Skip to content
This repository has been archived by the owner on Jun 21, 2022. It is now read-only.

Prisma Cloud fix config: /package.json and 12 more #20

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

prisma-cloud-devsecops[bot]
Copy link

Prisma Cloud has created this PR to fix Supply Chain risks found in files in this project.

Changes included in this PR:

  • /package.json
  • /package-lock.json
  • /main.tf:aws_s3_bucket.data
  • /main.tf:aws_s3_bucket.data
  • /main.tf:aws_s3_bucket.data
  • /main.tf:aws_s3_bucket.data
  • /main.tf:aws_s3_bucket.data_science
  • /main.tf:aws_s3_bucket.financials
  • /main.tf:aws_s3_bucket.financials
  • /main.tf:aws_s3_bucket.financials
  • /main.tf:aws_s3_bucket.logs
  • /main.tf:aws_s3_bucket.operations
  • /main.tf:aws_s3_bucket.operations

Policies:

  • Packages scan found vulnerabilities
  • Ensure that S3 buckets are encrypted with KMS by default
  • Ensure that S3 buckets are encrypted with KMS by default
  • Ensure all data stored in the S3 bucket have versioning enabled
  • Ensure all data stored in the S3 bucket have versioning enabled
  • S3 Bucket has an ACL defined which allows public READ access.
  • Ensure the S3 bucket has access logging enabled
  • Ensure the S3 bucket has access logging enabled
  • Ensure the S3 bucket has access logging enabled
  • Packages scan found vulnerabilities
  • Ensure that S3 buckets are encrypted with KMS by default
  • Ensure the S3 bucket has access logging enabled
  • Ensure that S3 buckets are encrypted with KMS by default

Please check the changes in this PR to ensure they do not introduce conflicts to your project.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants