Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[pull] master from nccgroup:master #14

Open
wants to merge 1,248 commits into
base: master
Choose a base branch
from
Open

[pull] master from nccgroup:master #14

wants to merge 1,248 commits into from
This pull request is big! We’re only showing the most recent 250 commits.

Commits on May 13, 2022

  1. Add services

    x4v13r64 committed May 13, 2022
    Configuration menu
    Copy the full SHA
    d757816 View commit details
    Browse the repository at this point in the history
  2. Add services

    x4v13r64 committed May 13, 2022
    Configuration menu
    Copy the full SHA
    8714bf4 View commit details
    Browse the repository at this point in the history
  3. Add services

    x4v13r64 committed May 13, 2022
    Configuration menu
    Copy the full SHA
    9414c24 View commit details
    Browse the repository at this point in the history
  4. Basic Functions support

    x4v13r64 committed May 13, 2022
    Configuration menu
    Copy the full SHA
    41e5e05 View commit details
    Browse the repository at this point in the history
  5. Configuration menu
    Copy the full SHA
    b82a450 View commit details
    Browse the repository at this point in the history
  6. Configuration menu
    Copy the full SHA
    e8703ca View commit details
    Browse the repository at this point in the history

Commits on May 14, 2022

  1. Update SQS encryption finding to for managed SSE

    In November 2021, AWS added managed server-side encryption for SQS: https://aws.amazon.com/about-aws/whats-new/2021/11/amazon-sqs-server-side-encryption-keys-sse/
    
    This should be acceptable to satisfy the "Queue with Encryption Disabled" rule.
    charlietran committed May 14, 2022
    Configuration menu
    Copy the full SHA
    ef7875f View commit details
    Browse the repository at this point in the history

Commits on May 17, 2022

  1. better implementation

    x4v13r64 committed May 17, 2022
    Configuration menu
    Copy the full SHA
    66e830e View commit details
    Browse the repository at this point in the history
  2. Improve implementation

    x4v13r64 committed May 17, 2022
    Configuration menu
    Copy the full SHA
    65f7941 View commit details
    Browse the repository at this point in the history
  3. Improve implementation

    x4v13r64 committed May 17, 2022
    Configuration menu
    Copy the full SHA
    660cff6 View commit details
    Browse the repository at this point in the history
  4. Add IAM informatino

    x4v13r64 committed May 17, 2022
    Configuration menu
    Copy the full SHA
    337b383 View commit details
    Browse the repository at this point in the history
  5. Format service names

    x4v13r64 committed May 17, 2022
    Configuration menu
    Copy the full SHA
    db36914 View commit details
    Browse the repository at this point in the history
  6. Configuration menu
    Copy the full SHA
    c89f521 View commit details
    Browse the repository at this point in the history
  7. Add resources

    x4v13r64 committed May 17, 2022
    Configuration menu
    Copy the full SHA
    f52eb00 View commit details
    Browse the repository at this point in the history
  8. Get non provider IDs

    x4v13r64 committed May 17, 2022
    Configuration menu
    Copy the full SHA
    5cd31d5 View commit details
    Browse the repository at this point in the history
  9. Reformat

    x4v13r64 committed May 17, 2022
    Configuration menu
    Copy the full SHA
    02f7b6e View commit details
    Browse the repository at this point in the history
  10. Add base partials

    x4v13r64 committed May 17, 2022
    Configuration menu
    Copy the full SHA
    cdeb557 View commit details
    Browse the repository at this point in the history
  11. Better parsing and rendering

    x4v13r64 committed May 17, 2022
    Configuration menu
    Copy the full SHA
    c8a6132 View commit details
    Browse the repository at this point in the history
  12. Better parsing and rendering

    x4v13r64 committed May 17, 2022
    Configuration menu
    Copy the full SHA
    c1193e1 View commit details
    Browse the repository at this point in the history

Commits on May 18, 2022

  1. Add finding

    x4v13r64 committed May 18, 2022
    Configuration menu
    Copy the full SHA
    55ee5ea View commit details
    Browse the repository at this point in the history
  2. Add finding

    x4v13r64 committed May 18, 2022
    Configuration menu
    Copy the full SHA
    f921014 View commit details
    Browse the repository at this point in the history
  3. Add finding

    x4v13r64 committed May 18, 2022
    Configuration menu
    Copy the full SHA
    f4f42a7 View commit details
    Browse the repository at this point in the history
  4. Show potential secrets

    x4v13r64 committed May 18, 2022
    Configuration menu
    Copy the full SHA
    b8600c0 View commit details
    Browse the repository at this point in the history
  5. Check for secrets

    x4v13r64 committed May 18, 2022
    Configuration menu
    Copy the full SHA
    35a63a2 View commit details
    Browse the repository at this point in the history
  6. Add rules

    x4v13r64 committed May 18, 2022
    Configuration menu
    Copy the full SHA
    7fd0af7 View commit details
    Browse the repository at this point in the history
  7. Configuration menu
    Copy the full SHA
    e2c2e17 View commit details
    Browse the repository at this point in the history
  8. Add rule

    x4v13r64 committed May 18, 2022
    Configuration menu
    Copy the full SHA
    76a1958 View commit details
    Browse the repository at this point in the history
  9. Add rule

    x4v13r64 committed May 18, 2022
    Configuration menu
    Copy the full SHA
    c090068 View commit details
    Browse the repository at this point in the history
  10. Update prose

    x4v13r64 committed May 18, 2022
    Configuration menu
    Copy the full SHA
    05efd63 View commit details
    Browse the repository at this point in the history
  11. Fix class element

    x4v13r64 committed May 18, 2022
    Configuration menu
    Copy the full SHA
    40997ea View commit details
    Browse the repository at this point in the history
  12. Add rule

    x4v13r64 committed May 18, 2022
    Configuration menu
    Copy the full SHA
    b014ce4 View commit details
    Browse the repository at this point in the history
  13. Add rule

    x4v13r64 committed May 18, 2022
    Configuration menu
    Copy the full SHA
    af5feb8 View commit details
    Browse the repository at this point in the history
  14. Add field

    x4v13r64 committed May 18, 2022
    Configuration menu
    Copy the full SHA
    4f1c41a View commit details
    Browse the repository at this point in the history
  15. Add prose

    x4v13r64 committed May 18, 2022
    Configuration menu
    Copy the full SHA
    515d049 View commit details
    Browse the repository at this point in the history
  16. Better presentation

    x4v13r64 committed May 18, 2022
    Configuration menu
    Copy the full SHA
    9f51fb9 View commit details
    Browse the repository at this point in the history
  17. Merge pull request #1365 from nccgroup/fix/1356

    Fix #1356: Restrict regexes including a $ at the end of the current expressions
    x4v13r64 authored May 18, 2022
    Configuration menu
    Copy the full SHA
    bf172f6 View commit details
    Browse the repository at this point in the history
  18. Sorted rulesets

    x4v13r64 committed May 18, 2022
    Configuration menu
    Copy the full SHA
    8018698 View commit details
    Browse the repository at this point in the history
  19. Merge branch 'enhancement/new-gcp-services' into develop-latacora

    # Conflicts:
    #	ScoutSuite/providers/gcp/facade/base.py
    #	ScoutSuite/providers/gcp/rules/rulesets/default.json
    #	ScoutSuite/providers/utils.py
    x4v13r64 committed May 18, 2022
    Configuration menu
    Copy the full SHA
    c33696a View commit details
    Browse the repository at this point in the history
  20. Sorted rulesets

    x4v13r64 committed May 18, 2022
    Configuration menu
    Copy the full SHA
    6d1dd81 View commit details
    Browse the repository at this point in the history
  21. Merge #1420

    x4v13r64 committed May 18, 2022
    Configuration menu
    Copy the full SHA
    dab56bc View commit details
    Browse the repository at this point in the history
  22. Configuration menu
    Copy the full SHA
    21500d3 View commit details
    Browse the repository at this point in the history
  23. Configuration menu
    Copy the full SHA
    6cd534d View commit details
    Browse the repository at this point in the history

Commits on May 20, 2022

  1. Add latest policies

    x4v13r64 committed May 20, 2022
    Configuration menu
    Copy the full SHA
    ed9b74c View commit details
    Browse the repository at this point in the history
  2. Configuration menu
    Copy the full SHA
    c523720 View commit details
    Browse the repository at this point in the history

Commits on May 26, 2022

  1. Add unit tests for regex fix

    At present, the new unit test fails. Bizarrely, the test works as
    expected if it is performed manually instead of using pytest (i.e.
    define SAMPLE_USER_DATA and then call ._identify_user_data_secrets()
    with it. The regexes also work correctly when tested interactively or at
    pythex.org.
    
    It just doesn't work correctly for pytest (and by presumption, for
    actual code -- I'm working to construct a test for that).
    rscottbailey committed May 26, 2022
    Configuration menu
    Copy the full SHA
    8a23084 View commit details
    Browse the repository at this point in the history
  2. Disable and annotate new unit test

    Good luck figuring this one out... I have verified actual behavior, and
    interactive invocation (of both the individual commands, and the method)
    work exactly as expected.
    
    For some reason, using pytest to evaluate this configuration appears to
    break proper parsing of the regular expressions (??!!?!) and the
    assertions in the test fail because they return substring matches which
    are explicitly prohibited by the final group of the regular expression.
    
    I have annotated the test to indicate it is expected to fail, and added
    documentation of actual "in the wild" behavior, which is as expected.
    rscottbailey committed May 26, 2022
    Configuration menu
    Copy the full SHA
    2f16303 View commit details
    Browse the repository at this point in the history

Commits on Jun 3, 2022

  1. Merge pull request #1425 from nccgroup/develop-latacora

    Develop latacora
    michyweb authored Jun 3, 2022
    Configuration menu
    Copy the full SHA
    58aa638 View commit details
    Browse the repository at this point in the history
  2. add DeviceCodeCredential authentication

    Replace InteractiveBrowserCredential with DeviceCodeCredential authentication method when specifying the "--user-account-browser" command line option to facilitate MFA authentication from Docker container.
    fernando-gallego authored Jun 3, 2022
    Configuration menu
    Copy the full SHA
    95297c6 View commit details
    Browse the repository at this point in the history
  3. Disable throttling check

    Comment out throttling check since is_throttled is not fully implemented and triggers some errors.
    fernando-gallego authored Jun 3, 2022
    Configuration menu
    Copy the full SHA
    3fe5cde View commit details
    Browse the repository at this point in the history
  4. Handle Graph API 404 responses

    Handle 404 responses from MS Graph API for queries targetting non-existent datasets (i.e. retrieving group details for groupless users).
    
    Fixes typo in get_policies exception.
    fernando-gallego authored Jun 3, 2022
    Configuration menu
    Copy the full SHA
    5a591de View commit details
    Browse the repository at this point in the history
  5. Handle VMs without diagnostics profile

    Handle errors caused by accessing boot_diagnostics attribute on VMs without a diagnostics profile configured.
    fernando-gallego authored Jun 3, 2022
    Configuration menu
    Copy the full SHA
    28d5bb2 View commit details
    Browse the repository at this point in the history
  6. Disable KeyVault diagnostic settings checks

    Disable checks related to KeyVault diagnostic settings since some of the functions involved do not work as expected. get_diagnostic_settings invokes the "list" operation from DiagnosticSettingsOperations for the MonitorManagementClient class, which expects a "resource_uri" parameter consisting on an Azure resource URI. This is not currently being passed onto that function correctly and generates errors.
    fernando-gallego authored Jun 3, 2022
    Configuration menu
    Copy the full SHA
    dd405f6 View commit details
    Browse the repository at this point in the history
  7. Disable KeyVault logging and diagnostic settings rules

    Disable logging and diagnostic settings checks for KeyVaults since related functions need to be fixed.
    fernando-gallego authored Jun 3, 2022
    Configuration menu
    Copy the full SHA
    4eaaae1 View commit details
    Browse the repository at this point in the history
  8. Disable KeyVault logging and diagnostic settings rules

    Disable logging and diagnostic settings checks for KeyVaults since related functions need to be fixed.
    fernando-gallego authored Jun 3, 2022
    Configuration menu
    Copy the full SHA
    0bddd9b View commit details
    Browse the repository at this point in the history
  9. Workaround for MissingApiVersionParameter error

    Workaround for MissingApiVersionParameter error raised by Azure API when calling "list" operation from ComplianceResultsOperations for the SecurityCenter client. Also waiting for further info from Azure Python SDK devs on this matter.
    fernando-gallego authored Jun 3, 2022
    Configuration menu
    Copy the full SHA
    230bd2a View commit details
    Browse the repository at this point in the history
  10. Better parsing

    x4v13r64 committed Jun 3, 2022
    Configuration menu
    Copy the full SHA
    0706135 View commit details
    Browse the repository at this point in the history

Commits on Jun 9, 2022

  1. Address #1415

    x4v13r64 committed Jun 9, 2022
    Configuration menu
    Copy the full SHA
    877ed8b View commit details
    Browse the repository at this point in the history

Commits on Jun 17, 2022

  1. Configuration menu
    Copy the full SHA
    8adc2db View commit details
    Browse the repository at this point in the history

Commits on Jun 27, 2022

  1. Remove duplicate link

    tkmru committed Jun 27, 2022
    Configuration menu
    Copy the full SHA
    bb8d13e View commit details
    Browse the repository at this point in the history

Commits on Jul 7, 2022

  1. Configuration menu
    Copy the full SHA
    430025d View commit details
    Browse the repository at this point in the history

Commits on Jul 15, 2022

  1. Version update

    Consultant committed Jul 15, 2022
    Configuration menu
    Copy the full SHA
    c6eca9d View commit details
    Browse the repository at this point in the history

Commits on Aug 26, 2022

  1. Merge pull request #1430 from kronicd/develop

    Updated dotnet current versions from 4.0 to 6.0
    michyweb authored Aug 26, 2022
    Configuration menu
    Copy the full SHA
    3ea07c9 View commit details
    Browse the repository at this point in the history

