aquasecurity / aquasecurity/cloudsploit
CIS compliance flag for Azure scan is not identifying any API calls
Open
- Dominant language
- JavaScript
- Stars
- 3.8k
- Forks
- 751
- Avg merge
- 11d 9h
- Merged PRs (30d)
- 3
Description
When using the `--compliance=cis2` or `--compliance=cis1` or `--compliance=cis` for Azure, I am getting following error:
ERROR: Nothing to collect.
Contributor guide
Research direction
Start by reproducing the Azure scan with --compliance=cis2, --compliance=cis1, and --compliance=cis, then trace why collection reports “Nothing to collect.” Review the Azure compliance collection entry points and confirm the fix causes the CIS scans to identify their API calls.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- azure, javascript
- Domain
- cloud, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100