Liam Galvin) - fix(terraform): Fix module loading from the local .terraform cache (https://github.com/aquasecurity/defsec#/defsec#648) (Liam Galvin) - fix(terraform): Prevent panics when block keys are unresolvable (https://github.com/aquasecurity/defsec#/defsec#646) (Liam Galvin) - fix(terraform): Fix resolution of provider-added values e.g. arn/id (https://github.com/aquasecurity/defsec#/defsec#645) (Liam Galvin) - fix(google): Fix false positive for Google Compute Firewall Rules (https://github.com/aquasecurity/defsec#/defsec#641) (Liam Galvin) - fix(google): Fix false positive in SQL instance backups for replicas (https://github.com/aquasecurity/defsec#/defsec#640) (Liam Galvin) - test: add tests for azure network tf adapters (https://github.com/aquasecurity/defsec#/defsec#634) (vanesasejdiu) - test: add tests for azure storage tf adapters (https://github.com/aquasecurity/defsec#/defsec#632) (vanesasejdiu) - test: add tests for google storage tf adapters (https://github.com/aquasecurity/defsec#/defsec#630) (vanesasejdiu) - fix: Single public IPs should ba acceptable as prefixes (https://github.com/aquasecurity/defsec#/defsec#629) (Owen Rumney) - fix: support source/target tags for GCP firewall (https://github.com/aquasecurity/defsec#/defsec#628) (Owen Rumney) - docs: Add example for >2.97.0 of the AzureRM provider for container logging (https://github.com/aquasecurity/defsec#/defsec#627) (Owen Rumney) - chore(deps): bump github.com/hashicorp/go-getter from 1.5.11 to 1.6.1 (https://github.com/aquasecurity/defsec#/defsec#620) (dependabot\[bot]) - test: add tests for google sql tf adapters (https://github.com/aquasecurity/defsec#/defsec#619) (vanesasejdiu) - test: add tests for google gke tf adapters (https://github.com/aquasecurity/defsec#/defsec#617) (vanesasejdiu) - test: add tests for google compute tf adapters (https://github.com/aquasecurity/defsec#/defsec#615) (vanesasejdiu) - perf: Improve code highlighting by caching syntax highlighted inputs (https://github.com/aquasecurity/defsec#/defsec#610) (Liam Galvin) - feat: Truncate source code with an optional limit (https://github.com/aquasecurity/defsec#/defsec#608) (Liam Galvin) - fix: Fix relative paths in JUnit output (https://github.com/aquasecurity/defsec#/defsec#605) (Liam Galvin) - fix: make highlight omit empty (https://github.com/aquasecurity/defsec#/defsec#602) (Owen Rumney) - fix: remove Highlighted from code explicitly (https://github.com/aquasecurity/defsec#/defsec#600) (Owen Rumney) - fix: Fix ansi double escapes (https://github.com/aquasecurity/defsec#/defsec#599) (Liam Galvin) - test: add tests for aws vpc tf adapters (https://github.com/aquasecurity/defsec#/defsec#597) (vanesasejdiu) - test: add tests for digital-ocean compute tf adapters (https://github.com/aquasecurity/defsec#/defsec#595) (vanesasejdiu) #### New Contributors - [@​smelchior](https://togithub.com/smelchior) made their first contribution in [https://github.com/aquasecurity/tfsec/pull/1751](https://togithub.com/aquasecurity/tfsec/pull/1751) **Full Changelog**: https://github.com/aquasecurity/tfsec/compare/v1.21.2...v1.22.0 ### [`v1.21.2`](https://togithub.com/aquasecurity/tfsec/releases/tag/v1.21.2) [Compare Source](https://togithub.com/aquasecurity/tfsec/compare/v1.21.1...v1.21.2) #### What's Changed - chore(deps): bump github.com/liamg/clinch from 1.5.6 to 1.6.1 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/aquasecurity/tfsec/pull/1737](https://togithub.com/aquasecurity/tfsec/pull/1737) - chore(deps): bump github/issue-labeler from 2.4.1 to 2.5 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/aquasecurity/tfsec/pull/1735](https://togithub.com/aquasecurity/tfsec/pull/1735) - chore(deps): bump golangci/golangci-lint-action from 3.1.0 to 3.2.0 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/aquasecurity/tfsec/pull/1734](https://togithub.com/aquasecurity/tfsec/pull/1734) - docs: Fix incorrect namespace usage in rego docs by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/tfsec/pull/1743](https://togithub.com/aquasecurity/tfsec/pull/1743) **Full Changelog**: https://github.com/aquasecurity/tfsec/compare/v1.21.1...v1.21.2 ### [`v1.21.1`](https://togithub.com/aquasecurity/tfsec/releases/tag/v1.21.1) [Compare Source](https://togithub.com/aquasecurity/tfsec/compare/v1.21.0...v1.21.1) #### What's Changed - fix: Fix JUnit paths by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/tfsec/pull/1740](https://togithub.com/aquasecurity/tfsec/pull/1740) **Full Changelog**: https://github.com/aquasecurity/tfsec/compare/v1.21.0...v1.21.1 ### [`v1.21.0`](https://togithub.com/aquasecurity/tfsec/releases/tag/v1.21.0) [Compare Source](https://togithub.com/aquasecurity/tfsec/compare/v1.20.2...v1.21.0) #### What's Changed - feat: Improved syntax highlighting via chroma in defsec by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/tfsec/pull/1724](https://togithub.com/aquasecurity/tfsec/pull/1724) - feat: Add customisable code themes by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/tfsec/pull/1725](https://togithub.com/aquasecurity/tfsec/pull/1725) **Full Changelog**: https://github.com/aquasecurity/tfsec/compare/v1.20.2...v1.21.0 ### [`v1.20.2`](https://togithub.com/aquasecurity/tfsec/releases/tag/v1.20.2) [Compare Source](https://togithub.com/aquasecurity/tfsec/compare/v1.20.1...v1.20.2) #### What's Changed - chore(deps): bump docker/login-action from 1 to 2 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/aquasecurity/tfsec/pull/1720](https://togithub.com/aquasecurity/tfsec/pull/1720) - fix(ignores): handle parameter based ignores in a foreach by [@​owenrumney](https://togithub.com/owenrumney) in [https://github.com/aquasecurity/tfsec/pull/1723](https://togithub.com/aquasecurity/tfsec/pull/1723) **Full Changelog**: https://github.com/aquasecurity/tfsec/compare/v1.20.1...v1.20.2 ### [`v1.20.1`](https://togithub.com/aquasecurity/tfsec/releases/tag/v1.20.1) [Compare Source](https://togithub.com/aquasecurity/tfsec/compare/v1.20.0...v1.20.1) #### What's Changed - chore: Update defsec to v0.54.0 by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/tfsec/pull/1715](https://togithub.com/aquasecurity/tfsec/pull/1715) - fix(parsing): Symlink resolution fix by [@​owenrumney](https://togithub.com/owenrumney) in [https://github.com/aquasecurity/tfsec/pull/1722](https://togithub.com/aquasecurity/tfsec/pull/1722) **Full Changelog**: https://github.com/aquasecurity/tfsec/compare/v1.20.0...v1.20.1 ### [`v1.20.0`](https://togithub.com/aquasecurity/tfsec/releases/tag/v1.20.0) [Compare Source](https://togithub.com/aquasecurity/tfsec/compare/v1.19.1...v1.20.0) #### What's Changed - fix: document all format options by [@​allcloud-jonathan](https://togithub.com/allcloud-jonathan) in [https://github.com/aquasecurity/tfsec/pull/1709](https://togithub.com/aquasecurity/tfsec/pull/1709) - docs: fix branch names in sarif github action by [@​gmarmstrong](https://togithub.com/gmarmstrong) in [https://github.com/aquasecurity/tfsec/pull/1701](https://togithub.com/aquasecurity/tfsec/pull/1701) - feat: Add syntax highlighting and clean up output by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/tfsec/pull/1714](https://togithub.com/aquasecurity/tfsec/pull/1714) #### New Contributors - [@​allcloud-jonathan](https://togithub.com/allcloud-jonathan) made their first contribution in [https://github.com/aquasecurity/tfsec/pull/1709](https://togithub.com/aquasecurity/tfsec/pull/1709) - [@​gmarmstrong](https://togithub.com/gmarmstrong) made their first contribution in [https://github.com/aquasecurity/tfsec/pull/1701](https://togithub.com/aquasecurity/tfsec/pull/1701) **Full Changelog**: https://github.com/aquasecurity/tfsec/compare/v1.19.1...v1.20.0 ### [`v1.19.1`](https://togithub.com/aquasecurity/tfsec/releases/tag/v1.19.1) [Compare Source](https://togithub.com/aquasecurity/tfsec/compare/v1.19.0...v1.19.1) #### What's Changed - fix: Always load embedded rego libraries by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/tfsec/pull/1700](https://togithub.com/aquasecurity/tfsec/pull/1700) - fix: foreach key by [@​owenrumney](https://togithub.com/owenrumney) in [https://github.com/aquasecurity/tfsec/pull/1703](https://togithub.com/aquasecurity/tfsec/pull/1703) **Full Changelog**: https://github.com/aquasecurity/tfsec/compare/v1.19.0...v1.19.1 ### [`v1.19.0`](https://togithub.com/aquasecurity/tfsec/releases/tag/v1.19.0) [Compare Source](https://togithub.com/aquasecurity/tfsec/compare/v1.18.0...v1.19.0) #### What's Changed - feat(flag): Add var-file flag in to duplicate tfvar-file by [@​owenrumney](https://togithub.com/owenrumney) in [https://github.com/aquasecurity/tfsec/pull/1683](https://togithub.com/aquasecurity/tfsec/pull/1683) - docs: Add link to Rego documentation by [@​atombrella](https://togithub.com/atombrella) in [https://github.com/aquasecurity/tfsec/pull/1686](https://togithub.com/aquasecurity/tfsec/pull/1686) - feat(defsec): Add support for applying rego rules to IAM policies by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/tfsec/pull/1676](https://togithub.com/aquasecurity/tfsec/pull/1676) - chore(deps): bump actions/stale from 4 to 5 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/aquasecurity/tfsec/pull/1673](https://togithub.com/aquasecurity/tfsec/pull/1673) - chore(deps): bump actions/setup-go from 2 to 3 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/aquasecurity/tfsec/pull/1672](https://togithub.com/aquasecurity/tfsec/pull/1672) - feat: Use new defsec options and improve path handling by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/tfsec/pull/1696](https://togithub.com/aquasecurity/tfsec/pull/1696) - chore(deps): bump crazy-max/ghaction-import-gpg from 4.3.0 to 4.4.0 by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/aquasecurity/tfsec/pull/1697](https://togithub.com/aquasecurity/tfsec/pull/1697) - chore(deps): bump defsec version by [@​owenrumney](https://togithub.com/owenrumney) in [https://github.com/aquasecurity/tfsec/pull/1699](https://togithub.com/aquasecurity/tfsec/pull/1699) - test: add tests for aws redshift tf adapters by [@​vanesasejdiu](https://togithub.com/vanesasejdiu) in [https://github.com/aquasecurity/defsec/pull/527](https://togithub.com/aquasecurity/defsec/pull/527) - fix(rule): GCP dnssec not applicable for private zones by [@​owenrumney](https://togithub.com/owenrumney) in [https://github.com/aquasecurity/defsec/pull/539](https://togithub.com/aquasecurity/defsec/pull/539) - test: add tests for aws lambda tf adapters by [@​vanesasejdiu](https://togithub.com/vanesasejdiu) in [https://github.com/aquasecurity/defsec/pull/529](https://togithub.com/aquasecurity/defsec/pull/529) **Full Changelog**: https://github.com/aquasecurity/tfsec/compare/v1.18.0...v1.19.0 ### [`v1.18.0`](https://togithub.com/aquasecurity/tfsec/releases/tag/v1.18.0) [Compare Source](https://togithub.com/aquasecurity/tfsec/compare/v1.17.0...v1.18.0) #### What's Changed - fix: remove duplication of checksum by [@​owenrumney](https://togithub.com/owenrumney) in [https://github.com/aquasecurity/tfsec/pull/1665](https://togithub.com/aquasecurity/tfsec/pull/1665) - feat(rego): Add --rego-only flag to run rego policies exclusively by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/tfsec/pull/1667](https://togithub.com/aquasecurity/tfsec/pull/1667) - fix(rego): Fix code highlighting for rego detections by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/tfsec/pull/1668](https://togithub.com/aquasecurity/tfsec/pull/1668) **Full Changelog**: https://github.com/aquasecurity/tfsec/compare/v1.17.0...v1.18.0 ### [`v1.17.0`](https://togithub.com/aquasecurity/tfsec/releases/tag/v1.17.0) [Compare Source](https://togithub.com/aquasecurity/tfsec/compare/v1.16.3...v1.17.0) #### What's Changed ##### Changes to tfsec - chore(defsec): Update defsec to v0.34.0 by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/tfsec/pull/1666](https://togithub.com/aquasecurity/tfsec/pull/1666) #### Changes to defsec - build(actions): Add cache action to speed up builds by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/defsec/pull/487](https://togithub.com/aquasecurity/defsec/pull/487) - fix(cloudformation): Fix margin removal for empty lines by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/defsec/pull/490](https://togithub.com/aquasecurity/defsec/pull/490) - fix(azurerm): Fix false positive on key vault secret expiration by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/defsec/pull/494](https://togithub.com/aquasecurity/defsec/pull/494) - fix(check): Fix false positive for azure network security rules by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/defsec/pull/498](https://togithub.com/aquasecurity/defsec/pull/498) - fix(avd): Fix avd docs generation by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/defsec/pull/499](https://togithub.com/aquasecurity/defsec/pull/499) - test(avd): Add test to ensure all avd docs are generated by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/defsec/pull/500](https://togithub.com/aquasecurity/defsec/pull/500) - fix(google): Fix GKE legacy endpoint use detection by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/defsec/pull/497](https://togithub.com/aquasecurity/defsec/pull/497) - feat(cf): Add support for AES256 enryption for s3 bucket in cloudformation by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/defsec/pull/496](https://togithub.com/aquasecurity/defsec/pull/496) - fix(check): Fix false positive for api gateway cache encryption by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/defsec/pull/495](https://togithub.com/aquasecurity/defsec/pull/495) - feat(azurerm): Add support for container logging via changes in latest azurerm terraform provider by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/defsec/pull/492](https://togithub.com/aquasecurity/defsec/pull/492) - feat(check): Add separate check for SNS encryption with CMK by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/defsec/pull/493](https://togithub.com/aquasecurity/defsec/pull/493) - feat(check): Add separate check for SQS CMK use by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/defsec/pull/491](https://togithub.com/aquasecurity/defsec/pull/491) **Full Changelog**: https://github.com/aquasecurity/tfsec/compare/v1.16.3...v1.17.0

### [`v1.16.3`](https://togithub.com/aquasecurity/tfsec/releases/tag/v1.16.3) [Compare Source](https://togithub.com/aquasecurity/tfsec/compare/v1.16.2...v1.16.3) #### What's Changed - fix: Fixes for multiple issues identified by adding flag tests by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/tfsec/pull/1662](https://togithub.com/aquasecurity/tfsec/pull/1662) - fix(config): Fix minimum_severity in yaml config files by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/tfsec/pull/1664](https://togithub.com/aquasecurity/tfsec/pull/1664) **Full Changelog**: https://github.com/aquasecurity/tfsec/compare/v1.16.2...v1.16.3 ### [`v1.16.2`](https://togithub.com/aquasecurity/tfsec/releases/tag/v1.16.2) [Compare Source](https://togithub.com/aquasecurity/tfsec/compare/v1.16.1...v1.16.2) #### What's Changed - fix: Paths/modules on Windows by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/tfsec/pull/1656](https://togithub.com/aquasecurity/tfsec/pull/1656) **Full Changelog**: https://github.com/aquasecurity/tfsec/compare/v1.16.1...v1.16.2 ### [`v1.16.1`](https://togithub.com/aquasecurity/tfsec/releases/tag/v1.16.1) [Compare Source](https://togithub.com/aquasecurity/tfsec/compare/v1.16.0...v1.16.1) #### What's Changed - fix: Fix Windows build by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/tfsec/pull/1655](https://togithub.com/aquasecurity/tfsec/pull/1655) **Full Changelog**: https://github.com/aquasecurity/tfsec/compare/v1.16.0...v1.16.1 ### [`v1.16.0`](https://togithub.com/aquasecurity/tfsec/releases/tag/v1.16.0) [Compare Source](https://togithub.com/aquasecurity/tfsec/compare/v1.15.4...v1.16.0) #### What's Changed - feat: Add fs.FS based scanning functionality and module handling by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/tfsec/pull/1649](https://togithub.com/aquasecurity/tfsec/pull/1649) - fix(defsec): Update defsec to v0.31.0 to fix multiple missing metadata issues by [@​liamg](https://togithub.com/liamg) in [https://github.com/aquasecurity/tfsec/pull/1652](https://togithub.com/aquasecurity/tfsec/pull/1652) **Full Changelog**: https://github.com/aquasecurity/tfsec/compare/v1.15.4...v1.16.0

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.



This PR was generated by Mend Renovate. View the repository job log.