Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Modify 1.2.3 Ensure that the DenyServiceExternalIPs is set in CIS-1.7/1.8 #1607

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

andypitcher
Copy link
Contributor

@andypitcher andypitcher commented Apr 30, 2024

Parent: #1606

Context: In CIS-1.7 and CIS-1.8 (master 1.2.3 Ensure that the DenyServiceExternalIPs is set) the operand is wrong and makes the check to WARN even if --enable-admission-plugins=DenyServiceExternalIPs is properly set.

This PR makes the following change to master 1.2.3 check for CIS-1.7 and CIS-1.8:

  • op changed from have to has and removed bin_op: or
  • remediation description changed to only include --enable-admission-plugins

@andypitcher andypitcher changed the title Modify 1.2.3 Ensure that the DenyServiceExternalIPs is set inc CIS-1.7/1.8 Modify 1.2.3 Ensure that the DenyServiceExternalIPs is set in CIS-1.7/1.8 Apr 30, 2024
 - op changed from `have` to `has` and removed bin_op: or
 - remediation description changed to only include --enable-admission-plugins
@andypitcher andypitcher force-pushed the fix-master-1.2.3-DenyServiceExternalIPs branch from 2edf840 to e2184fb Compare April 30, 2024 23:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant