<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>Guardrails Changelog</title>
        <link>https://turbot.com/guardrails/changelog</link>
        <description>Changelog for Guardrails</description>
        <language>en</language>
        <lastBuildDate>Thu, 07 May 2026 09:00:00 GMT</lastBuildDate>
        <atom:link href="https://turbot.com/guardrails/changelog/feed.xml" rel="self" type="application/rss+xml"/>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-v5-45-0</guid>
            <title>aws v5.45.0 - Account CMDB now captures Operations and Billing alternate contacts</title>
            <link>https://turbot.com/guardrails/changelog/aws-v5-45-0</link>
            <description>_What&apos;s new?_

- The `AWS &gt; Account &gt; CMDB` control now captures `AlternateOperationsContact` and `AlternateBillingContact` alongside the existing `AlternateSecurityContact`. These fields are populated from the AWS Account alternate contact API and are available for querying and policy enforcement. Accounts without a contact configured or without sufficient permissions will show `null` for the respective fields.</description>
            <pubDate>Thu, 07 May 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-v5-44-0</guid>
            <title>aws v5.44.0 - Bedrock Policy resource type for AWS Organizations</title>
            <link>https://turbot.com/guardrails/changelog/aws-v5-44-0</link>
            <description>_Resource Types_

_Added_

- AWS &gt; Organizations &gt; Bedrock Policy

_Control Types_

_Added_

- AWS &gt; Organizations &gt; Bedrock Policy &gt; CMDB
- AWS &gt; Organizations &gt; Bedrock Policy &gt; Discovery

_Policy Types_

_Added_

- AWS &gt; Organizations &gt; Bedrock Policy &gt; CMDB

_Action Types_

_Added_

- AWS &gt; Organizations &gt; Bedrock Policy &gt; Router</description>
            <pubDate>Wed, 06 May 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-quicksight-v5-4-1</guid>
            <title>aws-quicksight v5.4.1 - Fixed Account Settings Discovery control entering an error state in some accounts</title>
            <link>https://turbot.com/guardrails/changelog/aws-quicksight-v5-4-1</link>
            <description>_Bug fixes_

- Fixed the `AWS &gt; QuickSight &gt; Account Settings &gt; Discovery` control crashing with `TypeError: err.isNotFound is not a function` when the underlying QuickSight API call returned an error such as the account not being subscribed to QuickSight or the caller lacking the required permissions. The control now correctly recognises not-found errors and exits cleanly instead of masking the original AWS error with a JavaScript TypeError.</description>
            <pubDate>Wed, 06 May 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-prevention-v5-2-0</guid>
            <title>aws-prevention v5.2.0 - AWS Bedrock prevention objectives and examples</title>
            <link>https://turbot.com/guardrails/changelog/aws-prevention-v5-2-0</link>
            <description>_Bug fixes_

- Fixed SCP Allow Boundary discovery incorrectly flagging every AWS service as blocked on organizational units that have FullAWSAccess plus deny-only SCPs attached. The discovery control was dropping AWS-managed SCPs (including FullAWSAccess) from its input query, which prevented the FullAWSAccess-aware code paths from running and made every such OU fall into the restrictive-boundary path.
- Fixed SCP allow boundary prevention discovery so it updates correctly when SCPs are attached, modified, or detached from an organizational unit, account, or organization root. Also fixed prevention discovery for EC2 account attributes, IAM password policy, S3 public access, SCP deny, RCP deny, and SCP allow boundary so that existing preventions are removed when the underlying AWS configuration is cleared.

_Prevention Objectives_

_Added_

- Enforce VPC endpoint for AWS Bedrock invocations
- Enforce approved foundation models for AWS Bedrock
- Restrict AWS Bedrock Marketplace model endpoints to approved vendors
- Restrict AWS Bedrock agent action groups to approved sources
- Restrict AWS Bedrock third-party knowledge bases to approved secret ARNs

_Prevention Examples_

_Added_

- Enforce approved foundation models for AWS Bedrock agents
- Require VPC endpoint for AWS Bedrock invocations
- Require approved foundation models for AWS Bedrock invocations
- Restrict AWS Bedrock Marketplace model endpoints
- Restrict AWS Bedrock agent action groups to approved sources
- Restrict AWS Bedrock third-party knowledge base integrations to approved secret ARNs</description>
            <pubDate>Wed, 06 May 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-bedrock-v5-6-0</guid>
            <title>aws-bedrock v5.6.0 - Action Group and Guardrail resource types</title>
            <link>https://turbot.com/guardrails/changelog/aws-bedrock-v5-6-0</link>
            <description>_Resource Types_

_Added_

- AWS &gt; Bedrock &gt; Action Group
- AWS &gt; Bedrock &gt; Guardrail

_Control Types_

_Added_

- AWS &gt; Bedrock &gt; Action Group &gt; Allowed
- AWS &gt; Bedrock &gt; Action Group &gt; Allowed &gt; Custom
- AWS &gt; Bedrock &gt; Action Group &gt; CMDB
- AWS &gt; Bedrock &gt; Action Group &gt; Discovery
- AWS &gt; Bedrock &gt; Guardrail &gt; Allowed
- AWS &gt; Bedrock &gt; Guardrail &gt; Allowed &gt; Custom
- AWS &gt; Bedrock &gt; Guardrail &gt; Allowed &gt; Region
- AWS &gt; Bedrock &gt; Guardrail &gt; CMDB
- AWS &gt; Bedrock &gt; Guardrail &gt; Discovery
- AWS &gt; Bedrock &gt; Guardrail &gt; Tags

_Policy Types_

_Added_

- AWS &gt; Bedrock &gt; Action Group &gt; Allowed
- AWS &gt; Bedrock &gt; Action Group &gt; Allowed &gt; Custom
- AWS &gt; Bedrock &gt; Action Group &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; Bedrock &gt; Action Group &gt; CMDB
- AWS &gt; Bedrock &gt; Action Group &gt; Regions
- AWS &gt; Bedrock &gt; Guardrail &gt; Allowed
- AWS &gt; Bedrock &gt; Guardrail &gt; Allowed &gt; Custom
- AWS &gt; Bedrock &gt; Guardrail &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; Bedrock &gt; Guardrail &gt; Allowed &gt; Region
- AWS &gt; Bedrock &gt; Guardrail &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; Bedrock &gt; Guardrail &gt; CMDB
- AWS &gt; Bedrock &gt; Guardrail &gt; Regions
- AWS &gt; Bedrock &gt; Guardrail &gt; Tags
- AWS &gt; Bedrock &gt; Guardrail &gt; Tags &gt; Template

_Action Types_

_Added_

- AWS &gt; Bedrock &gt; Action Group &gt; Delete
- AWS &gt; Bedrock &gt; Action Group &gt; Delete from AWS
- AWS &gt; Bedrock &gt; Action Group &gt; Router
- AWS &gt; Bedrock &gt; Guardrail &gt; Delete
- AWS &gt; Bedrock &gt; Guardrail &gt; Delete from AWS
- AWS &gt; Bedrock &gt; Guardrail &gt; Router
- AWS &gt; Bedrock &gt; Guardrail &gt; Set Tags
- AWS &gt; Bedrock &gt; Guardrail &gt; Skip alarm for Tags control
- AWS &gt; Bedrock &gt; Guardrail &gt; Skip alarm for Tags control [90 days]
- AWS &gt; Bedrock &gt; Guardrail &gt; Update Tags</description>
            <pubDate>Wed, 06 May 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-v5-36-0</guid>
            <title>gcp v5.36.0 - Added policy to support Workload Identity Federation for organizations</title>
            <link>https://turbot.com/guardrails/changelog/gcp-v5-36-0</link>
            <description>_What&apos;s new?_

- Added the `GCP &gt; Workload Identity Pool Provider` policy type, which stores the WIF Pool Provider resource name to support Workload Identity Federation for GCP Organizations.</description>
            <pubDate>Tue, 05 May 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-msk-v5-8-3</guid>
            <title>aws-msk v5.8.3 - Fixed Allowed Regions [Default] policy for the service failing with runnable input query error</title>
            <link>https://turbot.com/guardrails/changelog/aws-msk-v5-8-3</link>
            <description>_Bug fixes_

- The `AWS &gt; MSK &gt; Allowed Regions [Default]` policy previously failed with a &quot;Runnable input query failed&quot; error on all AWS accounts because it referenced a non-existent policy. The policy now correctly inherits from `AWS &gt; Allowed Regions [Default]`policy.</description>
            <pubDate>Tue, 05 May 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ec2-v5-54-1</guid>
            <title>aws-ec2 v5.54.1 - Fixed Launch Template Version and Load Balancer Listener Discovery controls erroring on deleted parent resources</title>
            <link>https://turbot.com/guardrails/changelog/aws-ec2-v5-54-1</link>
            <description>_Bug fixes_

- Fixed `Launch Template Version &gt; Discovery` and `Load Balancer Listener &gt; Discovery` controls erroring when the parent resource is deleted in AWS. Both controls now trigger the parent&apos;s CMDB cleanup on `InvalidLaunchTemplateId.NotFound`/`LoadBalancerNotFoundException` API errors.</description>
            <pubDate>Tue, 05 May 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-v5-43-7</guid>
            <title>aws v5.43.7 - Global Event Handlers now deliver real-time CMDB updates for all event types across regions</title>
            <link>https://turbot.com/guardrails/changelog/aws-v5-43-7</link>
            <description>_Bug fixes_

- Fixed an issue where `AWS &gt; Turbot &gt; Event Handlers [Global]` deployments were not forwarding certain event types from non-primary regions to the primary region&apos;s event bus. Only events with the `AWS API Call via CloudTrail` detail-type were being forwarded, so events such as `EBS Volume Notification`, `EC2 Instance State-change Notification`, `AWS Service Event via CloudTrail` (AppStream `CreateImage`, QuickSight, Organizations), and `AWS Console Action via CloudTrail` (Billing Console region enable/disable) emitted in non-primary regions were not reaching Guardrails. The non-primary forwarding rule now covers all detail-types defined in the configured event patterns, so Global Event Handlers deployments receive real-time CMDB updates for these events from every region.
- Added `AttachedPolicies` in definitions on `account`, `organizationRoot`, and `organizationalUnit` resource data schemas. Enables downstream mods to query attached SCPs, RCPs, and other organization policies via typed GraphQL field access instead of reading raw `data`.</description>
            <pubDate>Mon, 27 Apr 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-iam-v5-48-3</guid>
            <title>aws-iam v5.48.3 - Fixed IAM group membership and provisioning issues in the Managed permissions stack</title>
            <link>https://turbot.com/guardrails/changelog/aws-iam-v5-48-3</link>
            <description>_Bug fixes_

- The `AWS &gt; Turbot &gt; IAM &gt; Group &gt; Managed` control incorrectly flagged existing members of service-specific IAM groups (for example, `stepfunctions_admin`, `secretsmanager_admin`, and `cloudwatch_operator`) for removal, because the control could not match those members against their existing Guardrails grants. Existing group members are now recognized correctly and are no longer reported as unauthorized.
- The `AWS &gt; Turbot &gt; IAM &gt; Managed &gt; Provision Managed Resources` action generated invalid ARNs containing `undefined` in place of the account ID (for example, `arn:aws:iam::undefined:policy/turbot/...`) and created duplicate &quot;ghost&quot; entries in CMDB alongside the real IAM policies, roles, users, and groups it provisioned. This affected workspaces whose account metadata had been populated by earlier discovery runs. ARNs are now generated with the correct account ID, and duplicate CMDB entries are no longer created.</description>
            <pubDate>Fri, 24 Apr 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/ted-v1-53-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.53.0 - PgBouncer on Fargate and Gen 8 Graviton4 RDS support</title>
            <link>https://turbot.com/guardrails/changelog/ted-v1-53-0</link>
            <description>_What&apos;s new?_

- Added Fargate launch type support for PgBouncer, with auto-derived CPU / memory and pool sizing based on max server connections.
- Added support for Gen 8 Graviton4 RDS instance types (`db.m8g`, `db.r8g`).
- Simplified PgBouncer CloudFormation parameters — seven resource and pool-size parameters have been consolidated under a single `PgBouncerCpu` with auto-derivation.
- `PgBouncerMaxDbConnections` has been renamed to `PgBouncerMaxServerConnections`.

_Bug fixes_

- Retain the PgBouncer CloudWatch log group when PgBouncer is disabled, so existing logs aren&apos;t lost on stack update.</description>
            <pubDate>Thu, 23 Apr 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-58-1</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.58.1 - AI provider fixes and OCL CIDR operators restored</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-58-1</link>
            <description>_What&apos;s new?_

- Server
  - Individual AI features (e.g. Policy Pack Summary) now work when enabled independently of the global AI toggle — credentials are returned whenever the provider is configured.

_Bug fixes_

- Server
  - Resolved an issue where the Azure OpenAI provider could fail on the Policy Pack Summary control due to configuration errors.
  - Addressed a problem where certain CIDR comparison checks were not working correctly after a recent update.

_Requirements_

- Upgrade to `5.58.0` requires your workspace to be on `5.55.x`
- PostgreSQL (RDS engine): &gt;= 15
- TEF: 1.70.0
- TED: 1.37.0
- Mods:
  - @turbot/turbot: 5.57.0

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Thu, 23 Apr 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-v5-39-3</guid>
            <title>azure v5.39.3 - Fixed subscription policy CMDB controls failing due to missing tenant metadata</title>
            <link>https://turbot.com/guardrails/changelog/azure-v5-39-3</link>
            <description>_Bug fixes_

- Fixed `Azure &gt; Subscription Policy &gt; CMDB` failing due to missing tenant IDs in resource AKAs. Any broken records currently in CMDB are automatically cleaned up by the `Azure &gt; Subscription Policy &gt; CMDB` control and recreated with the correct AKA by `Azure &gt; Subscription Policy &gt; Discovery`.</description>
            <pubDate>Wed, 22 Apr 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-v5-39-2</guid>
            <title>azure v5.39.2 - Fixed several Policy Discovery controls failing to create resources when Azure tenants have resources with non-unique names</title>
            <link>https://turbot.com/guardrails/changelog/azure-v5-39-2</link>
            <description>_Bug fixes_

- Fixed `Azure &gt; Policy Definition &gt; Discovery`, `Azure &gt; Policy Assignment &gt; Discovery`, `Azure &gt; Policy Set Definition &gt; Discovery`, and `Azure &gt; Subscription Policy &gt; Discovery` controls failing to create new resources when two Azure tenants in the same Guardrails workspace have resources with non-unique names. The AKAs for these resource types now start with `azure:///tenants/{tenantId}/`. Any resources currently in CMDB will have their current AKAs replaced with the new format.</description>
            <pubDate>Fri, 17 Apr 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ec2-v5-54-0</guid>
            <title>aws-ec2 v5.54.0 - Configure deregistration protection for AMIs</title>
            <link>https://turbot.com/guardrails/changelog/aws-ec2-v5-54-0</link>
            <description>_What&apos;s new?_

- Configure deregistration protection for AMIs. To get started, set the `AWS &gt; EC2 &gt; AMI &gt; Deregistration Protection` policy.
- AMI CMDB details will now also include details about the EC2 instances that refer the AMI.

_Control Types_

- AWS &gt; EC2 &gt; AMI &gt; Deregistration Protection

_Policy Types_

- AWS &gt; EC2 &gt; AMI &gt; Deregistration Protection

_Action Types_

- AWS &gt; EC2 &gt; AMI &gt; Update Deregistration Protection</description>
            <pubDate>Fri, 17 Apr 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-network-v5-30-3</guid>
            <title>azure-network v5.30.3 - Fixed Network Security Group Ingress/Egress Rules Approved controls incorrectly handling bare IP addresses</title>
            <link>https://turbot.com/guardrails/changelog/azure-network-v5-30-3</link>
            <description>_Bug fixes_

- Fixed Network Security Group Ingress/Egress Rules Approved controls incorrectly handling bare IP addresses (e.g., `8.8.8.8`) in `sourceAddressPrefix`. Bare IPs are now normalized to CIDR notation (`8.8.8.8/32`) so that `bitmaskLength` and OCL CIDR comparison operators work correctly.</description>
            <pubDate>Thu, 16 Apr 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-efs-v5-12-2</guid>
            <title>aws-efs v5.12.2 - File system CMDB data will now be refreshed correctly on mount target deletions</title>
            <link>https://turbot.com/guardrails/changelog/aws-efs-v5-12-2</link>
            <description>_Bug fixes_

- The file system CMDB data was not being refreshed when its mount targets were deleted, which could cause the `Allowed Encryption at Rest` control to use stale data. This has now been fixed, and the file system CMDB is correctly updated on any of its mount target deletions.</description>
            <pubDate>Tue, 14 Apr 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ec2-v5-53-1</guid>
            <title>aws-ec2 v5.53.1 - Fixed EC2 Instance Metadata Service control not sending action notifications</title>
            <link>https://turbot.com/guardrails/changelog/aws-ec2-v5-53-1</link>
            <description>_Bug fixes_

- Fixed `AWS &gt; EC2 &gt; Instance &gt; Metadata Service` control not sending action notifications.</description>
            <pubDate>Fri, 10 Apr 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-network-v5-30-2</guid>
            <title>azure-network v5.30.2 - Ingress Rules and Egress Rules Approved controls will no longer delete rules of the opposite direction</title>
            <link>https://turbot.com/guardrails/changelog/azure-network-v5-30-2</link>
            <description>_Bug fixes_

- The `Azure &gt; Network &gt; Network Security Group &gt; Ingress Rules &gt; Approved` and `Azure &gt; Network &gt; Network Security Group &gt; Egress Rules &gt; Approved` controls, when set to `Enforce: Delete unapproved`, would inadvertently delete all security rules of the opposite direction (e.g., enforcing ingress rules would delete all egress rules). This has now been fixed and the controls will only revoke unapproved rules of their respective direction without affecting rules of the opposite direction.</description>
            <pubDate>Thu, 09 Apr 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-70-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.70.0 - Node.js 24 Lambda runtime support</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-70-0</link>
            <description>_What&apos;s new?_

- Added support for Node.js 24 in the Lambda runtime environment.</description>
            <pubDate>Mon, 06 Apr 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-58-0</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.58.0 - New UI, SIEM integrations, policy simulators, and AI chat</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-58-0</link>
            <description>_What&apos;s new?_

This release delivers a comprehensive new user interface alongside SIEM integrations, cloud policy simulators, and an AI chat assistant. The server runtime has been upgraded to Node.js 24 LTS with a full migration from AWS SDK v2 to v3.

Key capabilities include:

- **New UI** built on React 19 with redesigned Dashboard, Prevention Explorer, connection wizards for all supported cloud providers, and a developer palette for contextual debugging.
- **SIEM integrations** for CloudTrail Lake and Splunk, enabling security event querying and denial event analysis directly from Guardrails.
- **Policy simulators** for AWS SCP, Azure Policy, and GCP Org Policy to test and validate policy impact before enforcement.
- **AI Chat** assistant (Turbie) with contextual help on controls, policies, and alarms.
- **OCI support** expanded with cloud hierarchy viewer, compartment management, and improved discovery.
- **Platform upgrades** including Node.js 24 LTS, AWS SDK v3 migration, and updated dependencies.

_Requirements_

- Upgrade to `5.58.0` requires your workspace to be on `5.55.x`
- PostgreSQL (RDS engine): &gt;= 15
- TEF: 1.70.0
- TED: 1.37.0
- Mods:
  - @turbot/turbot: 5.57.0

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Mon, 06 Apr 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/oci-v5-0-3</guid>
            <title>oci v5.0.3 - Fixed missing icons for OCI and tenancy resource types</title>
            <link>https://turbot.com/guardrails/changelog/oci-v5-0-3</link>
            <description>_Bug fixes_

- Fixed missing icons for OCI and tenancy resource types.</description>
            <pubDate>Thu, 02 Apr 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-network-v5-30-1</guid>
            <title>azure-network v5.30.1 - Ingress Rules and Egress Rules Approved controls will no longer fail on large NSGs</title>
            <link>https://turbot.com/guardrails/changelog/azure-network-v5-30-1</link>
            <description>_Bug fixes_

- Fixed an issue where the `Azure &gt; Network &gt; Network Security Group &gt; Ingress Rules &gt; Approved` and `Egress Rules &gt; Approved` controls would fail with an internal error on large NSGs with 60+ security rules, wide port ranges (e.g., 49152-65535), and many CIDR addresses.
- Intelligent Assessment controls will now also work with AWS Bedrock and Azure OpenAI credentials.</description>
            <pubDate>Thu, 02 Apr 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-v5-35-2</guid>
            <title>gcp v5.35.2 - Organization CMDB control now respects Discovery Level policy settings</title>
            <link>https://turbot.com/guardrails/changelog/gcp-v5-35-2</link>
            <description>_Bug fixes_

- The `GCP &gt; Organization &gt; CMDB` control now respects the settings defined in the `GCP &gt; Organization &gt; Discovery Level` policy. This feature requires Turbot Guardrails Enterprise (TE) version 5.56.0 or later.
- Intelligent Assessment controls will now also work with AWS Bedrock and Azure OpenAI credentials.</description>
            <pubDate>Wed, 01 Apr 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-virtualdesktop-v5-2-0</guid>
            <title>azure-virtualdesktop v5.2.0 - Configure public network access for workspaces and host pools</title>
            <link>https://turbot.com/guardrails/changelog/azure-virtualdesktop-v5-2-0</link>
            <description>_What&apos;s new?_

- You can now configure public network access for the workspaces. To get started, set the `Azure &gt; Virtual Desktop &gt; Workspace &gt; Public Network Access` policy.
- You can now configure public network access for the host pools. To get started, set the `Azure &gt; Virtual Desktop &gt; Host Pool &gt; Public Network Access` policy.

_Control Types_

- Azure &gt; Virtual Desktop &gt; Host Pool &gt; Public Network Access
- Azure &gt; Virtual Desktop &gt; Workspace &gt; Public Network Access

_Policy Types_

- Azure &gt; Virtual Desktop &gt; Host Pool &gt; Public Network Access
- Azure &gt; Virtual Desktop &gt; Workspace &gt; Public Network Access

_Action Types_

- Azure &gt; Virtual Desktop &gt; Host Pool &gt; Set Public Network Access
- Azure &gt; Virtual Desktop &gt; Workspace &gt; Set Public Network Access</description>
            <pubDate>Mon, 30 Mar 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-v5-39-1</guid>
            <title>azure v5.39.1 - Fixed Intelligent Assessment controls to use updated policy URIs</title>
            <link>https://turbot.com/guardrails/changelog/azure-v5-39-1</link>
            <description>_Bug fixes_

- Fixed Intelligent Assessment controls to use updated policy URIs.</description>
            <pubDate>Mon, 30 Mar 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-redis-v5-3-0</guid>
            <title>azure-redis v5.3.0 - Configure firewall rules for redis cache</title>
            <link>https://turbot.com/guardrails/changelog/azure-redis-v5-3-0</link>
            <description>_What&apos;s new?_

- You can now configure firewall rules for redis cache. To get started, set the `Azure &gt; Redis &gt; Redis Cache &gt; Firewall &gt; *` policies.

_Control Types_

- Azure &gt; Redis &gt; Redis Cache &gt; Firewall
- Azure &gt; Redis &gt; Redis Cache &gt; Firewall &gt; IP Ranges
- Azure &gt; Redis &gt; Redis Cache &gt; Firewall &gt; IP Ranges &gt; Approved
- Azure &gt; Redis &gt; Redis Cache &gt; Firewall &gt; IP Ranges &gt; Required

_Policy Types_

- Azure &gt; Redis &gt; Redis Cache &gt; Firewall
- Azure &gt; Redis &gt; Redis Cache &gt; Firewall &gt; IP Ranges
- Azure &gt; Redis &gt; Redis Cache &gt; Firewall &gt; IP Ranges &gt; Approved
- Azure &gt; Redis &gt; Redis Cache &gt; Firewall &gt; IP Ranges &gt; Approved &gt; Compiled Rules
- Azure &gt; Redis &gt; Redis Cache &gt; Firewall &gt; IP Ranges &gt; Approved &gt; IP Addresses
- Azure &gt; Redis &gt; Redis Cache &gt; Firewall &gt; IP Ranges &gt; Approved &gt; Rules
- Azure &gt; Redis &gt; Redis Cache &gt; Firewall &gt; IP Ranges &gt; Required
- Azure &gt; Redis &gt; Redis Cache &gt; Firewall &gt; IP Ranges &gt; Required &gt; Items

_Action Types_

- Azure &gt; Redis &gt; Redis Cache &gt; Update Firewall
- Azure &gt; Redis &gt; Redis Cache &gt; Update Firewall IP Ranges</description>
            <pubDate>Mon, 30 Mar 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-prevention-v5-1-0</guid>
            <title>azure-prevention v5.1.0 - Added prevention examples and removed deprecated objectives</title>
            <link>https://turbot.com/guardrails/changelog/azure-prevention-v5-1-0</link>
            <description>_What&apos;s new?_

- Added 7 new prevention examples covering Azure Defender, soft delete, NSG requirements, customer-managed keys, and location restrictions. Removed 16 deprecated prevention objectives and examples related to activity log alerts, Defender notifications, key rotation, resource logging, and soft delete.

_Prevention Objectives_

_Removed_

- Enforce activity log alert for Azure NSG changes
- Enforce activity log alert for Azure NSG deletion
- Enforce activity log alert for Azure Policy assignment creation
- Enforce activity log alert for Azure Policy assignment deletion
- Enforce activity log alert for Azure SQL firewall rule changes
- Enforce activity log alert for Azure SQL firewall rule deletion
- Enforce activity log alert for Azure Service Health
- Enforce activity log alert for Azure public IP changes
- Enforce activity log alert for Azure public IP deletion
- Enforce activity log alert for Azure security solution changes
- Enforce activity log alert for Azure security solution deletion
- Enforce alert severity notifications for Azure Defender
- Enforce automatic key rotation for Azure Key Vault
- Enforce resource logging for Azure services
- Enforce security alert notifications for Azure subscription owners
- Require security contact email for Azure Defender

_Prevention Examples_

- Enforce Defender for Azure APIs
- Enforce soft delete for Azure Storage blobs
- Enforce soft delete for Azure Storage containers
- Require NSG for Azure Network subnets
- Require customer-managed keys for Azure Databricks DBFS root
- Require customer-managed keys for Azure Databricks managed services
- Restrict Azure resources to allowed locations

_Removed_

- Enforce activity log alert for Azure NSG changes
- Enforce activity log alert for Azure NSG deletion
- Enforce activity log alert for Azure SQL firewall rule changes
- Enforce activity log alert for Azure SQL firewall rule deletion
- Enforce activity log alert for Azure Service Health
- Enforce activity log alert for Azure policy assignment creation
- Enforce activity log alert for Azure policy assignment deletion
- Enforce activity log alert for Azure public IP changes
- Enforce activity log alert for Azure public IP deletion
- Enforce activity log alert for Azure security solution changes
- Enforce activity log alert for Azure security solution deletion
- Enforce alert severity notifications for Azure Defender
- Enforce automatic key rotation for Azure Key Vault
- Enforce resource logging for Azure services
- Enforce security alert notifications for Azure subscription owners
- Enforce soft delete for Azure Storage blobs
- Enforce soft delete for Azure Storage containers
- Require customer-managed keys for Azure Databricks DBFS root
- Require customer-managed keys for Azure Databricks managed services
- Require security contact email for Azure Defender</description>
            <pubDate>Mon, 30 Mar 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/github-prevention-v5-2-0</guid>
            <title>github-prevention v5.2.0 - Added supply chain security objectives for release assets and Actions SHA pinning</title>
            <link>https://turbot.com/guardrails/changelog/github-prevention-v5-2-0</link>
            <description>_What&apos;s new?_

- Added 2 new prevention objectives for supply chain security: prohibit modification of published release assets, and require GitHub Actions to use pinned commit references (SHA pinning).

_Prevention Objectives_

- Prohibit GitHub published release asset modification
- Require pinned commit references for GitHub Actions

_Prevention Examples_

- Lock published release assets for GitHub organizations
- Require SHA pinning for GitHub Actions in organizations</description>
            <pubDate>Fri, 27 Mar 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-prevention-v5-1-0</guid>
            <title>gcp-prevention v5.1.0 - Added control mappings and Terraform examples for DNS, API key, encryption, logging, and compute objectives</title>
            <link>https://turbot.com/guardrails/changelog/gcp-prevention-v5-1-0</link>
            <description>_What&apos;s new?_

- Added Turbot Guardrails control mappings and Terraform examples for 8 prevention objectives covering DNS security, API key restrictions, encryption, logging, and compute security.

_Prevention Examples_

- Enforce CMEK for GCP Dataproc clusters
- Enforce DNSSEC configuration to prohibit RSASHA1 key signing for GCP Cloud DNS managed zones
- Enforce DNSSEC configuration to prohibit RSASHA1 zone signing for GCP Cloud DNS managed zones
- Enforce KMS key rotation period for GCP crypto keys
- Require API restrictions for GCP API keys
- Require Confidential Computing for GCP Compute Engine instances
- Require host restrictions for GCP API keys
- Require logging for GCP Cloud DNS managed zones</description>
            <pubDate>Fri, 27 Mar 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-sql-v5-23-0</guid>
            <title>azure-sql v5.23.0 - Configure public network access for managed instances</title>
            <link>https://turbot.com/guardrails/changelog/azure-sql-v5-23-0</link>
            <description>_Bug fixes_

- Fixed Intelligent Assessment controls to use updated policy URIs.

_What&apos;s new?_

- You can now configure public network access for managed instances. To get started, set the `Azure &gt; SQL &gt; Managed Instance &gt; Public Network Access` policy.

_Control Types_

- Azure &gt; SQL &gt; Managed Instance &gt; Public Endpoint

_Policy Types_

- Azure &gt; SQL &gt; Managed Instance &gt; Public Endpoint

_Action Types_

- Azure &gt; SQL &gt; Managed Instance &gt; Set Public Endpoint</description>
            <pubDate>Fri, 27 Mar 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-apimanagement-v5-10-0</guid>
            <title>azure-apimanagement v5.10.0 - Track and manage API resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-apimanagement-v5-10-0</link>
            <description>_What&apos;s new?_

- You can now configure protocols for APIs. To get started with these new controls, please see the `Azure &gt; API Management &gt; API &gt; Protocols &gt; *` policies.
- We&apos;ve updated internal dependencies and now use the latest Azure SDK versions to discover and manage API management resources in Guardrails. This release includes breaking changes in the CMDB data for services. We recommend updating your existing policy settings to refer to the updated attributes as mentioned below.

Added:

- `legacyPortalStatus`
- `developerPortalStatus`

Removed:

- `portalUrl`

Modified:

- The value of the attribute `platformVersion` has been changed from `stv2` to `stv2.1`

_Resource Types_

- Azure &gt; API Management &gt; API

_Control Types_

- Azure &gt; API Management &gt; API &gt; Active
- Azure &gt; API Management &gt; API &gt; Allowed
- Azure &gt; API Management &gt; API &gt; Allowed &gt; Custom
- Azure &gt; API Management &gt; API &gt; CMDB
- Azure &gt; API Management &gt; API &gt; Discovery
- Azure &gt; API Management &gt; API &gt; Protocols

_Policy Types_

- Azure &gt; API Management &gt; API &gt; Active
- Azure &gt; API Management &gt; API &gt; Active &gt; Age
- Azure &gt; API Management &gt; API &gt; Active &gt; Last Modified
- Azure &gt; API Management &gt; API &gt; Allowed
- Azure &gt; API Management &gt; API &gt; Allowed &gt; Custom
- Azure &gt; API Management &gt; API &gt; Allowed &gt; Custom &gt; Rules
- Azure &gt; API Management &gt; API &gt; CMDB
- Azure &gt; API Management &gt; API &gt; Protocols
- Azure &gt; API Management &gt; API &gt; Protocols &gt; URL Scheme
- Azure &gt; API Management &gt; API &gt; Regions

_Action Types_

- Azure &gt; API Management &gt; API &gt; Delete
- Azure &gt; API Management &gt; API &gt; Router
- Azure &gt; API Management &gt; API &gt; Update API Protocols</description>
            <pubDate>Fri, 27 Mar 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-v5-43-6</guid>
            <title>aws v5.43.6 - Custom AKAs for Organization resources are now preserved in CMDB</title>
            <link>https://turbot.com/guardrails/changelog/aws-v5-43-6</link>
            <description>_Bug fixes_

- Custom AKAs added to Organization, Organization Root, and Organizational Unit resources were not preserved in Turbot CMDB because their respective CMDB controls would overwrite them. This is now fixed and all such custom AKAs will now be stored correctly in Turbot CMDB.
- Fixed Intelligent Assessment controls to use updated policy URIs.</description>
            <pubDate>Thu, 26 Mar 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-prevention-v5-1-2</guid>
            <title>aws-prevention v5.1.2 - Fixed Control Tower enabled control discovery objective matching</title>
            <link>https://turbot.com/guardrails/changelog/aws-prevention-v5-1-2</link>
            <description>_Bug fixes_

- Control Tower enabled control discovery has been fixed to correctly match objectives via controlGlobalId static mappings — a property name mismatch (`argument` vs `arguments`) caused all matches to silently fail. The `requirePermissionBoundariesForPrivilegedAwsIamRoles` objective now declares `iam:PermissionsBoundary` as a required condition, improving SCP scoring accuracy for negated condition operators. Event data synced for 15 objectives. Unenforced RDS cluster actions and dead `s3:CreateMultipartUpload` action removed from example SCPs.</description>
            <pubDate>Thu, 26 Mar 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ec2-v5-53-0</guid>
            <title>aws-ec2 v5.53.0 - Added support for 21 new ELB security policies including FIPS and Post-Quantum</title>
            <link>https://turbot.com/guardrails/changelog/aws-ec2-v5-53-0</link>
            <description>_What&apos;s new?_

- Updated the `AWS &gt; EC2 &gt; Load Balancer Listener &gt; SSL Policy &gt; Allowed` and `AWS &gt; EC2 &gt; Load Balancer Listener &gt; SSL Policy &gt; Default` policies to include 21 new AWS ELB security policies, covering FIPS, Post-Quantum (PQ), and combined FIPS+PQ categories.</description>
            <pubDate>Thu, 26 Mar 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ecr-v5-17-0</guid>
            <title>aws-ecr v5.17.0 - Added support for enforcing lifecycle policy rules on ECR repositories</title>
            <link>https://turbot.com/guardrails/changelog/aws-ecr-v5-17-0</link>
            <description>_What&apos;s new?_

- Added new `AWS &gt; ECR &gt; Repository &gt; Lifecycle Policy &gt; Required` control that allows customers to enforce lifecycle policy rules on private ECR repositories.

_Control Types_

- AWS &gt; ECR &gt; Repository &gt; Lifecycle Policy
- AWS &gt; ECR &gt; Repository &gt; Lifecycle Policy &gt; Required

_Policy Types_

- AWS &gt; ECR &gt; Repository &gt; Lifecycle Policy
- AWS &gt; ECR &gt; Repository &gt; Lifecycle Policy &gt; Required
- AWS &gt; ECR &gt; Repository &gt; Lifecycle Policy &gt; Required &gt; Items

_Action Types_

- AWS &gt; ECR &gt; Repository &gt; Update Lifecycle Policy</description>
            <pubDate>Wed, 25 Mar 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-lambda-v5-20-0</guid>
            <title>aws-lambda v5.20.0 - CMDB control for function will no longer fail in GovCloud and China partitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-lambda-v5-20-0</link>
            <description>_What&apos;s new?_

_Control Types_

- AWS &gt; Lambda &gt; Function &gt; Allowed
- AWS &gt; Lambda &gt; Function &gt; Allowed &gt; Custom
- AWS &gt; Lambda &gt; Function &gt; Allowed &gt; Region
- AWS &gt; Lambda &gt; Function Alias &gt; Allowed
- AWS &gt; Lambda &gt; Function Alias &gt; Allowed &gt; Custom
- AWS &gt; Lambda &gt; Function Alias &gt; Allowed &gt; Region
- AWS &gt; Lambda &gt; Function Version &gt; Allowed
- AWS &gt; Lambda &gt; Function Version &gt; Allowed &gt; Custom
- AWS &gt; Lambda &gt; Function Version &gt; Allowed &gt; Region
- AWS &gt; Lambda &gt; Layer &gt; Allowed
- AWS &gt; Lambda &gt; Layer &gt; Allowed &gt; Custom
- AWS &gt; Lambda &gt; Layer &gt; Allowed &gt; Region

_Policy Types_

- AWS &gt; Lambda &gt; Allowed Regions [Default]
- AWS &gt; Lambda &gt; Function &gt; Allowed
- AWS &gt; Lambda &gt; Function &gt; Allowed &gt; Custom
- AWS &gt; Lambda &gt; Function &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; Lambda &gt; Function &gt; Allowed &gt; Region
- AWS &gt; Lambda &gt; Function &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; Lambda &gt; Function Alias &gt; Allowed
- AWS &gt; Lambda &gt; Function Alias &gt; Allowed &gt; Custom
- AWS &gt; Lambda &gt; Function Alias &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; Lambda &gt; Function Alias &gt; Allowed &gt; Region
- AWS &gt; Lambda &gt; Function Alias &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; Lambda &gt; Function Version &gt; Allowed
- AWS &gt; Lambda &gt; Function Version &gt; Allowed &gt; Custom
- AWS &gt; Lambda &gt; Function Version &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; Lambda &gt; Function Version &gt; Allowed &gt; Region
- AWS &gt; Lambda &gt; Function Version &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; Lambda &gt; Layer &gt; Allowed
- AWS &gt; Lambda &gt; Layer &gt; Allowed &gt; Custom
- AWS &gt; Lambda &gt; Layer &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; Lambda &gt; Layer &gt; Allowed &gt; Region
- AWS &gt; Lambda &gt; Layer &gt; Allowed &gt; Region &gt; Regions

_Bug fixes_

- Fixed `AWS &gt; Lambda &gt; Function &gt; CMDB` control failing in GovCloud and China partitions. The control now gracefully skips the Function URL configuration lookup in partitions where Lambda Function URLs are not supported.
- Intelligent Assessment controls will now also work with AWS Bedrock and Azure OpenAI credentials.</description>
            <pubDate>Tue, 24 Mar 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ec2-v5-52-0</guid>
            <title>aws-ec2 v5.52.0 - Added support for `Active &gt; Running` policy for EC2 instances</title>
            <link>https://turbot.com/guardrails/changelog/aws-ec2-v5-52-0</link>
            <description>_What&apos;s new?_

- Added a new `AWS &gt; EC2 &gt; Instance &gt; Active &gt; Running` policy that checks whether an EC2 instance is in a running state. Available policy values are `Force inactive if not running`, `Force inactive if not running 24 hours`, and `Force inactive if not running for 48 hours`. Additionally, a new `Delete inactive with 2 days warning` enforcement option has been added to the `AWS &gt; EC2 &gt; Instance &gt; Active` policy.

_Policy Types_

- AWS &gt; EC2 &gt; Instance &gt; Active &gt; Running</description>
            <pubDate>Mon, 23 Mar 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/guardrails-prevention-v5-1-0</guid>
            <title>guardrails-prevention v5.1.0 - Refined LLM extraction prompts for improved output quality</title>
            <link>https://turbot.com/guardrails/changelog/guardrails-prevention-v5-1-0</link>
            <description>_What&apos;s new?_

- Refined the LLM extraction prompts to improve output quality. Titles are now shorter and cleaner, capped at 40 characters without resource names or account IDs. A new overview field captures coverage, limitations, exceptions, and threat context in a structured way. The prompt has also been restructured to separate resource context from title generation, improving extraction accuracy.</description>
            <pubDate>Fri, 20 Mar 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/github-v5-7-0</guid>
            <title>github v5.7.0 - Organization CMDB now includes workflow permissions and fork PR policies</title>
            <link>https://turbot.com/guardrails/changelog/github-v5-7-0</link>
            <description>_What&apos;s new?_

- Organization CMDB data will now also include details for default workflow permissions, fork PR contributor approval policy, fork PR workflows for private repositories, and self-hosted runner access policy.</description>
            <pubDate>Fri, 20 Mar 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/github-prevention-v5-1-0</guid>
            <title>github-prevention v5.1.0 - Added objective to prohibit public repository creation by members</title>
            <link>https://turbot.com/guardrails/changelog/github-prevention-v5-1-0</link>
            <description>_What&apos;s new?_

- Added new objective to prohibit public repository creation by members, and fixed objectives that were missing mappings in their definition to match to their respective preventions correctly.

_Prevention Objectives_

- Prohibit GitHub organization public repository creation by members

_Prevention Examples_

- Block public repository creation for GitHub organization members
- Prohibit public repository creation for GitHub organizations</description>
            <pubDate>Fri, 20 Mar 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-prevention-v5-0-1</guid>
            <title>gcp-prevention v5.0.1 - Fixed incorrect objective matching in prevention discovery controls</title>
            <link>https://turbot.com/guardrails/changelog/gcp-prevention-v5-0-1</link>
            <description>_Bug fixes_

- Prevention discovery controls would sometimes match preventions to objectives incorrectly because of incorrect query limit in GraphQL queries. This is now fixed.</description>
            <pubDate>Fri, 20 Mar 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-prevention-v5-1-0</guid>
            <title>aws-prevention v5.1.0 - Improved SCP and RCP objective matching accuracy</title>
            <link>https://turbot.com/guardrails/changelog/aws-prevention-v5-1-0</link>
            <description>_What&apos;s new?_

- SCP and RCP objective matching has been redesigned for improved accuracy and consistency. Six multi-statement objectives have been split into single-statement sub-objectives for precise matching. RCP deny examples have been added for 18 objectives and unenforceable SCP examples have been removed. Prevention rules now include an `overview` field.

_Prevention Fact Types_

- AWS Condition Scope
- AWS Deny Scope

_Prevention Objectives_

- Enforce IMDSv2 for AWS EC2 instance launch
- Enforce IMDSv2 for running AWS EC2 instances
- Prohibit AWS Elastic IP association
- Prohibit AWS VPC peering connections
- Prohibit AWS cross-region networking services
- Prohibit public IP assignment at AWS EC2 instance launch
- Safeguard AWS EC2 AMI block public access setting from modification
- Safeguard AWS Lambda code signing configuration from modification

_Removed_

- Enforce IMDSv2 for AWS EC2 instances
- Prohibit AWS EC2 cross-region networking
- Prohibit AWS EC2 instance internet access

