diff --git a/rules/unauthenticated-service/raw.rego b/rules/unauthenticated-service/raw.rego index cdc4c9cc..6e311218 100644 --- a/rules/unauthenticated-service/raw.rego +++ b/rules/unauthenticated-service/raw.rego @@ -17,19 +17,18 @@ deny contains msga if { service_name := service.metadata.name has_unauthenticated_service(service_name, service.metadata.namespace, service_scan_result) - # Path to the service object - path := "spec" - msga := { "alertMessage": sprintf("Unauthenticated service %v exposes %v", [service_name, wl.metadata.name]), "alertScore": 7, "fixPaths": [], - "reviewPaths": [path], + "reviewPaths": [], "failedPaths": [], "packagename": "armo_builtins", "alertObject": {"k8sApiObjects": [wl]}, "relatedObjects": [ - {"object": service}, + {"object": service, + "reviewPaths": ["spec"], + }, ], } } diff --git a/rules/unauthenticated-service/test/fail_service/expected.json b/rules/unauthenticated-service/test/fail_service/expected.json index 6a14dcbd..3d733686 100644 --- a/rules/unauthenticated-service/test/fail_service/expected.json +++ b/rules/unauthenticated-service/test/fail_service/expected.json @@ -45,10 +45,10 @@ } } }, - "reviewPaths": null + "reviewPaths": ["spec"] } ], - "reviewPaths": ["spec"], + "reviewPaths": [], "ruleStatus": "" } ]