Master - #55
Conversation
Bumps [@babel/traverse](https://github.com/babel/babel/tree/HEAD/packages/babel-traverse) from 7.9.0 to 7.23.2. - [Release notes](https://github.com/babel/babel/releases) - [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md) - [Commits](https://github.com/babel/babel/commits/v7.23.2/packages/babel-traverse) --- updated-dependencies: - dependency-name: "@babel/traverse" dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
…traverse-7.23.2 Bump @babel/traverse from 7.9.0 to 7.23.2
Signed-off-by: Md Sulaiman <51925710+sulaiman-coder@users.noreply.github.com>
Bumps [@octokit/app](https://github.com/octokit/app.js) from 14.0.1 to 14.0.2. - [Release notes](https://github.com/octokit/app.js/releases) - [Commits](octokit/app.js@v14.0.1...v14.0.2) --- updated-dependencies: - dependency-name: "@octokit/app" dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [follow-redirects](https://github.com/follow-redirects/follow-redirects) from 1.15.3 to 1.15.4. - [Release notes](https://github.com/follow-redirects/follow-redirects/releases) - [Commits](follow-redirects/follow-redirects@v1.15.3...v1.15.4) --- updated-dependencies: - dependency-name: follow-redirects dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
…-redirects-1.15.4 Bump follow-redirects from 1.15.3 to 1.15.4
…t/app-14.0.2 Bump @octokit/app from 14.0.1 to 14.0.2
Signed-off-by: NxPKG <116948796+NxPKG@users.noreply.github.com>
Signed-off-by: NxPKG <116948796+NxPKG@users.noreply.github.com>
* ci: build * Update scans_ci.yml Signed-off-by: NxPKG <116948796+NxPKG@users.noreply.github.com> * 1.0.0 add * Update README.md Signed-off-by: NxPKG <116948796+NxPKG@users.noreply.github.com> * Azure/gov cloud --------- Signed-off-by: NxPKG <116948796+NxPKG@users.noreply.github.com>
* ci: build * Update scans_ci.yml Signed-off-by: NxPKG <116948796+NxPKG@users.noreply.github.com> * 1.0.0 add * Update README.md Signed-off-by: NxPKG <116948796+NxPKG@users.noreply.github.com> * Azure/gov cloud * fix index --------- Signed-off-by: NxPKG <116948796+NxPKG@users.noreply.github.com>
Signed-off-by: gitworkflows <118260833+gitworkflows@users.noreply.github.com>
Signed-off-by: gitworkflows <118260833+gitworkflows@users.noreply.github.com>
Signed-off-by: gitworkflows <118260833+gitworkflows@users.noreply.github.com>
Signed-off-by: gitworkflows <118260833+gitworkflows@users.noreply.github.com>
Signed-off-by: gitworkflows <118260833+gitworkflows@users.noreply.github.com>
Signed-off-by: gitworkflows <118260833+gitworkflows@users.noreply.github.com>
Signed-off-by: gitworkflows <118260833+gitworkflows@users.noreply.github.com>
chore: update CI/CD pipeline, add PR template, and improve documentation
Bumps the npm_and_yarn group with 1 update in the / directory: [minimatch](https://github.com/isaacs/minimatch). Updates `minimatch` from 3.1.3 to 10.2.2 - [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md) - [Commits](isaacs/minimatch@v3.1.3...v10.2.2) --- updated-dependencies: - dependency-name: minimatch dependency-version: 10.2.2 dependency-type: direct:production dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com>
…uditing Platform 🚀 AWS • Azure • GCP • Oracle • GitHub (#52) * Merge pull request #1 from envrs/feature/update-ci-cd-and-docs Feature/update ci cd and docs * feat: ☁️ CloudExploit by KhulnaSoft Security, Ltd. 🔐 Multi‑Cloud Security Auditing Platform 🚀 AWS • Azure • GCP • Oracle • GitHub * Update helpers/shared.js Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> Signed-off-by: fortishield <161459699+FortiShield@users.noreply.github.com> * 🔧 Fix multiple issues across plugins, collectors, and helpers - Remove invalid apis property from 9 privilege analysis plugins (no-op run functions) - Fix regexMismatch length checks in iamRolePolicies.js to use Object.keys() - Fix GuardDuty BridgeResourceNameIdentifier to use 'detectorId' instead of 'id' - Update broken repo links in docs (cloudexploit/scans -> khulnasoft/cloudexploit) - Fix queueService collector to use QueueServiceClient instead of TableServiceClient * feat: migration uv --------- Signed-off-by: fortishield <161459699+FortiShield@users.noreply.github.com> Co-authored-by: fortishield <161459699+FortiShield@users.noreply.github.com> Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> Co-authored-by: xeondesk <xeondesk@gmail.com>
