Repository navigation
fix(query): changed all dockerfile queries for case insensitive support of dockerfile commands - #8006
Closed
cx-andre-pereira wants to merge 197 commits into
Closed
cx-andre-pereira wants to merge 197 commits into
cx-andre-pereira wants to merge 197 commits into
Conversation
cx-andre-pereira
marked this pull request as ready for review
April 2, 2026 11:31
cx-andre-pereira
force-pushed
the
Dockerfile_queries_fix_for_case_insensitivity
branch
from
April 7, 2026 22:28
db1b7e2 to
47b647e
Compare
cx-andre-pereira
force-pushed
the
Dockerfile_queries_fix_for_case_insensitivity
branch
from
July 8, 2026 13:50
c705f07 to
a500e92
Compare
…or multiple volumes cases (Checkmarx#7947) * fix EFS Volume With Disabled Transit Encryption query for multiple volumes cases in tf and cf * update: dockerfile images
…x#7997) * add bad utf conversions to unwanted in analyzer * add bad utf conversions to unwanted in analyzer * update e2e tests and uts to cover valid ansible samples * update base images --------- Co-authored-by: cx-miguel-silva <100352574+cx-miguel-silva@users.noreply.github.com>
Updated Trivy action version from v0.34.2 to v0.35.0 in both scanning steps.
* update: login to DockerHub to token * bump: kics github action version
* add arm64 testing infra * add arm64 testing infra * bump images * ci * update e2e infra * update e2e infra * improve docker ubi 8 to support arm * improve docker ubi 8 to support arm * improve docker ubi 8 to support arm * improve docker ubi 8 to support arm * fix vulnerabilities * fix vulnerabilities * fix vulnerabilities * fix vulnerabilities * fix vulnerabilities --------- Co-authored-by: cx-miguel-silva <100352574+cx-miguel-silva@users.noreply.github.com> Co-authored-by: Artur Ribeiro <153724638+cx-artur-ribeiro@users.noreply.github.com>
Checkmarx#7955) * first commit * rewrite previous changes * causing remediation error on purpose * some changes * . * . * added remediatedFiles to error output in remediation tests * restored directories removed by mistake * removed files * Delete assets/queries/terraform/aws/api_gateway_access_logging_disabled/payloads/all_payloads.json * Delete assets/queries/terraform/aws/sns_topic_is_publicly_accessible/payloads/all_payloads.json * Delete assets/queries/terraform/aws/sns_topic_is_publicly_accessible/payloads directory * Delete assets/queries/terraform/aws/sns_topic_is_publicly_accessible/samples/sample.tf * Delete assets/queries/terraform/gcp/ensure_essential_contacts_is_configured_for_organization/payloads/all_payloads.json * Delete assets/queries/terraform/gcp/ensure_essential_contacts_is_configured_for_organization/payloads directory * Delete assets/queries/terraform/gcp/ensure_gke_version_management_is_automated_using_release_channels/payloads/all_payloads.json * Delete assets/queries/terraform/gcp/ensure_gke_version_management_is_automated_using_release_channels/payloads directory * Delete assets/queries/terraform/gcp/google_kubernetes_engine_cluster_have_alpha_features_enabled/payloads/all_payloads.json * Delete assets/queries/terraform/gcp/legacy_networks_do_not_exist_for_older_google_projects/payloads/test_payload.json * Delete assets/queries/terraform/gcp/legacy_networks_do_not_exist_for_older_google_projects/payloads directory * Delete assets/queries/terraform/gcp/logs_and_alerts_missing_audit_configuration_changes/payloads/all_payloads.json * Delete assets/queries/terraform/gcp/logs_and_alerts_missing_audit_configuration_changes/payloads directory * Delete assets/queries/terraform/gcp/logs_and_alerts_missing_custom_role_changes/test/test.tf * Delete assets/queries/terraform/gcp/logs_and_alerts_missing_custom_role_changes/payloads directory * Delete assets/queries/terraform/gcp/logs_and_alerts_missing_project_ownership_assignment_and_changes/payloads/positive1_payload.json * Delete assets/queries/terraform/gcp/logs_and_alerts_missing_project_ownership_assignment_and_changes/payloads directory * Delete assets/queries/terraform/gcp/shielded_gke_node_do_not_have_integrity_monitoring_enabled/payloads/all_payloads.json * Delete assets/queries/terraform/gcp/shielded_gke_node_do_not_have_integrity_monitoring_enabled/payloads directory * Delete assets/queries/terraform/gcp/sql_db_instance_external_scripts_enabled/test/negative.tf * Delete assets/queries/terraform/gcp/sql_db_instance_external_scripts_enabled/test directory * Delete assets/queries/terraform/gcp/sql_db_instance_external_scripts_enabled directory * added remediation problems to the query * fixed golint problems * golint * change on the query * fixing line that surpasses the 140 characters limits by go-ci/lint * . * changed e2e test to see HTML results output * . * . * . * removed one query in the results * indenting json output on E2E test HTML report * changed fixture results * changed comparison using listA and list B, to Expected and Actual lists * some changes on the json output * reverted changes on E2E results outputs * put listA and listB side by side * fully implemented red line for diff line * added queryName in the output * final improvement on HTML E2E test results output * removed unnecessary comment * revert changes made on E2E fixtures * reverted changes on E2E files * reverted changes on E2E files * reverted changes on the wrong go template file * fixing go lint errors * fixing go lint error * go lint error fixing * go lint error fixing * go lint error fixing * fixing go lint errors * fixing go lint errors * fixing go lint errors * fixing go lint errors * fixing go lint errors * fixing go lint errors * keeping up with the codacy quality standards * improvements on the code * trimmed lines before direct comparisons * adding the e2e-report file again * changing google.golang.org/grpc version from 1.77.0 to 1.79.3 * fixed analyze command in e2e test * covered FileStats field comparison on e2e tests * reverting changes made on analyze.go file * changed moby/buildkit version from 0.26.3 to 0.28.1 * revert changes * changed moby/buildkit version from 0.26.3 to 0.28.1 * fixing unproperly formatted code * fixed path * fixed unproperly formatted code * removed commented code * fixed some E2E tests not showing the intended output format * final fix for the tests that are currently without the proper HTML report output format * changing code to reduce cyclomatic complexity * fixing code to be properly formatted * removed unnecessary printf's * fixing the code using gofmt * changed github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream and github.com/aws/aws-sdk-go-v2/service/s3 version in go.mod --------- Co-authored-by: Artur Ribeiro <153724638+cx-artur-ribeiro@users.noreply.github.com>
* Update github action to use SHA * Update vulnerable dependency * Update dockerfiles to use go 1.26.2 * Rollback go.mod to 1.25.5 * Fix vulnerabilities * Fix vulnerabilities * Update go version * Suppress vulnerability * Update dockerfile * Update .grype.yaml Co-authored-by: Rui Araújo Gomes <110477212+cx-rui-araujo@users.noreply.github.com> * Small update --------- Co-authored-by: Rui Araújo Gomes <110477212+cx-rui-araujo@users.noreply.github.com>
…marx#7994) * changed go-ci.yml to use a script to check searchLine * . * fixed print to not use f when is missing placeholders * removed unnecessary action * fixed typo * fixing issues from codacy * updated go image in Dockerfile * update go images * changed git image * changing positive expected results * added requests to requirements file * changed searchLine to get -1 value * added debug prints * added exception type * fixing error in script * removed trailing whitespace * changed to run the other script * debugging test directory path * changed scripts that run on the action * removed f-string without placeholders * inverted changes on the query * changed positive_expected_result * changed filename to fileName * added print for debugging processes * added print to see content value * changed script * testing searchLine != searchLine * removed unnecessary sorting on the results in execution context * removed unused requirements.txt file * reverter changes on positie_expected_results * changes on the script and removed unnecessary go setup * changed query to get errors on go-ci action * parsing json data into objects * small change to test if this is the root of the problem * reverted changes * fixing misspelled directory name * fixing some errors in the script used in the validate-search-line job in go-ci action * fixed misspelled field in validate_scan_results function * simplifying code * using pymarshal to use models that unmarshal json content directly * fixing errors in results_models pymarshal import * testing searchLine defined to '-1' hardcoded value * convert line and searchLine to int * adding print's for debug purposes * adding print's for debug purposes * fixing cases where searchLine is defined to an hardcoded value of -1 * added prints for debug purposes * debug prints * debug prints * debug prints * changes for debug purposes * . * changes * trying to fix cases with -1 hardcoded on searchLine * changes * more changes * trying type_assert * trying type_assert * trying type_assert * trying type_assert * trying type_assert * testing new scenario * testing test3 case from artur test branch * testing test3 case from artur test branch * back to the other scenario * back to the other scenario again * used unmarshal_json from pumarshal to unmarshal the json with the results * testing hardcoded .1 again * trying case - common_lib.build_search_line([shdfosdhfoisdhf], []), * reverting changes on dockerfiles * removed the usage of type_assert to be more permissive about fields not defined on the results file * changed to see other case output in the actions * added field queries_failed_to_execute * changing query searchLine field to test another scenario * changed to another scenario * reverting changes made on the query * changed to test scenario when "searchLine": common_lib.build_search_line(["potatos"], []) * testing scenario where searchLine is defined to '-1' * removed unnecessary pymarshal pip instalation * testing another scenario * testing searchLine defined to '-1' * testing searchLine defined to 'potatos' * reverting query changezs * reverting changes on query * reverting changes on docker files * reverting changes on dockerfiles * removed \n * adding debug prints to see the output from variables produced by dorny/path * added \n * added echo for debug purposes * Reverting changes on Dockerfile * adding print on script * testing outcome * using Set Up python step outcome value to define if validate search line in modified queries runs or not * changing go-jose version * changing script code to match Codacy best practices * changing code to comply with the Codacy quality standards * changing go.mod * fixing Codacy issues * changing Go and Git images on Dockerfile * changing go.mod * reverting changes on go.mod * changing go version * fixing scripts according to Codacy issues * fixing script to be up to the Codacy quality standards * fixing Codacy issues * fixing Codacy issues * fixing Codacy issues * fixing D212 in validate_search_line.py file * reverting changes to fix D212 --------- Co-authored-by: Artur Ribeiro <153724638+cx-artur-ribeiro@users.noreply.github.com>
* Change to use actions role * Update run-projects.yaml
* ci: fix aws secrets * ci: fix permissions * ci: remove audience * ci: test gh token * ci: use sha
…n" CloudFormation and Terraform queries (Checkmarx#8030) * Added missing check/associated tests to cloudFormation and Terraform iam_policy data exfiltration queries --------- Co-authored-by: Artur Ribeiro <153724638+cx-artur-ribeiro@users.noreply.github.com>
Signed-off-by: StepSecurity Bot <bot@stepsecurity.io> Co-authored-by: stepsecurity-app[bot] <188008098+stepsecurity-app[bot]@users.noreply.github.com>
Signed-off-by: StepSecurity Bot <bot@stepsecurity.io> Co-authored-by: stepsecurity-app[bot] <188008098+stepsecurity-app[bot]@users.noreply.github.com>
Signed-off-by: Yevgeny Kuznetsov <yevgeny.kuznetsov@checkmarx.com>
…Checkmarx#8076) * update: dockerfile and fix vulnerabilities * update: dockerfile with arguments before both FROM for universal scope * update: vulnerable packages and dockerfile images * ci: trigger * fix: dockerfile deprecation notice for LegacyKeyValueFormat
…xclusion based regex
…ine FROM statements are compatible, fixed whitespace support for ARG/comments in dockerfiles and fix new E2E results
* fix insecure temp file * fix insecure temp file perms * add path traversal sanitation * add path traversal sanitization * add path traversal sanitization tests * add path traversal sanitization e2e tests * add path traversal sanitization e2e tests * fix lint issues * fix secrets inspector possible resource exhaustion * fix secrets line detection for end of document specific case * bump deps and actions versions * bump deps and actions versions * [StepSecurity] Apply security best practices (Checkmarx#8060) Signed-off-by: StepSecurity Bot <bot@stepsecurity.io> Co-authored-by: stepsecurity-app[bot] <188008098+stepsecurity-app[bot]@users.noreply.github.com> * [StepSecurity] Apply security best practices (Checkmarx#8063) Signed-off-by: StepSecurity Bot <bot@stepsecurity.io> Co-authored-by: stepsecurity-app[bot] <188008098+stepsecurity-app[bot]@users.noreply.github.com> * chore: remove Dependabot configuration * Remove old SBOM (Checkmarx#8071) Signed-off-by: Yevgeny Kuznetsov <yevgeny.kuznetsov@checkmarx.com> * fix(vulnerabilities): update dockerfile and fix trivy vulnerabilities (Checkmarx#8076) * update: dockerfile and fix vulnerabilities * update: dockerfile with arguments before both FROM for universal scope * update: vulnerable packages and dockerfile images * ci: trigger * fix: dockerfile deprecation notice for LegacyKeyValueFormat --------- Signed-off-by: StepSecurity Bot <bot@stepsecurity.io> Signed-off-by: Yevgeny Kuznetsov <yevgeny.kuznetsov@checkmarx.com> Co-authored-by: cx-miguel-silva <100352574+cx-miguel-silva@users.noreply.github.com> Co-authored-by: stepsecurity-app[bot] <188008098+stepsecurity-app[bot]@users.noreply.github.com> Co-authored-by: Ohad Israeli <243351248+cx-ohad-israeli@users.noreply.github.com> Co-authored-by: Yevgeny Kuznetsov <yevgeny.kuznetsov@checkmarx.com> Co-authored-by: Artur Ribeiro <153724638+cx-artur-ribeiro@users.noreply.github.com>
…ng (Checkmarx#8085) * fixs for ast 154904, loop on RUN commands and 2 unrelated queries changed * Fixed unnecessary space affecting distance calculation/ line in vulnerability result * Update packages again
…ry to handle 'require_ssl' field deprecation (Checkmarx#8029) * First commit: udpated query to handle deprecation of 'require_ssl' field, support for all 'ssl_mode' field values, new tests and metadata Url updated * Small change to comments for consistency sake * New samples and auxiliary functions to properly handle SQLSERVER databases (do not support 'TRUSTED_CLIENT_CERTIFICATE_REQUIRED' value * Expected values and some test changes * Fix expected results again --------- Co-authored-by: Alon Rosenhek <80337069+cx-alon-rosenhek@users.noreply.github.com>
… accounting for specific digest values (Checkmarx#8033) * Fix check for ':latest' to ensure it is used as a sufix on the image reference (no @sha...) * feat(tests): improving E2E HTML report and output on remediation tests (Checkmarx#7955) * first commit * rewrite previous changes * causing remediation error on purpose * some changes * . * . * added remediatedFiles to error output in remediation tests * restored directories removed by mistake * removed files * Delete assets/queries/terraform/aws/api_gateway_access_logging_disabled/payloads/all_payloads.json * Delete assets/queries/terraform/aws/sns_topic_is_publicly_accessible/payloads/all_payloads.json * Delete assets/queries/terraform/aws/sns_topic_is_publicly_accessible/payloads directory * Delete assets/queries/terraform/aws/sns_topic_is_publicly_accessible/samples/sample.tf * Delete assets/queries/terraform/gcp/ensure_essential_contacts_is_configured_for_organization/payloads/all_payloads.json * Delete assets/queries/terraform/gcp/ensure_essential_contacts_is_configured_for_organization/payloads directory * Delete assets/queries/terraform/gcp/ensure_gke_version_management_is_automated_using_release_channels/payloads/all_payloads.json * Delete assets/queries/terraform/gcp/ensure_gke_version_management_is_automated_using_release_channels/payloads directory * Delete assets/queries/terraform/gcp/google_kubernetes_engine_cluster_have_alpha_features_enabled/payloads/all_payloads.json * Delete assets/queries/terraform/gcp/legacy_networks_do_not_exist_for_older_google_projects/payloads/test_payload.json * Delete assets/queries/terraform/gcp/legacy_networks_do_not_exist_for_older_google_projects/payloads directory * Delete assets/queries/terraform/gcp/logs_and_alerts_missing_audit_configuration_changes/payloads/all_payloads.json * Delete assets/queries/terraform/gcp/logs_and_alerts_missing_audit_configuration_changes/payloads directory * Delete assets/queries/terraform/gcp/logs_and_alerts_missing_custom_role_changes/test/test.tf * Delete assets/queries/terraform/gcp/logs_and_alerts_missing_custom_role_changes/payloads directory * Delete assets/queries/terraform/gcp/logs_and_alerts_missing_project_ownership_assignment_and_changes/payloads/positive1_payload.json * Delete assets/queries/terraform/gcp/logs_and_alerts_missing_project_ownership_assignment_and_changes/payloads directory * Delete assets/queries/terraform/gcp/shielded_gke_node_do_not_have_integrity_monitoring_enabled/payloads/all_payloads.json * Delete assets/queries/terraform/gcp/shielded_gke_node_do_not_have_integrity_monitoring_enabled/payloads directory * Delete assets/queries/terraform/gcp/sql_db_instance_external_scripts_enabled/test/negative.tf * Delete assets/queries/terraform/gcp/sql_db_instance_external_scripts_enabled/test directory * Delete assets/queries/terraform/gcp/sql_db_instance_external_scripts_enabled directory * added remediation problems to the query * fixed golint problems * golint * change on the query * fixing line that surpasses the 140 characters limits by go-ci/lint * . * changed e2e test to see HTML results output * . * . * . * removed one query in the results * indenting json output on E2E test HTML report * changed fixture results * changed comparison using listA and list B, to Expected and Actual lists * some changes on the json output * reverted changes on E2E results outputs * put listA and listB side by side * fully implemented red line for diff line * added queryName in the output * final improvement on HTML E2E test results output * removed unnecessary comment * revert changes made on E2E fixtures * reverted changes on E2E files * reverted changes on E2E files * reverted changes on the wrong go template file * fixing go lint errors * fixing go lint error * go lint error fixing * go lint error fixing * go lint error fixing * fixing go lint errors * fixing go lint errors * fixing go lint errors * fixing go lint errors * fixing go lint errors * fixing go lint errors * keeping up with the codacy quality standards * improvements on the code * trimmed lines before direct comparisons * adding the e2e-report file again * changing google.golang.org/grpc version from 1.77.0 to 1.79.3 * fixed analyze command in e2e test * covered FileStats field comparison on e2e tests * reverting changes made on analyze.go file * changed moby/buildkit version from 0.26.3 to 0.28.1 * revert changes * changed moby/buildkit version from 0.26.3 to 0.28.1 * fixing unproperly formatted code * fixed path * fixed unproperly formatted code * removed commented code * fixed some E2E tests not showing the intended output format * final fix for the tests that are currently without the proper HTML report output format * changing code to reduce cyclomatic complexity * fixing code to be properly formatted * removed unnecessary printf's * fixing the code using gofmt * changed github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream and github.com/aws/aws-sdk-go-v2/service/s3 version in go.mod --------- Co-authored-by: Artur Ribeiro <153724638+cx-artur-ribeiro@users.noreply.github.com> * fix(workflows): update github actions to use SHA (Checkmarx#8035) * Update github action to use SHA * Update vulnerable dependency * Update dockerfiles to use go 1.26.2 * Rollback go.mod to 1.25.5 * Fix vulnerabilities * Fix vulnerabilities * Update go version * Suppress vulnerability * Update dockerfile * Update .grype.yaml Co-authored-by: Rui Araújo Gomes <110477212+cx-rui-araujo@users.noreply.github.com> * Small update --------- Co-authored-by: Rui Araújo Gomes <110477212+cx-rui-araujo@users.noreply.github.com> * feat(action): added validation for searchLine field in actions (Checkmarx#7994) * changed go-ci.yml to use a script to check searchLine * . * fixed print to not use f when is missing placeholders * removed unnecessary action * fixed typo * fixing issues from codacy * updated go image in Dockerfile * update go images * changed git image * changing positive expected results * added requests to requirements file * changed searchLine to get -1 value * added debug prints * added exception type * fixing error in script * removed trailing whitespace * changed to run the other script * debugging test directory path * changed scripts that run on the action * removed f-string without placeholders * inverted changes on the query * changed positive_expected_result * changed filename to fileName * added print for debugging processes * added print to see content value * changed script * testing searchLine != searchLine * removed unnecessary sorting on the results in execution context * removed unused requirements.txt file * reverter changes on positie_expected_results * changes on the script and removed unnecessary go setup * changed query to get errors on go-ci action * parsing json data into objects * small change to test if this is the root of the problem * reverted changes * fixing misspelled directory name * fixing some errors in the script used in the validate-search-line job in go-ci action * fixed misspelled field in validate_scan_results function * simplifying code * using pymarshal to use models that unmarshal json content directly * fixing errors in results_models pymarshal import * testing searchLine defined to '-1' hardcoded value * convert line and searchLine to int * adding print's for debug purposes * adding print's for debug purposes * fixing cases where searchLine is defined to an hardcoded value of -1 * added prints for debug purposes * debug prints * debug prints * debug prints * changes for debug purposes * . * changes * trying to fix cases with -1 hardcoded on searchLine * changes * more changes * trying type_assert * trying type_assert * trying type_assert * trying type_assert * trying type_assert * testing new scenario * testing test3 case from artur test branch * testing test3 case from artur test branch * back to the other scenario * back to the other scenario again * used unmarshal_json from pumarshal to unmarshal the json with the results * testing hardcoded .1 again * trying case - common_lib.build_search_line([shdfosdhfoisdhf], []), * reverting changes on dockerfiles * removed the usage of type_assert to be more permissive about fields not defined on the results file * changed to see other case output in the actions * added field queries_failed_to_execute * changing query searchLine field to test another scenario * changed to another scenario * reverting changes made on the query * changed to test scenario when "searchLine": common_lib.build_search_line(["potatos"], []) * testing scenario where searchLine is defined to '-1' * removed unnecessary pymarshal pip instalation * testing another scenario * testing searchLine defined to '-1' * testing searchLine defined to 'potatos' * reverting query changezs * reverting changes on query * reverting changes on docker files * reverting changes on dockerfiles * removed \n * adding debug prints to see the output from variables produced by dorny/path * added \n * added echo for debug purposes * Reverting changes on Dockerfile * adding print on script * testing outcome * using Set Up python step outcome value to define if validate search line in modified queries runs or not * changing go-jose version * changing script code to match Codacy best practices * changing code to comply with the Codacy quality standards * changing go.mod * fixing Codacy issues * changing Go and Git images on Dockerfile * changing go.mod * reverting changes on go.mod * changing go version * fixing scripts according to Codacy issues * fixing script to be up to the Codacy quality standards * fixing Codacy issues * fixing Codacy issues * fixing Codacy issues * fixing D212 in validate_search_line.py file * reverting changes to fix D212 --------- Co-authored-by: Artur Ribeiro <153724638+cx-artur-ribeiro@users.noreply.github.com> * Change to use actions role (Checkmarx#8040) * Change to use actions role * Update run-projects.yaml * ci(secrets): use aws oidc (Checkmarx#8041) * ci: fix aws secrets * ci: fix permissions * ci: remove audience * ci: test gh token * ci: use sha * fix(query): fix FP results on "IAM policy allows for data exfiltration" CloudFormation and Terraform queries (Checkmarx#8030) * Added missing check/associated tests to cloudFormation and Terraform iam_policy data exfiltration queries --------- Co-authored-by: Artur Ribeiro <153724638+cx-artur-ribeiro@users.noreply.github.com> * [StepSecurity] Apply security best practices (Checkmarx#8060) Signed-off-by: StepSecurity Bot <bot@stepsecurity.io> Co-authored-by: stepsecurity-app[bot] <188008098+stepsecurity-app[bot]@users.noreply.github.com> * [StepSecurity] Apply security best practices (Checkmarx#8063) Signed-off-by: StepSecurity Bot <bot@stepsecurity.io> Co-authored-by: stepsecurity-app[bot] <188008098+stepsecurity-app[bot]@users.noreply.github.com> * chore: remove Dependabot configuration * Remove old SBOM (Checkmarx#8071) Signed-off-by: Yevgeny Kuznetsov <yevgeny.kuznetsov@checkmarx.com> * fix(vulnerabilities): update dockerfile and fix trivy vulnerabilities (Checkmarx#8076) * update: dockerfile and fix vulnerabilities * update: dockerfile with arguments before both FROM for universal scope * update: vulnerable packages and dockerfile images * ci: trigger * fix: dockerfile deprecation notice for LegacyKeyValueFormat * bug(security): fix security vulnerability findings (Checkmarx#8084) * fix insecure temp file * fix insecure temp file perms * add path traversal sanitation * add path traversal sanitization * add path traversal sanitization tests * add path traversal sanitization e2e tests * add path traversal sanitization e2e tests * fix lint issues * fix secrets inspector possible resource exhaustion * fix secrets line detection for end of document specific case * bump deps and actions versions * bump deps and actions versions * [StepSecurity] Apply security best practices (Checkmarx#8060) Signed-off-by: StepSecurity Bot <bot@stepsecurity.io> Co-authored-by: stepsecurity-app[bot] <188008098+stepsecurity-app[bot]@users.noreply.github.com> * [StepSecurity] Apply security best practices (Checkmarx#8063) Signed-off-by: StepSecurity Bot <bot@stepsecurity.io> Co-authored-by: stepsecurity-app[bot] <188008098+stepsecurity-app[bot]@users.noreply.github.com> * chore: remove Dependabot configuration * Remove old SBOM (Checkmarx#8071) Signed-off-by: Yevgeny Kuznetsov <yevgeny.kuznetsov@checkmarx.com> * fix(vulnerabilities): update dockerfile and fix trivy vulnerabilities (Checkmarx#8076) * update: dockerfile and fix vulnerabilities * update: dockerfile with arguments before both FROM for universal scope * update: vulnerable packages and dockerfile images * ci: trigger * fix: dockerfile deprecation notice for LegacyKeyValueFormat --------- Signed-off-by: StepSecurity Bot <bot@stepsecurity.io> Signed-off-by: Yevgeny Kuznetsov <yevgeny.kuznetsov@checkmarx.com> Co-authored-by: cx-miguel-silva <100352574+cx-miguel-silva@users.noreply.github.com> Co-authored-by: stepsecurity-app[bot] <188008098+stepsecurity-app[bot]@users.noreply.github.com> Co-authored-by: Ohad Israeli <243351248+cx-ohad-israeli@users.noreply.github.com> Co-authored-by: Yevgeny Kuznetsov <yevgeny.kuznetsov@checkmarx.com> Co-authored-by: Artur Ribeiro <153724638+cx-artur-ribeiro@users.noreply.github.com> * Requested change * update images and pacakges for vulnerabilities * bump compress to 1.18.7 --------- Signed-off-by: StepSecurity Bot <bot@stepsecurity.io> Signed-off-by: Yevgeny Kuznetsov <yevgeny.kuznetsov@checkmarx.com> Co-authored-by: Ricardo Jesus <219317970+cx-ricardo-jesus@users.noreply.github.com> Co-authored-by: Artur Ribeiro <153724638+cx-artur-ribeiro@users.noreply.github.com> Co-authored-by: Bruno Silva <73999905+cx-bruno-silva@users.noreply.github.com> Co-authored-by: Rui Araújo Gomes <110477212+cx-rui-araujo@users.noreply.github.com> Co-authored-by: João Reigota <74597872+cx-joao-reigota@users.noreply.github.com> Co-authored-by: Rafael Carvalho <153817659+cx-rafael-carvalho@users.noreply.github.com> Co-authored-by: stepsecurity-app[bot] <188008098+stepsecurity-app[bot]@users.noreply.github.com> Co-authored-by: Ohad Israeli <243351248+cx-ohad-israeli@users.noreply.github.com> Co-authored-by: Yevgeny Kuznetsov <yevgeny.kuznetsov@checkmarx.com> Co-authored-by: Miguel da Silva <100352574+cx-miguel-dasilva@users.noreply.github.com> Co-authored-by: cx-miguel-silva <100352574+cx-miguel-silva@users.noreply.github.com>
…/cicd (Checkmarx#8089) * added coverage for github.event.comment.user.login in issue_comment event type * added coverage for some pattern in push events in Run Block Injection query * added coverage for some pattern in push events in Script Block Injection query * added pattern that was only covered by the run block injection query
…Checkmarx#8087) * added new case on the negative tests * updating query --------- Co-authored-by: Alon Rosenhek <80337069+cx-alon-rosenhek@users.noreply.github.com>
…kerfile (Checkmarx#8090) * solved specific FP for RUN commands with multiple flags with arguments * added new test samples * covered the scenarios where there is a RUN command with a list
cx-andre-pereira
force-pushed
the
Dockerfile_queries_fix_for_case_insensitivity
branch
from
July 28, 2026 17:28
aaadece to
d10f038
Compare
…://github.com/cx-andre-pereira/kics into Dockerfile_queries_fix_for_case_insensitivity
This was referenced Sep 8, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Reason for Proposed Changes
The changes from #7995 (included in this PR) enable scanned Dockerfiles to recognize valid case-insensitive syntax. However, none of the existing Dockerfile queries were prepared for this — all of them contain hardcoded uppercase references to Docker commands.
Additionally, testing revealed that the existing query logic, payload generation, and engine line-searching logic did not support multiple
FROMstatements associated with the same image within a single document. In such cases, only the firstFROMstatement would produce results; the engine was unable to flag any subsequent occurrences.Proposed Changes
New auxiliary functions
Two new helper functions were added to the common library
dockerfile.rego:get_original_from_command— Extracts theFROMcommand with its original casing along with theLineHintvalue for that command.add_line_hint— Appends the extractedLineHintto the string using^as a separator.The
LineHintvalue enables the engine to distinguish between multipleFROMstatements referencing the same image.Query updates
searchKeyvalue. On the engine side, preserving the original casing ofFROMenables more precise searching through the source file. TheLineHintvalue is consumed bydocker_detectand stripped by thevulnerability_builderbefore results are emitted.Parser changes
FROMstatement generates a distinct object. Previously, allFROMcommands referencing the same image were merged into a single object.Test coverage
A new positive and negative sample was added to every test folder. These mirror the existing
positive/positive1andnegative/negative1tests but use all-lowercase commands.A new E2E test (107) was added, it tests that the payload/results of a scan on a multistage dockerfile sample with duplicate
FROMstatements is parsed/flagged as expected.New test based on
OriginalData4added to the docker_detect_test file, also checks that a multistage sample with duplicateFROMstatements flags properly.TestDockerSearchKeyLineHintRemovalwas added to the vulnerability_builder_test file, as the name implies it checks that theLineHintappended to the searchKey value of a sample dockefile query is removed properly.Updated Documentation/Script
searchKeyvalue attribution.validate_search_line.pyCI script was updated to account for the fact that Dockerfile queries do not currently supportsearchLinevalues. The script now excludes all queries under thedockerfilequeries folder.I submit this contribution under the Apache-2.0 license.