1
0
mirror of https://github.com/aquasecurity/kube-bench.git synced 2024-11-21 23:58:06 +00:00

Commit Graph

  • 3d4ce590fb Fix kubelet file permission to check for Abubakr-Sadik Nii Nai Davis 2024-10-10 15:41:22 +0000
  • 1ee8c9252d
    Merge ddba9859dd into e47725299e Darius Mejeras 2024-10-10 13:05:56 +0600
  • 7d3797df64
    Merge branch 'main' into eks-1-5 afdesk 2024-10-10 13:05:49 +0600
  • 0d13ecef52
    Merge branch 'main' into gke1.6 afdesk 2024-10-10 10:41:47 +0600
  • e47725299e
    build(deps): bump gorm.io/driver/postgres from 1.5.6 to 1.5.9 (#1698) dependabot[bot] 2024-10-10 10:37:41 +0600
  • fcda8cf547 Change scored field for all node tests to true Abubakr-Sadik Nii Nai Davis 2024-10-09 04:51:14 +0000
  • 3d61d46c8f
    Merge branch 'main' into eks-1-5 afdesk 2024-10-08 10:22:51 +0600
  • 3741c1faba
    build(deps): bump gorm.io/driver/postgres from 1.5.6 to 1.5.9 dependabot[bot] 2024-10-07 19:43:35 +0000
  • ec9b88a846
    Merge branch 'main' into gke1.6 afdesk 2024-10-07 11:01:28 +0600
  • e8562f2944
    Extend default kubelet configlist to fit AWS EKS (#1637) Matthias Muth 2024-10-04 10:08:03 +0200
  • 01314a6a72
    Merge branch 'main' into main afdesk 2024-10-04 13:43:57 +0600
  • 3a0ccc440c
    fix: rh-1.0 check 4.1.3 typo (#1652) Arano-kai 2024-10-04 10:42:56 +0300
  • cfd40665db
    Merge branch 'main' into bugfix/rh-1.0_4.1.3_typo afdesk 2024-10-04 13:33:11 +0600
  • c683e93968
    build(deps): bump github.com/aws/aws-sdk-go-v2/service/securityhub (#1696) dependabot[bot] 2024-10-04 12:21:07 +0600
  • 00ad2b3244
    Merge branch 'main' into dependabot/go_modules/github.com/aws/aws-sdk-go-v2/service/securityhub-1.53.3 afdesk 2024-10-04 12:11:23 +0600
  • e75cd6bbc8
    Updated KUBECTL_VERSION to 1.31.0 for fixing vulnerabilities (#1690) jdesouza 2024-10-03 13:43:01 -0300
  • 375b90d506
    Update go.mod jdesouza 2024-10-03 09:22:15 -0300
  • 3506312b62
    Merge branch 'main' into dependabot/go_modules/github.com/aws/aws-sdk-go-v2/service/securityhub-1.53.3 afdesk 2024-10-03 09:22:51 +0600
  • 7594761f3f
    Merge branch 'main' into main afdesk 2024-10-03 09:21:00 +0600
  • d8f041a826
    build(deps): bump alpine from 3.20.0 to 3.20.3 (#1676) dependabot[bot] 2024-10-03 09:20:12 +0600
  • 32af0a6104
    Merge branch 'main' into dependabot/docker/alpine-3.20.3 afdesk 2024-10-03 08:57:16 +0600
  • a4af123191
    Merge branch 'main' into main afdesk 2024-10-01 12:18:15 +0600
  • 495cea6939
    Merge branch 'main' into dependabot/go_modules/k8s.io/apimachinery-0.31.1 afdesk 2024-10-01 12:00:15 +0600
  • 80feee111d
    Merge branch 'main' into dependabot/go_modules/github.com/aws/aws-sdk-go-v2/service/securityhub-1.53.3 afdesk 2024-10-01 11:53:18 +0600
  • 7ea1d59bb1
    update audit script for cis-1.9 kubernetes policies id 5.1.6 (#1655) Winnerson Kharsunai 2024-10-01 11:18:02 +0530
  • 7ed5d4dabd
    build(deps): bump alpine from 3.20.0 to 3.20.3 dependabot[bot] 2024-10-01 05:33:07 +0000
  • 298a766bb7
    build(deps): bump golang from 1.22.4 to 1.23.1 dependabot[bot] 2024-10-01 05:33:05 +0000
  • fc5eeb1126
    Merge branch 'main' into fix/cis-1.9_kubernetes-policies_5.1.6 afdesk 2024-10-01 11:32:56 +0600
  • 89842dcaaa
    update dockerfile to add package findutils (#1657) Winnerson Kharsunai 2024-10-01 11:02:23 +0530
  • 43e600940c
    Merge branch 'main' into fix/cis-1.9_kubernetes-policies_5.1.5 afdesk 2024-10-01 11:18:55 +0600
  • 03d728374e
    Merge branch 'main' into main jdesouza 2024-09-30 08:07:51 -0300
  • eb22797152
    Merge branch 'main' into dependabot/go_modules/github.com/aws/aws-sdk-go-v2/service/securityhub-1.53.3 afdesk 2024-09-30 12:14:02 +0600
  • d555302a0c
    Merge branch 'main' into dependabot/go_modules/k8s.io/apimachinery-0.31.1 afdesk 2024-09-30 12:13:49 +0600
  • 674d8e8bb7
    Update command to build docker to run in EKS cluster (#1648) za 2024-09-30 13:13:10 +0700
  • 11f82bb01f
    Merge branch 'main' into update-command-running-on-eks afdesk 2024-09-30 11:23:01 +0600
  • a68ca44716
    Merge branch 'main' into fix/cis-1.9_kubernetes-policies_5.1.6 afdesk 2024-09-30 10:39:28 +0600
  • 4b4c1ce709
    Modify 1.2.3 Ensure that the DenyServiceExternalIPs is set in CIS-1.7/1.8 (#1607) Andy Pitcher 2024-09-30 00:30:59 -0400
  • d7b3d33f19
    Merge branch 'main' into fix-master-1.2.3-DenyServiceExternalIPs afdesk 2024-09-30 10:11:06 +0600
  • b85ec78a84
    Fix CIS-1.9 policies 5.1.1/5.1.5 typos (#1658) Andy Pitcher 2024-09-29 23:54:45 -0400
  • 5b13c08d1f
    Merge branch 'main' into fix-master-1.2.3-DenyServiceExternalIPs afdesk 2024-09-30 09:54:16 +0600
  • f79413bac5
    Merge branch 'main' into bugfix/rh-1.0_4.1.3_typo afdesk 2024-09-28 14:32:49 +0600
  • 6b82a25422
    Merge branch 'main' into cis-1.9-fix-policies-5.1.1 afdesk 2024-09-28 13:40:56 +0600
  • 448a23a416
    build(deps): bump github.com/aws/aws-sdk-go-v2/service/securityhub dependabot[bot] 2024-09-28 07:39:00 +0000
  • bfee38157b
    build(deps): bump k8s.io/apimachinery from 0.29.3 to 0.31.1 dependabot[bot] 2024-09-28 07:37:38 +0000
  • f6877e3c17
    Fix issue 1595: failed to output to ASFF (#1691) Wolfgang Reichert 2024-09-28 09:36:44 +0200
  • d407bfaf26 Merge branch 'main' of github.com:jdesouza/kube-bench jdesouza 2024-09-27 10:48:00 -0300
  • 8d41e95742 Fixed kubectl version jdesouza 2024-09-27 10:47:25 -0300
  • 2cd4fa363d
    Merge branch 'main' into cis-1.9-fix-policies-5.1.1 Andy Pitcher 2024-09-26 10:23:35 -0400
  • dd6602de91
    Merge branch 'main' into fix-master-1.2.3-DenyServiceExternalIPs Andy Pitcher 2024-09-26 10:19:32 -0400
  • 97c577180c
    Merge branch 'main' into main jdesouza 2024-09-26 08:07:38 -0300
  • 52e8ca8f30
    Merge branch 'main' into fix-issue-1595-security-hub Wolfgang Reichert 2024-09-26 11:36:09 +0200
  • 54fb51c33b Fix issue 1595: failed to output to ASFF Wolfgang Reichert 2024-09-26 11:32:49 +0200
  • 2751f87034
    Fix audit and remediation for CIS-1.9 master 1.1.13/1.1.14 (#1649) Andy Pitcher 2024-09-26 00:45:48 -0400
  • f91e5da5ee
    Merge branch 'main' into cis-1.9-fix-master-1.1.13-14 afdesk 2024-09-26 10:19:30 +0600
  • 2da3c53095 Bumped kubectl version for fixing vulnerabilities jdesouza 2024-09-25 16:42:20 -0300
  • d630013b04 Bumped Go to 1.22.7 for fixing Critical/High vulberabilities jdesouza 2024-09-25 10:25:44 -0300
  • 2fc601a0b6 Bumped Go to 1.22.7 for fixing Critical/High vulberabilities jdesouza 2024-09-25 10:24:26 -0300
  • a9422a6623
    Overhaul of K3s scans (#1659) Derek Nola 2024-09-25 00:12:02 -0700
  • 62056499a5
    Merge branch 'main' into k3s_overhaul afdesk 2024-09-24 21:10:32 +0600
  • f8b6f2fc19
    chore: fixed vulns - bump Go version (#1687) mjshastha 2024-09-24 11:42:40 +0530
  • 492816b380
    Merge branch 'main' into KBvulnsInGo afdesk 2024-09-24 11:57:58 +0600
  • c533d68bad
    FIXING RKE-2-CIS-1.24 Checks (#1688) Saurabh Misra 2024-09-24 11:26:58 +0530
  • e7a2b7b0c8 Merge branch 'main' into KBvulnsInGo mjshastha 2024-09-20 15:53:13 +0530
  • 29c56de77e
    build(deps): bump github.com/aws/aws-sdk-go-v2/service/securityhub dependabot[bot] 2024-09-23 19:56:39 +0000
  • ef1968b42d Fix tests for makeIPTablesUtilChaings Abubakr-Sadik Nii Nai Davis 2024-09-23 14:57:42 +0000
  • e30c1e692a Workaround: hardcode kubelet config path for gke-1.6.0 Abubakr-Sadik Nii Nai Davis 2024-09-23 13:56:15 +0000
  • a2ed76b783 FIXING RKE-2-CIS-1.24 Checks Saurabh Misra 2024-09-23 16:16:04 +0530
  • de27981736 Fixed vulns - bump Go version. mjshastha 2024-09-20 15:49:15 +0530
  • ec71eb89c2
    Merge 72f5a54777 into 5a3fd1d896 Saurabh Misra 2024-09-19 12:40:05 +0000
  • 72f5a54777 FIXING RKE2-CIS-1.24 CHECKS . MASTER: a. Checks 1.1.10,1.1.20 are manual according to https://docs.rke2.io/security/cis_self_assessment124#1110-ensure-that-the-container-network-interface-file-ownership-is-set-to-root-manual and https://docs.rke2.io/security/cis_self_assessment124#1110-ensure-that-the-container-network-interface-file-ownership-is-set-to-root-manual respectively. b. Check 1.3.6 is not relevant to an RKE2 cluster as RKE2 rotates TLS certificates internally - https://github.com/rancher/dashboard/issues/4485. We will skip it and not score it Saurabh Misra 2024-09-19 18:08:05 +0530
  • 1ae56423b8
    Merge ba6cb26582 into 5a3fd1d896 Saurabh Misra 2024-09-19 11:00:20 +0000
  • ba6cb26582 FIXING RKE2-CIS-1.24 CHECKS Saurabh Misra 2024-09-19 12:44:55 +0530
  • bc50889995
    Merge 7e59a9d555 into 5a3fd1d896 Saurabh Misra 2024-09-19 06:58:14 +0000
  • 7e59a9d555 FIXING RKE CIS CHECKS Saurabh Misra 2024-09-16 16:06:42 +0530
  • 5ce3fa5c12
    build(deps): bump github.com/aws/aws-sdk-go-v2/service/securityhub dependabot[bot] 2024-09-16 19:30:32 +0000
  • 39dd50c5cf NDEV-20011 : adding AKS 1.5.0 benchmarks deboshree-b 2024-09-11 16:54:29 +0530
  • 083b0029dd NDEV-20011 : updating test for gke 1.6.0 - 4.1.4 benchmark deboshree-b 2024-09-10 17:51:33 +0530
  • 5e7030ffbb NDEV-20011 : adding gke-1.6.0 in config.yaml deboshree-b 2024-09-10 17:09:02 +0530
  • 1388da7aa0 NDEV-20011 : adding type and test for scored = true benchmarks deboshree-b 2024-09-10 15:10:41 +0530
  • f55346bea9 NDEV-20011 : adding gke 1.6.0 benchmark deboshree-b 2024-09-10 15:02:48 +0530
  • dca7e3354f
    build(deps): bump github.com/aws/aws-sdk-go-v2/service/securityhub dependabot[bot] 2024-09-09 19:14:30 +0000
  • e96f30891e Add gke-1.6.0 benchmark selection based on k8s version Abubakr-Sadik Nii Nai Davis 2024-09-03 10:29:55 +0000
  • f3e0d5056b Fix formatting across gke-1.6.0 files Abubakr-Sadik Nii Nai Davis 2024-09-02 05:31:06 +0000
  • 53d3af18bb
    Remove incorrect use of check_for_default_sa.sh script Derek Nola 2024-08-27 10:52:19 -0700
  • e602ff47bf
    Matched Manual/Automated to correct scoring (false/true) Derek Nola 2024-08-27 10:49:41 -0700
  • 7f9f5e44c0
    Merge journalctl checks for K3s Derek Nola 2024-08-27 10:42:32 -0700
  • d215c4c698
    build(deps): bump github.com/aws/aws-sdk-go-v2/service/securityhub dependabot[bot] 2024-08-26 20:03:31 +0000
  • e85614e3e2 Revert "NDEV-20011 : adding CIS GKE-1.6.0 benchmarks" deboshree-b 2024-08-26 07:31:24 +0530
  • 2668e26687 Revert "NDEV-20011 : initial commit for other benchmarks" deboshree-b 2024-08-26 07:30:24 +0530
  • 96a8081e8d NDEV-20011 : initial commit for other benchmarks deboshree-b 2024-08-26 05:57:53 +0530
  • ebd34d5b91 Add master recommendations Abubakr-Sadik Nii Nai Davis 2024-08-24 20:38:07 +0000
  • 69222c1d31 Add managed services and policy recommendation Abubakr-Sadik Nii Nai Davis 2024-08-24 20:37:18 +0000
  • 2a8c05edef Apply changes for CIS-1.9 Andy Pitcher 2024-08-21 15:34:42 -0400
  • 1f003a6249 Modify 1.2.3 Ensure that the DenyServiceExternalIPs is set - op changed from have to has and removed bin_op: or - remediation description changed to only include --enable-admission-plugins Andy Pitcher 2024-04-30 18:23:19 -0400
  • ac2f2cff69 Add new lines to CIS-1.9 Andy Pitcher 2024-08-20 21:38:19 -0400
  • b779b38a6d Fix typo CIS-1.9 5.1.5 Andy Pitcher 2024-08-20 21:20:29 -0400
  • 2e027a4182
    CIS 1.9 - Fix incorrectly failing tests 1.1.13 and 1.1.14 Christian Skarby 2024-08-20 10:17:43 +0200
  • d567c74692
    build(deps): bump golang from 1.22.4 to 1.23.0 dependabot[bot] 2024-08-19 19:37:59 +0000
  • 4ef81dc9d5
    build(deps): bump k8s.io/apimachinery from 0.29.3 to 0.31.0 dependabot[bot] 2024-08-19 19:04:03 +0000
  • 1f11ceeab5
    build(deps): bump github.com/aws/aws-sdk-go-v2/service/securityhub dependabot[bot] 2024-08-19 19:03:50 +0000