Bumps the npm_and_yarn group with 1 update in the / directory: [minimatch](https://github.com/isaacs/minimatch). Updates `minimatch` from 3.1.3 to 10.2.2 - [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md) - [Commits](isaacs/minimatch@v3.1.3...v10.2.2) --- updated-dependencies: - dependency-name: minimatch dependency-version: 10.2.2 dependency-type: direct:production dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: KhulnaSoft bot <43526132+khulnasoft-bot@users.noreply.github.com>
|
Important Review skippedToo many files! This PR contains 2998 files, which is 2898 over the limit of 100. To get a review, reduce the PR to 100 files or fewer by splitting it into smaller PRs or changing its base branch. Upgrade to a paid plan to raise the limit. Usage-priced reviews support at most 300 files. ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: ⛔ Files ignored due to path filters (2)
📒 Files selected for processing (2998)
You can disable this status message by setting the |
|
PR Summary by QodoRebrand to CloudExploit; add remediation flow and Azure GovCloud support
AI Description
Diagram
High-Level Assessment
Files changed (20)
|
Code Review by Qodo
1. Remediation hooks unchecked
|
| postRun('Error: ASL: Wrong ASL Version: ', e); | ||
| } | ||
|
|
||
| aslRunner(collection, plugin.asl, resourceMap, postRun); |
There was a problem hiding this comment.
1. Asl require crash 🐞 Bug ☼ Reliability
In engine.js, if loading the ASL runner module fails, the code still calls aslRunner(...) even though it may be undefined, which throws a TypeError and can abort the scan when --run-asl is enabled.
Agent Prompt
## Issue description
When `plugin.asl` is present and `settings['run-asl']` is enabled, `engine.js` dynamically loads an ASL runner module. If the `require()` fails, the catch block logs via `postRun(...)` but execution continues and still invokes `aslRunner(...)`, which may be undefined, causing a runtime crash.
## Issue Context
This occurs in the ASL execution branch in the plugin loop. The code should either (a) return/short-circuit after the load failure, or (b) fall back to `plugin.run(...)`, or (c) skip the plugin with a clear error.
## Fix Focus Areas
- engine.js[242-259]
ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools
| if (settings.remediate && settings.remediate.includes(pluginId)){ | ||
| plugin.apis_remediate.forEach(function(api) { | ||
| if (apiCalls.indexOf(api) === -1) apiCalls.push(api); | ||
| }); |
There was a problem hiding this comment.
2. Remediation hooks unchecked 🐞 Bug ☼ Reliability
engine.js assumes any plugin listed in settings.remediate has apis_remediate and a remediate() function; selecting a plugin without these fields causes a runtime exception during API-call planning or remediation execution.
Agent Prompt
## Issue description
The remediation feature currently assumes all plugin IDs in `settings.remediate` are remediation-capable. The engine unconditionally iterates `plugin.apis_remediate` (can be undefined) and later calls `plugin.remediate(...)` (can be undefined), which can crash the scan.
## Issue Context
Not all existing plugins define remediation hooks. For example, `publicS3Origin` defines only `apis` and `run`.
## Fix Focus Areas
- engine.js[132-141]
- engine.js[221-233]
- plugins/aws/cloudfront/publicS3Origin.js[4-16]
ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools




No description provided.