Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Rule for github_repository seems to be wrongly placed under gcp #325

Closed
HorizonNet opened this issue Sep 15, 2020 · 2 comments · Fixed by #334
Closed

Rule for github_repository seems to be wrongly placed under gcp #325

HorizonNet opened this issue Sep 15, 2020 · 2 comments · Fixed by #334

Comments

@HorizonNet
Copy link
Contributor

HorizonNet commented Sep 15, 2020

The rule accurics.gcp.IAM.145 is currently located under gcp, which isn't intuitive as it is targeting the GitHub provider and not GCP. It would be better to move its own policy set.

@williepaul
Copy link
Contributor

@HorizonNet Agreed--the policy is written for that provider specifically. I think for now we may want to keep two copies of the rule, one in a provider-specific folder, and the original one. Ideally, probably it'll be helpful just to detect all providers used and enable the corresponding policies by default.

@HorizonNet
Copy link
Contributor Author

Added a first draft for the provider. Some points are probably still missing. Started by trying to simulate what was done for the gcp policies.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging a pull request may close this issue.

3 participants