Skip to content

fix(sdk): update Trend Micro URLs in AWS metadata files - #10068

Merged
danibarranqueroo merged 12 commits into
masterfrom
fix-trendmicro-links
Feb 23, 2026
Merged

danibarranqueroo merged 12 commits into
masterfrom
fix-trendmicro-links

Conversation

@HugoPBrito

@HugoPBrito HugoPBrito commented Feb 13, 2026 •

Copy link
Copy Markdown
Contributor

Context

Trend Micro CloudOne Conformity will reach End-of-Life (EOL) in July 2026. The platform is being replaced by Trend Micro Vision One Cloud Risk Management. All CloudOne Conformity URLs in AWS check metadata files are being updated to point to the new Vision One platform to ensure users have access to current security guidance.

Description

This PR updates 221 AWS metadata files to replace deprecated Trend Micro CloudOne Conformity URLs with the new Trend Micro Vision One Cloud Risk Management URLs.

Key Changes:

  • URL Migration: CloudOne Conformity → Vision One Cloud Risk Management
    • Old: https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/...
    • New: https://www.trendmicro.com/trendaivisiononecloudriskmanagement/knowledge-base/aws/...
  • URL Verification: All 221 new Vision One URLs verified to return HTTP 200 OK
  • Comprehensive Coverage: Updated metadata for 53 AWS services (accessanalyzer, account, acm, apigateway, autoscaling, awslambda, backup, bedrock, cloudformation, cloudfront, cloudtrail, cloudwatch, dlm, dms, documentdb, dynamodb, ec2, ecr, ecs, eks, elasticache, elasticbeanstalk, elb, elbv2, emr, eventbridge, firehose, glue, guardduty, iam, inspector2, kafka, kinesis, kms, mq, neptune, networkfirewall, opensearch, rds, redshift, route53, s3, sagemaker, sns, sqs, storagegateway, trustedadvisor, vpc, wafv2, wellarchitected, workspaces)

Why This Matters:

  • Ensures users can access up-to-date security guidance from Trend Micro's active platform
  • Prevents broken links when CloudOne Conformity is sunset in July 2026
  • Maintains alignment with Trend Micro's current cloud security best practices

Note: Other providers (Azure, GCP, Alibaba Cloud, Oracle Cloud) also have deprecated CloudOne Conformity URLs, but not all Vision One URLs are functional for those providers yet. Those will be addressed in follow-up PRs once the URLs are verified.

Related Work:

Steps to review

  1. Verify URL pattern replacement:

    git diff master...HEAD | grep -E "(cloudoneconformity|trendaivisiononecloudriskmanagement)"
    • Confirm all cloudoneconformity → trendaivisiononecloudriskmanagement replacements
  2. Spot-check URL validity (sample 5-10 random files):

    # Example: Check KMS metadata
    cat prowler/providers/aws/services/kms/kms_key_not_publicly_accessible/kms_key_not_publicly_accessible.metadata.json | grep RelatedUrl
    # Verify URL returns 200 OK
    curl -I https://www.trendmicro.com/trendaivisiononecloudriskmanagement/knowledge-base/aws/KMS/kms-key-not-publicly-accessible.html
  3. Validate JSON integrity:

    # Ensure all metadata files are valid JSON
    find prowler/providers/aws/services/ -name "*.metadata.json" -exec python3 -m json.tool {} \; > /dev/null
  4. Check service coverage - Verify 53 AWS services updated:

    git diff --name-only master...HEAD | cut -d'/' -f5 | sort -u | wc -l

Checklist

Community Checklist
  • This feature/issue is listed in here or roadmap.prowler.com
  • Is it assigned to me, if not, request it via the issue/feature in here or Prowler Community Slack
  • Are there new checks included in this PR? No
    • If so, do we need to update permissions for the provider? N/A
  • Review if the code is being covered by tests. (No code changes, only metadata URLs)
  • Review if code is being documented following https://github.com/google/styleguide/blob/gh-pages/pyguide.md#38-comments-and-docstrings (No code changes)
  • Review if backport is needed. (No - metadata update only)
  • Review if is needed to change the Readme.md (No)
  • Ensure new entries are added to CHANGELOG.md, if applicable. (Done)

SDK/CLI

  • Are there new checks included in this PR? No
    • If so, do we need to update permissions for the provider? N/A

UI (if applicable)

  • N/A - SDK-only changes

API (if applicable)

  • N/A - SDK-only changes

License

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

- Replace deprecated CloudOne Conformity URLs (EOL July 2026) with Trend Micro Vision One URLs
- Verify all Vision One URLs return HTTP 200 OK (221 files updated)
- Ensure check metadata points to active security knowledge base
@HugoPBrito
HugoPBrito requested review from a team February 13, 2026 15:54
@github-actions github-actions Bot added provider/aws Issues/PRs related with the AWS provider metadata-review labels Feb 13, 2026
@github-actions

github-actions Bot commented Feb 13, 2026 •

Copy link
Copy Markdown
Contributor

✅ All necessary CHANGELOG.md files have been updated.

@github-actions

github-actions Bot commented Feb 13, 2026 •

Copy link
Copy Markdown
Contributor

✅ Conflict Markers Resolved

All conflict markers have been successfully resolved in this pull request.

@github-actions

github-actions Bot commented Feb 13, 2026 •

Copy link
Copy Markdown
Contributor

🔒 Container Security Scan

Image: prowler:66ddfe1
Last scan: 2026-02-23 09:22:21 UTC

📊 Vulnerability Summary

Severity Count
🔴 Critical 5
Total 5

5 package(s) affected

⚠️ Action Required

Critical severity vulnerabilities detected. These should be addressed before merging:

  • Review the detailed scan results
  • Update affected packages to patched versions
  • Consider using a different base image if updates are unavailable

📋 Resources:

@codecov

codecov Bot commented Feb 13, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 78.14%. Comparing base (9f6121b) to head (62a1986).
⚠️ Report is 5 commits behind head on master.

Additional details and impacted files
@@             Coverage Diff             @@
##           master   #10068       +/-   ##
===========================================
+ Coverage   65.92%   78.14%   +12.21%     
===========================================
  Files          93      835      +742     
  Lines        6363    23633    +17270     
===========================================
+ Hits         4195    18468    +14273     
- Misses       2168     5165     +2997     
Flag Coverage Δ
prowler-py3.10-aws 78.10% <ø> (?)
prowler-py3.10-lib ?
prowler-py3.11-aws 78.08% <ø> (?)
prowler-py3.11-lib ?
prowler-py3.12-aws 78.08% <ø> (?)
prowler-py3.12-lib ?
prowler-py3.9-lib ?

Flags with carried forward coverage won't be shown. Click here to find out more.

Components Coverage Δ
prowler 78.14% <ø> (+12.21%) ⬆️
api ∅ <ø> (∅)
🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

- Remove 13 deprecated docs.prowler.com URLs from 10 AWS checks
- docs.prowler.com is no longer maintained
- Canonical documentation is now at hub.prowler.com (already referenced in Recommendation.Url)
- Affected services: account, cloudtrail, cloudwatch, dynamodb, glacier, opensearch
- Remove 69 deprecated docs.prowler.com URLs from Azure (8), Kubernetes (59), and OracleCloud (2)
- docs.prowler.com is no longer maintained (discontinued documentation site)
- Canonical documentation is now at hub.prowler.com
@github-actions github-actions Bot added provider/azure Issues/PRs related with the Azure provider provider/kubernetes Issues/PRs related with the Kubernetes provider provider/oci Issues/PRs related with the OCI provider labels Feb 16, 2026
Reverting commits 431151b and efd3d70.

The URL removal for Kubernetes, Azure, and OracleCloud was too aggressive,
removing entire Remediation fields instead of just the deprecated URLs.

Keeping only AWS changes which were properly scoped to AdditionalURLs field.
@github-actions github-actions Bot removed provider/azure Issues/PRs related with the Azure provider provider/kubernetes Issues/PRs related with the Kubernetes provider provider/oci Issues/PRs related with the OCI provider labels Feb 16, 2026
- Add AWS documentation URLs to cloudtrail_multi_region_enabled_logging_management_events
- Add AWS documentation URLs to codepipeline_project_repo_private
- Ensure all checks have relevant reference URLs
- Update CheckTitle to be more descriptive and specific
- Add CheckType for AWS Security Best Practices compliance
- Fix ResourceIdTemplate to use correct ARN format for CodePipeline
- Change ResourceType from generic 'Other' to 'AwsCodePipelinePipeline'
- Add Categories: supply-chain-security, secrets-management
- Enhance Description and Risk with markdown formatting and detailed explanations
- Clear RelatedUrl (following metadata guidelines)
- Replace redirecting URLs in AdditionalURLs with direct links (verified 200 OK)
- Add comprehensive remediation code examples for CLI, CloudFormation, Terraform, and Console
- Improve Recommendation text with security best practices
- Update Recommendation.Url to hub.prowler.com
- Add detailed Notes explaining check behavior
@HugoPBrito HugoPBrito changed the title fix(sdk): update Trend Micro URLs in AWS metadata files fix(sdk): update Trend Micro URLs across all providers metadata files Feb 23, 2026
@github-actions github-actions Bot added provider/azure Issues/PRs related with the Azure provider provider/oci Issues/PRs related with the OCI provider provider/alibabacloud Issues/PRs related with the Alibaba Cloud provider labels Feb 23, 2026
@HugoPBrito HugoPBrito changed the title fix(sdk): update Trend Micro URLs across all providers metadata files fix(sdk): update Trend Micro URLs in AWS metadata files Feb 23, 2026
@github-actions github-actions Bot removed provider/azure Issues/PRs related with the Azure provider provider/oci Issues/PRs related with the OCI provider provider/alibabacloud Issues/PRs related with the Alibaba Cloud provider labels Feb 23, 2026
@danibarranqueroo
danibarranqueroo merged commit 5830cb6 into master Feb 23, 2026
37 checks passed
@danibarranqueroo
danibarranqueroo deleted the fix-trendmicro-links branch February 23, 2026 12:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

metadata-review provider/aws Issues/PRs related with the AWS provider

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants