-
Notifications
You must be signed in to change notification settings - Fork 347
fix(query): adding missing function_app resources to terraform/azure queries #7744
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
cx-andre-pereira
merged 21 commits into
master
from
AST-114931-FN-Missing_resources_for_terraform_azure_queries_2_function_apps
Oct 13, 2025
Merged
fix(query): adding missing function_app resources to terraform/azure queries #7744
cx-andre-pereira
merged 21 commits into
master
from
AST-114931-FN-Missing_resources_for_terraform_azure_queries_2_function_apps
Oct 13, 2025
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
…orm_azure_queries_2_function_apps
…14931-FN-Missing_resources_for_terraform_azure_queries_2_function_apps
…ries_2_function_apps' of https://github.com/Checkmarx/kics into AST-114931-FN-Missing_resources_for_terraform_azure_queries_2_function_apps
…orm_azure_queries_2_function_apps
…orm_azure_queries_2_function_apps
…orm_azure_queries_2_function_apps
…orm_azure_queries_2_function_apps
cx-artur-ribeiro
approved these changes
Oct 13, 2025
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Great work André, LGTM!
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Closes #6927
Reason for Proposed Changes
(Queries 1-4 are handled in the "parent" Pull Request where this issue was first handled for some similar "azurerm_app_service" resource related queries)
Proposed Changes
✅Function App Not Using Latest TLS Encryption Version
✅Function App Managed Identity Disabled
✅Function App HTTP2 Disabled
✅Function App FTPS Enforce Disabled
✅Function App Client Certificates Unrequired
✅Function App Authentication Disabled
types
array to include the relevant resource types. For details on the analog's implementation : PR7591 and PR7715. Simply put the older resource only has the "auth_settings" field to check while the newly supported ones have that same resource plus the new "auth_settings_v2", and both can be defined concurrently in which case the v2 takes precedence, so the logic for the query and the tests had to be more complex/comprehensive overall.Final Note : So as to follow inline with #7759 plenty of
!= ""
and analog!= "none"
needless bits of query logic have been removed in d2037b0.I submit this contribution under the Apache-2.0 license.