Commits on Aug 28, 2022

  1. Configuration menu
    Copy the full SHA
    aed8f74 View commit details
    Browse the repository at this point in the history

Commits on Aug 31, 2022

  1. Merge pull request #1448 from tkmru/fix/azure-phone

    Security Contact Phone in azure means a phone number
    fernando-gallego authored Aug 31, 2022
    Configuration menu
    Copy the full SHA
    4509aee View commit details
    Browse the repository at this point in the history
  2. Merge pull request #1438 from Anthirian/master

    Fix docker-compose build error
    fernando-gallego authored Aug 31, 2022
    Configuration menu
    Copy the full SHA
    233ab7c View commit details
    Browse the repository at this point in the history
  3. Merge pull request #1431 from tkmru/fix-duplicate-link

    Remove duplicate link
    fernando-gallego authored Aug 31, 2022
    Configuration menu
    Copy the full SHA
    c70528b View commit details
    Browse the repository at this point in the history
  4. Merge pull request #1426 from nccgroup/bugfix/issues/1415

    Bugfix/SNS permissions
    fernando-gallego authored Aug 31, 2022
    Configuration menu
    Copy the full SHA
    03bc585 View commit details
    Browse the repository at this point in the history
  5. Merge pull request #1418 from rbailey-godaddy/bugfix/userdata-secrets…

    …-regexs
    
    Adjust AWS "secrets" regular expressions
    fernando-gallego authored Aug 31, 2022
    Configuration menu
    Copy the full SHA
    66a6de7 View commit details
    Browse the repository at this point in the history

Commits on Sep 1, 2022

  1. Configuration menu
    Copy the full SHA
    59b0315 View commit details
    Browse the repository at this point in the history
  2. Update AWS IPs

    fernando-gallego committed Sep 1, 2022
    Configuration menu
    Copy the full SHA
    4dfd04c View commit details
    Browse the repository at this point in the history
  3. Add flag to authenticate against an AWS China region

    Consultant committed Sep 1, 2022
    Configuration menu
    Copy the full SHA
    3faf763 View commit details
    Browse the repository at this point in the history
  4. Configuration menu
    Copy the full SHA
    5de8a96 View commit details
    Browse the repository at this point in the history
  5. removed unnecessary print

    Consultant committed Sep 1, 2022
    Configuration menu
    Copy the full SHA
    ee4fd9a View commit details
    Browse the repository at this point in the history
  6. Configuration menu
    Copy the full SHA
    4dd7eb4 View commit details
    Browse the repository at this point in the history

Commits on Sep 2, 2022

  1. Configuration menu
    Copy the full SHA
    56de0be View commit details
    Browse the repository at this point in the history
  2. Configuration menu
    Copy the full SHA
    01428f5 View commit details
    Browse the repository at this point in the history
  3. Revert "removed unnecessary print"

    This reverts commit ee4fd9a.
    fernando-gallego committed Sep 2, 2022
    Configuration menu
    Copy the full SHA
    8e37d90 View commit details
    Browse the repository at this point in the history
  4. Configuration menu
    Copy the full SHA
    d064666 View commit details
    Browse the repository at this point in the history

Commits on Sep 5, 2022

  1. Merge pull request #1453 from nccgroup/develop

    Release v5.12.0
    fernando-gallego authored Sep 5, 2022
    Configuration menu
    Copy the full SHA
    6b8debb View commit details
    Browse the repository at this point in the history

Commits on Sep 9, 2022

  1. fixing typo

    yaleman committed Sep 9, 2022
    Configuration menu
    Copy the full SHA
    732bd73 View commit details
    Browse the repository at this point in the history

Commits on Sep 15, 2022

  1. Handle empty function 'maxInstances'

    Handle error when function has no maxInstances attribute defined
    fernando-gallego authored Sep 15, 2022
    Configuration menu
    Copy the full SHA
    41e360e View commit details
    Browse the repository at this point in the history

Commits on Sep 19, 2022

  1. Configuration menu
    Copy the full SHA
    4799df8 View commit details
    Browse the repository at this point in the history

Commits on Sep 21, 2022

  1. Merge pull request #1459 from tkmru/fix/docs-to-learn

    docs.microsoft.com->learn.microsoft.com in Azure document
    michyweb authored Sep 21, 2022
    Configuration menu
    Copy the full SHA
    b9c47f2 View commit details
    Browse the repository at this point in the history
  2. Merge pull request #1456 from yaleman/typo

    Fixing typo in container-set-init.sh
    michyweb authored Sep 21, 2022
    Configuration menu
    Copy the full SHA
    dff1a4b View commit details
    Browse the repository at this point in the history
  3. Merge pull request #1452 from FlorinAsavoaie/fix/aws-arm64

    Fix AWS when building for arm64
    michyweb authored Sep 21, 2022
    Configuration menu
    Copy the full SHA
    888916f View commit details
    Browse the repository at this point in the history

Commits on Sep 22, 2022

  1. Kubescout Alpha

    liyun-li committed Sep 22, 2022
    Configuration menu
    Copy the full SHA
    5507cc6 View commit details
    Browse the repository at this point in the history
  2. Merge pull request #1460 from liyun-li/develop

    Kubescout Alpha
    michyweb authored Sep 22, 2022
    Configuration menu
    Copy the full SHA
    cf44beb View commit details
    Browse the repository at this point in the history

Commits on Sep 24, 2022

  1. Configuration menu
    Copy the full SHA
    5e1fdf8 View commit details
    Browse the repository at this point in the history
  2. Configuration menu
    Copy the full SHA
    44c9e2c View commit details
    Browse the repository at this point in the history

Commits on Sep 29, 2022

  1. azure/rules/findings/rbac-administering-resource-locks-assigned.json:…

    … Typo fix
    
    Assigne -> Assign
    elimisteve authored Sep 29, 2022
    Configuration menu
    Copy the full SHA
    8887ad2 View commit details
    Browse the repository at this point in the history

Commits on Oct 5, 2022

  1. Exclude SMTP port 25 from rule

    We should exclude port 25 from `ec2-security-group-opens-port-to-all` because it already is covered by `ec2-security-group-opens-known-port-to-all` (as SMTP)
    rbailey-godaddy authored and rscottbailey committed Oct 5, 2022
    Configuration menu
    Copy the full SHA
    b324389 View commit details
    Browse the repository at this point in the history
  2. Bug fix

    Remove the assumption that all Secrets have a `data` field.
    liyun-li committed Oct 5, 2022
    Configuration menu
    Copy the full SHA
    981670f View commit details
    Browse the repository at this point in the history

Commits on Oct 6, 2022

  1. Secret redaction logic improvement

    Remove the assumption the `data` field in every Secret is a dictionary.
    liyun-li committed Oct 6, 2022
    Configuration menu
    Copy the full SHA
    3d5a1aa View commit details
    Browse the repository at this point in the history
  2. Configuration menu
    Copy the full SHA
    d6e0e28 View commit details
    Browse the repository at this point in the history

Commits on Oct 10, 2022

  1. remove unnecessary typing

    This typing seems to have caused some compatibility issues.
    liyun-li committed Oct 10, 2022
    Configuration menu
    Copy the full SHA
    3e3fd65 View commit details
    Browse the repository at this point in the history

Commits on Oct 11, 2022

  1. Merge pull request #1468 from liyun-li/develop

    Kubescout bug fix
    michyweb authored Oct 11, 2022
    Configuration menu
    Copy the full SHA
    6563ac8 View commit details
    Browse the repository at this point in the history

Commits on Oct 20, 2022

  1. Format findings

    x4v13r64 committed Oct 20, 2022
    Configuration menu
    Copy the full SHA
    d3002c2 View commit details
    Browse the repository at this point in the history
  2. Format findings

    x4v13r64 committed Oct 20, 2022
    Configuration menu
    Copy the full SHA
    d56bf14 View commit details
    Browse the repository at this point in the history
  3. Format findings

    x4v13r64 committed Oct 20, 2022
    Configuration menu
    Copy the full SHA
    79667f1 View commit details
    Browse the repository at this point in the history
  4. Support LBs

    x4v13r64 committed Oct 20, 2022
    Configuration menu
    Copy the full SHA
    7403e8b View commit details
    Browse the repository at this point in the history
  5. Configuration menu
    Copy the full SHA
    860cdb2 View commit details
    Browse the repository at this point in the history

Commits on Oct 21, 2022

  1. Add default values

    x4v13r64 committed Oct 21, 2022
    Configuration menu
    Copy the full SHA
    9315ae0 View commit details
    Browse the repository at this point in the history
  2. Add findings

    x4v13r64 committed Oct 21, 2022
    Configuration menu
    Copy the full SHA
    a32df60 View commit details
    Browse the repository at this point in the history
  3. Format

    x4v13r64 committed Oct 21, 2022
    Configuration menu
    Copy the full SHA
    1b6aa70 View commit details
    Browse the repository at this point in the history
  4. Format

    x4v13r64 committed Oct 21, 2022
    Configuration menu
    Copy the full SHA
    75c8b68 View commit details
    Browse the repository at this point in the history
  5. Catch task exceptions

    x4v13r64 committed Oct 21, 2022
    Configuration menu
    Copy the full SHA
    9e8bbc8 View commit details
    Browse the repository at this point in the history

Commits on Oct 27, 2022

  1. Catch ranges from 1-65535

    x4v13r64 committed Oct 27, 2022
    Configuration menu
    Copy the full SHA
    ba8e184 View commit details
    Browse the repository at this point in the history
  2. Better logic

    x4v13r64 committed Oct 27, 2022
    Configuration menu
    Copy the full SHA
    a748c41 View commit details
    Browse the repository at this point in the history
  3. Improve rule

    x4v13r64 committed Oct 27, 2022
    Configuration menu
    Copy the full SHA
    5c29988 View commit details
    Browse the repository at this point in the history
  4. Add missing rule to ruleset

    x4v13r64 committed Oct 27, 2022
    Configuration menu
    Copy the full SHA
    ec8fa81 View commit details
    Browse the repository at this point in the history
  5. Configuration menu
    Copy the full SHA
    65a8bf5 View commit details
    Browse the repository at this point in the history

Commits on Oct 28, 2022

  1. Guard vs undefined EnableTerminationProtection

    At least in our environment, the `EnableTerminationProtection` attribute
    does not appear to be defined on all AWS CloudFormation stacks. Fix
    reference so the suitable default value is provided in this case,
    instead of raising an exception.
    
    Signed-off-by: Scott Bailey <[email protected]>
    rscottbailey committed Oct 28, 2022
    Configuration menu
    Copy the full SHA
    884d41f View commit details
    Browse the repository at this point in the history
  2. Defend vs NotificationARNs

    Not all AWS CloudFormation stacks appear to have NotificationARNs
    attributes. Fix reference so it provides equivalent default instead of
    raising exception.
    
    Signed-off-by: Scott Bailey <[email protected]>
    rscottbailey committed Oct 28, 2022
    Configuration menu
    Copy the full SHA
    12f554e View commit details
    Browse the repository at this point in the history

Commits on Nov 15, 2022

  1. Configuration menu
    Copy the full SHA
    7ca0500 View commit details
    Browse the repository at this point in the history
  2. Configuration menu
    Copy the full SHA
    0f2b48e View commit details
    Browse the repository at this point in the history

Commits on Nov 28, 2022

  1. Enhancement/S3-TlsVersion

    Adds additional checks to determine if Secure Transport is enabled. By Default, ScoutSuite only checks for the boolean aws:SecureTr
    ansport. This adds support for S3:TlsVersion, and uses the operating assumption that TLS 1.2 is the lowest secure version.
    twilson-bf committed Nov 28, 2022
    Configuration menu
    Copy the full SHA
    4892251 View commit details
    Browse the repository at this point in the history

Commits on Dec 12, 2022

  1. Improve check

    x4v13r64 committed Dec 12, 2022
    Configuration menu
    Copy the full SHA
    92cda50 View commit details
    Browse the repository at this point in the history
  2. Fix finding logic

    x4v13r64 committed Dec 12, 2022
    Configuration menu
    Copy the full SHA
    65cac92 View commit details
    Browse the repository at this point in the history

Commits on Jan 3, 2023

  1. Update main workflow

    testing checkout and setup-python new versions
    michyweb authored Jan 3, 2023
    Configuration menu
    Copy the full SHA
    9349d03 View commit details
    Browse the repository at this point in the history
  2. workflow test

    michyweb authored Jan 3, 2023
    Configuration menu
    Copy the full SHA
    0a2534d View commit details
    Browse the repository at this point in the history
  3. update main workflow

    michyweb authored Jan 3, 2023
    Configuration menu
    Copy the full SHA
    afee500 View commit details
    Browse the repository at this point in the history
  4. fix throttling test

    michyweb authored Jan 3, 2023
    Configuration menu
    Copy the full SHA
    3a4acf2 View commit details
    Browse the repository at this point in the history
  5. Merge pull request #1492 from michyweb/master

    Bugfix Workflow and pytest issues
    michyweb authored Jan 3, 2023
    Configuration menu
    Copy the full SHA
    eb57832 View commit details
    Browse the repository at this point in the history
  6. Merge pull request #1487 from nccgroup/bugfix/gke-findings

    Bugfix/GKE finding
    michyweb authored Jan 3, 2023
    Configuration menu
    Copy the full SHA
    8749775 View commit details
    Browse the repository at this point in the history
  7. Merge pull request #1482 from nccgroup/enhancement/include-on-fail

    GCP include all services when Service Usage API is disabled
    michyweb authored Jan 3, 2023
    Configuration menu
    Copy the full SHA
    205d996 View commit details
    Browse the repository at this point in the history
  8. Merge pull request #1481 from nccgroup/enhancement/check-elbv2-redirects

    Enhancement/Check elbv2 redirects
    michyweb authored Jan 3, 2023
    Configuration menu
    Copy the full SHA
    cbc48e7 View commit details
    Browse the repository at this point in the history
  9. Merge pull request #1476 from nccgroup/enhancement/catch-1-6

    Enhancement/Catch 1-65535 ranges
    michyweb authored Jan 3, 2023
    Configuration menu
    Copy the full SHA
    ded64a9 View commit details
    Browse the repository at this point in the history
  10. Merge pull request #1477 from nccgroup/enhancement/public-access-prev…

    …ention
    
    Enhancement/public access prevention
    michyweb authored Jan 3, 2023
    Configuration menu
    Copy the full SHA
    963cb91 View commit details
    Browse the repository at this point in the history
  11. Merge pull request #1475 from nccgroup/enhancement/catch_task_exceptions

    Enhancement/Catch task exceptions
    michyweb authored Jan 3, 2023
    Configuration menu
    Copy the full SHA
    795fc59 View commit details
    Browse the repository at this point in the history
  12. Merge pull request #1474 from nccgroup/enhancement/gcp-lb-support

    Enhancement/Add support for GCP LBs
    michyweb authored Jan 3, 2023
    Configuration menu
    Copy the full SHA
    185f1d5 View commit details
    Browse the repository at this point in the history
  13. Merge pull request #1464 from elimisteve/patch-1

    azure/rules/findings/rbac-administering-resource-locks-assigned.json: Typo fix
    michyweb authored Jan 3, 2023
    Configuration menu
    Copy the full SHA
    d9708d3 View commit details
    Browse the repository at this point in the history
  14. Merge pull request #1485 from twilson-bf/Enhancement/S3-TlsVersion

    Enhancement/S3-TlsVersion
    michyweb authored Jan 3, 2023
    Configuration menu
    Copy the full SHA
    efb7b5a View commit details
    Browse the repository at this point in the history
  15. Merge pull request #1479 from rbailey-godaddy/bugfix/aws-cloudformati…

    …on-stack-parse
    
    Handle missing CloudFormation stack attributes gracefully
    michyweb authored Jan 3, 2023
    Configuration menu
    Copy the full SHA
    23ec346 View commit details
    Browse the repository at this point in the history

Commits on Jan 16, 2023

  1. Configuration menu
    Copy the full SHA
    72ce1b5 View commit details
    Browse the repository at this point in the history
  2. Configuration menu
    Copy the full SHA
    6475f25 View commit details
    Browse the repository at this point in the history
  3. Configuration menu
    Copy the full SHA
    ffcf1a9 View commit details
    Browse the repository at this point in the history

Commits on Mar 2, 2023

  1. Configuration menu
    Copy the full SHA
    a4f1722 View commit details
    Browse the repository at this point in the history

Commits on Mar 9, 2023

  1. Configuration menu
    Copy the full SHA
    ba1b21e View commit details
    Browse the repository at this point in the history

Commits on Mar 13, 2023

  1. Changing regex to comply with python3.11

    Python3.11 changed the re module. Global flags are required to be at the start of the expression.
    Fixing the error message:
    "__main__.py L211: Initialization failure: global flags not at the start of the expression at position 6"
    Also addresses: #1480 (comment)
    fl0mb authored Mar 13, 2023
    Configuration menu
    Copy the full SHA
    8f93753 View commit details
    Browse the repository at this point in the history

Commits on Mar 23, 2023

  1. Make test case insensitive

    x4v13r64 committed Mar 23, 2023
    Configuration menu
    Copy the full SHA
    8cd0f3b View commit details
    Browse the repository at this point in the history
  2. Configuration menu
    Copy the full SHA
    e5a30c7 View commit details
    Browse the repository at this point in the history
  3. Configuration menu
    Copy the full SHA
    3f456a7 View commit details
    Browse the repository at this point in the history
  4. Configuration menu
    Copy the full SHA
    77388ef View commit details
    Browse the repository at this point in the history

Commits on Mar 31, 2023

  1. Configuration menu
    Copy the full SHA
    b9261c8 View commit details
    Browse the repository at this point in the history
  2. GCP credential expiry check

    ncc-akis committed Mar 31, 2023
    Configuration menu
    Copy the full SHA
    8ae2a0a View commit details
    Browse the repository at this point in the history
  3. Merge pull request #1520 from ncc-akis/bugfix/handle_gcp_api_errors

    Bugfix/handle gcp api and auth errors
    fernando-gallego authored Mar 31, 2023
    Configuration menu
    Copy the full SHA
    7d8d81f View commit details
    Browse the repository at this point in the history

Commits on Apr 5, 2023

  1. Configuration menu
    Copy the full SHA
    b75d315 View commit details
    Browse the repository at this point in the history
  2. Configuration menu
    Copy the full SHA
    6cd1de5 View commit details
    Browse the repository at this point in the history
  3. fix(gcp): False positive on pubsup only cloud functions

    If an app is not accessible with an http url, we have a false positive
    on th http exposure
    saez0pub committed Apr 5, 2023
    Configuration menu
    Copy the full SHA
    6584afb View commit details
    Browse the repository at this point in the history
  4. fix(gcp): None as cloudfunctions environment_variables

    If we have no environment variable on cloud function
    AttributeError: 'NoneType' object has no attribute 'items'
    in get_environment_secrets function
    saez0pub committed Apr 5, 2023
    Configuration menu
    Copy the full SHA
    b1d9602 View commit details
    Browse the repository at this point in the history

Commits on Apr 6, 2023

  1. Configuration menu
    Copy the full SHA
    b5d0b6c View commit details
    Browse the repository at this point in the history

Commits on Apr 11, 2023

  1. Configuration menu
    Copy the full SHA
    d18a9c7 View commit details
    Browse the repository at this point in the history

Commits on Apr 18, 2023

  1. Configuration menu
    Copy the full SHA
    0548ff1 View commit details
    Browse the repository at this point in the history
  2. formatting

    cckev committed Apr 18, 2023
    Configuration menu
    Copy the full SHA
    f495d9e View commit details
    Browse the repository at this point in the history

Commits on May 5, 2023

  1. Merge pull request #1524 from liyun-li/fix-json

    Fix JSON formatting of policies
    liyun-li authored May 5, 2023
    Configuration menu
    Copy the full SHA
    a236eb8 View commit details
    Browse the repository at this point in the history

Commits on May 15, 2023

  1. Merge pull request #1510 from fl0mb/bugfix/1480-python3.11-regex-change

    Changing regex to comply with python3.11
    fernando-gallego authored May 15, 2023
    Configuration menu
    Copy the full SHA
    e730a50 View commit details
    Browse the repository at this point in the history
  2. Update regexp for Python 3.11

    Moved global flag in regexp to beginning of the expression to enable compatibility with Python 3.11
    fernando-gallego authored May 15, 2023
    Configuration menu
    Copy the full SHA
    db7890f View commit details
    Browse the repository at this point in the history

