kaplanlior
Repos
51
Followers
55
Following
34

The PHP Interpreter

C
2
2

Clone of Debian Installer (d-i) repository from https://anonscm.debian.org/viewvc/d-i/

1
5

Extension for IBM DB2 Universal Database, IBM Cloudscape, and Apache Derby

0
0

Read-only LibreOffice core repo - no pull request (use gerrit instead https://gerrit.libreoffice.org/) - don't download zip, use https://dev-www.libreoffice.org/bundles/ instead

1907
521

A platform for planning and crowdfunding co-created events.

4
8

A module for managing volunteers at Midburn – the Israeli Burning Man community

Events

issue comment
feat: ignore terraform cache folders

@dim-ops don't forget to remove the draft status for this PR so we can review it. If you need any help before that - ping me.

Created at 21 hours ago
opened issue
Add KICS for k8s scanning

It's great that you have trivy to highlight security issues, I'd suggest you'll add KICS as well.

Will be happy to help if you want.

Created at 1 week ago

Update multiple Blackhat event CFP dates

Created at 1 week ago

Add Open Source Summit (Europe)

Created at 1 week ago
issue comment
Potentially wrong queries

Do you suggest to to remove these queries or change their severity (e.g. informational) ?

Created at 1 week ago
issue comment
Using Kics Query to detect admin policy attached to a Permission set - AWS SSO

The github action now uses KICS 1.6.11.

Created at 1 week ago
Image checkmarx/kics:gh-action-kics1.6 contains old version of kics

Thanks Thomas,

The KICS github action uses a different tag to select which version of KICS it runs. We usually advance it a week past the release to verify there aren't any regressions.

After some gap in this, two days ago we jumped from 1.6.6 to 1.6.11.

Created at 1 week ago
delete branch
kaplanlior delete branch feature/kicsbot-update-queries-docs
Created at 2 weeks ago

docs(queries): update queries catalog

Created at 2 weeks ago
pull request closed
docs(queries): update queries catalog

Automated Changes Updating queries' documentation. Triggered by SHA: 74baef571165c8cc15ed7940b92c1e69625a439c

Created at 2 weeks ago

ci(deps): bump golang from 1.20.1-alpine to 1.20.2-alpine

Bumps golang from 1.20.1-alpine to 1.20.2-alpine.


updated-dependencies:

  • dependency-name: golang dependency-type: direct:production update-type: version-update:semver-patch ...

Signed-off-by: dependabot[bot] support@github.com

Created at 2 weeks ago
delete branch
kaplanlior delete branch dependabot/docker/golang-1.20.2-alpine
Created at 2 weeks ago
pull request closed
ci(deps): bump golang from 1.20.1-alpine to 1.20.2-alpine

Bumps golang from 1.20.1-alpine to 1.20.2-alpine.

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Created at 2 weeks ago
issue comment
Terraform: Flag embededded access key and secret key as insecure

Thanks Trevor for the report.

Do you want to try and create a query to catch this case? https://docs.kics.io/latest/creating-queries/

We'll be happy to help if you're up to the challenge (:

Created at 2 weeks ago
Created at 2 weeks ago
opened issue
Reduce docker image size

For KICS 1.6.x the docker images size is around 1 GB. Our goal is to reduce the image size or offer another image with extended abilities / files.

Removing terraformer would save ~ 900 MB 60 terraform binary 460 terraform providers 380 terraformer binary

Taking into account we might want to keep the terraform binary for future uses.

Created at 3 weeks ago
Add Kaplan Open Source (Israel)

There isn't. I would keep the Hebrew one.

Created at 3 weeks ago
issue comment
Dockerfiles use outdated terraform (and tf providers) with critical vulnerabilities

https://github.com/hashicorp/terraform/issues/32606 says goutils doesn't affect terraform. We'll upgrade in any case for the latest stable which has this fix (1.3.9).

Created at 1 month ago
Add Kaplan Open Source (Israel)
Created at 1 month ago
Created at 1 month ago