Azure / Azure/Azure-Verified-Modules

AzAdvertizer data changes detected

Open
#2,580 1 comment 0 reactions 0 assignees View on GitHub
Needs: Triage :mag:
Dominant language
PowerShell
Stars
580
Forks
161
Avg merge
11h 3m
Merged PRs (30d)
15

Description

Azure Advertizer Data Diff Report

Resource Type: microsoft.network/azurefirewalls
--------------------------------------------------
New APRL Recommendations:
- [Monitor "AZFW Latency Probe" metric](https://azure.github.io/Azure-Proactive-Resiliency-Library-v2/azure-resources/Network/azureFirewalls/#monitor-azfw-latency-probe-metric)

Resource Type: microsoft.security/awsresource
--------------------------------------------------
New Advisor Recommendations:
- [Avoid the use of the "root" account](https://portal.azure.com/#view/Microsoft_Azure_Expert/RecommendationList.ReactView/recommendationTypeId/a47a6c3b-0629-406c-ad09-d91f7d9f78a3)
- [IAM policies that allow full "*:*" administrative privileges should not be created](https://portal.azure.com/#view/Microsoft_Azure_Expert/RecommendationList.ReactView/recommendationTypeId/1d08b362-7e24-46b0-bed1-4a6c1d1526a5)
- [Public access restrictions should be configured for CodeArtifact repositories](https://portal.azure.com/#view/Microsoft_Azure_Expert/RecommendationList.ReactView/recommendationTypeId/e050ba79-f615-470c-986c-752dd19b9137)
- [Strong authentication should be enabled on CodePipeline Webhook configuration](https://portal.azure.com/#view/Microsoft_Azure_Expert/RecommendationList.ReactView/recommendationTypeId/88a4692f-9255-4585-9e31-3ef630622059)
- [Public access restrictions should be configured for CodeArtifact domains](https://portal.azure.com/#view/Microsoft_Azure_Expert/RecommendationList.ReactView/recommendationTypeId/441eb484-e870-40ab-a533-87291de6c59f)
- [Restrictions for transitive external package ingestion should be enabled on CodeArtifact repositories](https://portal.azure.com/#view/Microsoft_Azure_Expert/RecommendationList.ReactView/recommendationTypeId/de81d052-52d6-4414-b24f-6fcd807bbab3)
- [Public network access should be disabled for LightSail Relational Database Service](https://portal.azure.com/#view/Microsoft_Azure_Expert/RecommendationList.ReactView/recommendationTypeId/a5797112-60f7-4c2b-99ac-e6de00e758ea)
- [High privilege permission set assignments should be restricted on AWS SSO](https://portal.azure.com/#view/Microsoft_Azure_Expert/RecommendationList.ReactView/recommendationTypeId/812e1796-a611-4643-a108-f8d215c49d8e)
- [Public access for publishers should be disabled on Amazon SNS topics](https://portal.azure.com/#view/Microsoft_Azure_Expert/RecommendationList.ReactView/recommendationTypeId/d7effe85-e3d7-4cd0-8e56-17f714cb500a)
- [Public access for subscribers should be disabled on Amazon SNS topic](https://portal.azure.com/#view/Microsoft_Azure_Expert/RecommendationList.ReactView/recommendationTypeId/bde46d3a-9640-41a3-9a5d-c84b595d8547)

Contributor guide

No contributing guide indexed for this repository

Research direction

The issue is an AzAdvertizer data-diff report covering Azure Firewall and AWS-related recommendations, but it names no repository files, tests, or entry point. Review how these recommendations are represented in Azure-Verified-Modules and determine the expected update and acceptance criteria before starting; the report itself does not define what done looks like.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, azure
Domain
cloud, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.