Commits on May 18, 2023

  1. Better API failsafe

    liyun-li committed May 18, 2023
    Configuration menu
    Copy the full SHA
    18f0cee View commit details
    Browse the repository at this point in the history
  2. Configuration menu
    Copy the full SHA
    d6a0601 View commit details
    Browse the repository at this point in the history
  3. Merge pull request #1535 from liyun-li/develop

    Add code to continue downloading from API in the event that one resource cannot be retrieved
    liyun-li authored May 18, 2023
    Configuration menu
    Copy the full SHA
    0ef92cf View commit details
    Browse the repository at this point in the history

Commits on May 19, 2023

  1. Configuration menu
    Copy the full SHA
    4bdc430 View commit details
    Browse the repository at this point in the history
  2. Configuration menu
    Copy the full SHA
    764ad94 View commit details
    Browse the repository at this point in the history
  3. Merge pull request #1467 from rbailey-godaddy/bugfix/smtp-double-jeop…

    …ardy
    
    Exclude SMTP port 25 from rule
    liyun-li authored May 19, 2023
    Configuration menu
    Copy the full SHA
    86d5961 View commit details
    Browse the repository at this point in the history

Commits on May 24, 2023

  1. fix issue #1537

    michyweb committed May 24, 2023
    Configuration menu
    Copy the full SHA
    06bc502 View commit details
    Browse the repository at this point in the history
  2. Configuration menu
    Copy the full SHA
    b775a41 View commit details
    Browse the repository at this point in the history

Commits on May 25, 2023

  1. Configuration menu
    Copy the full SHA
    6549177 View commit details
    Browse the repository at this point in the history
  2. remove key_map

    cckev committed May 25, 2023
    Configuration menu
    Copy the full SHA
    dc75b2e View commit details
    Browse the repository at this point in the history

Commits on May 26, 2023

  1. Merge pull request #1526 from cckev/bugfix/s3-policy-key-name-case-se…

    …nsitive
    
    Fix (AWS): Bucket Allowing Clear Text (HTTP) Communication Case-insensitive Conditional Key Name
    michyweb authored May 26, 2023
    Configuration menu
    Copy the full SHA
    6ee3eaf View commit details
    Browse the repository at this point in the history

Commits on May 29, 2023

  1. Merge pull request #1523 from HIKster/develop

    Fix (GCP): Remove credentials validity checks which cause issues
    fernando-gallego authored May 29, 2023
    Configuration menu
    Copy the full SHA
    27d208e View commit details
    Browse the repository at this point in the history
  2. Merge pull request #1506 from wrightmalone/bugfix/1505-failed-to-proc…

    …ess-rule-c2-instance-in-security-group
    
    add dashboard_name to rule ec2-instance-in-security-group.json
    fernando-gallego authored May 29, 2023
    Configuration menu
    Copy the full SHA
    73459b6 View commit details
    Browse the repository at this point in the history
  3. Merge pull request #1504 from zachfey/bugfix/1503-fix-az-aad-fetch-ad…

    …ditional-users
    
    Update azure-mgmt-authorization
    fernando-gallego authored May 29, 2023
    Configuration menu
    Copy the full SHA
    fc23d9d View commit details
    Browse the repository at this point in the history

Commits on May 30, 2023

  1. Update __main__.py

    fernando-gallego authored May 30, 2023
    Configuration menu
    Copy the full SHA
    d6cf479 View commit details
    Browse the repository at this point in the history

Commits on Jun 1, 2023

  1. Update finding

    x4v13r64 committed Jun 1, 2023
    Configuration menu
    Copy the full SHA
    91d5280 View commit details
    Browse the repository at this point in the history
  2. Logical order

    x4v13r64 committed Jun 1, 2023
    Configuration menu
    Copy the full SHA
    18b6d6a View commit details
    Browse the repository at this point in the history

Commits on Jun 5, 2023

  1. Merge pull request #1522 from saez0pub/fix/gcp_audit

    Fix(gcp): update cloudsql api and edge case configurations
    liyun-li authored Jun 5, 2023
    Configuration menu
    Copy the full SHA
    acf7bda View commit details
    Browse the repository at this point in the history

Commits on Jun 6, 2023

  1. Update __init__.py

    michyweb authored Jun 6, 2023
    Configuration menu
    Copy the full SHA
    36d8bd9 View commit details
    Browse the repository at this point in the history

Commits on Jun 13, 2023

  1. Update setup.py

    Update supported Python versions.
    fernando-gallego authored Jun 13, 2023
    Configuration menu
    Copy the full SHA
    40d699c View commit details
    Browse the repository at this point in the history

Commits on Jun 14, 2023

  1. Update testing.yml

    Update Python versions.
    fernando-gallego authored Jun 14, 2023
    Configuration menu
    Copy the full SHA
    0798a3a View commit details
    Browse the repository at this point in the history
  2. Update setup.py

    Adding Python v3.9
    fernando-gallego authored Jun 14, 2023
    Configuration menu
    Copy the full SHA
    3d3fa71 View commit details
    Browse the repository at this point in the history

Commits on Jun 27, 2023

  1. Configuration menu
    Copy the full SHA
    7619c30 View commit details
    Browse the repository at this point in the history

Commits on Jun 28, 2023

  1. Configuration menu
    Copy the full SHA
    44d9851 View commit details
    Browse the repository at this point in the history
  2. Configuration menu
    Copy the full SHA
    7543cd7 View commit details
    Browse the repository at this point in the history
  3. Configuration menu
    Copy the full SHA
    477a82b View commit details
    Browse the repository at this point in the history
  4. Configuration menu
    Copy the full SHA
    da6b28b View commit details
    Browse the repository at this point in the history

Commits on Jun 29, 2023

  1. Configuration menu
    Copy the full SHA
    baedf24 View commit details
    Browse the repository at this point in the history
  2. Configuration menu
    Copy the full SHA
    98e514e View commit details
    Browse the repository at this point in the history
  3. Configuration menu
    Copy the full SHA
    0ef4154 View commit details
    Browse the repository at this point in the history
  4. Configuration menu
    Copy the full SHA
    791f3cc View commit details
    Browse the repository at this point in the history
  5. Configuration menu
    Copy the full SHA
    cef3a70 View commit details
    Browse the repository at this point in the history
  6. Configuration menu
    Copy the full SHA
    334fafa View commit details
    Browse the repository at this point in the history
  7. Merge pull request #1548 from ncc-akis/bugfix/lb_exceptions

    Bugfix/lb exceptions
    michyweb authored Jun 29, 2023
    Configuration menu
    Copy the full SHA
    cb7299d View commit details
    Browse the repository at this point in the history

Commits on Jun 30, 2023

  1. Merge pull request #1545 from ncc-akis/bugfix/fix_sqldb_ad_admin_asse…

    …ssment
    
    Ensure correct SQL DB AD Admin check
    fernando-gallego authored Jun 30, 2023
    Configuration menu
    Copy the full SHA
    afecedf View commit details
    Browse the repository at this point in the history
  2. Merge pull request #1546 from ncc-akis/bugfix/workflow_python_version…

    …_fix
    
    Quoted Python version numbers
    fernando-gallego authored Jun 30, 2023
    Configuration menu
    Copy the full SHA
    242458a View commit details
    Browse the repository at this point in the history
  3. Merge pull request #1547 from ncc-akis/feature/evaluate_ade_status

    Use Azure ADE status to prevent false positives
    fernando-gallego authored Jun 30, 2023
    Configuration menu
    Copy the full SHA
    7125290 View commit details
    Browse the repository at this point in the history
  4. Merge pull request #1538 from nccgroup/issues-1529

     GCP rule ssl_required not accurate
    fernando-gallego authored Jun 30, 2023
    Configuration menu
    Copy the full SHA
    219c9a5 View commit details
    Browse the repository at this point in the history

Commits on Jul 3, 2023

  1. Merge pull request #1549 from ncc-akis/bugfix/false_negative_keyvault…

    …_purge_protection
    
    Bugfix/false negative keyvault purge protection
    fernando-gallego authored Jul 3, 2023
    Configuration menu
    Copy the full SHA
    00ab346 View commit details
    Browse the repository at this point in the history
  2. Configuration menu
    Copy the full SHA
    e2f0274 View commit details
    Browse the repository at this point in the history
  3. Configuration menu
    Copy the full SHA
    d083f92 View commit details
    Browse the repository at this point in the history
  4. Update vaults.py

    fernando-gallego authored Jul 3, 2023
    Configuration menu
    Copy the full SHA
    592505e View commit details
    Browse the repository at this point in the history
  5. Merge pull request #1552 from ncc-akis/feature/az_keyvault_new_rules

    New rules for Azure Key Vault
    fernando-gallego authored Jul 3, 2023
    Configuration menu
    Copy the full SHA
    3caf861 View commit details
    Browse the repository at this point in the history
  6. Configuration menu
    Copy the full SHA
    643acd0 View commit details
    Browse the repository at this point in the history

Commits on Jul 5, 2023

  1. Update __init__.py

    Change to v5.13.0
    fernando-gallego authored Jul 5, 2023
    Configuration menu
    Copy the full SHA
    0c90ab9 View commit details
    Browse the repository at this point in the history
  2. Merge pull request #1555 from nccgroup/develop

    Release v5.13.0
    fernando-gallego authored Jul 5, 2023
    Configuration menu
    Copy the full SHA
    91d90e3 View commit details
    Browse the repository at this point in the history

Commits on Sep 22, 2023

  1. Update README.md

    fernando-gallego authored Sep 22, 2023
    Configuration menu
    Copy the full SHA
    967ec54 View commit details
    Browse the repository at this point in the history

Commits on Oct 16, 2023

  1. Merge branch 'master' into enhancement/docker-update

    Jason Ross committed Oct 16, 2023
    Configuration menu
    Copy the full SHA
    ff47599 View commit details
    Browse the repository at this point in the history
  2. updated for 5.13

    Jason Ross committed Oct 16, 2023
    Configuration menu
    Copy the full SHA
    b3e33df View commit details
    Browse the repository at this point in the history
  3. changed to python 3.12

    Jason Ross committed Oct 16, 2023
    Configuration menu
    Copy the full SHA
    2ffe244 View commit details
    Browse the repository at this point in the history
  4. Configuration menu
    Copy the full SHA
    7468072 View commit details
    Browse the repository at this point in the history
  5. added combined env

    Jason Ross committed Oct 16, 2023
    Configuration menu
    Copy the full SHA
    f165e94 View commit details
    Browse the repository at this point in the history

Commits on Nov 8, 2023

  1. Update route53-domain-transferlock-not-authorized.json

    Remove *.uk domains as they now support domain locks.
    launchdaemon authored Nov 8, 2023
    Configuration menu
    Copy the full SHA
    4a9c2b7 View commit details
    Browse the repository at this point in the history

Commits on Nov 30, 2023

  1. Configuration menu
    Copy the full SHA
    8c1ee62 View commit details
    Browse the repository at this point in the history

Commits on Jan 20, 2024

  1. Rule to check if EBS default encryption is enabled.

    It seems to work but there are issues with the display; see "TKTK"
    comments in .../services.ec2.regions.id.regional_settings.html.
    
    Still needs tests.
    rdegraaf-ncc3 committed Jan 20, 2024
    Configuration menu
    Copy the full SHA
    cd9b789 View commit details
    Browse the repository at this point in the history

Commits on Jan 22, 2024

  1. Configuration menu
    Copy the full SHA
    524b807 View commit details
    Browse the repository at this point in the history

Commits on Feb 4, 2024

  1. added-digitalocean-support

    asifwani committed Feb 4, 2024
    Configuration menu
    Copy the full SHA
    54147a0 View commit details
    Browse the repository at this point in the history

Commits on Feb 9, 2024

  1. added-pagination-support

    asifwani committed Feb 9, 2024
    Configuration menu
    Copy the full SHA
    63b1b40 View commit details
    Browse the repository at this point in the history

Commits on Feb 27, 2024

  1. Fixes 'Key Vault Not Recoverable' check

    ScoutSuite previously did not flag key vaults for which the API returned
    enable_soft_delete = null. Such key vaults have neither soft-delete nor
    purge protecton enabled and are also not recoverable. The check would
    only flag key vaults for which enable_soft_delete = false.
    rieck-srlabs committed Feb 27, 2024
    Configuration menu
    Copy the full SHA
    f7350ba View commit details
    Browse the repository at this point in the history
  2. Fixes 'Key Vault Role Based Access Control Disabled' check

    ScoutSuite failed to flag key vaults where the enable_rbac_authorization
    field was set to null. Through manual configuration in the Azure portal
    I confirmed that RBAC Access Control is disabled if this field is set
    to null.
    rieck-srlabs committed Feb 27, 2024
    Configuration menu
    Copy the full SHA
    137228e View commit details
    Browse the repository at this point in the history
  3. Corrected display name for 'Blob Containers Allowing Public Access'

    The test scans Blob Containers, not Storage Accounts.
    There is a 1:n relationship between Storage Accounts and Blob Containers.
    rieck-srlabs committed Feb 27, 2024
    Configuration menu
    Copy the full SHA
    e011d48 View commit details
    Browse the repository at this point in the history
  4. Improves 'Access Keys Not Rotated' check

    - Updates azure-mgmt-storage to 17.0.0
    - Only consider storage accounts that allow access key access for the check
    - Display the access key status in the results
    rieck-srlabs committed Feb 27, 2024
    Configuration menu
    Copy the full SHA
    22c5bf6 View commit details
    Browse the repository at this point in the history

Commits on Feb 29, 2024

  1. Merge pull request #1610 from rieck-srlabs/bugfix/1606-fix-keyvault-n…

    …ot-recoverable
    
    Fixes 'Key Vault Not Recoverable' check
    fernando-gallego authored Feb 29, 2024
    Configuration menu
    Copy the full SHA
    631cd70 View commit details
    Browse the repository at this point in the history

Commits on Mar 4, 2024

  1. AWS EBS default encryption: fixed display problems.

    Apparently ScoutSuite makes the implicit assumption that all settings
    are associated with resources, rather than directly to the region +
    service. So we move the regional EBS settings into a fake resource.
    This means that paths now need to include an ID for the "resource".
    rdegraaf-ncc3 committed Mar 4, 2024
    Configuration menu
    Copy the full SHA
    d7485d2 View commit details
    Browse the repository at this point in the history

Commits on Mar 5, 2024

  1. Configuration menu
    Copy the full SHA
    f90bcd0 View commit details
    Browse the repository at this point in the history
  2. Configuration menu
    Copy the full SHA
    01de9d0 View commit details
    Browse the repository at this point in the history
  3. Configuration menu
    Copy the full SHA
    d640d66 View commit details
    Browse the repository at this point in the history
  4. Configuration menu
    Copy the full SHA
    68e9199 View commit details
    Browse the repository at this point in the history

Commits on Mar 7, 2024

  1. Merge pull request #1614 from rdegraaf/feature/1584-aws-ebs-encryption

    Feature/1584 aws ebs encryption
    fernando-gallego authored Mar 7, 2024
    Configuration menu
    Copy the full SHA
    7a6e3c7 View commit details
    Browse the repository at this point in the history

Commits on Apr 12, 2024

  1. Configuration menu
    Copy the full SHA
    e500930 View commit details
    Browse the repository at this point in the history

Commits on Apr 16, 2024

  1. Configuration menu
    Copy the full SHA
    6bd204a View commit details
    Browse the repository at this point in the history

Commits on Apr 17, 2024

  1. Configuration menu
    Copy the full SHA
    869919c View commit details
    Browse the repository at this point in the history

Commits on May 7, 2024

  1. Digital Ocean Integration

    ltoroncc committed May 7, 2024
    Configuration menu
    Copy the full SHA
    f06df79 View commit details
    Browse the repository at this point in the history
  2. Merge pull request #1604 from asifwani/feature/digitalocean-cloud-sup…

    …port
    
    Feature/DigitalOcean support
    fernando-gallego authored May 7, 2024
    Configuration menu
    Copy the full SHA
    b334dd5 View commit details
    Browse the repository at this point in the history
  3. Configuration menu
    Copy the full SHA
    29e8063 View commit details
    Browse the repository at this point in the history
  4. Merge pull request #1632 from ltoroncc/master

    Review/Fixes for DigitalOcean to overwrite PR #1604
    fernando-gallego authored May 7, 2024
    Configuration menu
    Copy the full SHA
    2f91ee6 View commit details
    Browse the repository at this point in the history

Commits on May 8, 2024

  1. Merge pull request #1589 from Tim-Hoekstra/master

    Fixed incompatible packages - Update requirements.txt
    fernando-gallego authored May 8, 2024
    Configuration menu
    Copy the full SHA
    373fc14 View commit details
    Browse the repository at this point in the history
  2. Configuration menu
    Copy the full SHA
    4ff22f3 View commit details
    Browse the repository at this point in the history
  3. Update requirements.txt

    Update some GCP dependencies as in #1589 and pin protobuf 3.20.1 since more recent versions break GCP libs
    fernando-gallego authored May 8, 2024
    Configuration menu
    Copy the full SHA
    8dbdf2f View commit details
    Browse the repository at this point in the history
  4. Merge pull request #1633 from nccgroup/revert-1589-master

    Revert "Fixed incompatible packages - Update requirements.txt"
    fernando-gallego authored May 8, 2024
    Configuration menu
    Copy the full SHA
    7feb470 View commit details
    Browse the repository at this point in the history
  5. Merge pull request #1586 from launchdaemon/bugfix/route53-domain-lock…

    …-update
    
    Bugfix/route53 domain lock update
    fernando-gallego authored May 8, 2024
    Configuration menu
    Copy the full SHA
    6bd80c6 View commit details
    Browse the repository at this point in the history
  6. Configuration menu
    Copy the full SHA
    8694556 View commit details
    Browse the repository at this point in the history
  7. Configuration menu
    Copy the full SHA
    3654d54 View commit details
    Browse the repository at this point in the history
  8. Merge pull request #1611 from rieck-srlabs/bugfix/1607-fix-keyvault-r…

    …bac-disabled
    
    Fixes 'Key Vault Role Based Access Control Disabled' check
    fernando-gallego authored May 8, 2024
    Configuration menu
    Copy the full SHA
    e89be59 View commit details
    Browse the repository at this point in the history
  9. Merge pull request #1612 from rieck-srlabs/bugfix/1608-improve-blob-c…

    …ontainer-labeling
    
    Corrected display name for 'Blob Containers Allowing Public Access'
    fernando-gallego authored May 8, 2024
    Configuration menu
    Copy the full SHA
    cba4cc0 View commit details
    Browse the repository at this point in the history
  10. Merge pull request #1613 from rieck-srlabs/bugfix/1609-ignore-storage…

    …-accounts-without-access-keys
    
    Improves 'Access Keys Not Rotated' check
    fernando-gallego authored May 8, 2024
    Configuration menu
    Copy the full SHA
    902bf36 View commit details
    Browse the repository at this point in the history
  11. Merge pull request #1623 from rieck-srlabs/bugfix/1621-improve-aws-un…

    …used-credentials
    
     Bugfix/1621 Improve AWS unused credential issue flagging
    fernando-gallego authored May 8, 2024
    Configuration menu
    Copy the full SHA
    c1434c2 View commit details
    Browse the repository at this point in the history
  12. Merge pull request #1627 from rieck-srlabs/bugfix/1626-improve-aws-ke…

    …y-rotation-rule-name
    
    Improves iam-user-no-key-rotation rule
    fernando-gallego authored May 8, 2024
    Configuration menu
    Copy the full SHA
    0a31ecc View commit details
    Browse the repository at this point in the history
  13. Merge pull request #1629 from rieck-srlabs/feature/1628-ebs-volume-de…

    …tail-view-highlighting
    
    Adds highlighting for "EBS Volume Not Encrypted" detail view
    fernando-gallego authored May 8, 2024
    Configuration menu
    Copy the full SHA
    6df2cfa View commit details
    Browse the repository at this point in the history
  14. Merge pull request #1582 from rossja/master

    Docker refactor
    fernando-gallego authored May 8, 2024
    Configuration menu
    Copy the full SHA
    de1b62c View commit details
    Browse the repository at this point in the history

Commits on May 9, 2024

  1. Merge pull request #1515 from nccgroup/case-insensitive-conditionals

    Case insensitive conditionals
    fernando-gallego authored May 9, 2024
    Configuration menu
    Copy the full SHA
    891c337 View commit details
    Browse the repository at this point in the history

Commits on May 10, 2024

  1. Update __init__.py

    Update to v5.14.0
    fernando-gallego authored May 10, 2024
    Configuration menu
    Copy the full SHA
    4194142 View commit details
    Browse the repository at this point in the history
  2. Merge pull request #1635 from nccgroup/develop

    Release 5.14.0
    fernando-gallego authored May 10, 2024
    Configuration menu
    Copy the full SHA
    7909f2f View commit details
    Browse the repository at this point in the history