Skip to content

Conversation

@cx-ben-alvo
Copy link
Collaborator

No description provided.

@cx-ben-alvo
Copy link
Collaborator Author

cx-ben-alvo commented Jan 29, 2025

Logo
Checkmarx One – Scan Summary & Details7e77777f-2158-4e54-9d88-3085da34e7dd

New Issues (8)

Checkmarx found the following issues in this Pull Request

Severity Issue Source File / Package Checkmarx Insight
HIGH Passwords And Secrets - Generic Password /release.yml: 82
detailsQuery to find passwords and secrets in infrastructure code.
MEDIUM ALB Deletion Protection Disabled /positive1.tf: 15
detailsApplication Load Balancer should have deletion protection enabled
MEDIUM ALB Listening on HTTP /positive1.tf: 9
detailsAWS Application Load Balancer (alb) should not listen on HTTP
MEDIUM ALB Not Dropping Invalid Headers /positive1.tf: 15
detailsIt's considered a best practice when using Application Load Balancers to drop invalid header fields
LOW APT-GET Missing Flags To Avoid Manual Input /Dockerfile: 5
detailsCheck if apt-get calls use flags to avoid user manual input.
LOW Healthcheck Instruction Missing /Dockerfile: 1
detailsEnsure that HEALTHCHECK is being used. The HEALTHCHECK instruction tells Docker how to test a container to check that it is still working
LOW IAM Access Analyzer Not Enabled /positive1.tf: 1
detailsIAM Access Analyzer should be enabled and configured to continuously monitor resource permissions
LOW Shield Advanced Not In Use /positive1.tf: 15
detailsAWS Shield Advanced should be used for Amazon Route 53 hosted zone, AWS Global Accelerator accelerator, Elastic IP Address, Elastic Load Balancing,...

@cx-ben-alvo cx-ben-alvo merged commit 31ceb15 into main Jan 29, 2025
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants