Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(query): lambda_iam_invokefunction_misconfigured #6822

Merged
merged 17 commits into from
Feb 27, 2024

Conversation

Tohar-orca
Copy link
Contributor

@Tohar-orca Tohar-orca commented Dec 5, 2023

Proposed Changes

  • fix a potential FP where a Lambda function's ARN is referenced, rather than explicitly written out
  • change the wording of "S3 Bucket SSE Disabled" to be more clear
  • fix a potential FP in cases where a aws_cloudwatch_log_group names were not being properly escaped for use in regex in api_gateway_with_cloudwatch_logging_disabled

I submit this contribution under the Apache-2.0 license.

@github-actions github-actions bot added community Community contribution query New query feature labels Dec 5, 2023
@github-actions github-actions bot added the aws PR related with AWS Cloud label Dec 18, 2023
@gabriel-cx
Copy link
Collaborator

Hi @Tohar-orca,

Thanks for your feedback! Our AppSec team is analyzing it. We will give you our feedback as soon as we get the info from AppSec team.

@Tohar-orca
Copy link
Contributor Author

Hi @Tohar-orca,

Thanks for your feedback! Our AppSec team is analyzing it. We will give you our feedback as soon as we get the info from AppSec team.

Hey @gabriel-cx , any update?

@gabriel-cx
Copy link
Collaborator

Hi @Tohar-orca ,

Your contribution looks good, thank you! We will merge it!

@gabriel-cx gabriel-cx merged commit 6b9fa67 into Checkmarx:master Feb 27, 2024
22 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
aws PR related with AWS Cloud community Community contribution query New query feature
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants