Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update dependency checkov to v2.5.20 #7

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

renovate[bot]
Copy link

@renovate renovate bot commented Apr 24, 2022

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
checkov ==2.0.1076 -> ==2.5.20 age adoption passing confidence

Release Notes

bridgecrewio/checkov (checkov)

v2.5.20

Compare Source

v2.5.19

Compare Source

v2.5.18

Compare Source

Feature

  • general: Adds GHA support for skip-frameworks, skip-cve-package & output-bc-ids flags - #​5619
  • terraform: Ensure that the SQL database is zone-redundant - #​5540
  • terraform: Ensure the Azure Event Hub Namespace is zone redundant - #​5538

Bug Fix

  • bicep: enforce encryption flag to be string for CKV_AZURE_97 - #​5669
  • terraform_plan: Add provisioners to TF Plan parser - #​5622

v2.5.17

Compare Source

v2.5.16

Compare Source

v2.5.15

Compare Source

Feature

  • terraform: Support for merge func inside jsondecode - #​5656

Bug Fix

  • sca: make the abs path to be correcnt - #​5660

v2.5.14

Compare Source

v2.5.13

Compare Source

Feature

  • arm: implement CKV_AZURE_103 for ARM - #​5527
  • arm: implement CKV_AZURE_96 for ARM - #​5506
  • arm: implement CKV_AZURE_97 for ARM - #​5515

Bug Fix

  • terraform: Added a check to make sure dynamic "blocks" are of the expected type - #​5642
  • terraform: update CKV_AWS_339 valid EKS versions - #​5652

v2.5.12

Compare Source

v2.5.11

Compare Source

Feature

  • sca: giving file path on relative the the current dir for cases there is no either specified root_folder and the is no repo scan dir - #​5654

v2.5.10

Compare Source

Feature

  • terraform: support scanning of Terraform managed modules instead of downloading them - #​5635

Bug Fix

  • terraform: Fixing issues with checks CKV_AZURE_226 & CKV_AZURE_227 - #​5638

v2.5.9

Compare Source

Feature

  • sca: support case where there are no cves suppressions - #​5636

v2.5.8

Compare Source

Feature

  • general: Remove code upload for on-prem integrations - #​5624

v2.5.7

Compare Source

v2.5.6

Compare Source

Feature

  • arm: implement CKV_AZURE_95 for ARM - #​5500
  • general: Added source and target to edge data - #​5621

Bug Fix

  • terraform_plan: add azurerm_portal_dashboard to jsonify list - #​5618
  • terraform: check if the dynamic name is one of the resources block - #​5607

v2.5.5

Compare Source

v2.5.4

Compare Source

v2.5.3

Compare Source

Breaking Change

  • general: remove Python 3.7 - #​5605
  • graph: remove CHECKOV_CREATE_GRAPH env var to control graph creation - #​5606

Bug Fix

  • dockerfile: fix Docker image scan - #​5617
  • openapi: Take into account that security is at the root level of your OpenAPI specification. - #​5603
  • terraform: stop CKV_GCP_43 crashing when not a string - #​5561

v2.5.2

Compare Source

v2.5.1

Compare Source

v2.5.0

Compare Source

v2.4.61

Compare Source

Bug Fix

  • terraform: fix upload resource_subgraph_maps - #​5615

Platform

  • terraform: Upload resource subgraph map - #​5612

v2.4.60

Compare Source

v2.4.59

Compare Source

Platform

  • terraform: fix in subgraphs uploads - #​5610

v2.4.58

Compare Source

Platform

  • terraform: upload tf sub graphs - #​5596

v2.4.57

Compare Source

Feature

  • terraform: Ensure ephemeral disks are used for OS disks - #​5584
  • terraform: Ensure that App Service plan is zone redundant - #​5577
  • terraform: Ensure that the AKS cluster encrypt temp disks, caches, and data flows between Compute and Storage resources - #​5588

v2.4.56

Compare Source

v2.4.55

Compare Source

Feature

  • general: Add image referencer rustworkx support - #​5564
  • general: Add rustworkx support - #​5595
  • terraform: Adding 2 new AWS policies - #​5599
  • terraform: simply IMDSv2 checks - #​5601

v2.4.54

Compare Source

v2.4.53

Compare Source

v2.4.52

Compare Source

v2.4.51

Compare Source

Feature

  • arm: CKV_AZURE_88 convert to arm check - #​5465
  • arm: implement CKV_AZURE_149 for ARM - #​5496

