kubescape / regolibrary

The regolibrary package contains the controls Kubescape uses for detecting misconfigurations in Kubernetes manifests.
Apache License 2.0
120 stars 48 forks source link

Initial SOC2 framework support #550

Closed slashben closed 11 months ago

slashben commented 11 months ago

type:

Enhancement


description:

This PR introduces an initial framework for SOC2 compliance. The new framework is defined in a JSON file and includes:


main_files_walkthrough:

files: - `frameworks/soc2.json`: Added a new JSON file to define the SOC2 compliance framework. This includes the framework's name, description, attributes, scanning scope, type tags, and active controls. Each active control has a unique control ID and provides a name, description, long description, and remediation (where applicable).

User Description:

Overview

Adding a framework for SOC2 compliance

codiumai-pr-agent-free[bot] commented 11 months ago

PR Analysis

How to use

Instructions > To invoke the PR-Agent, add a comment using one of the following commands: > **/review**: Request a review of your Pull Request. > **/describe**: Update the PR title and description based on the contents of the PR. > **/improve [--extended]**: Suggest code improvements. Extended mode provides a higher quality feedback. > **/ask \**: Ask a question about the PR. > **/update_changelog**: Update the changelog based on the PR's contents. > **/add_docs**: Generate docstring for new components introduced in the PR. > **/generate_labels**: Generate labels for the PR based on the PR's contents. > see the [tools guide](https://github.com/Codium-ai/pr-agent/blob/main/docs/TOOLS_GUIDE.md) for more details. >To edit any configuration parameter from the [configuration.toml](https://github.com/Codium-ai/pr-agent/blob/main/pr_agent/settings/configuration.toml), add --config_path=new_value. >For example: /review --pr_reviewer.extra_instructions="focus on the file: ..." >To list the possible configuration parameters, add a **/config** comment.