Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feat(critical): add critical severity to KICS github action #107

Merged
merged 3 commits into from
Mar 18, 2024

Conversation

ArturRibeiro-CX
Copy link
Collaborator

  • KICS github action is able to give proper feedback when it detects critical severity (exit code 60)

Copy link

github-actions bot commented Mar 15, 2024

kics-logo

KICS version: v1.7.13

Category Results
HIGH HIGH 3
MEDIUM MEDIUM 2
LOW LOW 0
INFO INFO 0
TRACE TRACE 0
TOTAL TOTAL 5
Metric Values
Files scanned placeholder 2
Files parsed placeholder 2
Files failed to scan placeholder 0
Total executed queries placeholder 1045
Queries failed to execute placeholder 0
Execution time placeholder 28

Queries Results

Query Name Query Id Severity Platform Category Experimental Description File Name Line Resource Type Resource Name Issue Type Search Key Expected Value Actual Value Remediation Remediation Type
AD Admin Not Configured For SQL Server a3a055d2-9a2e-4cc9-b9fb-12850a1a3a4b HIGH Terraform Insecure Configurations false The Active Directory Administrator is not configured for a SQL server test/samples/positive1.tf 6 azurerm_sql_server mysqlserver1 MissingAttribute azurerm_sql_server[positive2] A 'azurerm_sql_active_directory_administrator' should be defined for 'azurerm_sql_server[positive2]' A 'azurerm_sql_active_directory_administrator' is not defined for 'azurerm_sql_server[positive2]'
Admin User Enabled For Container Registry b897dfbf-322c-45a8-b67c-1e698beeaa51 HIGH Terraform Access Control false Admin user is enabled for Container Registry test/samples/positive2.tf 11 azurerm_container_registry containerRegistry1 IncorrectValue azurerm_container_registry[positive2].admin_enabled 'admin_enabled' equal 'false' 'admin_enabled' equal 'true' {"after":"false","before":"true"} replacement
Passwords And Secrets - Generic Password 487f4be7-3fd9-4506-a07a-eae252180c08 HIGH Common Secret Management false Query to find passwords and secrets in infrastructure code. test/samples/positive1.tf 12 RedundantAttribute Hardcoded secret key should not appear in source Hardcoded secret key appears in source
SQL Server Auditing Disabled f7e296b0-6660-4bc5-8f87-22ac4a815edf MEDIUM Terraform Observability false Make sure that for SQL Servers, 'Auditing' is set to 'On' test/samples/positive1.tf 6 azurerm_sql_server mysqlserver1 MissingAttribute azurerm_sql_server[positive2] 'azurerm_sql_server.positive2.extended_auditing_policy' should exist 'azurerm_sql_server.positive2.extended_auditing_policy' does not exist
SQL Server Predictable Active Directory Account Name bcd3fc01-5902-4f2a-b05a-227f9bbf5450 MEDIUM Terraform Best Practices false Azure SQL Server must avoid using predictable Active Directory Administrator Account names, like 'Admin', which means the attribute 'login' must be set to a name that is not easy to predict test/samples/positive1.tf 18 azurerm_sql_active_directory_administrator positive3 IncorrectValue azurerm_sql_active_directory_administrator[positive3].login 'azurerm_sql_active_directory_administrator[positive3].login' should not be predictable' 'azurerm_sql_active_directory_administrator[positive3].login' is predictable

@cxMiguelSilva cxMiguelSilva merged commit 03c9abe into master Mar 18, 2024
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants