1
0
mirror of https://github.com/aquasecurity/kube-bench.git synced 2024-11-22 08:08:07 +00:00

feat: use CIS EKS 1.5.0 by default

This commit is contained in:
Peter Balogh 2024-08-05 15:16:57 +02:00
parent 489865ce3d
commit cf0c87bbbe
No known key found for this signature in database
GPG Key ID: 9A75A748F9634752
4 changed files with 10 additions and 4 deletions

View File

@ -114,8 +114,8 @@ groups:
text: "Minimize the admission of containers wishing to share the host network namespace (Automated)"
type: "manual"
remediation: |
Create a PSP as described in the Kubernetes documentation, ensuring that the
.spec.hostNetwork field is omitted or set to false.
Add policies to each namespace in the cluster which has user workloads to restrict the
admission of hostNetwork containers.
scored: false
- id: 4.2.5

View File

@ -460,6 +460,12 @@ func TestValidTargets(t *testing.T) {
targets: []string{"node", "policies", "controlplane", "managedservices"},
expected: true,
},
{
name: "eks-1.5.0 valid",
benchmark: "eks-1.5.0",
targets: []string{"node", "policies", "controlplane", "managedservices"},
expected: true,
},
}
for _, c := range cases {

View File

@ -489,7 +489,7 @@ func getPlatformBenchmarkVersion(platform Platform) string {
glog.V(3).Infof("getPlatformBenchmarkVersion platform: %s", platform)
switch platform.Name {
case "eks":
return "eks-1.2.0"
return "eks-1.5.0"
case "gke":
switch platform.Version {
case "1.15", "1.16", "1.17", "1.18", "1.19":

View File

@ -650,7 +650,7 @@ func Test_getPlatformBenchmarkVersion(t *testing.T) {
args: args{
platform: Platform{Name: "eks"},
},
want: "eks-1.2.0",
want: "eks-1.5.0",
},
{
name: "gke 1.19",