fix(queries): fixed fp for trusted_microsoft_services_not_enabled and default_azure_storage_account_network_access_is_too_permissive #7678
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Closes #
Reason for Proposed Changes
network_rules
is not defined, it returns a positive result but that should not happen when the resource is a function app (i.e., tagbdo-attached-service
set to"function"
) for theazurerm_storage_account
.public_network_access_enabled
is set totrue
.Proposed Changes
is_function_app
that checks if a resource is a function app by checking the tags.not is_function_app(resource)
) before returning a positive result when the fieldpublic_network_access_enabled
is set totrue
.I submit this contribution under the Apache-2.0 license.