feat(deps): bump aquasecurity/trivy-action from 0.24.0 to 0.28.0 #548
Annotations
8 errors
Parse scan results
AVD-AWS-0052: Load balancers should drop invalid headers
Passing unknown or invalid headers through to the target poses a potential risk of compromise.
|
Parse scan results
AVD-AWS-0053: Load balancer is exposed to the internet.
There are many scenarios in which you would want to expose a load balancer to the wider internet, but this check exists as a warning to prevent accidental exposure of internal assets. You should ensure that this resource should be exposed publicly.
|
Parse scan results:
main.tf#L37
AVD-AWS-0005: API Gateway domain name uses outdated SSL/TLS protocols.
You should not use outdated/insecure TLS versions for encryption. You should be using TLS v1.2+.
|
Parse scan results:
main.tf#L33
AVD-AWS-0005: API Gateway domain name uses outdated SSL/TLS protocols.
You should not use outdated/insecure TLS versions for encryption. You should be using TLS v1.2+.
|
Parse scan results:
main.tf#L41
AVD-AWS-0005: API Gateway domain name uses outdated SSL/TLS protocols.
You should not use outdated/insecure TLS versions for encryption. You should be using TLS v1.2+.
|
Parse scan results:
main.tf#L18
AVD-AWS-0054: Use of plain HTTP.
Plain HTTP is unencrypted and human-readable. This means that if a malicious actor was to eavesdrop on your connection, they would be able to see all of your data flowing back and forth.
|
Parse scan results:
main.tf#L29
AVD-AZU-0038: Enable disk encryption on managed disk
Manage disks should be encrypted at rest. When specifying the <code>encryption_settings</code> block, the enabled attribute should be set to <code>true</code>.
|
Parse scan results
Process completed with exit code 1.
|
Loading