Bug Fix

  • terraform: Adding missing null checks - #​5589

v2.4.50

Compare Source

Feature

v2.4.49

Compare Source

v2.4.48

Compare Source

Platform

  • general: expose retry and timeout configuration for interaction with the platform - #​5585

v2.4.47

Compare Source

Feature

  • sca: creating alias mapping for javascript - #​5567
  • sca: creating alias mapping for javascript - #​5582
  • sca: revert creating alias mapping for javascript - #​5581

Bug Fix

  • general: fix print to encode in windows - #​5572
  • terraform: Nested source_module_objects with missing foreach key - #​5580

v2.4.46

Compare Source

v2.4.45

Compare Source

v2.4.44

Compare Source

v2.4.43

Compare Source

v2.4.42

Compare Source

v2.4.41

Compare Source

v2.4.40

Compare Source

v2.4.39

Compare Source

Feature

  • arm: implement CKV2_AZURE_27 for arm - #​5534
  • terraform: Add new policy for deprecated runtimes - #​5555
  • terraform: Ensure Event Hub Namespace uses at least TLS 1.2 - #​5535
  • terraform: Ensure that the Ledger feature is enabled on database that requires cryptographic proof and nonrepudiation of data integrity - #​5541

v2.4.38

Compare Source

v2.4.37

Compare Source

v2.4.36

Compare Source

Feature

Bug Fix

  • terraform: Module from_dict func to static func - #​5562

v2.4.35

Compare Source

v2.4.34

Compare Source

v2.4.33

Compare Source

Feature

  • general: attempt to fix overload in loaders and add tests - #​5549
  • general: remove 3.7 integ. test - #​5556
  • general: remove line to force code change - #​5558
  • terraform: add check Neptune DB clusters should be configured to copy tags to snapshots - #​5552
  • terraform: add CKV_AWS_361 to ensure Neptune DB cluster has adequate backup retention - #​5548

Bug Fix

  • terraform: Fix external_modules_source_map serialization - #​5546

v2.4.32

Compare Source

Feature

  • terraform: add check for Neptune DB clusters IAM database auth enabled - #​5545
  • terraform: add CKV_AWS_360 to ensure backup retention period on AWS Document DB - #​5547

v2.4.31

Compare Source

v2.4.30

Compare Source

Feature

  • terraform: add public network checks for Azure Function and Web Apps - #​5533

v2.4.29

Compare Source

Feature

  • arm: Implement CKV_AZURE_111 in ARM - #​5528
  • arm: implement CKV_AZURE_134 for ARM - #​5518
  • arm: implement CKV_AZURE_160 for arm - #​5526
  • arm: implement CKV_AZURE_89 for ARM - #​5529

Bug Fix

  • terraform: CKV_AWS_208 bug fix - #​5512

v2.4.28

Compare Source

v2.4.27

Compare Source

Feature

  • general: Check module download - #​5525
  • general: Check module download and quit on failure - #​5523

v2.4.26

Compare Source

v2.4.25

Compare Source

Feature

  • arm: Implement CKV_AZURE_101 for ARM - #​5516
  • arm: implement CKV_AZURE_107 for arm - #​5514
  • arm: implement CKV_AZURE_113 for ARM - #​5510

v2.4.24

Compare Source

v2.4.23

Compare Source

v2.4.22

Compare Source

Feature

  • arm: implement CKV_AZURE_112 for arm - #​5507
  • arm: implement CKV_AZURE_40 for ARM - #​5499
  • arm: implement CKV_AZURE_58 for ARM - #​5497
  • arm: implement CKV_AZURE_94 for arm - #​5508

Bug Fix

  • helm: Changed error message to failure to better differentiate problems - #​5517
  • terraform_json: correctly parse data blocks in Terraform JSON - #​5509
  • terraform: continue processing of TF modules in the same file - #​5503
  • terraform: fix error type - #​5513

v2.4.21

Compare Source

v2.4.20

Compare Source

v2.4.19

Compare Source

v2.4.18

Compare Source

Feature

  • arm: implement CKV_AZURE_100 for arm - #​5490
  • arm: implement CKV_AZURE_114 for arm - #​5489
  • arm: implement CKV_AZURE_130 for arm - #​5485
  • arm: implement CKV_AZURE_151 for arm - #​5484

Bug Fix

  • arm: correctly handle json files with comments and output parsing errors - #​5495

v2.4.17

Compare Source

v2.4.16

Compare Source

v2.4.15

Compare Source

v2.4.14

Compare Source

Feature

  • arm: CKV_AZURE_66 implement config logging check for arm - #​5464
  • arm: convert CKV_AZURE_65 to arm - #​5467
  • arm: Implement CKV_AZURE_109 in arm - #​5483
  • arm: implement CKV_AZURE_63 for arm - #​5475
  • arm: implement CKV_AZURE_80 in arm - #​5476
  • secrets: fix resource in git history scan - #​5482

Bug Fix

  • terraform: extend CKV2_AWS_5 to include aws_appstream_fleet (#​5487) - #​5491

v2.4.13

Compare Source

v2.4.12

Compare Source

v2.4.11

Compare Source

v2.4.10

Compare Source

Feature

  • arm: migrate check CKV_AZURE_50 to arm - #​5453
  • arm: translate tf CKV_AZURE_93 check to arm - #​5450
  • kubernetes: Added new endpoint for both helm and kustomize - #​5481

Bug Fix

  • dockerfile: consider platform flag in CKV_DOCKER_7 - #​5468
  • kustomize: support kubectl 1.28+ - #​5480

v2.4.9

Compare Source

v2.4.8

Compare Source

v2.4.7

Compare Source

Feature

  • secrets: handle non iac secrets FP - #​5478

v2.4.6

Compare Source

Bug Fix

  • terraform: Replaced / with os.pathsep to support windows better in terraform runner - #​5473

Documentation

v2.4.5

Compare Source

Bug Fix

  • terraform: Fix for-each/count updating inner for each index for every child resource - #​5463

v2.4.4

Compare Source

Platform

  • sca: Filter IR FW upload results by supportedIrFw list - #​5448

v2.4.3

Compare Source

v2.4.2

Compare Source

Feature

  • dockerfile: Add CKV2_DOCKER_17 for chpasswd - #​5441

Bug Fix

  • kustomize: Fix kustomize ignoring external policy dir command line options - #​5436

v2.4.1

Compare Source

Feature

  • terraform: Remove old tf parser - #​5420

Bug Fix

  • terraform: ensure TFModule is created properly in definition context - #​5446

v2.4.0

Compare Source

v2.3.366

Compare Source

v2.3.365

Compare Source

Feature

  • terraform: Removed most usages of enable_nested_modules - #​5415

v2.3.364

Compare Source

Feature

  • sca: update spdx-tools dep to version 0.8.0 and lower bound it - #​5431
  • terraform: Add address field on vertices even if render_variables is set to False - #​5434

Bug Fix

  • terraform: add new attached resource possibility to CKV2_AWS_23 #​5424 - #​5429
  • terraform: fix ordering issue in CKV_AWS_358 - #​5425

v2.3.363

Compare Source

v2.3.362

Compare Source

v2.3.361

Compare Source

Bug Fix

  • arm: improve CKV_AZURE_24 check - #​5427

v2.3.360

Compare Source

Bug Fix

  • general: Fix empty credentials file issue - #​5421

v2.3.359

Compare Source

v2.3.358

Compare Source

Feature
  • secrets: Make non-entropy signatures take precedence over entropy signatures - #​5412
Bug Fix
  • terraform: Remove DMS S3 check CKV_AWS_299 - #​5413

v2.3.357

Compare Source

v2.3.356

Compare Source

Feature
  • terraform: Github Actions OIDC trust policy check - #​5402

v2.3.355

Compare Source

v2.3.354

Compare Source

Feature
  • general: allow --var-file to be passed as environment variable - #​5406
  • terraform: Add new policy to ensure AWS Transfer server only allows secure protocols - #​5409
Platform
  • general: remove obsolete run config fallback API call - #​5404
Documentation
  • gha: Update setup-python version in GitHub Actions.md - #​5393

v2.3.353

Compare Source

v2.3.352

Compare Source

v2.3.351

Compare Source

Feature
  • terraform: new serialization methods for module and block - #​5391
Bug Fix
  • terraform: pr for upgrade-checkov - #​5400

v2.3.350

Compare Source

v2.3.349

Compare Source

Bug Fix
  • terraform: add TFDefinitionKey to get_entity_context_and_evaluations - #​5392
  • terraform: consider new domain attribute in CKV2_AWS_19 - #​5383

v2.3.348

Compare Source

v2.3.347

Compare Source

Feature
  • sca: support composer.json - #​5382
  • terraform: Use new function to create multi graph instead of single graph - #​5375
Platform
  • general: Implement SSO Relay State Parameter in Checkov Output Links - #​5217

v2.3.346

Compare Source

v2.3.345

Compare Source

v2.3.344

Compare Source

v2.3.343

Compare Source

Feature
  • sca: fix package line numbers - #​5376
Bug Fix
  • terraform: Fix CKV_AWS_104 to support new values - #​5377

v2.3.342

Compare Source

v2.3.341

Compare Source

v2.3.340

Compare Source

Feature

  • general: enrich terraform definitions context key - #​5350

Bug Fix

  • terraform: fix get module name - foreach or count - #​5373

v2.3.339

Compare Source

v2.3.338

Compare Source

Feature
  • terraform: add new function to create module and definitions with tests - #​5362
  • terraform: GCP Ensure IAM Workload identity is restricted - #​5369
Bug Fix
  • general: fix inline suppression collection inside lists - #​5370

v2.3.337

Compare Source

v2.3.336

Compare Source

v2.3.335

Compare Source

Bug Fix
  • terraform: leverage read_file_with_any_encoding to safely look for modules - #​5360

v2.3.334

Compare Source

Feature
  • general: Add resource code filter to all checkov loggers - #​5356
  • general: Infrastructure for custom code logger filter - #​5346
Bug Fix
  • kustomize: Avoid index error when calculating file path - #​5357

v2.3.333

Compare Source

v2.3.332

Compare Source

v2.3.331

Compare Source

Feature
  • openapi: Add CKV_OPENAPI_21 - #​5268
Bug Fix
  • secrets: handle regex error in custom secrets gracefully - #​5355
Documentation
  • general: update docs about installation guidelines - #​5352

v2.3.330

Compare Source

v2.3.329

Compare Source

Feature
  • github: Add ability for External checks with git branch - #​5337
  • sca: add fix command and code for indirect deps - #​5347
Bug Fix
  • kubernetes: No dups when extracting images - #​5339

v2.3.328

Compare Source

v2.3.327

Compare Source

v2.3.326

Compare Source

Feature
  • sca: add fix code and command to cve report - #​5333
  • sca: fix code block array structure - #​5338
Bug Fix
  • general: properly encode non supported chars in SARIF uri field - #​5336
Documentation
  • sca: Add SCA skip comments to docs - #​5330

v2.3.325

Compare Source

v2.3.324

Compare Source

Bug Fix

  • kustomize: Added support for case where no parents are found for the relative fie path - #​5332
  • terraform: Update CKV2_AWS_12 for the new defaults - #​5203

v2.3.323

Compare Source

v2.3.322

Compare Source

v2.3.321

Compare Source

Feature
  • kustomize: Support child k8s resources inside kustomize origin annotations - #​5328

v2.3.320

Compare Source

Bug Fix
  • kustomize: Checked for existence of caller_file_path in definitions_raw - #​5324
  • openapi: Fix ws for CKV_OPENAPI_20 - #​5317
  • terraform: CKV_AWS_342 - managed rules have predefined actions - #​5322

v2.3.319

Compare Source

v2.3.318

Compare Source

Feature
  • general: support UTF-16 and other encodings in multiple frameworks - #​5308
  • kustomize: add back reverted kustomize annotations and update build github action to use github runners - #​5316
  • kustomize: Add origin annotations to calculate bases of kustomize checks - #​5298

v2.3.317

Compare Source

v2.3.316

Compare Source

Feature
  • secrets: Improve the entropy keyword combinator secret scanner - #​5307
Bug Fix
  • openapi: Fix CKV_OpenAPI_20 - #​5302
  • terraform: fix invalid value in CKV_AWS_304 - #​5301
  • terraform: support new field in CKV2_AWS_3 - #​5304

v2.3.315

Compare Source

v2.3.314

Compare Source

Feature
  • dockerfile: add ARM build for K8s container image - #​5293
  • general: Add checkov.spec to enable PyInstaller - #​5281
Bug Fix
  • terraform: remove CKV2_AZURE_18 check and improve CKV2_AZURE_1 - #​5294

v2.3.313

Compare Source

v2.3.312

Compare Source

Platform
  • general: use sca inline suppressions - #​5285

v2.3.311

Compare Source

Feature

  • openapi: New OpenAPI check CKV_OPENAPI_20 - #​5253

v2.3.310

Compare Source

Bug Fix
  • terraform: remove deprecated check CKV_GCP_67 - #​5275
Documentation

v2.3.309

Compare Source

Feature
  • graph: add experimental debug output for graph check evaluation - #​5257
Bug Fix
  • general: revert add composer files to supported package files - #​5269
Platform
  • general: add composer files to supported package files - #​5263

v2.3.308

Compare Source

v2.3.307

Compare Source

v2.3.306

Compare Source

Feature

  • terraform: add module check for commit hash revision usage - #​5261

Bug Fix

  • openapi: add security definition type validation into CKV_OPENAPI_9 - #​5262
  • secrets: fix secrets omit crash when value is not string - #​5260
  • terraform: ignore local modules in CKV_TF_1 - #​5264

v2.3.305

Compare Source

v2.3.304

Compare Source

v2.3.303

Compare Source

Bug Fix
  • arm: consider encryption property in CKV_AZURE_2 - #​5254

v2.3.302

Compare Source

Bug Fix
  • terraform: add missing AWS RDS CA certificate identifiers for aws_db_instance resource - #​5247

v2.3.301

Compare Source

Feature
  • general: remove log from parallel common - #​5244
Platform
  • general: Fix local repo generated name if ends with / - #​5243

v2.3.300

Compare Source

v2.3.299

Compare Source

Feature

  • terraform: ensure kms key policy is defined - #​5235

Bug Fix

  • sca: fix wrongly invoked Image Referencer scanning when scanning a single file - #​5237
  • terraform_plan: add terraform plan vertices to terraform graph if not exist - #​5230

v2.3.298

Compare Source

v2.3.297

Compare Source

v2.3.296

Compare Source

Bug Fix
  • dockerfile: negative is_dockerfile() lookup on .dockerignore suffix - #​5219
  • terraform: fix empty value issue for CKV_GIT_4 - #​5222
Documentation
  • graph: add jsonpath custom policy example - #​5221

v2.3.295

Compare Source

v2.3.294

Compare Source

Feature
  • gha: add skip_path flag to GHA and allow multiple values in var_file - #​5213
  • sca: add root package name and version to csv sbom - #​5211

v2.3.293

Compare Source

v2.3.292

Compare Source

Feature
  • arm: Handle another structure for SQL retention policy - #​5210
Bug Fix
  • secrets: limit line length for custom secrets - #​5208
  • terraform: Update GCP checks for plan files - #​5197

v2.3.291

Compare Source

[v2.3.290](https://redirect.github.com/bridgecrewio/checkov/compare/2.3.2


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot changed the title Update dependency checkov to v2.0.1077 Update dependency checkov to v2.0.1078 Apr 24, 2022
@renovate renovate bot changed the title Update dependency checkov to v2.0.1078 Update dependency checkov to v2.0.1079 Apr 24, 2022
@renovate renovate bot changed the title Update dependency checkov to v2.0.1079 Update dependency checkov to v2.0.1082 Apr 25, 2022
@renovate renovate bot changed the title Update dependency checkov to v2.0.1082 Update dependency checkov to v2.0.1083 Apr 25, 2022
@renovate renovate bot changed the title Update dependency checkov to v2.0.1083 Update dependency checkov to v2.0.1084 Apr 25, 2022
@renovate renovate bot changed the title Update dependency checkov to v2.0.1084 Update dependency checkov to v2.0.1085 Apr 27, 2022
@renovate renovate bot changed the title Update dependency checkov to v2.0.1085 Update dependency checkov to v2.0.1086 Apr 27, 2022
@renovate renovate bot changed the title Update dependency checkov to v2.0.1086 Update dependency checkov to v2.0.1088 Apr 27, 2022
@renovate renovate bot changed the title Update dependency checkov to v2.0.1088 Update dependency checkov to v2.0.1092 Apr 28, 2022
@renovate renovate bot changed the title Update dependency checkov to v2.0.1092 Update dependency checkov to v2.0.1095 Apr 28, 2022
@renovate renovate bot changed the title Update dependency checkov to v2.0.1095 Update dependency checkov to v2.0.1098 Apr 28, 2022
@renovate renovate bot changed the title Update dependency checkov to v2.0.1098 Update dependency checkov to v2.0.1100 Apr 29, 2022
@renovate renovate bot changed the title Update dependency checkov to v2.0.1100 Update dependency checkov to v2.0.1102 May 1, 2022
@renovate renovate bot changed the title Update dependency checkov to v2.0.1102 Update dependency checkov to v2.0.1105 May 2, 2022
@renovate renovate bot changed the title Update dependency checkov to v2.0.1105 Update dependency checkov to v2.0.1107 May 2, 2022
@renovate renovate bot changed the title Update dependency checkov to v2.5.2 Update dependency checkov to v2.5.3 Oct 4, 2023
@renovate renovate bot changed the title Update dependency checkov to v2.5.3 Update dependency checkov to v2.5.4 Oct 5, 2023
@renovate renovate bot changed the title Update dependency checkov to v2.5.4 Update dependency checkov to v2.5.6 Oct 5, 2023
@renovate renovate bot changed the title Update dependency checkov to v2.5.6 Update dependency checkov to v2.5.7 Oct 11, 2023
@renovate renovate bot changed the title Update dependency checkov to v2.5.7 Update dependency checkov to v2.5.8 Oct 12, 2023
@renovate renovate bot changed the title Update dependency checkov to v2.5.8 Update dependency checkov to v2.5.9 Oct 15, 2023
@renovate renovate bot changed the title Update dependency checkov to v2.5.9 Update dependency checkov to v2.5.10 Oct 16, 2023
@renovate renovate bot changed the title Update dependency checkov to v2.5.10 Update dependency checkov to v2.5.11 Oct 17, 2023
@renovate renovate bot changed the title Update dependency checkov to v2.5.11 Update dependency checkov to v2.5.13 Oct 18, 2023
@renovate renovate bot changed the title Update dependency checkov to v2.5.13 Update dependency checkov to v2.5.14 Oct 19, 2023
@renovate renovate bot changed the title Update dependency checkov to v2.5.14 Update dependency checkov to v2.5.15 Oct 19, 2023
@renovate renovate bot changed the title Update dependency checkov to v2.5.15 Update dependency checkov to v2.5.17 Oct 22, 2023
@renovate renovate bot changed the title Update dependency checkov to v2.5.17 Update dependency checkov to v2.5.18 Oct 22, 2023
@renovate renovate bot changed the title Update dependency checkov to v2.5.18 Update dependency checkov to v2.5.19 Oct 23, 2023
@renovate renovate bot changed the title Update dependency checkov to v2.5.19 Update dependency checkov to v2.5.20 Nov 22, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants