Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Apcxtest patch 6 #161

Open
wants to merge 2 commits into
base: main
Choose a base branch
from
Open

Apcxtest patch 6 #161

wants to merge 2 commits into from

Conversation

apcxtest
Copy link
Owner

@apcxtest apcxtest commented Jun 4, 2024

No description provided.

@apcxtest
Copy link
Owner Author

apcxtest commented Jun 4, 2024

Logo
Checkmarx One – Scan Summary & Details88b353e9-db63-4340-9c3f-4b5fe2022469

Policy Management Violations

Policy Name Rule(s) Break Build
aptest policy testrepopub rule false

New Issues

Severity Issue Source File / Package Checkmarx Insight
MEDIUM Unpinned Actions Full Length Commit SHA /cxaction.yml: [24](https://github.com/apcxtest/test-repo-pub/blob/apcxtest-patch-6//.github/workflows/cxaction.yml# L24) Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps...

Fixed Issues

Severity Issue Source File / Package
HIGH ALB Listening on HTTP /positive2.tf: [70](https://github.com/apcxtest/test-repo-pub/blob/apcxtest-patch-6//astsubmodule/terraform_examples/positive2.tf# L70)
HIGH ALB Listening on HTTP /positive1.tf: [9](https://github.com/apcxtest/test-repo-pub/blob/apcxtest-patch-6//astsubmodule/terraform_examples/positive1.tf# L9)
HIGH EC2 Instance Has Public IP /negative2.tf: [96](https://github.com/apcxtest/test-repo-pub/blob/apcxtest-patch-6//astsubmodule/terraform_examples/negative2.tf# L96)
HIGH EC2 Instance Has Public IP /positive2.tf: [82](https://github.com/apcxtest/test-repo-pub/blob/apcxtest-patch-6//astsubmodule/terraform_examples/positive2.tf# L82)
HIGH EC2 Instance Has Public IP /negative2.tf: [109](https://github.com/apcxtest/test-repo-pub/blob/apcxtest-patch-6//astsubmodule/terraform_examples/negative2.tf# L109)
HIGH EC2 Instance Has Public IP /positive2.tf: [108](https://github.com/apcxtest/test-repo-pub/blob/apcxtest-patch-6//astsubmodule/terraform_examples/positive2.tf# L108)
HIGH EC2 Instance Has Public IP /positive2.tf: [95](https://github.com/apcxtest/test-repo-pub/blob/apcxtest-patch-6//astsubmodule/terraform_examples/positive2.tf# L95)
HIGH EC2 Instance Has Public IP /negative2.tf: [83](https://github.com/apcxtest/test-repo-pub/blob/apcxtest-patch-6//astsubmodule/terraform_examples/negative2.tf# L83)
HIGH Missing User Instruction /Dockerfile: [1](https://github.com/apcxtest/test-repo-pub/blob/apcxtest-patch-6//astsubmodule/Dockerfile# L1)
MEDIUM ALB Not Dropping Invalid Headers /positive1.tf: [15](https://github.com/apcxtest/test-repo-pub/blob/apcxtest-patch-6//astsubmodule/terraform_examples/positive1.tf# L15)
MEDIUM ALB Not Dropping Invalid Headers /negative2.tf: [49](https://github.com/apcxtest/test-repo-pub/blob/apcxtest-patch-6//astsubmodule/terraform_examples/negative2.tf# L49)
MEDIUM ALB Not Dropping Invalid Headers /positive2.tf: [49](https://github.com/apcxtest/test-repo-pub/blob/apcxtest-patch-6//astsubmodule/terraform_examples/positive2.tf# L49)
MEDIUM ALB Not Dropping Invalid Headers /negative1.tf: [15](https://github.com/apcxtest/test-repo-pub/blob/apcxtest-patch-6//astsubmodule/terraform_examples/negative1.tf# L15)
MEDIUM Apt Get Install Pin Version Not Defined /Dockerfile: [5](https://github.com/apcxtest/test-repo-pub/blob/apcxtest-patch-6//astsubmodule/Dockerfile# L5)
MEDIUM Unpinned Actions Full Length Commit SHA /cxaction.yml: [18](https://github.com/apcxtest/test-repo-pub/blob/apcxtest-patch-6//.github/workflows/cxaction.yml# L18)
MEDIUM Unpinned Actions Full Length Commit SHA /cxaction.yml: [30](https://github.com/apcxtest/test-repo-pub/blob/apcxtest-patch-6//.github/workflows/cxaction.yml# L30)
MEDIUM VPC Without Network Firewall /positive2.tf: [26](https://github.com/apcxtest/test-repo-pub/blob/apcxtest-patch-6//astsubmodule/terraform_examples/positive2.tf# L26)
MEDIUM VPC Without Network Firewall /negative2.tf: [26](https://github.com/apcxtest/test-repo-pub/blob/apcxtest-patch-6//astsubmodule/terraform_examples/negative2.tf# L26)
LOW ALB Deletion Protection Disabled /negative2.tf: [49](https://github.com/apcxtest/test-repo-pub/blob/apcxtest-patch-6//astsubmodule/terraform_examples/negative2.tf# L49)
LOW ALB Deletion Protection Disabled /positive1.tf: [15](https://github.com/apcxtest/test-repo-pub/blob/apcxtest-patch-6//astsubmodule/terraform_examples/positive1.tf# L15)
LOW ALB Deletion Protection Disabled /positive2.tf: [49](https://github.com/apcxtest/test-repo-pub/blob/apcxtest-patch-6//astsubmodule/terraform_examples/positive2.tf# L49)
LOW ALB Deletion Protection Disabled /negative1.tf: [15](https://github.com/apcxtest/test-repo-pub/blob/apcxtest-patch-6//astsubmodule/terraform_examples/negative1.tf# L15)
LOW EC2 Instance Using Default Security Group /negative2.tf: [97](https://github.com/apcxtest/test-repo-pub/blob/apcxtest-patch-6//astsubmodule/terraform_examples/negative2.tf# L97)
LOW EC2 Instance Using Default Security Group /negative2.tf: [84](https://github.com/apcxtest/test-repo-pub/blob/apcxtest-patch-6//astsubmodule/terraform_examples/negative2.tf# L84)
LOW EC2 Instance Using Default Security Group /positive2.tf: [109](https://github.com/apcxtest/test-repo-pub/blob/apcxtest-patch-6//astsubmodule/terraform_examples/positive2.tf# L109)
LOW EC2 Instance Using Default Security Group /positive2.tf: [83](https://github.com/apcxtest/test-repo-pub/blob/apcxtest-patch-6//astsubmodule/terraform_examples/positive2.tf# L83)
LOW EC2 Instance Using Default Security Group /positive2.tf: [96](https://github.com/apcxtest/test-repo-pub/blob/apcxtest-patch-6//astsubmodule/terraform_examples/positive2.tf# L96)
LOW EC2 Instance Using Default Security Group /negative2.tf: [110](https://github.com/apcxtest/test-repo-pub/blob/apcxtest-patch-6//astsubmodule/terraform_examples/negative2.tf# L110)
LOW Healthcheck Instruction Missing /Dockerfile: [1](https://github.com/apcxtest/test-repo-pub/blob/apcxtest-patch-6//astsubmodule/Dockerfile# L1)
LOW IAM Access Analyzer Not Enabled /positive1.tf: [1](https://github.com/apcxtest/test-repo-pub/blob/apcxtest-patch-6//astsubmodule/terraform_examples/positive1.tf# L1)
LOW IAM Access Analyzer Not Enabled /negative2.tf: [26](https://github.com/apcxtest/test-repo-pub/blob/apcxtest-patch-6//astsubmodule/terraform_examples/negative2.tf# L26)
LOW IAM Access Analyzer Not Enabled /positive2.tf: [26](https://github.com/apcxtest/test-repo-pub/blob/apcxtest-patch-6//astsubmodule/terraform_examples/positive2.tf# L26)
LOW IAM Access Analyzer Not Enabled /negative1.tf: [1](https://github.com/apcxtest/test-repo-pub/blob/apcxtest-patch-6//astsubmodule/terraform_examples/negative1.tf# L1)
LOW Shield Advanced Not In Use /negative1.tf: [15](https://github.com/apcxtest/test-repo-pub/blob/apcxtest-patch-6//astsubmodule/terraform_examples/negative1.tf# L15)
LOW Shield Advanced Not In Use /negative2.tf: [49](https://github.com/apcxtest/test-repo-pub/blob/apcxtest-patch-6//astsubmodule/terraform_examples/negative2.tf# L49)
LOW Shield Advanced Not In Use /positive1.tf: [15](https://github.com/apcxtest/test-repo-pub/blob/apcxtest-patch-6//astsubmodule/terraform_examples/positive1.tf# L15)
LOW Shield Advanced Not In Use /positive2.tf: [49](https://github.com/apcxtest/test-repo-pub/blob/apcxtest-patch-6//astsubmodule/terraform_examples/positive2.tf# L49)
LOW VPC FlowLogs Disabled /negative2.tf: [26](https://github.com/apcxtest/test-repo-pub/blob/apcxtest-patch-6//astsubmodule/terraform_examples/negative2.tf# L26)
LOW VPC FlowLogs Disabled /positive2.tf: [26](https://github.com/apcxtest/test-repo-pub/blob/apcxtest-patch-6//astsubmodule/terraform_examples/positive2.tf# L26)

@apcxtest apcxtest closed this Jun 4, 2024
@apcxtest apcxtest reopened this Jun 4, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant