<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Code Security: Policy Ids for Errors in Prisma Cloud Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/code-security-policy-ids-for-errors/m-p/541587#M941</link>
    <description>&lt;P&gt;A policy ID like "&lt;SPAN&gt;8060797_AWS_1672940525627&lt;/SPAN&gt;" is the format of a custom build policy (CCS). Maybe a clone of the OOTB policy?&lt;/P&gt;</description>
    <pubDate>Tue, 09 May 2023 15:44:12 GMT</pubDate>
    <dc:creator>tplisson</dc:creator>
    <dc:date>2023-05-09T15:44:12Z</dc:date>
    <item>
      <title>Code Security: Policy Ids for Errors</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/code-security-policy-ids-for-errors/m-p/541488#M938</link>
      <description>&lt;P&gt;When scanning IAC with Bridgecrew GitHub action, an error may be returned as "Check: 8060797_AWS_1672940525627: "AWS Lambda function is not configured for function-level concurrent execution Limit" with a link to &lt;A href="https://docs.bridgecrew.io/docs/ensure-that-aws-lambda-function-is-configured-for-function-level-concurrent-execution-limit" target="_blank"&gt;https://docs.bridgecrew.io/docs/ensure-that-aws-lambda-function-is-configured-for-function-level-concurrent-execution-limit&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Why is the 8060797_AWS_1672940525627 shown as the policy id rather than the native policy id - either BC_AWS_GENERAL_63 or CKV_AWS_115?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the API to list errors (/code/api/v1/errors/file), the response still returns 8060797_AWS_1672940525627 rather than a native ID as errorId.&amp;nbsp; The API does not return a link to documentation.&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Linking errors to the underlying OOTB policy is challenging without the native policy id.&lt;/P&gt;</description>
      <pubDate>Mon, 08 May 2023 21:34:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/code-security-policy-ids-for-errors/m-p/541488#M938</guid>
      <dc:creator>JSchneider1</dc:creator>
      <dc:date>2023-05-08T21:34:44Z</dc:date>
    </item>
    <item>
      <title>Re: Code Security: Policy Ids for Errors</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/code-security-policy-ids-for-errors/m-p/541587#M941</link>
      <description>&lt;P&gt;A policy ID like "&lt;SPAN&gt;8060797_AWS_1672940525627&lt;/SPAN&gt;" is the format of a custom build policy (CCS). Maybe a clone of the OOTB policy?&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2023 15:44:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/code-security-policy-ids-for-errors/m-p/541587#M941</guid>
      <dc:creator>tplisson</dc:creator>
      <dc:date>2023-05-09T15:44:12Z</dc:date>
    </item>
    <item>
      <title>Re: Code Security: Policy Ids for Errors</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/code-security-policy-ids-for-errors/m-p/541591#M942</link>
      <description>&lt;P&gt;A custom policy would explain it.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, I know this one is not.&lt;/P&gt;
&lt;P&gt;When viewing the policy definition in the console, it says "&lt;SPAN&gt;This policy is defined in Checkov, for more information about this policy's exact definition visit&lt;/SPAN&gt;&lt;A class="text-link dark:text-dark-bg-link hover:underline hover:cursor-pointer text-xs inline-flex items-center" href="https://github.com/bridgecrewio/checkov" target="_blank" rel="noopener noreferrer"&gt;https://github.com/bridgecrewio/checkov&lt;/A&gt;".&lt;/P&gt;
&lt;P&gt;When querying policy details through the API, the createdBy attribute =&amp;nbsp;&lt;SPAN&gt;"Prisma&amp;nbsp;Cloud&amp;nbsp;System&amp;nbsp;Admin".&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I know we've at one time disabled, re-enabled, and updated the labels on this policy (and most other OOTB build policies).&amp;nbsp; Maybe there was a side effect of one of those operations.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;So I agree that indications are that somehow Prisma Cloud is inaccurately seeing this and other many other of our OOTB build policies as custom policies.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2023 16:24:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/code-security-policy-ids-for-errors/m-p/541591#M942</guid>
      <dc:creator>JSchneider1</dc:creator>
      <dc:date>2023-05-09T16:24:26Z</dc:date>
    </item>
  </channel>
</rss>

