Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(rules): dedupe AVD-AWS-0180 #26

Merged
merged 4 commits into from
Oct 24, 2023
Merged

chore(rules): dedupe AVD-AWS-0180 #26

merged 4 commits into from
Oct 24, 2023

Conversation

simar7
Copy link
Member

@simar7 simar7 commented Oct 24, 2023

@nikpivkin
Copy link
Contributor

@simar7 We must keep the no_public_db_access.cf.go and no_public_db_access.tf.go files, since they are used in the Rego rule. https://github.com/aquasecurity/trivy-policies/blob/main/rules/cloud/policies/aws/rds/disable_public_access.rego#L22-L25

Only RDS instances are checked in the Rego rule, but not RDS cluster instances as is done in the Go rule. https://github.com/aquasecurity/trivy-policies/blob/main/rules/cloud/policies/aws/rds/no_public_db_access.go#L39-L50

@simar7
Copy link
Member Author

simar7 commented Oct 24, 2023

@simar7 We must keep the no_public_db_access.cf.go and no_public_db_access.tf.go files, since they are used in the Rego rule. https://github.com/aquasecurity/trivy-policies/blob/main/rules/cloud/policies/aws/rds/disable_public_access.rego#L22-L25

Only RDS instances are checked in the Rego rule, but not RDS cluster instances as is done in the Go rule. https://github.com/aquasecurity/trivy-policies/blob/main/rules/cloud/policies/aws/rds/no_public_db_access.go#L39-L50

good catch, I merged your PR.

@simar7 simar7 merged commit d9abb81 into main Oct 24, 2023
4 checks passed
@simar7 simar7 deleted the dedupe-avd-aws-0180 branch October 24, 2023 23:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

fix: Dedupe AVD-AWS-0180 rule
2 participants