_Prevention Examples_

- Allow approved AWS services
- Allow resources in approved AWS regions
- Block all public sharing of AWS EBS snapshots
- Block inbound and outbound internet connections to your VPCs through an internet gateway (IGW) or egress-only internet gateway (EIGW)
- Block public sharing of AWS Machine Images (AMIs)
- Deny API actions over insecure transport for AWS S3
- Deny AWS Virtual Private Network (VPN) connections
- Deny EC2 instance launch without IAM instance role
- Deny IAM user management actions without MFA
- Deny access key creation for AWS IAM users
- Deny access key operations for AWS IAM root user
- Deny actions as a root user
- Deny all AWS IAM root user actions
- Deny creation of AWS IAM users
- Deny creation of access keys for the root user
- Deny cross region replication for S3 buckets
- Deny deletion of AWS IAM support access role
- Deny deletion of AWS VPC flow logs
- Deny direct permissions attachment to AWS IAM users
- Deny disablement and deletion of AWS KMS keys
- Deny disablement of AWS Security Hub configuration
- Deny disablement of amazon inspector configuration
- Deny full access policy attachment for AWS CloudShell
- Deny insecure transport at resource level for AWS S3
- Deny modification of AWS CloudTrail configuration
- Deny modification of AWS CloudWatch alarms
- Deny modification of AWS Config configuration
- Deny modification of AWS DynamoDB table point in time recovery configuration
- Deny modification of AWS EBS encryption by default configuration
- Deny modification of AWS EBS snapshot block public access configuration
- Deny modification of AWS EC2 IMDS default settings
- Deny modification of AWS EC2 image block public access configuration
- Deny modification of AWS EC2 serial console access configuration
- Deny modification of AWS IAM Access Analyzer configuration
- Deny modification of AWS IAM role configuration
- Deny modification of AWS IAM role trust policy configuration
- Deny modification of AWS S3 account public access block configuration
- Deny modification of AWS S3 bucket encryption configuration
- Deny modification of AWS S3 bucket lifecycle policy configuration
- Deny modification of AWS S3 bucket logging configuration
- Deny modification of AWS S3 bucket logging configuration
- Deny modification of AWS VPC network ACL rules
- Deny modification of AWS VPC route tables
- Deny modification of AWS VPC security group rules
- Deny modification of AWS VPC security group rules
- Deny modification of AWS account alternate security contact
- Deny modification of AWS account contact information
- Deny policy changes to an AWS S3 bucket
- Deny public function URLs for AWS Lambda
- Deny public resource policies for AWS Lambda functions
- Deny publicly accessible creation for AWS RDS DB instances
- Deny removal of AWS IAM permission boundaries
- Deny removal of AWS IAM root user MFA devices
- Deny removal of AWS IAM user MFA devices
- Deny replication configuration for AWS S3 buckets
- Deny resource creation without security classification tags
- Deny resources in unapproved AWS regions
- Deny resources in unapproved regions
- Deny resources in unapproved regions in landing zone
- Deny sharing of public AWS EBS snapshots
- Deny single-AZ creation for AWS RDS DB instances
- Deny the use of AWS EC2 VM import and export
- Deny the use of deprecated AWS EC2 RequestSpotFleet and RequestSpotInstances API actions
- Deny unapproved AWS EC2 instance types
- Deny unapproved AWS services
- Deny unencrypted creation for AWS EBS volumes
- Deny unencrypted creation for AWS EFS file systems
- Deny unencrypted creation for AWS RDS DB instances
- Deny unencrypted listeners for AWS Elastic Load Balancing
- Deny versioning changes for AWS S3 buckets
- Deny virtual MFA operations for AWS IAM root user
- Deny weakening of AWS IAM account password policy
- Deny weakening of AWS IAM account password policy
- Deny weakening of AWS IAM account password policy
- Deny wildcard administrative policy attachment for AWS IAM
- Disable AWS EC2 Serial Console access
- Disable access to the EC2 serial console for all EC2 instances
- Enable AWS EBS Snapshot Block Public Access for account
- Enable AWS EBS encryption by default for account
- Enable AWS EC2 Image Block Public Access
- Enable account-level Block Public Access for AWS S3
- Enable account-level Block Public Access for AWS S3
- Enable account-level Block Public Access for AWS S3
- Enable account-level Block Public Access for AWS S3
- Enforce AWS GuardDuty enablement
- Enforce Access Logging for AWS S3 Buckets
- Enforce Block Public Access for AWS S3 accounts
- Enforce Block Public Access for AWS S3 accounts
- Enforce Block Public Access for AWS S3 accounts
- Enforce Block Public Access for AWS S3 accounts
- Enforce Block Public Access for AWS S3 buckets
- Enforce Block Public Access for AWS S3 buckets
- Enforce Block Public Access for AWS S3 buckets
- Enforce Block Public Access for AWS S3 buckets
- Enforce HTTPS-only access for AWS S3 buckets
- Enforce IAM instance roles for AWS EC2 instances
- Enforce IMDSv2 defaults for AWS EC2 account attributes
- Enforce IMDSv2 for AWS EC2 instances
- Enforce IMDSv2 for running AWS EC2 instances
- Enforce MFA Delete for AWS S3 buckets
- Enforce Multi-AZ deployments for AWS RDS DB instances
- Enforce approved AMI sources for AWS EC2 instances
- Enforce approved accounts for AWS Lambda functions
- Enforce approved images for AWS EC2 AMIs
- Enforce approved instance types for AWS EC2 instances
- Enforce auto minor version upgrade for AWS RDS DB instances
- Enforce block public ACLs for AWS S3 buckets
- Enforce block public policy for AWS S3 buckets
- Enforce deactivation of unused AWS IAM access keys
- Enforce default security groups with no rules to restrict all traffic for AWS VPC security groups
- Enforce encryption at rest for AWS CloudTrail logs
- Enforce encryption at rest for AWS RDS DB instances
- Enforce encryption by default for AWS EC2 accounts
- Enforce encryption for AWS EFS file systems
- Enforce group-based permissions for AWS IAM users
- Enforce ignore public ACLs for AWS S3 buckets
- Enforce lifecycle policies for AWS S3 buckets
- Enforce lifecycle policies for versioned AWS S3 buckets
- Enforce minimum password length for AWS IAM password policy
- Enforce non-public accessibility for AWS RDS DB instances
- Enforce password reuse prevention for AWS IAM password policy
- Enforce removal of AWS IAM AWSCloudShellFullAccess policy
- Enforce removal of AWS IAM users
- Enforce removal of AdministratorAccess policy for AWS IAM
- Enforce removal of expired AWS IAM server certificates
- Enforce removal of login profiles for AWS IAM users
- Enforce restrict public buckets for AWS S3 buckets
- Enforce rotation of AWS IAM access keys every 90 days
- Enforce secure Network ACL configurations denying public access to admin ports for AWS VPC Network ACLs
- Enforce secure security group configurations denying public access to admin ports for AWS VPC security groups
- Enforce single active access key per AWS IAM user
- Enforce versioning for AWS S3 buckets
- Enforce versioning for AWS S3 buckets
- Prevent IAM policies with wildcard actions via Guard
- Prevent IAM policies with wildcard actions via Lambda
- Prevent IAM policies with wildcard actions via proactive control
- Prevent S3 buckets without versioning via Guard
- Prevent S3 buckets without versioning via Lambda
- Prevent S3 buckets without versioning via proactive control
- Prevent creation of AWS EC2 instances with IMDSv1 via Guard
- Prevent creation of AWS EC2 instances with IMDSv1 via Lambda
- Prevent public S3 bucket creation via Guard
- Prevent public S3 bucket creation via Guard
- Prevent public S3 bucket creation via Guard
- Prevent public S3 bucket creation via Guard
- Prohibit AWS EBS direct API calls
- Prohibit AWS EBS snapshot public restore
- Prohibit AWS EBS snapshot public sharing
- Prohibit AWS EC2 VM import and export
- Prohibit AWS EC2 deprecated Spot instance APIs
- Prohibit AWS Elastic IP association
- Prohibit AWS VPC VPN connections
- Prohibit AWS VPC internet connections
- Prohibit AWS VPC peering connections
- Prohibit AWS cross-region networking services
- Prohibit IAM Customer Managed Policies with Wildcard Service Actions
- Prohibit IAM Inline Policies with Administrative Wildcard Permissions
- Prohibit IAM Managed Policies with Administrative Wildcard Permissions
- Prohibit Public AWS ECR Repositories
- Prohibit public IP assignment at AWS EC2 instance launch
- Prohibit public internet access to AWS VPC resources
- Require AWS CloudHSM key origin for AWS KMS keys
- Require AWS CloudHSM key origin for AWS KMS keys
- Require AWS IAM privileged role permission boundaries
- Require AWS KMS grants only for AWS services
- Require AWS KMS grants only for AWS services
- Require Block Public Access for S3 Buckets
- Require Block Public Access for S3 Buckets
- Require Block Public Access for S3 Buckets
- Require Block Public Access for S3 Buckets
- Require Encryption for EBS Volumes
- Require Encryption for Launch Template EBS Volumes
- Require IMDSv2 for AWS EC2 instance launch
- Require KMS encryption for AWS S3 buckets
- Require MFA for AWS IAM root user actions
- Require MFA for AWS S3 bucket versioning configuration changes
- Require MFA for AWS SSM Session Manager
- Require MFA for delete actions on S3 buckets
- Require RSA key length greater than 2048 bits for AWS KMS asymmetric keys
- Require RSA key length greater than 2048 bits for AWS KMS asymmetric keys
- Require Server Side Encryption for S3 Buckets
- Require VPC endpoints for AWS DynamoDB access
- Require all object uploads to AWS S3 buckets to use server-side encryption with an AWS KMS key (SSE-KMS)
- Require an AWS EBS snapshot to be created from an encrypted EC2 volume
- Require approved AWS Marketplace subscriptions
- Require approved sources for AWS ECR container registry
- Require approved sources for AWS Lambda layers
- Require attribute-based access control for AWS IAM sensitive data access
- Require bypass policy lockout safety check for AWS KMS keys
- Require bypass policy lockout safety check for AWS KMS keys
- Require code signing for AWS Lambda functions
- Require encryption at rest for AWS EBS snapshots
- Require external key store key origin for AWS KMS keys
- Require external key store key origin for AWS KMS keys
- Require imported key material for AWS KMS keys
- Require imported key material for AWS KMS keys
- Require organization-only access for AWS KMS resources
- Require organization-only access for AWS KMS resources
- Require that AWS EBS direct APIs are not called
- Require that an AWS EBS snapshot cannot be publicly restorable
- Require that an attached AWS EBS volume is configured to encrypt data at rest
- Safeguard AWS EC2 AMI block public access setting from modification
- Safeguard AWS Lambda code signing configuration from modification
- Safeguard AWS S3 bucket encryption configuration from modification
- Safeguard AWS S3 bucket policies from modification
- Set IMDSv2 defaults for AWS EC2 instances
- Set comprehensive password policy for AWS IAM
- Set minimum password length for AWS IAM password policy
- Set password reuse prevention for AWS IAM password policy

_Removed_

- Allow approved AWS services
- Allow resources in approved AWS regions
- Block all public sharing of AWS EBS snapshots
- Block inbound and outbound internet connections to your VPCs through an internet gateway (IGW) or egress-only internet gateway (EIGW)
- Block public sharing of AWS Machine Images (AMIs)
- Deny API actions over insecure transport for AWS S3
- Deny AWS Virtual Private Network (VPN) connections
- Deny EC2 instance launch without IAM instance role
- Deny access key creation for AWS IAM users
- Deny access key operations for AWS IAM root user
- Deny actions as a root user
- Deny all AWS IAM root user actions
- Deny creation of AWS IAM users
- Deny creation of access keys for the root user
- Deny credential updates for AWS IAM users
- Deny cross region replication for S3 buckets
- Deny cross-region networking for AWS EC2, AWS CloudFront, and AWS Global Accelerator
- Deny deletion of AWS IAM support access role
- Deny deletion of AWS VPC flow logs
- Deny direct permissions attachment to AWS IAM users
- Deny disablement and deletion of AWS KMS keys
- Deny disablement of AWS GuardDuty configuration
- Deny disablement of AWS Security Hub configuration
- Deny disablement of amazon inspector configuration
- Deny full access policy attachment for AWS CloudShell
- Deny insecure transport at resource level for AWS S3
- Deny internet access for an AWS VPC instance managed by a customer
- Deny modification of AWS CloudTrail configuration
- Deny modification of AWS CloudWatch alarms
- Deny modification of AWS Config configuration
- Deny modification of AWS DynamoDB table point in time recovery configuration
- Deny modification of AWS EBS encryption by default configuration
- Deny modification of AWS EBS snapshot block public access configuration
- Deny modification of AWS EC2 IMDS default settings
- Deny modification of AWS EC2 image block public access configuration
- Deny modification of AWS EC2 instance IMDSv2 configuration
- Deny modification of AWS EC2 serial console access configuration
- Deny modification of AWS IAM Access Analyzer configuration
- Deny modification of AWS IAM role configuration
- Deny modification of AWS IAM role trust policy configuration
- Deny modification of AWS S3 account public access block configuration
- Deny modification of AWS S3 account public access block configuration
- Deny modification of AWS S3 bucket encryption configuration
- Deny modification of AWS S3 bucket lifecycle policy configuration
- Deny modification of AWS S3 bucket logging configuration
- Deny modification of AWS S3 bucket logging configuration
- Deny modification of AWS S3 bucket object lock configuration
- Deny modification of AWS VPC network ACL rules
- Deny modification of AWS VPC route tables
- Deny modification of AWS VPC security group rules
- Deny modification of AWS account alternate security contact
- Deny modification of AWS account contact information
- Deny password operations for AWS IAM users
- Deny policy changes to an AWS S3 bucket
- Deny public function URLs for AWS Lambda
- Deny public repository creation for AWS ECR
- Deny public resource policies for AWS Lambda functions
- Deny publicly accessible creation for AWS RDS DB instances
- Deny removal of AWS IAM permission boundaries
- Deny removal of AWS IAM root user MFA devices
- Deny removal of AWS IAM user MFA devices
- Deny replication configuration for AWS S3 buckets
- Deny resource creation without security classification tags
- Deny resources in unapproved AWS regions
- Deny resources in unapproved regions
- Deny resources in unapproved regions in landing zone
- Deny sharing of public AWS EBS snapshots
- Deny single-AZ creation for AWS RDS DB instances
- Deny the use of AWS EC2 VM import and export
- Deny the use of deprecated AWS EC2 RequestSpotFleet and RequestSpotInstances API actions
- Deny unapproved AWS EC2 instance types
- Deny unapproved AWS services
- Deny unencrypted creation for AWS EBS volumes
- Deny unencrypted creation for AWS EFS file systems
- Deny unencrypted creation for AWS RDS DB instances
- Deny unencrypted listeners for AWS Elastic Load Balancing
- Deny versioning changes for AWS S3 buckets
- Deny virtual MFA operations for AWS IAM root user
- Deny weakening of AWS IAM account password policy
- Deny wildcard administrative policy attachment for AWS IAM
- Disable AWS EC2 Serial Console access
- Disable access to the EC2 serial console for all EC2 instances
- Enable AWS EBS Snapshot Block Public Access for account
- Enable AWS EBS encryption by default for account
- Enable AWS EC2 Image Block Public Access
- Enable account-level Block Public Access for AWS S3
- Enforce Access Logging for AWS S3 Buckets
- Enforce Block Public Access for AWS S3 accounts
- Enforce Block Public Access for AWS S3 buckets
- Enforce HTTPS-only access for AWS S3 buckets
- Enforce IAM instance roles for AWS EC2 instances
- Enforce IMDSv2 defaults for AWS EC2 account attributes
- Enforce IMDSv2 for AWS EC2 instances
- Enforce Multi-AZ deployments for AWS RDS DB instances
- Enforce approved AMI sources for AWS EC2 instances
- Enforce approved accounts for AWS Lambda functions
- Enforce approved images for AWS EC2 AMIs
- Enforce approved instance types for AWS EC2 instances
- Enforce auto minor version upgrade for AWS RDS DB instances
- Enforce deactivation of unused AWS IAM access keys
- Enforce default security groups with no rules to restrict all traffic for AWS VPC security groups
- Enforce encryption at rest for AWS CloudTrail logs
- Enforce encryption at rest for AWS RDS DB instances
- Enforce encryption by default for AWS EC2 accounts
- Enforce encryption for AWS EFS file systems
- Enforce group-based permissions for AWS IAM users
- Enforce lifecycle policies for AWS S3 buckets
- Enforce lifecycle policies for versioned AWS S3 buckets
- Enforce minimum password length for AWS IAM password policy
- Enforce non-public accessibility for AWS RDS DB instances
- Enforce password reuse prevention for AWS IAM password policy
- Enforce removal of AWS IAM AWSCloudShellFullAccess policy
- Enforce removal of AWS IAM users
- Enforce removal of AdministratorAccess policy for AWS IAM
- Enforce removal of expired AWS IAM server certificates
- Enforce removal of login profiles for AWS IAM users
- Enforce rotation of AWS IAM access keys every 90 days
- Enforce secure Network ACL configurations denying public access to admin ports for AWS VPC Network ACLs
- Enforce secure security group configurations denying public access to admin ports for AWS VPC security groups
- Enforce single active access key per AWS IAM user
- Enforce versioning for AWS S3 buckets
- Prevent IAM policies with wildcard actions via Guard
- Prevent IAM policies with wildcard actions via Lambda
- Prevent IAM policies with wildcard actions via proactive control
- Prevent S3 buckets without versioning via Guard
- Prevent S3 buckets without versioning via Lambda
- Prevent S3 buckets without versioning via proactive control
- Prevent creation of AWS EC2 instances with IMDSv1 via Guard
- Prevent creation of AWS EC2 instances with IMDSv1 via Lambda
- Prevent public S3 bucket creation via Guard
- Prohibit IAM Customer Managed Policies with Wildcard Service Actions
- Prohibit IAM Inline Policies with Administrative Wildcard Permissions
- Prohibit IAM Managed Policies with Administrative Wildcard Permissions
- Require AWS CloudHSM key origin for AWS KMS keys
- Require AWS IAM privileged role permission boundaries
- Require AWS KMS grants only for AWS services
- Require Block Public Access for S3 Buckets
- Require Encryption for EBS Volumes
- Require Encryption for Launch Template EBS Volumes
- Require IMDSv2 for AWS EC2 instances
- Require MFA for AWS IAM root user actions
- Require MFA for AWS IAM user actions
- Require MFA for AWS S3 bucket versioning configuration changes
- Require MFA for AWS SSM Session Manager
- Require MFA for delete actions on S3 buckets
- Require RSA key length greater than 2048 bits for AWS KMS asymmetric keys
- Require Server Side Encryption for S3 Buckets
- Require VPC endpoints for AWS DynamoDB access
- Require VPC endpoints for AWS S3 access
- Require all object uploads to AWS S3 buckets to use server-side encryption with an AWS KMS key (SSE-KMS)
- Require an AWS EBS snapshot to be created from an encrypted EC2 volume
- Require approved AMI sources for AWS EC2 instances
- Require approved AWS Marketplace subscriptions
- Require approved sources for AWS ECR container registry
- Require approved sources for AWS Lambda layers
- Require attribute-based access control for AWS IAM sensitive data access
- Require bypass policy lockout safety check for AWS KMS keys
- Require code signing for AWS Lambda functions
- Require external key store key origin for AWS KMS keys
- Require imported key material for AWS KMS keys
- Require organization accounts for AWS STS assume role
- Require organization-only access for AWS KMS resources
- Require that AWS EBS direct APIs are not called
- Require that an AWS EBS snapshot cannot be publicly restorable
- Require that an attached AWS EBS volume is configured to encrypt data at rest
- Set IMDSv2 defaults for AWS EC2 instances
- Set comprehensive password policy for AWS IAM
- Set minimum password length for AWS IAM password policy
- Set password reuse prevention for AWS IAM password policy</description>
            <pubDate>Fri, 20 Mar 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/oci-v5-0-2</guid>
            <title>oci v5.0.2 - OCI credentials are now redacted in control logs</title>
            <link>https://turbot.com/guardrails/changelog/oci-v5-0-2</link>
            <description>_Bug fixes_

- Fixed OCI credentials being visible in control logs. Credential fields are now automatically redacted and will appear as `&lt;sensitive&gt;` in process logs.
- OCI tenancy and compartment resources will now have the `cloudParentId` set correctly.</description>
            <pubDate>Thu, 19 Mar 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/oci-storage-v5-1-0</guid>
            <title>oci-storage v5.1.0 - Manage bucket public access and versioning</title>
            <link>https://turbot.com/guardrails/changelog/oci-storage-v5-1-0</link>
            <description>_Bug fixes_

- Fixed OCI credentials being visible in control logs. Credential fields are now automatically redacted and will appear as `&lt;sensitive&gt;` in process logs.

_Control Types_

- OCI &gt; Storage &gt; Bucket &gt; Public Access
- OCI &gt; Storage &gt; Bucket &gt; Versioning

_Policy Types_

- OCI &gt; Storage &gt; Bucket &gt; Public Access
- OCI &gt; Storage &gt; Bucket &gt; Versioning

_Action Types_

- OCI &gt; Storage &gt; Bucket &gt; Disable Versioning
- OCI &gt; Storage &gt; Bucket &gt; Enable Versioning
- OCI &gt; Storage &gt; Bucket &gt; Set Private
- OCI &gt; Storage &gt; Bucket &gt; Set Public - Object Read
- OCI &gt; Storage &gt; Bucket &gt; Set Public - Object Read Without List
- OCI &gt; Storage &gt; Bucket &gt; Set Public Access</description>
            <pubDate>Thu, 19 Mar 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/oci-credential-redaction-release</guid>
            <title>OCI mods updated with credential redaction</title>
            <link>https://turbot.com/guardrails/changelog/oci-credential-redaction-release</link>
            <description>_Bug fixes_

- The following OCI mods have been updated to redact credentials in control logs. Credential fields will now automatically appear as `&lt;sensitive&gt;` in process logs.

  - oci-networking `v5.0.1`
  - oci-compute `v5.0.1`
  - oci-iam `v5.0.1`</description>
            <pubDate>Thu, 19 Mar 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-v5-35-1</guid>
            <title>gcp v5.35.1 - Project CMDB control now handles rate limiting and transient errors gracefully</title>
            <link>https://turbot.com/guardrails/changelog/gcp-v5-35-1</link>
            <description>_Bug fixes_

- The `GCP &gt; Project &gt; CMDB` control would sometimes enter an error state due to rate limiting or transient errors. It now properly handles such errors.</description>
            <pubDate>Thu, 19 Mar 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-prevention-v5-0-0</guid>
            <title>azure-prevention v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/azure-prevention-v5-0-0</link>
            <description>_What&apos;s new?_

_Control Types_

- Azure &gt; Access Review Schedule Definition &gt; Prevention
- Azure &gt; Access Review Schedule Definition &gt; Prevention &gt; Discovery
- Azure &gt; Authorization Policy &gt; Prevention
- Azure &gt; Authorization Policy &gt; Prevention &gt; Discovery
- Azure &gt; Conditional Access Policy &gt; Prevention
- Azure &gt; Conditional Access Policy &gt; Prevention &gt; Discovery
- Azure &gt; Device Registration Policy &gt; Prevention
- Azure &gt; Device Registration Policy &gt; Prevention &gt; Discovery
- Azure &gt; Group Setting &gt; Prevention
- Azure &gt; Group Setting &gt; Prevention &gt; Discovery
- Azure &gt; Identity Security Defaults Enforcement Policy &gt; Prevention
- Azure &gt; Identity Security Defaults Enforcement Policy &gt; Prevention &gt; Discovery
- Azure &gt; Policy Assignment &gt; Built-in Policy Prevention
- Azure &gt; Policy Assignment &gt; Built-in Policy Prevention &gt; Discovery
- Azure &gt; Policy Assignment &gt; Custom Policy Prevention
- Azure &gt; Policy Assignment &gt; Custom Policy Prevention &gt; Discovery
- Azure &gt; Subscription &gt; Prevention
- Azure &gt; Subscription &gt; Prevention &gt; Discovery
- Azure &gt; Subscription Policy &gt; Prevention
- Azure &gt; Subscription Policy &gt; Prevention &gt; Discovery
- Azure &gt; Tenant &gt; Prevention
- Azure &gt; Tenant &gt; Prevention &gt; Discovery

_Prevention Types_

- Azure Built-In Policy
- Azure Custom Policy
- Azure Databricks Cluster Policy
- Azure Resource Provider Registration
- Azure Subscription Policy
- Entra ID Access Review
- Entra ID Authentication Methods Policy
- Entra ID Authorization Policy
- Entra ID Conditional Access Policy
- Entra ID Device Registration Policy
- Entra ID Group Setting
- Entra ID Security Defaults Policy

_Prevention Benchmarks_

- Azure CIS v5.0.0
- Azure P1 Preventions</description>
            <pubDate>Thu, 19 Mar 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-iam-v5-48-0</guid>
            <title>aws-iam v5.48.0 - Tag Guardrails-managed IAM policies</title>
            <link>https://turbot.com/guardrails/changelog/aws-iam-v5-48-0</link>
            <description>_What&apos;s new?_

- Added `AWS &gt; Turbot &gt; Permissions &gt; Policy &gt; Tags` policy to support tagging Guardrails-managed IAM policies. Tags defined in this policy are applied to all IAM policies created by the Guardrails IAM stack.

_Policy Types_

- AWS &gt; Turbot &gt; Permissions &gt; Policy &gt; Tags</description>
            <pubDate>Thu, 19 Mar 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/mass-azure-mod-release-event-grid</guid>
            <title>Azure mods updated with Event Grid support for real-time event handling</title>
            <link>https://turbot.com/guardrails/changelog/mass-azure-mod-release-event-grid</link>
            <description>_What&apos;s new?_

- The following Azure mods have been updated with support for Azure Event Grid–based event handlers to enable real-time event processing. Each mod now includes custom event patterns for its resource types, allowing the `Azure &gt; Turbot &gt; Event Handlers [Event Grid]` control to automatically generate the correct event subscriptions. To get started, set the `Azure &gt; Turbot &gt; Event Handlers [Event Grid]` policy to `Enforce: Configured`.

  - azure-aks `v5.12.0`
  - azure-alertsmanagement `v5.1.0`
  - azure-apimanagement `v5.9.0`
  - azure-applicationgateway `v5.12.0`
  - azure-applicationinsights `v5.13.0`
  - azure-appservice `v5.18.0`
  - azure-automation `v5.6.0`
  - azure-botservice `v5.1.0`
  - azure-cognitiveservices `v5.1.0`
  - azure-compute `v5.28.0`
  - azure-containerregistry `v5.8.0`
  - azure-cosmosdb `v5.14.0`
  - azure-databricks `v5.9.0`
  - azure-datafactory `v5.12.0`
  - azure-dns `v5.13.0`
  - azure-firewall `v5.12.0`
  - azure-iam `v5.17.0`
  - azure-keyvault `v5.21.0`
  - azure-loadbalancer `v5.12.0`
  - azure-loganalytics `v5.14.0`
  - azure-managedidentity `v5.6.0`
  - azure-monitor `v5.14.0`
  - azure-mysql `v5.20.0`
  - azure-network `v5.30.0`
  - azure-networkwatcher `v5.16.0`
  - azure-postgresql `v5.22.0`
  - azure-provider `v5.23.0`
  - azure-recoveryservice `v5.11.0`
  - azure-redis `v5.2.0`
  - azure-relay `v5.7.0`
  - azure-searchmanagement `v5.13.0`
  - azure-securitycenter `v5.10.0`
  - azure-servicebus `v5.7.0`
  - azure-signalr `v5.7.0`
  - azure-sql `v5.22.0`
  - azure-sqlvirtualmachine `v5.5.0`
  - azure-storage `v5.32.0`
  - azure-synapseanalytics `v5.15.0`
  - azure-virtualdesktop `v5.1.0`

_Note_

This feature requires `@turbot/azure` v5.36.0 or later and TE v5.55.6 or later. Event Grid support is currently available only in Azure Commercial Cloud (not Gov Cloud).</description>
            <pubDate>Thu, 19 Mar 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-v5-35-0</guid>
            <title>gcp v5.35.0 - Track and manage organization policy and organization policy constraint resources</title>
            <link>https://turbot.com/guardrails/changelog/gcp-v5-35-0</link>
            <description>_Resource Types_

- GCP &gt; Organization Policy
- GCP &gt; Organization Policy Constraint

_Control Types_

- GCP &gt; Organization Policy &gt; CMDB
- GCP &gt; Organization Policy &gt; Discovery
- GCP &gt; Organization Policy Constraint &gt; CMDB
- GCP &gt; Organization Policy Constraint &gt; Discovery

_Policy Types_

- GCP &gt; Organization Policy &gt; CMDB
- GCP &gt; Organization Policy Constraint &gt; CMDB

_Action Types_

- GCP &gt; Organization Policy &gt; Router
- GCP &gt; Organization Policy Constraint &gt; Router</description>
            <pubDate>Wed, 18 Mar 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-prevention-v5-0-0</guid>
            <title>gcp-prevention v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/gcp-prevention-v5-0-0</link>
            <description>_What&apos;s new?_

_Control Types_

- GCP &gt; Organization Policy &gt; Custom Policy Prevention
- GCP &gt; Organization Policy &gt; Custom Policy Prevention &gt; Discovery
- GCP &gt; Organization Policy &gt; Predefined Policy Prevention
- GCP &gt; Organization Policy &gt; Predefined Policy Prevention &gt; Discovery
- GCP &gt; Organization Policy Constraint &gt; Prevention
- GCP &gt; Organization Policy Constraint &gt; Prevention &gt; Discovery
- GCP &gt; Project &gt; API Enabled Prevention
- GCP &gt; Project &gt; API Enabled Prevention &gt; Discovery

_Prevention Types_

- GCP API State
- GCP Custom Organization Policy
- GCP Default Enforced Constraint
- GCP Predefined Organization Policy

_Prevention Benchmarks_

- GCP CIS v4.0.0
- GCP P1 Preventions</description>
            <pubDate>Wed, 18 Mar 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/github-v5-6-1</guid>
            <title>github v5.6.1 - Organization and repository resources now have the correct cloudParentId</title>
            <link>https://turbot.com/guardrails/changelog/github-v5-6-1</link>
            <description>_Bug fixes_

- GitHub organization and repository resources will now have the `cloudParentId` set correctly.</description>
            <pubDate>Tue, 17 Mar 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/github-v5-6-0</guid>
            <title>github v5.6.0 - Track and manage branch and ruleset resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/github-v5-6-0</link>
            <description>_What&apos;s new?_

_Resource Types_

- GitHub &gt; Branch
- GitHub &gt; Ruleset

_Control Types_

- GitHub &gt; Branch &gt; CMDB
- GitHub &gt; Branch &gt; Discovery
- GitHub &gt; Ruleset &gt; CMDB
- GitHub &gt; Ruleset &gt; Discovery

_Policy Types_

- GitHub &gt; Branch &gt; CMDB
- GitHub &gt; Ruleset &gt; CMDB

_Action Types_

- GitHub &gt; Branch &gt; Router
- GitHub &gt; Ruleset &gt; Router</description>
            <pubDate>Tue, 17 Mar 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/github-prevention-v5-0-0</guid>
            <title>github-prevention v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/github-prevention-v5-0-0</link>
            <description>_What&apos;s new?_

_Control Types_

- GitHub &gt; Branch &gt; Protection Prevention
- GitHub &gt; Branch &gt; Protection Prevention &gt; Discovery
- GitHub &gt; Organization &gt; Setting Prevention
- GitHub &gt; Organization &gt; Setting Prevention &gt; Discovery
- GitHub &gt; Repository &gt; Setting Prevention
- GitHub &gt; Repository &gt; Setting Prevention &gt; Discovery
- GitHub &gt; Ruleset &gt; Ruleset Prevention
- GitHub &gt; Ruleset &gt; Ruleset Prevention &gt; Discovery

_Prevention Types_

- GitHub Actions Permission
- GitHub Branch Protection
- GitHub Branch Ruleset
- GitHub Organization Setting
- GitHub Repository Setting
- GitHub Tag Ruleset

_Prevention Benchmarks_

- GitHub CIS v1.1.0
- GitHub P1 Preventions</description>
            <pubDate>Tue, 17 Mar 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-v5-43-5</guid>
            <title>aws v5.43.5 - Account resource AKAs in CMDB will now be set more reliably</title>
            <link>https://turbot.com/guardrails/changelog/aws-v5-43-5</link>
            <description>_Bug fixes_

- The AKAs for account resources in CMDB will now be set more reliably by the `AWS &gt; Account &gt; Discovery` control.</description>
            <pubDate>Tue, 17 Mar 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-bedrock-v5-5-0</guid>
            <title>aws-bedrock v5.5.0 - Add Bedrock-specific region exceptions for cross-region inference</title>
            <link>https://turbot.com/guardrails/changelog/aws-bedrock-v5-5-0</link>
            <description>_What&apos;s new?_

- Added `AWS &gt; Bedrock &gt; Permissions &gt; Lockdown &gt; Regions` policy to allow Bedrock-specific region exceptions for cross-region inference. When configured, Bedrock API calls are allowed in both the global lockdown regions and the additional Bedrock-specific regions.

_Policy Types_

- AWS &gt; Bedrock &gt; Permissions &gt; Lockdown &gt; Regions
- AWS &gt; Turbot &gt; Permissions &gt; Compiled &gt; Lockdown Statements &gt; @turbot/aws-bedrock</description>
            <pubDate>Mon, 16 Mar 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-v5-39-0</guid>
            <title>azure v5.39.0 - Subscription CMDB data now includes registered resource providers</title>
            <link>https://turbot.com/guardrails/changelog/azure-v5-39-0</link>
            <description>_What&apos;s new?_

- Subscription CMDB data now also includes details of the registered resource providers.</description>
            <pubDate>Fri, 13 Mar 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-v5-38-0</guid>
            <title>azure v5.38.0 - Added support for Azure Policy resource types and Management Group Activity Log Poller</title>
            <link>https://turbot.com/guardrails/changelog/azure-v5-38-0</link>
            <description>_Resource Types_

- Azure &gt; Policy Assignment
- Azure &gt; Policy Definition
- Azure &gt; Policy Set Definition
- Azure &gt; Subscription Policy

_Control Types_

- Azure &gt; Policy Assignment &gt; Active
- Azure &gt; Policy Assignment &gt; CMDB
- Azure &gt; Policy Assignment &gt; Discovery
- Azure &gt; Policy Definition &gt; Active
- Azure &gt; Policy Definition &gt; CMDB
- Azure &gt; Policy Definition &gt; Discovery
- Azure &gt; Policy Set Definition &gt; CMDB
- Azure &gt; Policy Set Definition &gt; Discovery
- Azure &gt; Subscription Policy &gt; CMDB
- Azure &gt; Subscription Policy &gt; Discovery
- Azure &gt; Turbot &gt; Management Group Activity Log Poller

_Policy Types_

- Azure &gt; Policy Assignment &gt; Active
- Azure &gt; Policy Assignment &gt; Active &gt; Age
- Azure &gt; Policy Assignment &gt; Active &gt; Last Modified
- Azure &gt; Policy Assignment &gt; CMDB
- Azure &gt; Policy Definition &gt; Active
- Azure &gt; Policy Definition &gt; Active &gt; Age
- Azure &gt; Policy Definition &gt; Active &gt; Last Modified
- Azure &gt; Policy Definition &gt; CMDB
- Azure &gt; Policy Set Definition &gt; CMDB
- Azure &gt; Subscription Policy &gt; CMDB
- Azure &gt; Turbot &gt; Management Group Activity Log Poller
- Azure &gt; Turbot &gt; Management Group Activity Log Poller &gt; Excluded Events
- Azure &gt; Turbot &gt; Management Group Activity Log Poller &gt; Interval
- Azure &gt; Turbot &gt; Management Group Activity Log Poller &gt; Window

_Action Types_

- Azure &gt; Management Group &gt; Management Group Activity Log Poller
- Azure &gt; Management Group &gt; Management Group Event Handler
- Azure &gt; Policy Assignment &gt; Delete
- Azure &gt; Policy Assignment &gt; Router
- Azure &gt; Policy Definition &gt; Delete
- Azure &gt; Policy Definition &gt; Router
- Azure &gt; Policy Set Definition &gt; Delete
- Azure &gt; Policy Set Definition &gt; Router
- Azure &gt; Subscription Policy &gt; Router</description>
            <pubDate>Thu, 12 Mar 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-v5-37-0</guid>
            <title>azure v5.37.0 - Added support for tenant-level identity and access resources</title>
            <link>https://turbot.com/guardrails/changelog/azure-v5-37-0</link>
            <description>_Resource Types_

- Azure &gt; Access Review Schedule Definition
- Azure &gt; Authentication Methods Policy
- Azure &gt; Authorization Policy
- Azure &gt; Conditional Access Policy
- Azure &gt; Device Registration Policy
- Azure &gt; Group Setting
- Azure &gt; Identity Security Defaults Enforcement Policy

_Control Types_

- Azure &gt; Access Review Schedule Definition &gt; CMDB
- Azure &gt; Access Review Schedule Definition &gt; Discovery
- Azure &gt; Authentication Methods Policy &gt; CMDB
- Azure &gt; Authentication Methods Policy &gt; Discovery
- Azure &gt; Authorization Policy &gt; CMDB
- Azure &gt; Authorization Policy &gt; Discovery
- Azure &gt; Conditional Access Policy &gt; CMDB
- Azure &gt; Conditional Access Policy &gt; Discovery
- Azure &gt; Device Registration Policy &gt; CMDB
- Azure &gt; Device Registration Policy &gt; Discovery
- Azure &gt; Group Setting &gt; CMDB
- Azure &gt; Group Setting &gt; Discovery
- Azure &gt; Identity Security Defaults Enforcement Policy &gt; CMDB
- Azure &gt; Identity Security Defaults Enforcement Policy &gt; Discovery
- Azure &gt; Turbot &gt; Tenant Event Poller

_Policy Types_

- Azure &gt; Access Review Schedule Definition &gt; CMDB
- Azure &gt; Authentication Methods Policy &gt; CMDB
- Azure &gt; Authorization Policy &gt; CMDB
- Azure &gt; Conditional Access Policy &gt; CMDB
- Azure &gt; Device Registration Policy &gt; CMDB
- Azure &gt; Group Setting &gt; CMDB
- Azure &gt; Identity Security Defaults Enforcement Policy &gt; CMDB
- Azure &gt; Turbot &gt; Tenant Event Poller
- Azure &gt; Turbot &gt; Tenant Event Poller &gt; Excluded Events
- Azure &gt; Turbot &gt; Tenant Event Poller &gt; Interval
- Azure &gt; Turbot &gt; Tenant Event Poller &gt; Window

_Action Types_

- Azure &gt; Access Review Schedule Definition &gt; Delete
- Azure &gt; Access Review Schedule Definition &gt; Router
- Azure &gt; Authentication Methods Policy &gt; Router
- Azure &gt; Authorization Policy &gt; Router
- Azure &gt; Conditional Access Policy &gt; Delete
- Azure &gt; Device Registration Policy &gt; Router
- Azure &gt; Group Setting &gt; Delete
- Azure &gt; Group Setting &gt; Router
- Azure &gt; Identity Security Defaults Enforcement Policy &gt; Router
- Azure &gt; Tenant &gt; Event Poller
- Azure &gt; Tenant &gt; Tenant Event Handler</description>
            <pubDate>Tue, 10 Mar 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-vpc-security-v5-16-2</guid>
            <title>aws-vpc-security v5.16.2 - Fixed Security Group Rule CMDB control failing with duplicate AKA constraint violation</title>
            <link>https://turbot.com/guardrails/changelog/aws-vpc-security-v5-16-2</link>
            <description>_Bug fixes_

- Fixed an issue where the `AWS &gt; VPC &gt; Security Group Rule &gt; CMDB` control could fail with a duplicate AKA constraint violation when security group rules were rapidly deleted and recreated. Security group rules now use the `SecurityGroupRuleId`-based AKA, which is always available and guaranteed to be unique by AWS.</description>
            <pubDate>Tue, 10 Mar 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-iam-v5-23-1</guid>
            <title>gcp-iam v5.23.1 - Fixed Service Account CMDB control not refreshing on IAM role binding changes</title>
            <link>https://turbot.com/guardrails/changelog/gcp-iam-v5-23-1</link>
            <description>_Bug fixes_

- The `GCP &gt; IAM &gt; Service Account &gt; CMDB` control did not refresh when project-level IAM role bindings changed in GCP. This caused downstream controls to evaluate stale data. This has now been fixed.
- The `GCP &gt; IAM &gt; Service Account &gt; Project Role Bindings &gt; Approved` control failed with 409 Conflict errors when multiple service accounts in the same project had unapproved roles. This has now been fixed.</description>
            <pubDate>Fri, 06 Mar 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-v5-36-0</guid>
            <title>azure v5.36.0 - Real-time event handling via Azure Event Grid</title>
            <link>https://turbot.com/guardrails/changelog/azure-v5-36-0</link>
            <description>_What&apos;s new?_

- Added `Azure &gt; Turbot &gt; Event Handlers [Event Grid]` control for real-time event handling using Azure Event Grid as an alternative to Activity Log Alerts. Supports flexible System Topic management and custom event pattern generation for enabled resource types. To get started, set the `Azure &gt; Turbot &gt; Event Handlers [Event Grid]` policy to `Enforce: Configured`.

_Control Types_

- Azure &gt; Turbot &gt; Event Handlers [Event Grid]

_Policy Types_

- Azure &gt; Turbot &gt; Event Handlers [Event Grid]
- Azure &gt; Turbot &gt; Event Handlers [Event Grid] &gt; Custom Event Patterns
- Azure &gt; Turbot &gt; Event Handlers [Event Grid] &gt; Custom Event Patterns &gt; @turbot/azure
- Azure &gt; Turbot &gt; Event Handlers [Event Grid] &gt; Event Subscription
- Azure &gt; Turbot &gt; Event Handlers [Event Grid] &gt; Event Subscription &gt; Name Prefix
- Azure &gt; Turbot &gt; Event Handlers [Event Grid] &gt; Source
- Azure &gt; Turbot &gt; Event Handlers [Event Grid] &gt; System Topic
- Azure &gt; Turbot &gt; Event Handlers [Event Grid] &gt; System Topic &gt; Name
- Azure &gt; Turbot &gt; Event Handlers [Event Grid] &gt; System Topic &gt; Name Prefix
- Azure &gt; Turbot &gt; Event Handlers [Event Grid] &gt; System Topic &gt; Resource Group
- Azure &gt; Turbot &gt; Event Handlers [Event Grid] &gt; System Topic &gt; Tags
- Azure &gt; Turbot &gt; Event Handlers [Event Grid] &gt; System Topic Mode
- Azure &gt; Turbot &gt; Event Handlers [Event Grid] &gt; Version

_Note_

This feature requires TE v5.55.6 or later and is currently supported only in Azure Commercial Cloud (not Gov Cloud).</description>
            <pubDate>Tue, 03 Mar 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ecr-v5-16-2</guid>
            <title>aws-ecr v5.16.2 - Image router now correctly evaluates the CMDB policy at the repository level</title>
            <link>https://turbot.com/guardrails/changelog/aws-ecr-v5-16-2</link>
            <description>_Bug fixes_

- The `AWS &gt; ECR &gt; Image &gt; Router` action was incorrectly evaluating the `AWS &gt; ECR &gt; Image &gt; CMDB` policy at the region level instead of the repository level. This caused image resources to be upserted and then immediately deleted when the policy was set to `Enforce: Disabled` or `Skip` at the repository level (e.g., via a Policy Pack). The router now correctly evaluates the policy at the repository level.</description>
            <pubDate>Mon, 02 Mar 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ec2-v5-51-3</guid>
            <title>aws-ec2 v5.51.3 - Optimized GraphQL queries for multiple EC2 controls and actions</title>
            <link>https://turbot.com/guardrails/changelog/aws-ec2-v5-51-3</link>
            <description>_Bug fixes_

- We&apos;ve optimized the GraphQL queries for the `AWS &gt; EC2 &gt; Instance &gt; Approved`, `AWS &gt; EC2 &gt; Volume &gt; Approved`, and `AWS &gt; EC2 &gt; Account Attributes &gt; EBS Encryption by Default` controls, and the `AWS &gt; EC2 &gt; Network Interface &gt; Router` action. You won&apos;t notice any difference, but they should run a lot lighter now.</description>
            <pubDate>Fri, 27 Feb 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ec2-v5-51-2</guid>
            <title>aws-ec2 v5.51.2 - Optimized GraphQL queries for Snapshot Approved and Active controls</title>
            <link>https://turbot.com/guardrails/changelog/aws-ec2-v5-51-2</link>
            <description>_Bug fixes_

- We&apos;ve optimized the GraphQL queries for the `AWS &gt; EC2 &gt; Snapshot &gt; Approved` and `AWS &gt; EC2 &gt; Snapshot &gt; Active` controls. You won&apos;t notice any difference, but they should run much more efficiently now.</description>
            <pubDate>Thu, 26 Feb 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-69-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.69.0 - Amazon Linux 2023 migration and TLS 1.3 support</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-69-0</link>
            <description>_What&apos;s new?_

- Added support for additional EC2 instance types: R6a, R6g, R7a, and R7i.
- The default operating system for EC2 hosts has been upgraded to Amazon Linux 2023, with updated container image paths and startup configuration to match.
- Network load balancers and API endpoints now support TLS 1.3 for stronger encryption.</description>
            <pubDate>Tue, 24 Feb 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-55-5</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.55.5 - Improved materialization performance</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-55-5</link>
            <description>_What&apos;s new?_

- Server
  - Improved materialization performance by preventing controls from blocking on in-progress policy evaluations.

_Requirements_

- Upgrade to `5.55.5` requires your workspace to be on `5.54.x`
- PostgreSQL (RDS engine): &gt;= 15
- TEF: 1.69.0
- TED: 1.37.0
- Mods:
  - @turbot/turbot: 5.56.0

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Tue, 24 Feb 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-networkwatcher-v5-15-0</guid>
            <title>azure-networkwatcher v5.15.0 - Manage tags for Network Watcher Flow Log resources</title>
            <link>https://turbot.com/guardrails/changelog/azure-networkwatcher-v5-15-0</link>
            <description>_What&apos;s new?_

- Users can now create and manage tags for flow log resources. To get started, set the `Azure &gt; Network Watcher &gt; Flow Log &gt; Tags &gt; *` policies.

_Control Types_

- Azure &gt; Network Watcher &gt; Flow Log &gt; Allowed
- Azure &gt; Network Watcher &gt; Flow Log &gt; Allowed &gt; Custom
- Azure &gt; Network Watcher &gt; Flow Log &gt; Tags
- Azure &gt; Network Watcher &gt; Network Watcher &gt; Allowed
- Azure &gt; Network Watcher &gt; Network Watcher &gt; Allowed &gt; Custom
- Azure &gt; Network Watcher &gt; Network Watcher &gt; Allowed &gt; Region

_Policy Types_

- Azure &gt; Network Watcher &gt; Allowed Regions [Default]
- Azure &gt; Network Watcher &gt; Flow Log &gt; Allowed
- Azure &gt; Network Watcher &gt; Flow Log &gt; Allowed &gt; Custom
- Azure &gt; Network Watcher &gt; Flow Log &gt; Allowed &gt; Custom &gt; Rules
- Azure &gt; Network Watcher &gt; Flow Log &gt; Tags
- Azure &gt; Network Watcher &gt; Flow Log &gt; Tags &gt; Template
- Azure &gt; Network Watcher &gt; Network Watcher &gt; Allowed
- Azure &gt; Network Watcher &gt; Network Watcher &gt; Allowed &gt; Custom
- Azure &gt; Network Watcher &gt; Network Watcher &gt; Allowed &gt; Custom &gt; Rules
- Azure &gt; Network Watcher &gt; Network Watcher &gt; Allowed &gt; Region
- Azure &gt; Network Watcher &gt; Network Watcher &gt; Allowed &gt; Region &gt; Regions

_Action Types_

- Azure &gt; Network Watcher &gt; Flow Log &gt; Set Tags</description>
            <pubDate>Mon, 23 Feb 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-monitor-v5-13-0</guid>
            <title>azure-monitor v5.13.0 - Track and manage data collection endpoint resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-monitor-v5-13-0</link>
            <description>_Resource Types_

- Azure &gt; Monitor &gt; Data Collection Endpoint

_Control Types_

- Azure &gt; Monitor &gt; Action Group &gt; Allowed
- Azure &gt; Monitor &gt; Action Group &gt; Allowed &gt; Custom
- Azure &gt; Monitor &gt; Alerts &gt; Allowed
- Azure &gt; Monitor &gt; Alerts &gt; Allowed &gt; Custom
- Azure &gt; Monitor &gt; Data Collection Endpoint &gt; Active
- Azure &gt; Monitor &gt; Data Collection Endpoint &gt; Allowed
- Azure &gt; Monitor &gt; Data Collection Endpoint &gt; Allowed &gt; Custom
- Azure &gt; Monitor &gt; Data Collection Endpoint &gt; Allowed &gt; Region
- Azure &gt; Monitor &gt; Data Collection Endpoint &gt; CMDB
- Azure &gt; Monitor &gt; Data Collection Endpoint &gt; Discovery
- Azure &gt; Monitor &gt; Data Collection Endpoint &gt; Tags
- Azure &gt; Monitor &gt; Log Profile &gt; Allowed
- Azure &gt; Monitor &gt; Log Profile &gt; Allowed &gt; Custom
- Azure &gt; Monitor &gt; Metric Alert &gt; Allowed
- Azure &gt; Monitor &gt; Metric Alert &gt; Allowed &gt; Custom

_Policy Types_

- Azure &gt; Monitor &gt; Action Group &gt; Allowed
- Azure &gt; Monitor &gt; Action Group &gt; Allowed &gt; Custom
- Azure &gt; Monitor &gt; Action Group &gt; Allowed &gt; Custom &gt; Rules
- Azure &gt; Monitor &gt; Alerts &gt; Allowed
- Azure &gt; Monitor &gt; Alerts &gt; Allowed &gt; Custom
- Azure &gt; Monitor &gt; Alerts &gt; Allowed &gt; Custom &gt; Rules
- Azure &gt; Monitor &gt; Allowed Regions [Default]
- Azure &gt; Monitor &gt; Approved Regions [Default]
- Azure &gt; Monitor &gt; Data Collection Endpoint &gt; Active
- Azure &gt; Monitor &gt; Data Collection Endpoint &gt; Active &gt; Age
- Azure &gt; Monitor &gt; Data Collection Endpoint &gt; Active &gt; Last Modified
- Azure &gt; Monitor &gt; Data Collection Endpoint &gt; Allowed
- Azure &gt; Monitor &gt; Data Collection Endpoint &gt; Allowed &gt; Custom
- Azure &gt; Monitor &gt; Data Collection Endpoint &gt; Allowed &gt; Custom &gt; Rules
- Azure &gt; Monitor &gt; Data Collection Endpoint &gt; Allowed &gt; Region
- Azure &gt; Monitor &gt; Data Collection Endpoint &gt; Allowed &gt; Region &gt; Regions
- Azure &gt; Monitor &gt; Data Collection Endpoint &gt; CMDB
- Azure &gt; Monitor &gt; Data Collection Endpoint &gt; Regions
- Azure &gt; Monitor &gt; Data Collection Endpoint &gt; Tags
- Azure &gt; Monitor &gt; Data Collection Endpoint &gt; Tags &gt; Template
- Azure &gt; Monitor &gt; Log Profile &gt; Allowed
- Azure &gt; Monitor &gt; Log Profile &gt; Allowed &gt; Custom
- Azure &gt; Monitor &gt; Log Profile &gt; Allowed &gt; Custom &gt; Rules
- Azure &gt; Monitor &gt; Metric Alert &gt; Allowed
- Azure &gt; Monitor &gt; Metric Alert &gt; Allowed &gt; Custom
- Azure &gt; Monitor &gt; Metric Alert &gt; Allowed &gt; Custom &gt; Rules
- Azure &gt; Monitor &gt; Regions

_Action Types_

- Azure &gt; Monitor &gt; Data Collection Endpoint &gt; Delete
- Azure &gt; Monitor &gt; Data Collection Endpoint &gt; Router
- Azure &gt; Monitor &gt; Data Collection Endpoint &gt; Set Tags</description>
            <pubDate>Mon, 23 Feb 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-cognitiveservices-v5-0-0</guid>
            <title>azure-cognitiveservices v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/azure-cognitiveservices-v5-0-0</link>
            <description>_Resource Types_

- Azure &gt; Cognitive Services
- Azure &gt; Cognitive Services &gt; Account

_Control Types_

- Azure &gt; Cognitive Services &gt; Account &gt; Active
- Azure &gt; Cognitive Services &gt; Account &gt; Allowed
- Azure &gt; Cognitive Services &gt; Account &gt; Allowed &gt; Custom
- Azure &gt; Cognitive Services &gt; Account &gt; Allowed &gt; Region
- Azure &gt; Cognitive Services &gt; Account &gt; CMDB
- Azure &gt; Cognitive Services &gt; Account &gt; Discovery
- Azure &gt; Cognitive Services &gt; Account &gt; Tags

_Policy Types_

- Azure &gt; Cognitive Services &gt; Account &gt; Active
- Azure &gt; Cognitive Services &gt; Account &gt; Active &gt; Age
- Azure &gt; Cognitive Services &gt; Account &gt; Active &gt; Last Modified
- Azure &gt; Cognitive Services &gt; Account &gt; Allowed
- Azure &gt; Cognitive Services &gt; Account &gt; Allowed &gt; Custom
- Azure &gt; Cognitive Services &gt; Account &gt; Allowed &gt; Custom &gt; Rules
- Azure &gt; Cognitive Services &gt; Account &gt; Allowed &gt; Region
- Azure &gt; Cognitive Services &gt; Account &gt; Allowed &gt; Region &gt; Regions
- Azure &gt; Cognitive Services &gt; Account &gt; CMDB
- Azure &gt; Cognitive Services &gt; Account &gt; Regions
- Azure &gt; Cognitive Services &gt; Account &gt; Tags
- Azure &gt; Cognitive Services &gt; Account &gt; Tags &gt; Template
- Azure &gt; Cognitive Services &gt; Allowed Regions [Default]
- Azure &gt; Cognitive Services &gt; Approved Regions [Default]
- Azure &gt; Cognitive Services &gt; Enabled
- Azure &gt; Cognitive Services &gt; Permissions
- Azure &gt; Cognitive Services &gt; Permissions &gt; Levels
- Azure &gt; Cognitive Services &gt; Permissions &gt; Levels &gt; Modifiers
- Azure &gt; Cognitive Services &gt; Regions
- Azure &gt; Cognitive Services &gt; Tags Template [Default]
- Azure &gt; Turbot &gt; Permissions &gt; Compiled &gt; Levels &gt; @turbot/azure-cognitiveservices
- Azure &gt; Turbot &gt; Permissions &gt; Compiled &gt; Service Permissions &gt; @turbot/azure-cognitiveservices

_Action Types_

- Azure &gt; Cognitive Services &gt; Account &gt; Delete
- Azure &gt; Cognitive Services &gt; Account &gt; Router
- Azure &gt; Cognitive Services &gt; Account &gt; Set Tags</description>
            <pubDate>Mon, 23 Feb 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-botservice-v5-0-0</guid>
            <title>azure-botservice v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/azure-botservice-v5-0-0</link>
            <description>_Resource Types_

- Azure &gt; Bot Service
- Azure &gt; Bot Service &gt; Bot

_Control Types_

- Azure &gt; Bot Service &gt; Bot &gt; Active
- Azure &gt; Bot Service &gt; Bot &gt; Allowed
- Azure &gt; Bot Service &gt; Bot &gt; Allowed &gt; Custom
- Azure &gt; Bot Service &gt; Bot &gt; Allowed &gt; Region
- Azure &gt; Bot Service &gt; Bot &gt; CMDB
- Azure &gt; Bot Service &gt; Bot &gt; Discovery
- Azure &gt; Bot Service &gt; Bot &gt; Tags

_Policy Types_

- Azure &gt; Bot Service &gt; Allowed Regions [Default]
- Azure &gt; Bot Service &gt; Approved Regions [Default]
- Azure &gt; Bot Service &gt; Bot &gt; Active
- Azure &gt; Bot Service &gt; Bot &gt; Active &gt; Age
- Azure &gt; Bot Service &gt; Bot &gt; Active &gt; Last Modified
- Azure &gt; Bot Service &gt; Bot &gt; Allowed
- Azure &gt; Bot Service &gt; Bot &gt; Allowed &gt; Custom
- Azure &gt; Bot Service &gt; Bot &gt; Allowed &gt; Custom &gt; Rules
- Azure &gt; Bot Service &gt; Bot &gt; Allowed &gt; Region
- Azure &gt; Bot Service &gt; Bot &gt; Allowed &gt; Region &gt; Regions
- Azure &gt; Bot Service &gt; Bot &gt; CMDB
- Azure &gt; Bot Service &gt; Bot &gt; Regions
- Azure &gt; Bot Service &gt; Bot &gt; Tags
- Azure &gt; Bot Service &gt; Bot &gt; Tags &gt; Template
- Azure &gt; Bot Service &gt; Enabled
- Azure &gt; Bot Service &gt; Permissions
- Azure &gt; Bot Service &gt; Permissions &gt; Levels
- Azure &gt; Bot Service &gt; Permissions &gt; Levels &gt; Modifiers
- Azure &gt; Bot Service &gt; Regions
- Azure &gt; Bot Service &gt; Tags Template [Default]
- Azure &gt; Turbot &gt; Permissions &gt; Compiled &gt; Levels &gt; @turbot/azure-botservice
- Azure &gt; Turbot &gt; Permissions &gt; Compiled &gt; Service Permissions &gt; @turbot/azure-botservice

_Action Types_

- Azure &gt; Bot Service &gt; Bot &gt; Delete
- Azure &gt; Bot Service &gt; Bot &gt; Router
- Azure &gt; Bot Service &gt; Bot &gt; Set Tags</description>
            <pubDate>Mon, 23 Feb 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-appservice-v5-17-0</guid>
            <title>azure-appservice v5.17.0 - Track and manage connection resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-appservice-v5-17-0</link>
            <description>_Resource Types_

- Azure &gt; App Service &gt; Connection

_Control Types_

- Azure &gt; App Service &gt; App Service Plan &gt; Allowed
- Azure &gt; App Service &gt; App Service Plan &gt; Allowed &gt; Custom
- Azure &gt; App Service &gt; App Service Plan &gt; Allowed &gt; Region
- Azure &gt; App Service &gt; Connection &gt; Active
- Azure &gt; App Service &gt; Connection &gt; Allowed
- Azure &gt; App Service &gt; Connection &gt; Allowed &gt; Custom
- Azure &gt; App Service &gt; Connection &gt; Allowed &gt; Region
- Azure &gt; App Service &gt; Connection &gt; CMDB
- Azure &gt; App Service &gt; Connection &gt; Discovery
- Azure &gt; App Service &gt; Connection &gt; Tags
- Azure &gt; App Service &gt; Function App &gt; Allowed
- Azure &gt; App Service &gt; Function App &gt; Allowed &gt; Custom
- Azure &gt; App Service &gt; Function App &gt; Allowed &gt; Region
- Azure &gt; App Service &gt; Web App &gt; Allowed
- Azure &gt; App Service &gt; Web App &gt; Allowed &gt; Custom
- Azure &gt; App Service &gt; Web App &gt; Allowed &gt; Region

_Policy Types_

- Azure &gt; App Service &gt; Allowed Regions [Default]
- Azure &gt; App Service &gt; App Service Plan &gt; Allowed
- Azure &gt; App Service &gt; App Service Plan &gt; Allowed &gt; Custom
- Azure &gt; App Service &gt; App Service Plan &gt; Allowed &gt; Custom &gt; Rules
- Azure &gt; App Service &gt; App Service Plan &gt; Allowed &gt; Region
- Azure &gt; App Service &gt; App Service Plan &gt; Allowed &gt; Region &gt; Regions
- Azure &gt; App Service &gt; Connection &gt; Active
- Azure &gt; App Service &gt; Connection &gt; Active &gt; Age
- Azure &gt; App Service &gt; Connection &gt; Active &gt; Last Modified
- Azure &gt; App Service &gt; Connection &gt; Allowed
- Azure &gt; App Service &gt; Connection &gt; Allowed &gt; Custom
- Azure &gt; App Service &gt; Connection &gt; Allowed &gt; Custom &gt; Rules
- Azure &gt; App Service &gt; Connection &gt; Allowed &gt; Region
- Azure &gt; App Service &gt; Connection &gt; Allowed &gt; Region &gt; Regions
- Azure &gt; App Service &gt; Connection &gt; CMDB
- Azure &gt; App Service &gt; Connection &gt; Regions
- Azure &gt; App Service &gt; Connection &gt; Tags
- Azure &gt; App Service &gt; Connection &gt; Tags &gt; Template
- Azure &gt; App Service &gt; Function App &gt; Allowed
- Azure &gt; App Service &gt; Function App &gt; Allowed &gt; Custom
- Azure &gt; App Service &gt; Function App &gt; Allowed &gt; Custom &gt; Rules
- Azure &gt; App Service &gt; Function App &gt; Allowed &gt; Region
- Azure &gt; App Service &gt; Function App &gt; Allowed &gt; Region &gt; Regions
- Azure &gt; App Service &gt; Web App &gt; Allowed
- Azure &gt; App Service &gt; Web App &gt; Allowed &gt; Custom
- Azure &gt; App Service &gt; Web App &gt; Allowed &gt; Custom &gt; Rules
- Azure &gt; App Service &gt; Web App &gt; Allowed &gt; Region
- Azure &gt; App Service &gt; Web App &gt; Allowed &gt; Region &gt; Regions

_Action Types_

- Azure &gt; App Service &gt; Connection &gt; Delete
- Azure &gt; App Service &gt; Connection &gt; Router
- Azure &gt; App Service &gt; Connection &gt; Set Tags</description>
            <pubDate>Mon, 23 Feb 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-alertsmanagement-v5-0-0</guid>
            <title>azure-alertsmanagement v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/azure-alertsmanagement-v5-0-0</link>
            <description>_Resource Types_

- Azure &gt; Alerts Management
- Azure &gt; Alerts Management &gt; Smart Detector Alert Rule

_Control Types_

- Azure &gt; Alerts Management &gt; Smart Detector Alert Rule &gt; Active
- Azure &gt; Alerts Management &gt; Smart Detector Alert Rule &gt; Allowed
- Azure &gt; Alerts Management &gt; Smart Detector Alert Rule &gt; Allowed &gt; Custom
- Azure &gt; Alerts Management &gt; Smart Detector Alert Rule &gt; CMDB
- Azure &gt; Alerts Management &gt; Smart Detector Alert Rule &gt; Discovery
- Azure &gt; Alerts Management &gt; Smart Detector Alert Rule &gt; Tags

_Policy Types_

- Azure &gt; Alerts Management &gt; Allowed Regions [Default]
- Azure &gt; Alerts Management &gt; Approved Regions [Default]
- Azure &gt; Alerts Management &gt; Enabled
- Azure &gt; Alerts Management &gt; Permissions
- Azure &gt; Alerts Management &gt; Permissions &gt; Levels
- Azure &gt; Alerts Management &gt; Permissions &gt; Levels &gt; Modifiers
- Azure &gt; Alerts Management &gt; Regions
- Azure &gt; Alerts Management &gt; Smart Detector Alert Rule &gt; Active
- Azure &gt; Alerts Management &gt; Smart Detector Alert Rule &gt; Active &gt; Age
- Azure &gt; Alerts Management &gt; Smart Detector Alert Rule &gt; Active &gt; Last Modified
- Azure &gt; Alerts Management &gt; Smart Detector Alert Rule &gt; Active &gt; Status
- Azure &gt; Alerts Management &gt; Smart Detector Alert Rule &gt; Allowed
- Azure &gt; Alerts Management &gt; Smart Detector Alert Rule &gt; Allowed &gt; Custom
- Azure &gt; Alerts Management &gt; Smart Detector Alert Rule &gt; Allowed &gt; Custom &gt; Rules
- Azure &gt; Alerts Management &gt; Smart Detector Alert Rule &gt; CMDB
- Azure &gt; Alerts Management &gt; Smart Detector Alert Rule &gt; Regions
- Azure &gt; Alerts Management &gt; Smart Detector Alert Rule &gt; Tags
- Azure &gt; Alerts Management &gt; Smart Detector Alert Rule &gt; Tags &gt; Template
- Azure &gt; Alerts Management &gt; Tags Template [Default]
- Azure &gt; Turbot &gt; Permissions &gt; Compiled &gt; Levels &gt; @turbot/azure-alertsmanagement
- Azure &gt; Turbot &gt; Permissions &gt; Compiled &gt; Service Permissions &gt; @turbot/azure-alertsmanagement

_Action Types_

- Azure &gt; Alerts Management &gt; Smart Detector Alert Rule &gt; Delete
- Azure &gt; Alerts Management &gt; Smart Detector Alert Rule &gt; Router
- Azure &gt; Alerts Management &gt; Smart Detector Alert Rule &gt; Set Tags</description>
            <pubDate>Mon, 23 Feb 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/oci-networking-v5-0-0</guid>
            <title>oci-networking v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/oci-networking-v5-0-0</link>
            <description>_Resource Types_

- OCI &gt; Networking
- OCI &gt; Networking &gt; DRG
- OCI &gt; Networking &gt; Internet Gateway
- OCI &gt; Networking &gt; Load Balancer
- OCI &gt; Networking &gt; NAT Gateway
- OCI &gt; Networking &gt; Network Security Group
- OCI &gt; Networking &gt; Route Table
- OCI &gt; Networking &gt; Security List
- OCI &gt; Networking &gt; Service Gateway
- OCI &gt; Networking &gt; Subnet
- OCI &gt; Networking &gt; VCN

_Control Types_

- OCI &gt; Networking &gt; DRG &gt; Allowed
- OCI &gt; Networking &gt; DRG &gt; Allowed &gt; Custom
- OCI &gt; Networking &gt; DRG &gt; Allowed &gt; Region
- OCI &gt; Networking &gt; DRG &gt; CMDB
- OCI &gt; Networking &gt; DRG &gt; Defined Tags
- OCI &gt; Networking &gt; DRG &gt; Discovery
- OCI &gt; Networking &gt; DRG &gt; Freeform Tags
- OCI &gt; Networking &gt; Internet Gateway &gt; Allowed
- OCI &gt; Networking &gt; Internet Gateway &gt; Allowed &gt; Custom
- OCI &gt; Networking &gt; Internet Gateway &gt; Allowed &gt; Region
- OCI &gt; Networking &gt; Internet Gateway &gt; CMDB
- OCI &gt; Networking &gt; Internet Gateway &gt; Defined Tags
- OCI &gt; Networking &gt; Internet Gateway &gt; Discovery
- OCI &gt; Networking &gt; Internet Gateway &gt; Freeform Tags
- OCI &gt; Networking &gt; Load Balancer &gt; Allowed
- OCI &gt; Networking &gt; Load Balancer &gt; Allowed &gt; Custom
- OCI &gt; Networking &gt; Load Balancer &gt; Allowed &gt; Region
- OCI &gt; Networking &gt; Load Balancer &gt; CMDB
- OCI &gt; Networking &gt; Load Balancer &gt; Defined Tags
- OCI &gt; Networking &gt; Load Balancer &gt; Discovery
- OCI &gt; Networking &gt; Load Balancer &gt; Freeform Tags
- OCI &gt; Networking &gt; NAT Gateway &gt; Allowed
- OCI &gt; Networking &gt; NAT Gateway &gt; Allowed &gt; Custom
- OCI &gt; Networking &gt; NAT Gateway &gt; Allowed &gt; Region
- OCI &gt; Networking &gt; NAT Gateway &gt; CMDB
- OCI &gt; Networking &gt; NAT Gateway &gt; Defined Tags
- OCI &gt; Networking &gt; NAT Gateway &gt; Discovery
- OCI &gt; Networking &gt; NAT Gateway &gt; Freeform Tags
- OCI &gt; Networking &gt; Network Security Group &gt; Allowed
- OCI &gt; Networking &gt; Network Security Group &gt; Allowed &gt; Custom
- OCI &gt; Networking &gt; Network Security Group &gt; Allowed &gt; Region
- OCI &gt; Networking &gt; Network Security Group &gt; CMDB
- OCI &gt; Networking &gt; Network Security Group &gt; Defined Tags
- OCI &gt; Networking &gt; Network Security Group &gt; Discovery
- OCI &gt; Networking &gt; Network Security Group &gt; Freeform Tags
- OCI &gt; Networking &gt; Route Table &gt; Allowed
- OCI &gt; Networking &gt; Route Table &gt; Allowed &gt; Custom
- OCI &gt; Networking &gt; Route Table &gt; Allowed &gt; Region
- OCI &gt; Networking &gt; Route Table &gt; CMDB
- OCI &gt; Networking &gt; Route Table &gt; Defined Tags
- OCI &gt; Networking &gt; Route Table &gt; Discovery
- OCI &gt; Networking &gt; Route Table &gt; Freeform Tags
- OCI &gt; Networking &gt; Security List &gt; Allowed
- OCI &gt; Networking &gt; Security List &gt; Allowed &gt; Custom
- OCI &gt; Networking &gt; Security List &gt; Allowed &gt; Region
- OCI &gt; Networking &gt; Security List &gt; CMDB
- OCI &gt; Networking &gt; Security List &gt; Defined Tags
- OCI &gt; Networking &gt; Security List &gt; Discovery
- OCI &gt; Networking &gt; Security List &gt; Freeform Tags
- OCI &gt; Networking &gt; Service Gateway &gt; Allowed
- OCI &gt; Networking &gt; Service Gateway &gt; Allowed &gt; Custom
- OCI &gt; Networking &gt; Service Gateway &gt; Allowed &gt; Region
- OCI &gt; Networking &gt; Service Gateway &gt; CMDB
- OCI &gt; Networking &gt; Service Gateway &gt; Defined Tags
- OCI &gt; Networking &gt; Service Gateway &gt; Discovery
- OCI &gt; Networking &gt; Service Gateway &gt; Freeform Tags
- OCI &gt; Networking &gt; Subnet &gt; Allowed
- OCI &gt; Networking &gt; Subnet &gt; Allowed &gt; Custom
- OCI &gt; Networking &gt; Subnet &gt; Allowed &gt; Region
- OCI &gt; Networking &gt; Subnet &gt; CMDB
- OCI &gt; Networking &gt; Subnet &gt; Defined Tags
- OCI &gt; Networking &gt; Subnet &gt; Discovery
- OCI &gt; Networking &gt; Subnet &gt; Freeform Tags
- OCI &gt; Networking &gt; VCN &gt; Allowed
- OCI &gt; Networking &gt; VCN &gt; Allowed &gt; Custom
- OCI &gt; Networking &gt; VCN &gt; Allowed &gt; Region
- OCI &gt; Networking &gt; VCN &gt; CMDB
- OCI &gt; Networking &gt; VCN &gt; Defined Tags
- OCI &gt; Networking &gt; VCN &gt; Discovery
- OCI &gt; Networking &gt; VCN &gt; Freeform Tags

_Policy Types_

- OCI &gt; Networking &gt; Allowed Regions [Default]
- OCI &gt; Networking &gt; DRG &gt; Allowed
- OCI &gt; Networking &gt; DRG &gt; Allowed &gt; Custom
- OCI &gt; Networking &gt; DRG &gt; Allowed &gt; Custom &gt; Rules
- OCI &gt; Networking &gt; DRG &gt; Allowed &gt; Region
- OCI &gt; Networking &gt; DRG &gt; Allowed &gt; Region &gt; Regions
- OCI &gt; Networking &gt; DRG &gt; CMDB
- OCI &gt; Networking &gt; DRG &gt; Defined Tags
- OCI &gt; Networking &gt; DRG &gt; Defined Tags &gt; Template
- OCI &gt; Networking &gt; DRG &gt; Freeform Tags
- OCI &gt; Networking &gt; DRG &gt; Freeform Tags &gt; Template
- OCI &gt; Networking &gt; Internet Gateway &gt; Allowed
- OCI &gt; Networking &gt; Internet Gateway &gt; Allowed &gt; Custom
- OCI &gt; Networking &gt; Internet Gateway &gt; Allowed &gt; Custom &gt; Rules
- OCI &gt; Networking &gt; Internet Gateway &gt; Allowed &gt; Region
- OCI &gt; Networking &gt; Internet Gateway &gt; Allowed &gt; Region &gt; Regions
- OCI &gt; Networking &gt; Internet Gateway &gt; CMDB
- OCI &gt; Networking &gt; Internet Gateway &gt; Defined Tags
- OCI &gt; Networking &gt; Internet Gateway &gt; Defined Tags &gt; Template
- OCI &gt; Networking &gt; Internet Gateway &gt; Freeform Tags
- OCI &gt; Networking &gt; Internet Gateway &gt; Freeform Tags &gt; Template
- OCI &gt; Networking &gt; Load Balancer &gt; Allowed
- OCI &gt; Networking &gt; Load Balancer &gt; Allowed &gt; Custom
- OCI &gt; Networking &gt; Load Balancer &gt; Allowed &gt; Custom &gt; Rules
- OCI &gt; Networking &gt; Load Balancer &gt; Allowed &gt; Region
- OCI &gt; Networking &gt; Load Balancer &gt; Allowed &gt; Region &gt; Regions
- OCI &gt; Networking &gt; Load Balancer &gt; CMDB
- OCI &gt; Networking &gt; Load Balancer &gt; Defined Tags
- OCI &gt; Networking &gt; Load Balancer &gt; Defined Tags &gt; Template
- OCI &gt; Networking &gt; Load Balancer &gt; Freeform Tags
- OCI &gt; Networking &gt; Load Balancer &gt; Freeform Tags &gt; Template
- OCI &gt; Networking &gt; NAT Gateway &gt; Allowed
- OCI &gt; Networking &gt; NAT Gateway &gt; Allowed &gt; Custom
- OCI &gt; Networking &gt; NAT Gateway &gt; Allowed &gt; Custom &gt; Rules
- OCI &gt; Networking &gt; NAT Gateway &gt; Allowed &gt; Region
- OCI &gt; Networking &gt; NAT Gateway &gt; Allowed &gt; Region &gt; Regions
- OCI &gt; Networking &gt; NAT Gateway &gt; CMDB
- OCI &gt; Networking &gt; NAT Gateway &gt; Defined Tags
- OCI &gt; Networking &gt; NAT Gateway &gt; Defined Tags &gt; Template
- OCI &gt; Networking &gt; NAT Gateway &gt; Freeform Tags
- OCI &gt; Networking &gt; NAT Gateway &gt; Freeform Tags &gt; Template
- OCI &gt; Networking &gt; Network Security Group &gt; Allowed
- OCI &gt; Networking &gt; Network Security Group &gt; Allowed &gt; Custom
- OCI &gt; Networking &gt; Network Security Group &gt; Allowed &gt; Custom &gt; Rules
- OCI &gt; Networking &gt; Network Security Group &gt; Allowed &gt; Region
- OCI &gt; Networking &gt; Network Security Group &gt; Allowed &gt; Region &gt; Regions
- OCI &gt; Networking &gt; Network Security Group &gt; CMDB
- OCI &gt; Networking &gt; Network Security Group &gt; Defined Tags
- OCI &gt; Networking &gt; Network Security Group &gt; Defined Tags &gt; Template
- OCI &gt; Networking &gt; Network Security Group &gt; Freeform Tags
- OCI &gt; Networking &gt; Network Security Group &gt; Freeform Tags &gt; Template
- OCI &gt; Networking &gt; Regions
- OCI &gt; Networking &gt; Route Table &gt; Allowed
- OCI &gt; Networking &gt; Route Table &gt; Allowed &gt; Custom
- OCI &gt; Networking &gt; Route Table &gt; Allowed &gt; Custom &gt; Rules
- OCI &gt; Networking &gt; Route Table &gt; Allowed &gt; Region
- OCI &gt; Networking &gt; Route Table &gt; Allowed &gt; Region &gt; Regions
- OCI &gt; Networking &gt; Route Table &gt; CMDB
- OCI &gt; Networking &gt; Route Table &gt; Defined Tags
- OCI &gt; Networking &gt; Route Table &gt; Defined Tags &gt; Template
- OCI &gt; Networking &gt; Route Table &gt; Freeform Tags
- OCI &gt; Networking &gt; Route Table &gt; Freeform Tags &gt; Template
- OCI &gt; Networking &gt; Security List &gt; Allowed
- OCI &gt; Networking &gt; Security List &gt; Allowed &gt; Custom
- OCI &gt; Networking &gt; Security List &gt; Allowed &gt; Custom &gt; Rules
- OCI &gt; Networking &gt; Security List &gt; Allowed &gt; Region
- OCI &gt; Networking &gt; Security List &gt; Allowed &gt; Region &gt; Regions
- OCI &gt; Networking &gt; Security List &gt; CMDB
- OCI &gt; Networking &gt; Security List &gt; Defined Tags
- OCI &gt; Networking &gt; Security List &gt; Defined Tags &gt; Template
- OCI &gt; Networking &gt; Security List &gt; Freeform Tags
- OCI &gt; Networking &gt; Security List &gt; Freeform Tags &gt; Template
- OCI &gt; Networking &gt; Service Gateway &gt; Allowed
- OCI &gt; Networking &gt; Service Gateway &gt; Allowed &gt; Custom
- OCI &gt; Networking &gt; Service Gateway &gt; Allowed &gt; Custom &gt; Rules
- OCI &gt; Networking &gt; Service Gateway &gt; Allowed &gt; Region
- OCI &gt; Networking &gt; Service Gateway &gt; Allowed &gt; Region &gt; Regions
- OCI &gt; Networking &gt; Service Gateway &gt; CMDB
- OCI &gt; Networking &gt; Service Gateway &gt; Defined Tags
- OCI &gt; Networking &gt; Service Gateway &gt; Defined Tags &gt; Template
- OCI &gt; Networking &gt; Service Gateway &gt; Freeform Tags
- OCI &gt; Networking &gt; Service Gateway &gt; Freeform Tags &gt; Template
- OCI &gt; Networking &gt; Subnet &gt; Allowed
- OCI &gt; Networking &gt; Subnet &gt; Allowed &gt; Custom
- OCI &gt; Networking &gt; Subnet &gt; Allowed &gt; Custom &gt; Rules
- OCI &gt; Networking &gt; Subnet &gt; Allowed &gt; Region
- OCI &gt; Networking &gt; Subnet &gt; Allowed &gt; Region &gt; Regions
- OCI &gt; Networking &gt; Subnet &gt; CMDB
- OCI &gt; Networking &gt; Subnet &gt; Defined Tags
- OCI &gt; Networking &gt; Subnet &gt; Defined Tags &gt; Template
- OCI &gt; Networking &gt; Subnet &gt; Freeform Tags
- OCI &gt; Networking &gt; Subnet &gt; Freeform Tags &gt; Template
- OCI &gt; Networking &gt; VCN &gt; Allowed
- OCI &gt; Networking &gt; VCN &gt; Allowed &gt; Custom
- OCI &gt; Networking &gt; VCN &gt; Allowed &gt; Custom &gt; Rules
- OCI &gt; Networking &gt; VCN &gt; Allowed &gt; Region
- OCI &gt; Networking &gt; VCN &gt; Allowed &gt; Region &gt; Regions
- OCI &gt; Networking &gt; VCN &gt; CMDB
- OCI &gt; Networking &gt; VCN &gt; Defined Tags
- OCI &gt; Networking &gt; VCN &gt; Defined Tags &gt; Template
- OCI &gt; Networking &gt; VCN &gt; Freeform Tags
- OCI &gt; Networking &gt; VCN &gt; Freeform Tags &gt; Template

_Action Types_

- OCI &gt; Networking &gt; DRG &gt; Router
- OCI &gt; Networking &gt; DRG &gt; Update Defined Tags
- OCI &gt; Networking &gt; DRG &gt; Update Freeform Tags
- OCI &gt; Networking &gt; Internet Gateway &gt; Router
- OCI &gt; Networking &gt; Internet Gateway &gt; Update Defined Tags
- OCI &gt; Networking &gt; Internet Gateway &gt; Update Freeform Tags
- OCI &gt; Networking &gt; Load Balancer &gt; Router
- OCI &gt; Networking &gt; Load Balancer &gt; Update Defined Tags
- OCI &gt; Networking &gt; Load Balancer &gt; Update Freeform Tags
- OCI &gt; Networking &gt; NAT Gateway &gt; Router
- OCI &gt; Networking &gt; NAT Gateway &gt; Update Defined Tags
- OCI &gt; Networking &gt; NAT Gateway &gt; Update Freeform Tags
- OCI &gt; Networking &gt; Network Security Group &gt; Router
- OCI &gt; Networking &gt; Network Security Group &gt; Update Defined Tags
- OCI &gt; Networking &gt; Network Security Group &gt; Update Freeform Tags
- OCI &gt; Networking &gt; Route Table &gt; Router
- OCI &gt; Networking &gt; Route Table &gt; Update Defined Tags
- OCI &gt; Networking &gt; Route Table &gt; Update Freeform Tags
- OCI &gt; Networking &gt; Security List &gt; Router
- OCI &gt; Networking &gt; Security List &gt; Update Defined Tags
- OCI &gt; Networking &gt; Security List &gt; Update Freeform Tags
- OCI &gt; Networking &gt; Service Gateway &gt; Router
- OCI &gt; Networking &gt; Service Gateway &gt; Update Defined Tags
- OCI &gt; Networking &gt; Service Gateway &gt; Update Freeform Tags
- OCI &gt; Networking &gt; Subnet &gt; Router
- OCI &gt; Networking &gt; Subnet &gt; Update Defined Tags
- OCI &gt; Networking &gt; Subnet &gt; Update Freeform Tags
- OCI &gt; Networking &gt; VCN &gt; Router
- OCI &gt; Networking &gt; VCN &gt; Update Defined Tags
- OCI &gt; Networking &gt; VCN &gt; Update Freeform Tags</description>
            <pubDate>Wed, 18 Feb 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-sagemaker-v5-15-0</guid>
            <title>aws-sagemaker v5.15.0 - App CMDB control no longer enters error state due to duplicate AKAs</title>
            <link>https://turbot.com/guardrails/changelog/aws-sagemaker-v5-15-0</link>
            <description>_Bug fixes_

- Guardrails previously upserted SageMaker Apps into the CMDB using inconsistent AKA formats between Discovery and CMDB controls. This occasionally caused the `AWS &gt; SageMaker &gt; App &gt; CMDB` control to enter an error state due to duplicate AKAs. We have improved AKA generation to ensure Apps are now upserted more reliably and correctly.

_Control Types_

- AWS &gt; SageMaker &gt; Code Repository &gt; Allowed
- AWS &gt; SageMaker &gt; Code Repository &gt; Allowed &gt; Custom
- AWS &gt; SageMaker &gt; Code Repository &gt; Allowed &gt; Region
- AWS &gt; SageMaker &gt; Domain &gt; Allowed
- AWS &gt; SageMaker &gt; Domain &gt; Allowed &gt; Custom
- AWS &gt; SageMaker &gt; Domain &gt; Allowed &gt; Region
- AWS &gt; SageMaker &gt; Endpoint &gt; Allowed
- AWS &gt; SageMaker &gt; Endpoint &gt; Allowed &gt; Custom
- AWS &gt; SageMaker &gt; Endpoint &gt; Allowed &gt; Region
- AWS &gt; SageMaker &gt; Endpoint Configuration &gt; Allowed
- AWS &gt; SageMaker &gt; Endpoint Configuration &gt; Allowed &gt; Custom
- AWS &gt; SageMaker &gt; Endpoint Configuration &gt; Allowed &gt; Region
- AWS &gt; SageMaker &gt; Lifecycle Configuration &gt; Allowed
- AWS &gt; SageMaker &gt; Lifecycle Configuration &gt; Allowed &gt; Custom
- AWS &gt; SageMaker &gt; Lifecycle Configuration &gt; Allowed &gt; Region
- AWS &gt; SageMaker &gt; Model &gt; Allowed
- AWS &gt; SageMaker &gt; Model &gt; Allowed &gt; Custom
- AWS &gt; SageMaker &gt; Model &gt; Allowed &gt; Region
- AWS &gt; SageMaker &gt; Notebook Instance &gt; Allowed
- AWS &gt; SageMaker &gt; Notebook Instance &gt; Allowed &gt; Custom
- AWS &gt; SageMaker &gt; Notebook Instance &gt; Allowed &gt; Region
- AWS &gt; SageMaker &gt; Training Job &gt; Allowed
- AWS &gt; SageMaker &gt; Training Job &gt; Allowed &gt; Custom
- AWS &gt; SageMaker &gt; Training Job &gt; Allowed &gt; Region

_Policy Types_

- AWS &gt; SageMaker &gt; Code Repository &gt; Allowed
- AWS &gt; SageMaker &gt; Code Repository &gt; Allowed &gt; Custom
- AWS &gt; SageMaker &gt; Code Repository &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; SageMaker &gt; Code Repository &gt; Allowed &gt; Region
- AWS &gt; SageMaker &gt; Code Repository &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; SageMaker &gt; Domain &gt; Allowed
- AWS &gt; SageMaker &gt; Domain &gt; Allowed &gt; Custom
- AWS &gt; SageMaker &gt; Domain &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; SageMaker &gt; Domain &gt; Allowed &gt; Region
- AWS &gt; SageMaker &gt; Domain &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; SageMaker &gt; Endpoint &gt; Allowed
- AWS &gt; SageMaker &gt; Endpoint &gt; Allowed &gt; Custom
- AWS &gt; SageMaker &gt; Endpoint &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; SageMaker &gt; Endpoint &gt; Allowed &gt; Region
- AWS &gt; SageMaker &gt; Endpoint &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; SageMaker &gt; Endpoint Configuration &gt; Allowed
- AWS &gt; SageMaker &gt; Endpoint Configuration &gt; Allowed &gt; Custom
- AWS &gt; SageMaker &gt; Endpoint Configuration &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; SageMaker &gt; Endpoint Configuration &gt; Allowed &gt; Region
- AWS &gt; SageMaker &gt; Endpoint Configuration &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; SageMaker &gt; Lifecycle Configuration &gt; Allowed
- AWS &gt; SageMaker &gt; Lifecycle Configuration &gt; Allowed &gt; Custom
- AWS &gt; SageMaker &gt; Lifecycle Configuration &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; SageMaker &gt; Lifecycle Configuration &gt; Allowed &gt; Region
- AWS &gt; SageMaker &gt; Lifecycle Configuration &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; SageMaker &gt; Model &gt; Allowed
- AWS &gt; SageMaker &gt; Model &gt; Allowed &gt; Custom
- AWS &gt; SageMaker &gt; Model &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; SageMaker &gt; Model &gt; Allowed &gt; Region
- AWS &gt; SageMaker &gt; Model &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; SageMaker &gt; Notebook Instance &gt; Allowed
- AWS &gt; SageMaker &gt; Notebook Instance &gt; Allowed &gt; Custom
- AWS &gt; SageMaker &gt; Notebook Instance &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; SageMaker &gt; Notebook Instance &gt; Allowed &gt; Region
- AWS &gt; SageMaker &gt; Notebook Instance &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; SageMaker &gt; Training Job &gt; Allowed
- AWS &gt; SageMaker &gt; Training Job &gt; Allowed &gt; Custom
- AWS &gt; SageMaker &gt; Training Job &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; SageMaker &gt; Training Job &gt; Allowed &gt; Region
- AWS &gt; SageMaker &gt; Training Job &gt; Allowed &gt; Region &gt; Regions</description>
            <pubDate>Wed, 18 Feb 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-iam-v5-23-0</guid>
            <title>gcp-iam v5.23.0 - IAM role bindings enforcement now works correctly on projects with conditional bindings</title>
            <link>https://turbot.com/guardrails/changelog/gcp-iam-v5-23-0</link>
            <description>_Bug fixes_

- The approved controls for `GCP &gt; IAM &gt; Service Account &gt; Project Role Bindings`, `GCP &gt; IAM &gt; Service Account &gt; Role Bindings`, and `GCP &gt; IAM &gt; Project User &gt; Role Bindings` previously failed to delete unapproved role bindings on projects or service accounts with conditional IAM bindings. This has now been fixed, and enforcement and delete actions will work as expected.

_Control Types_

- GCP &gt; IAM &gt; API Key &gt; Allowed
- GCP &gt; IAM &gt; API Key &gt; Allowed &gt; Custom
- GCP &gt; IAM &gt; Project User &gt; Allowed
- GCP &gt; IAM &gt; Project User &gt; Allowed &gt; Custom
- GCP &gt; IAM &gt; Service Account &gt; Allowed
- GCP &gt; IAM &gt; Service Account &gt; Allowed &gt; Custom
- GCP &gt; IAM &gt; Service Account Key &gt; Allowed
- GCP &gt; IAM &gt; Service Account Key &gt; Allowed &gt; Custom

_Policy Types_

- GCP &gt; IAM &gt; API Key &gt; Allowed
- GCP &gt; IAM &gt; API Key &gt; Allowed &gt; Custom
- GCP &gt; IAM &gt; API Key &gt; Allowed &gt; Custom &gt; Rules
- GCP &gt; IAM &gt; Project User &gt; Allowed
- GCP &gt; IAM &gt; Project User &gt; Allowed &gt; Custom
- GCP &gt; IAM &gt; Project User &gt; Allowed &gt; Custom &gt; Rules
- GCP &gt; IAM &gt; Service Account &gt; Allowed
- GCP &gt; IAM &gt; Service Account &gt; Allowed &gt; Custom
- GCP &gt; IAM &gt; Service Account &gt; Allowed &gt; Custom &gt; Rules
- GCP &gt; IAM &gt; Service Account Key &gt; Allowed
- GCP &gt; IAM &gt; Service Account Key &gt; Allowed &gt; Custom
- GCP &gt; IAM &gt; Service Account Key &gt; Allowed &gt; Custom &gt; Rules</description>
            <pubDate>Tue, 17 Feb 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-provider-v5-22-0</guid>
            <title>azure-provider v5.22.0 - Track and manage Alerts Management resource providers in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-provider-v5-22-0</link>
            <description>_Resource Types_

- Azure &gt; Provider &gt; Alerts Management

_Control Types_

- Azure &gt; Provider &gt; Alerts Management &gt; CMDB
- Azure &gt; Provider &gt; Alerts Management &gt; Discovery
- Azure &gt; Provider &gt; Alerts Management &gt; Registered

_Policy Types_

- Azure &gt; Provider &gt; Alerts Management &gt; CMDB
- Azure &gt; Provider &gt; Alerts Management &gt; Registered

_Action Types_

- Azure &gt; Provider &gt; Alerts Management &gt; Set Registered</description>
            <pubDate>Tue, 17 Feb 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/oci-governance-v5-0-0</guid>
            <title>oci-governance v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/oci-governance-v5-0-0</link>
            <description>_Resource Types_

- OCI &gt; Governance
- OCI &gt; Governance &gt; Tag Default
- OCI &gt; Governance &gt; Tag Definition
- OCI &gt; Governance &gt; Tag Namespace

_Control Types_

- OCI &gt; Governance &gt; Tag Default &gt; CMDB
- OCI &gt; Governance &gt; Tag Default &gt; Discovery
- OCI &gt; Governance &gt; Tag Definition &gt; Allowed
- OCI &gt; Governance &gt; Tag Definition &gt; Allowed &gt; Custom
- OCI &gt; Governance &gt; Tag Definition &gt; CMDB
- OCI &gt; Governance &gt; Tag Definition &gt; Discovery
- OCI &gt; Governance &gt; Tag Namespace &gt; Allowed
- OCI &gt; Governance &gt; Tag Namespace &gt; Allowed &gt; Custom
- OCI &gt; Governance &gt; Tag Namespace &gt; CMDB
- OCI &gt; Governance &gt; Tag Namespace &gt; Discovery

_Policy Types_

- OCI &gt; Governance &gt; Tag Default &gt; CMDB
- OCI &gt; Governance &gt; Tag Definition &gt; Allowed
- OCI &gt; Governance &gt; Tag Definition &gt; Allowed &gt; Custom
- OCI &gt; Governance &gt; Tag Definition &gt; Allowed &gt; Custom &gt; Rules
- OCI &gt; Governance &gt; Tag Definition &gt; CMDB
- OCI &gt; Governance &gt; Tag Namespace &gt; Allowed
- OCI &gt; Governance &gt; Tag Namespace &gt; Allowed &gt; Custom
- OCI &gt; Governance &gt; Tag Namespace &gt; Allowed &gt; Custom &gt; Rules
- OCI &gt; Governance &gt; Tag Namespace &gt; CMDB

_Action Types_

- OCI &gt; Governance &gt; Tag Default &gt; Router
- OCI &gt; Governance &gt; Tag Definition &gt; Router
- OCI &gt; Governance &gt; Tag Namespace &gt; Router

_Note_

To ensure compatibility and proper functioning of the mod, please upgrade TE to v5.57.0 or higher.</description>
            <pubDate>Mon, 16 Feb 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-provider-v5-21-0</guid>
            <title>azure-provider v5.21.0 - Track and manage Bot Service and Data Box resource providers in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-provider-v5-21-0</link>
            <description>_Resource Types_

- Azure &gt; Provider &gt; Bot Service
- Azure &gt; Provider &gt; Data Box

_Control Types_

- Azure &gt; Provider &gt; Bot Service &gt; CMDB
- Azure &gt; Provider &gt; Bot Service &gt; Discovery
- Azure &gt; Provider &gt; Bot Service &gt; Registered
- Azure &gt; Provider &gt; Data Box &gt; CMDB
- Azure &gt; Provider &gt; Data Box &gt; Discovery
- Azure &gt; Provider &gt; Data Box &gt; Registered

_Policy Types_

- Azure &gt; Provider &gt; Bot Service &gt; CMDB
- Azure &gt; Provider &gt; Bot Service &gt; Registered
- Azure &gt; Provider &gt; Data Box &gt; CMDB
- Azure &gt; Provider &gt; Data Box &gt; Registered

_Action Types_

- Azure &gt; Provider &gt; Bot Service &gt; Set Registered
- Azure &gt; Provider &gt; Data Box &gt; Set Registered</description>
            <pubDate>Mon, 16 Feb 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/oci-v5-0-1</guid>
            <title>oci v5.0.1 - Compartment CMDB control will no longer fail to remove deleted compartments</title>
            <link>https://turbot.com/guardrails/changelog/oci-v5-0-1</link>
            <description>_Bug fixes_

- The `OCI &gt; Compartment &gt; CMDB` control previously failed to remove deleted compartments from Guardrails. The control now correctly handles OCI lifecycle states, deleting resources in the `DELETED` state and scheduling a re-run for transitioning states (`CREATING`, `DELETING`).</description>
            <pubDate>Fri, 13 Feb 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/oci-iam-v5-0-0</guid>
            <title>oci-iam v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/oci-iam-v5-0-0</link>
            <description>_Resource Types_

- OCI &gt; IAM
- OCI &gt; IAM &gt; API Key
- OCI &gt; IAM &gt; Auth Token
- OCI &gt; IAM &gt; Customer Secret Key
- OCI &gt; IAM &gt; DB Credential
- OCI &gt; IAM &gt; Dynamic Group
- OCI &gt; IAM &gt; Group
- OCI &gt; IAM &gt; OAuth Client Credential
- OCI &gt; IAM &gt; Policy
- OCI &gt; IAM &gt; SMTP Credential
- OCI &gt; IAM &gt; User

_Control Types_

- OCI &gt; IAM &gt; API Key &gt; Allowed
- OCI &gt; IAM &gt; API Key &gt; Allowed &gt; Custom
- OCI &gt; IAM &gt; API Key &gt; CMDB
- OCI &gt; IAM &gt; API Key &gt; Discovery
- OCI &gt; IAM &gt; Auth Token &gt; Allowed
- OCI &gt; IAM &gt; Auth Token &gt; Allowed &gt; Custom
- OCI &gt; IAM &gt; Auth Token &gt; CMDB
- OCI &gt; IAM &gt; Auth Token &gt; Discovery
- OCI &gt; IAM &gt; Customer Secret Key &gt; Allowed
- OCI &gt; IAM &gt; Customer Secret Key &gt; Allowed &gt; Custom
- OCI &gt; IAM &gt; Customer Secret Key &gt; CMDB
- OCI &gt; IAM &gt; Customer Secret Key &gt; Discovery
- OCI &gt; IAM &gt; DB Credential &gt; Allowed
- OCI &gt; IAM &gt; DB Credential &gt; Allowed &gt; Custom
- OCI &gt; IAM &gt; DB Credential &gt; CMDB
- OCI &gt; IAM &gt; DB Credential &gt; Discovery
- OCI &gt; IAM &gt; Dynamic Group &gt; Allowed
- OCI &gt; IAM &gt; Dynamic Group &gt; Allowed &gt; Custom
- OCI &gt; IAM &gt; Dynamic Group &gt; CMDB
- OCI &gt; IAM &gt; Dynamic Group &gt; Defined Tags
- OCI &gt; IAM &gt; Dynamic Group &gt; Discovery
- OCI &gt; IAM &gt; Dynamic Group &gt; Freeform Tags
- OCI &gt; IAM &gt; Group &gt; Allowed
- OCI &gt; IAM &gt; Group &gt; Allowed &gt; Custom
- OCI &gt; IAM &gt; Group &gt; CMDB
- OCI &gt; IAM &gt; Group &gt; Defined Tags
- OCI &gt; IAM &gt; Group &gt; Discovery
- OCI &gt; IAM &gt; Group &gt; Freeform Tags
- OCI &gt; IAM &gt; OAuth Client Credential &gt; Allowed
- OCI &gt; IAM &gt; OAuth Client Credential &gt; Allowed &gt; Custom
- OCI &gt; IAM &gt; OAuth Client Credential &gt; CMDB
- OCI &gt; IAM &gt; OAuth Client Credential &gt; Discovery
- OCI &gt; IAM &gt; Policy &gt; Allowed
- OCI &gt; IAM &gt; Policy &gt; Allowed &gt; Custom
- OCI &gt; IAM &gt; Policy &gt; CMDB
- OCI &gt; IAM &gt; Policy &gt; Defined Tags
- OCI &gt; IAM &gt; Policy &gt; Discovery
- OCI &gt; IAM &gt; Policy &gt; Freeform Tags
- OCI &gt; IAM &gt; SMTP Credential &gt; Allowed
- OCI &gt; IAM &gt; SMTP Credential &gt; Allowed &gt; Custom
- OCI &gt; IAM &gt; SMTP Credential &gt; CMDB
- OCI &gt; IAM &gt; SMTP Credential &gt; Discovery
- OCI &gt; IAM &gt; User &gt; Allowed
- OCI &gt; IAM &gt; User &gt; Allowed &gt; Custom
- OCI &gt; IAM &gt; User &gt; CMDB
- OCI &gt; IAM &gt; User &gt; Defined Tags
- OCI &gt; IAM &gt; User &gt; Discovery
- OCI &gt; IAM &gt; User &gt; Freeform Tags

_Policy Types_

- OCI &gt; IAM &gt; API Key &gt; Allowed
- OCI &gt; IAM &gt; API Key &gt; Allowed &gt; Custom
- OCI &gt; IAM &gt; API Key &gt; Allowed &gt; Custom &gt; Rules
- OCI &gt; IAM &gt; API Key &gt; CMDB
- OCI &gt; IAM &gt; Auth Token &gt; Allowed
- OCI &gt; IAM &gt; Auth Token &gt; Allowed &gt; Custom
- OCI &gt; IAM &gt; Auth Token &gt; Allowed &gt; Custom &gt; Rules
- OCI &gt; IAM &gt; Auth Token &gt; CMDB
- OCI &gt; IAM &gt; Customer Secret Key &gt; Allowed
- OCI &gt; IAM &gt; Customer Secret Key &gt; Allowed &gt; Custom
- OCI &gt; IAM &gt; Customer Secret Key &gt; Allowed &gt; Custom &gt; Rules
- OCI &gt; IAM &gt; Customer Secret Key &gt; CMDB
- OCI &gt; IAM &gt; DB Credential &gt; Allowed
- OCI &gt; IAM &gt; DB Credential &gt; Allowed &gt; Custom
- OCI &gt; IAM &gt; DB Credential &gt; Allowed &gt; Custom &gt; Rules
- OCI &gt; IAM &gt; DB Credential &gt; CMDB
- OCI &gt; IAM &gt; Dynamic Group &gt; Allowed
- OCI &gt; IAM &gt; Dynamic Group &gt; Allowed &gt; Custom
- OCI &gt; IAM &gt; Dynamic Group &gt; Allowed &gt; Custom &gt; Rules
- OCI &gt; IAM &gt; Dynamic Group &gt; CMDB
- OCI &gt; IAM &gt; Dynamic Group &gt; Defined Tags
- OCI &gt; IAM &gt; Dynamic Group &gt; Defined Tags &gt; Template
- OCI &gt; IAM &gt; Dynamic Group &gt; Freeform Tags
- OCI &gt; IAM &gt; Dynamic Group &gt; Freeform Tags &gt; Template
- OCI &gt; IAM &gt; Group &gt; Allowed
- OCI &gt; IAM &gt; Group &gt; Allowed &gt; Custom
- OCI &gt; IAM &gt; Group &gt; Allowed &gt; Custom &gt; Rules
- OCI &gt; IAM &gt; Group &gt; CMDB
- OCI &gt; IAM &gt; Group &gt; Defined Tags
- OCI &gt; IAM &gt; Group &gt; Defined Tags &gt; Template
- OCI &gt; IAM &gt; Group &gt; Freeform Tags
- OCI &gt; IAM &gt; Group &gt; Freeform Tags &gt; Template
- OCI &gt; IAM &gt; OAuth Client Credential &gt; Allowed
- OCI &gt; IAM &gt; OAuth Client Credential &gt; Allowed &gt; Custom
- OCI &gt; IAM &gt; OAuth Client Credential &gt; Allowed &gt; Custom &gt; Rules
- OCI &gt; IAM &gt; OAuth Client Credential &gt; CMDB
- OCI &gt; IAM &gt; Policy &gt; Allowed
- OCI &gt; IAM &gt; Policy &gt; Allowed &gt; Custom
- OCI &gt; IAM &gt; Policy &gt; Allowed &gt; Custom &gt; Rules
- OCI &gt; IAM &gt; Policy &gt; CMDB
- OCI &gt; IAM &gt; Policy &gt; Defined Tags
- OCI &gt; IAM &gt; Policy &gt; Defined Tags &gt; Template
- OCI &gt; IAM &gt; Policy &gt; Freeform Tags
- OCI &gt; IAM &gt; Policy &gt; Freeform Tags &gt; Template
- OCI &gt; IAM &gt; SMTP Credential &gt; Allowed
- OCI &gt; IAM &gt; SMTP Credential &gt; Allowed &gt; Custom
- OCI &gt; IAM &gt; SMTP Credential &gt; Allowed &gt; Custom &gt; Rules
- OCI &gt; IAM &gt; SMTP Credential &gt; CMDB
- OCI &gt; IAM &gt; User &gt; Allowed
- OCI &gt; IAM &gt; User &gt; Allowed &gt; Custom
- OCI &gt; IAM &gt; User &gt; Allowed &gt; Custom &gt; Rules
- OCI &gt; IAM &gt; User &gt; CMDB
- OCI &gt; IAM &gt; User &gt; Defined Tags
- OCI &gt; IAM &gt; User &gt; Defined Tags &gt; Template
- OCI &gt; IAM &gt; User &gt; Freeform Tags
- OCI &gt; IAM &gt; User &gt; Freeform Tags &gt; Template

_Action Types_

- OCI &gt; IAM &gt; API Key &gt; Router
- OCI &gt; IAM &gt; Auth Token &gt; Router
- OCI &gt; IAM &gt; Customer Secret Key &gt; Router
- OCI &gt; IAM &gt; DB Credential &gt; Router
- OCI &gt; IAM &gt; Dynamic Group &gt; Router
- OCI &gt; IAM &gt; Dynamic Group &gt; Update Defined Tags
- OCI &gt; IAM &gt; Dynamic Group &gt; Update Freeform Tags
- OCI &gt; IAM &gt; Group &gt; Router
- OCI &gt; IAM &gt; Group &gt; Update Defined Tags
- OCI &gt; IAM &gt; Group &gt; Update Freeform Tags
- OCI &gt; IAM &gt; OAuth Client Credential &gt; Router
- OCI &gt; IAM &gt; Policy &gt; Router
- OCI &gt; IAM &gt; Policy &gt; Update Defined Tags
- OCI &gt; IAM &gt; Policy &gt; Update Freeform Tags
- OCI &gt; IAM &gt; SMTP Credential &gt; Router
- OCI &gt; IAM &gt; User &gt; Router
- OCI &gt; IAM &gt; User &gt; Update Defined Tags
- OCI &gt; IAM &gt; User &gt; Update Freeform Tags

_Note_

To ensure compatibility and proper functioning of the mod, please upgrade TE to v5.57.0 or higher.</description>
            <pubDate>Thu, 12 Feb 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-cisv5-0-v5-0-1</guid>
            <title>azure-cisv5-0 v5.0.1 - Fixed title inconsistencies in section 7 control and policy types</title>
            <link>https://turbot.com/guardrails/changelog/azure-cisv5-0-v5-0-1</link>
            <description>_Bug fixes_

- Fixed title inconsistencies in section 7 control and policy types.

_Control Types_

_Renamed_

- `Azure &gt; CIS v5.0 &gt; 7 - Networking Services &gt; 7.08 Ensure that virtual network flow log retention days is set to greater than or equal to 90` to `Azure &gt; CIS v5.0 &gt; 7 - Networking Services &gt; 7.08 - Ensure that virtual network flow log retention days is set to greater than or equal to 90`

_Policy Types_

_Renamed_

- `Azure &gt; CIS v5.0 &gt; 7 - Networking Services &gt; 7 - Maximum Attestation Duration` to `Azure &gt; CIS v5.0 &gt; 7 - Networking Services &gt; Maximum Attestation Duration`</description>
            <pubDate>Thu, 12 Feb 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-cisv5-0-v5-0-0</guid>
            <title>azure-cisv5-0 v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/azure-cisv5-0-v5-0-0</link>
            <description>_Control Types_

- Azure &gt; CIS v5.0
- Azure &gt; CIS v5.0 &gt; 2 - Analytics Services
- Azure &gt; CIS v5.0 &gt; 2 - Analytics Services &gt; 2.01 - Azure Databricks
- Azure &gt; CIS v5.0 &gt; 2 - Analytics Services &gt; 2.01 - Azure Databricks &gt; 2.01.01 - Ensure that Azure Databricks is deployed in a customer-managed virtual network (VNet)
- Azure &gt; CIS v5.0 &gt; 2 - Analytics Services &gt; 2.01 - Azure Databricks &gt; 2.01.02 - Ensure that network security groups are configured for Databricks subnets
- Azure &gt; CIS v5.0 &gt; 2 - Analytics Services &gt; 2.01 - Azure Databricks &gt; 2.01.03 - Ensure that traffic is encrypted between cluster worker nodes
- Azure &gt; CIS v5.0 &gt; 2 - Analytics Services &gt; 2.01 - Azure Databricks &gt; 2.01.04 - Ensure that users and groups are synced from Microsoft Entra ID to Azure Databricks
- Azure &gt; CIS v5.0 &gt; 2 - Analytics Services &gt; 2.01 - Azure Databricks &gt; 2.01.05 - Ensure that Unity Catalog is configured for Azure Databricks
- Azure &gt; CIS v5.0 &gt; 2 - Analytics Services &gt; 2.01 - Azure Databricks &gt; 2.01.06 - Ensure that usage is restricted and expiry is enforced for Databricks personal access tokens
- Azure &gt; CIS v5.0 &gt; 2 - Analytics Services &gt; 2.01 - Azure Databricks &gt; 2.01.07 - Ensure that diagnostic log delivery is configured for Azure Databricks
- Azure &gt; CIS v5.0 &gt; 2 - Analytics Services &gt; 2.01 - Azure Databricks &gt; 2.01.08 - Ensure critical data in Azure Databricks is encrypted with customer-managed keys (CMK)
- Azure &gt; CIS v5.0 &gt; 2 - Analytics Services &gt; 2.01 - Azure Databricks &gt; 2.01.09 - Ensure &apos;No Public IP&apos; is set to &apos;Enabled&apos;
- Azure &gt; CIS v5.0 &gt; 2 - Analytics Services &gt; 2.01 - Azure Databricks &gt; 2.01.10 - Ensure &apos;Allow Public Network Access&apos; is set to &apos;Disabled&apos;
- Azure &gt; CIS v5.0 &gt; 2 - Analytics Services &gt; 2.01 - Azure Databricks &gt; 2.01.11 - Ensure private endpoints are used to access Azure Databricks workspaces
- Azure &gt; CIS v5.0 &gt; 3 - Compute Services
- Azure &gt; CIS v5.0 &gt; 3 - Compute Services &gt; 3.01 - Virtual Machines
- Azure &gt; CIS v5.0 &gt; 3 - Compute Services &gt; 3.01 - Virtual Machines &gt; 3.01.01 - Ensure only MFA enabled identities can access privileged Virtual Machine
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.01 - Security Defaults (Per-User MFA)
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.01 - Security Defaults (Per-User MFA) &gt; 5.01.01 - Ensure that &apos;security defaults&apos; is enabled in Microsoft Entra ID
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.01 - Security Defaults (Per-User MFA) &gt; 5.01.02 - Ensure that &apos;multifactor authentication&apos; is &apos;enabled&apos; for all users
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.01 - Security Defaults (Per-User MFA) &gt; 5.01.03 - Ensure that &apos;Allow users to remember multifactor authentication on devices they trust&apos; is disabled
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.02 - Conditional Access
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.02 - Conditional Access &gt; 5.02.01 - Ensure that &apos;trusted locations&apos; are defined
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.02 - Conditional Access &gt; 5.02.02 - Ensure that an exclusionary geographic Conditional Access policy is considered
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.02 - Conditional Access &gt; 5.02.03 - Ensure that an exclusionary Device code flow policy is considered
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.02 - Conditional Access &gt; 5.02.04 - Ensure that a multifactor authentication policy exists for all users
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.02 - Conditional Access &gt; 5.02.05 - Ensure that multifactor authentication is required for risky sign-ins
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.02 - Conditional Access &gt; 5.02.06 - Ensure that multifactor authentication is required for Windows Azure Service Management API
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.02 - Conditional Access &gt; 5.02.07 - Ensure that multifactor authentication is required to access Microsoft Admin Portals
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.02 - Conditional Access &gt; 5.02.08 - Ensure a Token Protection Conditional Access policy is considered
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.03 - Periodic Identity Reviews
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.03 - Periodic Identity Reviews &gt; 5.03.01 - Ensure that Azure admin accounts are not used for daily operations
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.03 - Periodic Identity Reviews &gt; 5.03.02 - Ensure that guest users are reviewed on a regular basis
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.03 - Periodic Identity Reviews &gt; 5.03.03 - Ensure that use of the &apos;User Access Administrator&apos; role is restricted
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.03 - Periodic Identity Reviews &gt; 5.03.04 - Ensure that all &apos;privileged&apos; role assignments are periodically reviewed
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.03 - Periodic Identity Reviews &gt; 5.03.05 - Ensure disabled user accounts do not have read, write, or owner permissions
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.03 - Periodic Identity Reviews &gt; 5.03.06 - Ensure &apos;Tenant Creator&apos; role assignments are periodically reviewed
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.03 - Periodic Identity Reviews &gt; 5.03.07 - Ensure all non-privileged role assignments are periodically reviewed
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.04 - Ensure that &apos;Restrict non-admin users from creating tenants&apos; is set to &apos;Yes&apos;
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.05 - Ensure that &apos;Number of methods required to reset&apos; is set to &apos;2&apos;
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.06 - Ensure that account &apos;Lockout Threshold&apos; is less than or equal to &apos;10&apos;
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.07 - Ensure that account &apos;Lockout duration in seconds&apos; is greater than or equal to &apos;60&apos;
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.08 - Ensure that a &apos;Custom banned password list&apos; is set to &apos;Enforce&apos;
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.09 - Ensure that &apos;Number of days before users are asked to re-confirm their authentication information&apos; is not set to &apos;0&apos;
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.10 - Ensure that &apos;Notify users on password resets?&apos; is set to &apos;Yes&apos;
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.11 - Ensure that &apos;Notify all admins when other admins reset their password?&apos; is set to &apos;Yes&apos;
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.12 - Ensure that &apos;User consent for applications&apos; is set to &apos;Do not allow user consent&apos;
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.13 - Ensure that &apos;User consent for applications&apos; is set to &apos;Allow user consent for apps from verified publishers, for selected permissions&apos;
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.14 - Ensure that &apos;Users can register applications&apos; is set to &apos;No&apos;
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.15 - Ensure that &apos;Guest users access restrictions&apos; is set to &apos;Guest user access is restricted to properties and memberships of their own directory objects&apos;
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.16 - Ensure that &apos;Guest invite restrictions&apos; is set to &apos;Only users assigned to specific admin roles [...]&apos; or &apos;No one [..]&apos;
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.17 - Ensure that &apos;Restrict access to Microsoft Entra admin center&apos; is set to &apos;Yes&apos;
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.18 - Ensure that &apos;Restrict user ability to access groups features in My Groups&apos; is set to &apos;Yes&apos;
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.19 - Ensure that &apos;Users can create security groups in Azure portals, API or PowerShell&apos; is set to &apos;No&apos;
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.20 - Ensure that &apos;Owners can manage group membership requests in My Groups&apos; is set to &apos;No&apos;
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.21 - Ensure that &apos;Users can create Microsoft 365 groups in Azure portals, API or PowerShell&apos; is set to &apos;No&apos;
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.22 - Ensure that &apos;Require Multifactor Authentication to register or join devices with Microsoft Entra&apos; is set to &apos;Yes&apos;
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.23 - Ensure That No Custom Subscription Administrator Roles Exist
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.24 - Ensure that a custom role is assigned permissions for administering resource locks
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.25 - Ensure that &apos;Subscription leaving Microsoft Entra tenant&apos; and &apos;Subscription entering Microsoft Entra tenant&apos; is set to &apos;Permit no one&apos;
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.26 - Ensure fewer than 5 users have global administrator assignment
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.27 - Ensure there are between 2 and 3 subscription owners
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.28 - Ensure passwordless authentication methods are considered
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.01 - Configuring Diagnostic Settings
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.01 - Configuring Diagnostic Settings &gt; 6.01.01.01 - Ensure that a &apos;Diagnostic Setting&apos; exists for Subscription Activity Logs
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.01 - Configuring Diagnostic Settings &gt; 6.01.01.02 - Ensure Diagnostic Setting captures appropriate categories
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.01 - Configuring Diagnostic Settings &gt; 6.01.01.03 - Ensure the storage account containing the container with activity logs is encrypted with customer-managed key (CMK)
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.01 - Configuring Diagnostic Settings &gt; 6.01.01.04 - Ensure that logging for Azure Key Vault is &apos;Enabled&apos;
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.01 - Configuring Diagnostic Settings &gt; 6.01.01.05 - Ensure that Network Security Group Flow logs are captured and sent to Log Analytics
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.01 - Configuring Diagnostic Settings &gt; 6.01.01.06 - Ensure that logging for Azure AppService &apos;HTTP logs&apos; is enabled
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.01 - Configuring Diagnostic Settings &gt; 6.01.01.07 - Ensure that virtual network flow logs are captured and sent to Log Analytics
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.01 - Configuring Diagnostic Settings &gt; 6.01.01.08 - Ensure that a Microsoft Entra diagnostic setting exists to send Microsoft Graph activity logs to an appropriate destination
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.01 - Configuring Diagnostic Settings &gt; 6.01.01.09 - Ensure that a Microsoft Entra diagnostic setting exists to send Microsoft Entra activity logs to an appropriate destination
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.01 - Configuring Diagnostic Settings &gt; 6.01.01.10 - Ensure that Intune logs are captured and sent to Log Analytics
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.02 - Monitoring using Activity Log Alerts
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.02 - Monitoring using Activity Log Alerts &gt; 6.01.02.01 - Ensure that Activity Log Alert exists for Create Policy Assignment
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.02 - Monitoring using Activity Log Alerts &gt; 6.01.02.02 - Ensure that Activity Log Alert exists for Delete Policy Assignment
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.02 - Monitoring using Activity Log Alerts &gt; 6.01.02.03 - Ensure that Activity Log Alert exists for Create or Update Network Security Group
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.02 - Monitoring using Activity Log Alerts &gt; 6.01.02.04 - Ensure that Activity Log Alert exists for Delete Network Security Group
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.02 - Monitoring using Activity Log Alerts &gt; 6.01.02.05 - Ensure that Activity Log Alert exists for Create or Update Security Solution
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.02 - Monitoring using Activity Log Alerts &gt; 6.01.02.06 - Ensure that Activity Log Alert exists for Delete Security Solution
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.02 - Monitoring using Activity Log Alerts &gt; 6.01.02.07 - Ensure that Activity Log Alert exists for Create or Update SQL Server Firewall Rule
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.02 - Monitoring using Activity Log Alerts &gt; 6.01.02.08 - Ensure that Activity Log Alert exists for Delete SQL Server Firewall Rule
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.02 - Monitoring using Activity Log Alerts &gt; 6.01.02.09 - Ensure that Activity Log Alert exists for Create or Update Public IP Address rule
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.02 - Monitoring using Activity Log Alerts &gt; 6.01.02.10 - Ensure that Activity Log Alert exists for Delete Public IP Address rule
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.02 - Monitoring using Activity Log Alerts &gt; 6.01.02.11 - Ensure that an Activity Log Alert exists for Service Health
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.03 - Configuring Application Insights
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.03 - Configuring Application Insights &gt; 6.01.03.01 - Ensure Application Insights are Configured
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.04 - Ensure that Azure Monitor Resource Logging is Enabled for All Services that Support it
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.05 - Ensure that SKU Basic/Consumption is not used on artifacts that need to be monitored (Particularly for Production Workloads)
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.02 - Ensure that Resource Locks are set for Mission-Critical Azure Resources
- Azure &gt; CIS v5.0 &gt; 7 - Networking Services
- Azure &gt; CIS v5.0 &gt; 7 - Networking Services &gt; 7.01 - Ensure that RDP access from the Internet is evaluated and restricted
- Azure &gt; CIS v5.0 &gt; 7 - Networking Services &gt; 7.02 - Ensure that SSH access from the Internet is evaluated and restricted
- Azure &gt; CIS v5.0 &gt; 7 - Networking Services &gt; 7.03 - Ensure that UDP access from the Internet is evaluated and restricted
- Azure &gt; CIS v5.0 &gt; 7 - Networking Services &gt; 7.04 - Ensure that HTTP(S) access from the Internet is evaluated and restricted
- Azure &gt; CIS v5.0 &gt; 7 - Networking Services &gt; 7.05 - Ensure that network security group flow log retention days is set to greater than or equal to 90
- Azure &gt; CIS v5.0 &gt; 7 - Networking Services &gt; 7.06 - Ensure that Network Watcher is &apos;Enabled&apos; for Azure Regions that are in use
- Azure &gt; CIS v5.0 &gt; 7 - Networking Services &gt; 7.07 - Ensure that Public IP addresses are Evaluated on a Periodic Basis
- Azure &gt; CIS v5.0 &gt; 7 - Networking Services &gt; 7.08 - Ensure that virtual network flow log retention days is set to greater than or equal to 90
- Azure &gt; CIS v5.0 &gt; 7 - Networking Services &gt; 7.09 - Ensure &apos;Authentication type&apos; is set to &apos;Azure Active Directory&apos; only for Azure VPN Gateway point-to-site configuration
- Azure &gt; CIS v5.0 &gt; 7 - Networking Services &gt; 7.10 - Ensure Azure Web Application Firewall (WAF) is enabled on Azure Application Gateway
- Azure &gt; CIS v5.0 &gt; 7 - Networking Services &gt; 7.11 - Ensure subnets are associated with network security groups
- Azure &gt; CIS v5.0 &gt; 7 - Networking Services &gt; 7.12 - Ensure the SSL policy&apos;s &apos;Min protocol version&apos; is set to &apos;TLSv1_2&apos; or higher on Azure Application Gateway
- Azure &gt; CIS v5.0 &gt; 7 - Networking Services &gt; 7.13 - Ensure &apos;HTTP2&apos; is set to &apos;Enabled&apos; on Azure Application Gateway
- Azure &gt; CIS v5.0 &gt; 7 - Networking Services &gt; 7.14 - Ensure request body inspection is enabled in Azure Web Application Firewall policy on Azure Application Gateway
- Azure &gt; CIS v5.0 &gt; 7 - Networking Services &gt; 7.15 - Ensure bot protection is enabled in Azure Web Application Firewall policy on Azure Application Gateway
- Azure &gt; CIS v5.0 &gt; 7 - Networking Services &gt; 7.16 - Ensure Azure Network Security Perimeter is used to secure Azure platform-as-a-service resources
- Azure &gt; CIS v5.0 &gt; 8 - Security Services
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.01 - Microsoft Cloud Security Posture Management (CSPM)
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.01 - Microsoft Cloud Security Posture Management (CSPM) &gt; 8.01.01.01 - Ensure Microsoft Defender CSPM is set to &apos;On&apos;
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.02 - Defender Plan: APIs
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.02 - Defender Plan: APIs &gt; 8.01.02.01 - Ensure Microsoft Defender for APIs is set to &apos;On&apos;
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.03 - Defender Plan: Servers
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.03 - Defender Plan: Servers &gt; 8.01.03.01 - Ensure that Defender for Servers is set to &apos;On&apos;
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.03 - Defender Plan: Servers &gt; 8.01.03.02 - Ensure that &apos;Vulnerability assessment for machines&apos; component status is set to &apos;On&apos;
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.03 - Defender Plan: Servers &gt; 8.01.03.03 - Ensure that &apos;Endpoint protection&apos; component status is set to &apos;On&apos;
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.03 - Defender Plan: Servers &gt; 8.01.03.04 - Ensure that &apos;Agentless scanning for machines&apos; component status is set to &apos;On&apos;
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.03 - Defender Plan: Servers &gt; 8.01.03.05 - Ensure that &apos;File Integrity Monitoring&apos; component status is set to &apos;On&apos;
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.04 - Defender Plan: Containers
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.04 - Defender Plan: Containers &gt; 8.01.04.01 - Ensure That Microsoft Defender for Containers Is Set To &apos;On&apos;
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.05 - Defender Plan: Storage
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.05 - Defender Plan: Storage &gt; 8.01.05.01 - Ensure That Microsoft Defender for Storage Is Set To &apos;On&apos;
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.05 - Defender Plan: Storage &gt; 8.01.05.02 - Ensure Advanced Threat Protection Alerts for Storage Accounts Are Monitored
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.06 - Defender Plan: App Service
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.06 - Defender Plan: App Service &gt; 8.01.06.01 - Ensure That Microsoft Defender for App Services Is Set To &apos;On&apos;
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.07 - Defender Plan: Databases
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.07 - Defender Plan: Databases &gt; 8.01.07.01 - Ensure That Microsoft Defender for Azure Cosmos DB Is Set To &apos;On&apos;
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.07 - Defender Plan: Databases &gt; 8.01.07.02 - Ensure That Microsoft Defender for Open-Source Relational Databases Is Set To &apos;On&apos;
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.07 - Defender Plan: Databases &gt; 8.01.07.03 - Ensure That Microsoft Defender for (Managed Instance) Azure SQL Databases Is Set To &apos;On&apos;
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.07 - Defender Plan: Databases &gt; 8.01.07.04 - Ensure That Microsoft Defender for SQL Servers on Machines Is Set To &apos;On&apos;
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.08 - Defender Plan: Key Vault
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.08 - Defender Plan: Key Vault &gt; 8.01.08.01 - Ensure That Microsoft Defender for Key Vault Is Set To &apos;On&apos;
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.09 - Defender Plan: Resource Manager
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.09 - Defender Plan: Resource Manager &gt; 8.01.09.01 - Ensure That Microsoft Defender for Resource Manager Is Set To &apos;On&apos;
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.10 - Ensure that Microsoft Defender for Cloud is configured to check VM operating systems for updates
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.11 - Ensure That Microsoft Cloud Security Benchmark policies are not set to &apos;Disabled&apos;
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.12 - Ensure That &apos;All users with the following roles&apos; is set to &apos;Owner&apos;
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.13 - Ensure &apos;Additional email addresses&apos; is Configured with a Security Contact Email
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.14 - Ensure that &apos;Notify about alerts with the following severity (or higher)&apos; is enabled
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.15 - Ensure that &apos;Notify about attack paths with the following risk level (or higher)&apos; is enabled
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.16 - Ensure that Microsoft Defender External Attack Surface Monitoring (EASM) is enabled
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.02 - Microsoft Defender for IoT
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.02 - Microsoft Defender for IoT &gt; 8.02.01 - Ensure That Microsoft Defender for IoT Hub Is Set To &apos;On&apos;
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.03 - Key Vault
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.03 - Key Vault &gt; 8.03.01 - Ensure that the Expiration Date is set for all Keys in RBAC Key Vaults
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.03 - Key Vault &gt; 8.03.02 - Ensure that the Expiration Date is set for all Keys in Non-RBAC Key Vaults
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.03 - Key Vault &gt; 8.03.03 - Ensure that the Expiration Date is set for all Secrets in RBAC Key Vaults
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.03 - Key Vault &gt; 8.03.04 - Ensure that the Expiration Date is set for all Secrets in Non-RBAC Key Vaults
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.03 - Key Vault &gt; 8.03.05 - Ensure &apos;Purge protection&apos; is set to &apos;Enabled&apos;
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.03 - Key Vault &gt; 8.03.06 - Ensure that Role Based Access Control for Azure Key Vault is enabled
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.03 - Key Vault &gt; 8.03.07 - Ensure Public Network Access is Disabled
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.03 - Key Vault &gt; 8.03.08 - Ensure Private Endpoints are used to access Azure Key Vault
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.03 - Key Vault &gt; 8.03.09 - Ensure automatic key rotation is enabled within Azure Key Vault
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.03 - Key Vault &gt; 8.03.10 - Ensure that Azure Key Vault Managed HSM is used when required
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.03 - Key Vault &gt; 8.03.11 - Ensure certificate &apos;Validity Period (in months)&apos; is less than or equal to &apos;12&apos;
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.04 - Azure Bastion
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.04 - Azure Bastion &gt; 8.04.01 - Ensure an Azure Bastion Host Exists
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.05 - Ensure Azure DDoS Network Protection is enabled on virtual networks
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.01 - Azure Files
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.01 - Azure Files &gt; 9.01.01 - Ensure soft delete for Azure File Shares is Enabled
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.01 - Azure Files &gt; 9.01.02 - Ensure &apos;SMB protocol version&apos; is set to &apos;SMB 3.1.1&apos; or higher for SMB file shares
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.01 - Azure Files &gt; 9.01.03 - Ensure &apos;SMB channel encryption&apos; is set to &apos;AES-256-GCM&apos; or higher for SMB file shares
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.02 - Azure Blob Storage
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.02 - Azure Blob Storage &gt; 9.02.01 - Ensure that soft delete for blobs on Azure Blob Storage storage accounts is Enabled
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.02 - Azure Blob Storage &gt; 9.02.02 - Ensure that soft delete for containers on Azure Blob Storage storage accounts is Enabled
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.02 - Azure Blob Storage &gt; 9.02.03 - Ensure &apos;Versioning&apos; is set to &apos;Enabled&apos; on Azure Blob Storage storage accounts
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.03 - Storage Accounts
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.03 - Storage Accounts &gt; 9.03.01 - Secrets and Keys
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.03 - Storage Accounts &gt; 9.03.01 - Secrets and Keys &gt; 9.03.01.01 - Ensure that &apos;Enable key rotation reminders&apos; is enabled for each Storage Account
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.03 - Storage Accounts &gt; 9.03.01 - Secrets and Keys &gt; 9.03.01.02 - Ensure that Storage Account Access Keys are Periodically Regenerated
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.03 - Storage Accounts &gt; 9.03.01 - Secrets and Keys &gt; 9.03.01.03 - Ensure &apos;Allow storage account key access&apos; for Azure Storage Accounts is &apos;Disabled&apos;
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.03 - Storage Accounts &gt; 9.03.02 - Networking
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.03 - Storage Accounts &gt; 9.03.02 - Networking &gt; 9.03.02.01 - Ensure Private Endpoints are used to access Storage Accounts
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.03 - Storage Accounts &gt; 9.03.02 - Networking &gt; 9.03.02.02 - Ensure that &apos;Public Network Access&apos; is &apos;Disabled&apos; for storage accounts
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.03 - Storage Accounts &gt; 9.03.02 - Networking &gt; 9.03.02.03 - Ensure default network access rule for storage accounts is set to deny
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.03 - Storage Accounts &gt; 9.03.03 - Identity and Access Management
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.03 - Storage Accounts &gt; 9.03.03 - Identity and Access Management &gt; 9.03.03.01 - Ensure that &apos;Default to Microsoft Entra authorization in the Azure portal&apos; is set to &apos;Enabled&apos;
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.03 - Storage Accounts &gt; 9.03.04 - Ensure that &apos;Secure transfer required&apos; is set to &apos;Enabled&apos;
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.03 - Storage Accounts &gt; 9.03.05 - Ensure &apos;Allow Azure services on the trusted services list to access this storage account&apos; is Enabled for Storage Account Access
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.03 - Storage Accounts &gt; 9.03.06 - Ensure the &apos;Minimum TLS version&apos; for storage accounts is set to &apos;Version 1.2&apos;
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.03 - Storage Accounts &gt; 9.03.07 - Ensure &apos;Cross Tenant Replication&apos; is not enabled
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.03 - Storage Accounts &gt; 9.03.08 - Ensure that &apos;Allow Blob Anonymous Access&apos; is set to &apos;Disabled&apos;
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.03 - Storage Accounts &gt; 9.03.09 - Ensure Azure Resource Manager Delete locks are applied to Azure Storage Accounts
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.03 - Storage Accounts &gt; 9.03.10 - Ensure Azure Resource Manager ReadOnly locks are considered for Azure Storage Accounts
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.03 - Storage Accounts &gt; 9.03.11 - Ensure Redundancy is set to &apos;geo-redundant storage (GRS)&apos; on critical Azure Storage Accounts

_Policy Types_

- Azure &gt; CIS v5.0
- Azure &gt; CIS v5.0 &gt; 2 - Analytics Services
- Azure &gt; CIS v5.0 &gt; 2 - Analytics Services &gt; 2.01 - Azure Databricks
- Azure &gt; CIS v5.0 &gt; 2 - Analytics Services &gt; 2.01 - Azure Databricks &gt; 2.01.01 - Ensure that Azure Databricks is deployed in a customer-managed virtual network (VNet)
- Azure &gt; CIS v5.0 &gt; 2 - Analytics Services &gt; 2.01 - Azure Databricks &gt; 2.01.02 - Ensure that network security groups are configured for Databricks subnets
- Azure &gt; CIS v5.0 &gt; 2 - Analytics Services &gt; 2.01 - Azure Databricks &gt; 2.01.02 - Ensure that network security groups are configured for Databricks subnets &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 2 - Analytics Services &gt; 2.01 - Azure Databricks &gt; 2.01.03 - Ensure that traffic is encrypted between cluster worker nodes
- Azure &gt; CIS v5.0 &gt; 2 - Analytics Services &gt; 2.01 - Azure Databricks &gt; 2.01.03 - Ensure that traffic is encrypted between cluster worker nodes &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 2 - Analytics Services &gt; 2.01 - Azure Databricks &gt; 2.01.04 - Ensure that users and groups are synced from Microsoft Entra ID to Azure Databricks
- Azure &gt; CIS v5.0 &gt; 2 - Analytics Services &gt; 2.01 - Azure Databricks &gt; 2.01.04 - Ensure that users and groups are synced from Microsoft Entra ID to Azure Databricks &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 2 - Analytics Services &gt; 2.01 - Azure Databricks &gt; 2.01.05 - Ensure that Unity Catalog is configured for Azure Databricks
- Azure &gt; CIS v5.0 &gt; 2 - Analytics Services &gt; 2.01 - Azure Databricks &gt; 2.01.05 - Ensure that Unity Catalog is configured for Azure Databricks &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 2 - Analytics Services &gt; 2.01 - Azure Databricks &gt; 2.01.06 - Ensure that usage is restricted and expiry is enforced for Databricks personal access tokens
- Azure &gt; CIS v5.0 &gt; 2 - Analytics Services &gt; 2.01 - Azure Databricks &gt; 2.01.06 - Ensure that usage is restricted and expiry is enforced for Databricks personal access tokens &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 2 - Analytics Services &gt; 2.01 - Azure Databricks &gt; 2.01.07 - Ensure that diagnostic log delivery is configured for Azure Databricks
- Azure &gt; CIS v5.0 &gt; 2 - Analytics Services &gt; 2.01 - Azure Databricks &gt; 2.01.07 - Ensure that diagnostic log delivery is configured for Azure Databricks &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 2 - Analytics Services &gt; 2.01 - Azure Databricks &gt; 2.01.08 - Ensure critical data in Azure Databricks is encrypted with customer-managed keys (CMK)
- Azure &gt; CIS v5.0 &gt; 2 - Analytics Services &gt; 2.01 - Azure Databricks &gt; 2.01.09 - Ensure &apos;No Public IP&apos; is set to &apos;Enabled&apos;
- Azure &gt; CIS v5.0 &gt; 2 - Analytics Services &gt; 2.01 - Azure Databricks &gt; 2.01.10 - Ensure &apos;Allow Public Network Access&apos; is set to &apos;Disabled&apos;
- Azure &gt; CIS v5.0 &gt; 2 - Analytics Services &gt; 2.01 - Azure Databricks &gt; 2.01.11 - Ensure private endpoints are used to access Azure Databricks workspaces
- Azure &gt; CIS v5.0 &gt; 2 - Analytics Services &gt; Maximum Attestation Duration
- Azure &gt; CIS v5.0 &gt; 3 - Compute Services
- Azure &gt; CIS v5.0 &gt; 3 - Compute Services &gt; 3.01 - Virtual Machines
- Azure &gt; CIS v5.0 &gt; 3 - Compute Services &gt; 3.01 - Virtual Machines &gt; 3.01.01 - Ensure only MFA enabled identities can access privileged Virtual Machine
- Azure &gt; CIS v5.0 &gt; 3 - Compute Services &gt; 3.01 - Virtual Machines &gt; 3.01.01 - Ensure only MFA enabled identities can access privileged Virtual Machine &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 3 - Compute Services &gt; Maximum Attestation Duration
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.01 - Security Defaults (Per-User MFA)
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.01 - Security Defaults (Per-User MFA) &gt; 5.01.01 - Ensure that &apos;security defaults&apos; is enabled in Microsoft Entra ID
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.01 - Security Defaults (Per-User MFA) &gt; 5.01.01 - Ensure that &apos;security defaults&apos; is enabled in Microsoft Entra ID &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.01 - Security Defaults (Per-User MFA) &gt; 5.01.02 - Ensure that &apos;multifactor authentication&apos; is &apos;enabled&apos; for all users
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.01 - Security Defaults (Per-User MFA) &gt; 5.01.02 - Ensure that &apos;multifactor authentication&apos; is &apos;enabled&apos; for all users &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.01 - Security Defaults (Per-User MFA) &gt; 5.01.03 - Ensure that &apos;Allow users to remember multifactor authentication on devices they trust&apos; is disabled
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.01 - Security Defaults (Per-User MFA) &gt; 5.01.03 - Ensure that &apos;Allow users to remember multifactor authentication on devices they trust&apos; is disabled &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.02 - Conditional Access
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.02 - Conditional Access &gt; 5.02.01 - Ensure that &apos;trusted locations&apos; are defined
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.02 - Conditional Access &gt; 5.02.02 - Ensure that an exclusionary geographic Conditional Access policy is considered
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.02 - Conditional Access &gt; 5.02.02 - Ensure that an exclusionary geographic Conditional Access policy is considered &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.02 - Conditional Access &gt; 5.02.03 - Ensure that an exclusionary Device code flow policy is considered
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.02 - Conditional Access &gt; 5.02.03 - Ensure that an exclusionary Device code flow policy is considered &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.02 - Conditional Access &gt; 5.02.04 - Ensure that a multifactor authentication policy exists for all users
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.02 - Conditional Access &gt; 5.02.04 - Ensure that a multifactor authentication policy exists for all users &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.02 - Conditional Access &gt; 5.02.05 - Ensure that multifactor authentication is required for risky sign-ins
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.02 - Conditional Access &gt; 5.02.05 - Ensure that multifactor authentication is required for risky sign-ins &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.02 - Conditional Access &gt; 5.02.06 - Ensure that multifactor authentication is required for Windows Azure Service Management API
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.02 - Conditional Access &gt; 5.02.07 - Ensure that multifactor authentication is required to access Microsoft Admin Portals
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.02 - Conditional Access &gt; 5.02.08 - Ensure a Token Protection Conditional Access policy is considered
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.02 - Conditional Access &gt; 5.02.08 - Ensure a Token Protection Conditional Access policy is considered &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.03 - Periodic Identity Reviews
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.03 - Periodic Identity Reviews &gt; 5.03.01 - Ensure that Azure admin accounts are not used for daily operations
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.03 - Periodic Identity Reviews &gt; 5.03.01 - Ensure that Azure admin accounts are not used for daily operations &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.03 - Periodic Identity Reviews &gt; 5.03.02 - Ensure that guest users are reviewed on a regular basis
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.03 - Periodic Identity Reviews &gt; 5.03.03 - Ensure that use of the &apos;User Access Administrator&apos; role is restricted
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.03 - Periodic Identity Reviews &gt; 5.03.04 - Ensure that all &apos;privileged&apos; role assignments are periodically reviewed
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.03 - Periodic Identity Reviews &gt; 5.03.04 - Ensure that all &apos;privileged&apos; role assignments are periodically reviewed &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.03 - Periodic Identity Reviews &gt; 5.03.05 - Ensure disabled user accounts do not have read, write, or owner permissions
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.03 - Periodic Identity Reviews &gt; 5.03.05 - Ensure disabled user accounts do not have read, write, or owner permissions &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.03 - Periodic Identity Reviews &gt; 5.03.06 - Ensure &apos;Tenant Creator&apos; role assignments are periodically reviewed
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.03 - Periodic Identity Reviews &gt; 5.03.06 - Ensure &apos;Tenant Creator&apos; role assignments are periodically reviewed &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.03 - Periodic Identity Reviews &gt; 5.03.07 - Ensure all non-privileged role assignments are periodically reviewed
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.03 - Periodic Identity Reviews &gt; 5.03.07 - Ensure all non-privileged role assignments are periodically reviewed &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.04 - Ensure that &apos;Restrict non-admin users from creating tenants&apos; is set to &apos;Yes&apos;
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.04 - Ensure that &apos;Restrict non-admin users from creating tenants&apos; is set to &apos;Yes&apos; &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.05 - Ensure that &apos;Number of methods required to reset&apos; is set to &apos;2&apos;
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.05 - Ensure that &apos;Number of methods required to reset&apos; is set to &apos;2&apos; &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.06 - Ensure that account &apos;Lockout Threshold&apos; is less than or equal to &apos;10&apos;
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.06 - Ensure that account &apos;Lockout Threshold&apos; is less than or equal to &apos;10&apos; &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.07 - Ensure that account &apos;Lockout duration in seconds&apos; is greater than or equal to &apos;60&apos;
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.07 - Ensure that account &apos;Lockout duration in seconds&apos; is greater than or equal to &apos;60&apos; &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.08 - Ensure that a &apos;Custom banned password list&apos; is set to &apos;Enforce&apos;
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.08 - Ensure that a &apos;Custom banned password list&apos; is set to &apos;Enforce&apos; &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.09 - Ensure that &apos;Number of days before users are asked to re-confirm their authentication information&apos; is not set to &apos;0&apos;
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.09 - Ensure that &apos;Number of days before users are asked to re-confirm their authentication information&apos; is not set to &apos;0&apos; &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.10 - Ensure that &apos;Notify users on password resets?&apos; is set to &apos;Yes&apos;
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.10 - Ensure that &apos;Notify users on password resets?&apos; is set to &apos;Yes&apos; &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.11 - Ensure that &apos;Notify all admins when other admins reset their password?&apos; is set to &apos;Yes&apos;
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.11 - Ensure that &apos;Notify all admins when other admins reset their password?&apos; is set to &apos;Yes&apos; &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.12 - Ensure that &apos;User consent for applications&apos; is set to &apos;Do not allow user consent&apos;
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.12 - Ensure that &apos;User consent for applications&apos; is set to &apos;Do not allow user consent&apos; &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.13 - Ensure that &apos;User consent for applications&apos; is set to &apos;Allow user consent for apps from verified publishers, for selected permissions&apos;
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.13 - Ensure that &apos;User consent for applications&apos; is set to &apos;Allow user consent for apps from verified publishers, for selected permissions&apos; &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.14 - Ensure that &apos;Users can register applications&apos; is set to &apos;No&apos;
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.15 - Ensure that &apos;Guest users access restrictions&apos; is set to &apos;Guest user access is restricted to properties and memberships of their own directory objects&apos;
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.15 - Ensure that &apos;Guest users access restrictions&apos; is set to &apos;Guest user access is restricted to properties and memberships of their own directory objects&apos; &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.16 - Ensure that &apos;Guest invite restrictions&apos; is set to &apos;Only users assigned to specific admin roles [...]&apos; or &apos;No one [..]&apos;
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.16 - Ensure that &apos;Guest invite restrictions&apos; is set to &apos;Only users assigned to specific admin roles [...]&apos; or &apos;No one [..]&apos; &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.17 - Ensure that &apos;Restrict access to Microsoft Entra admin center&apos; is set to &apos;Yes&apos;
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.17 - Ensure that &apos;Restrict access to Microsoft Entra admin center&apos; is set to &apos;Yes&apos; &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.18 - Ensure that &apos;Restrict user ability to access groups features in My Groups&apos; is set to &apos;Yes&apos;
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.18 - Ensure that &apos;Restrict user ability to access groups features in My Groups&apos; is set to &apos;Yes&apos; &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.19 - Ensure that &apos;Users can create security groups in Azure portals, API or PowerShell&apos; is set to &apos;No&apos;
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.20 - Ensure that &apos;Owners can manage group membership requests in My Groups&apos; is set to &apos;No&apos;
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.20 - Ensure that &apos;Owners can manage group membership requests in My Groups&apos; is set to &apos;No&apos; &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.21 - Ensure that &apos;Users can create Microsoft 365 groups in Azure portals, API or PowerShell&apos; is set to &apos;No&apos;
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.21 - Ensure that &apos;Users can create Microsoft 365 groups in Azure portals, API or PowerShell&apos; is set to &apos;No&apos; &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.22 - Ensure that &apos;Require Multifactor Authentication to register or join devices with Microsoft Entra&apos; is set to &apos;Yes&apos;
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.22 - Ensure that &apos;Require Multifactor Authentication to register or join devices with Microsoft Entra&apos; is set to &apos;Yes&apos; &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.23 - Ensure That No Custom Subscription Administrator Roles Exist
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.24 - Ensure that a custom role is assigned permissions for administering resource locks
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.24 - Ensure that a custom role is assigned permissions for administering resource locks &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.25 - Ensure that &apos;Subscription leaving Microsoft Entra tenant&apos; and &apos;Subscription entering Microsoft Entra tenant&apos; is set to &apos;Permit no one&apos;
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.25 - Ensure that &apos;Subscription leaving Microsoft Entra tenant&apos; and &apos;Subscription entering Microsoft Entra tenant&apos; is set to &apos;Permit no one&apos; &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.26 - Ensure fewer than 5 users have global administrator assignment
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.27 - Ensure there are between 2 and 3 subscription owners
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.27 - Ensure there are between 2 and 3 subscription owners &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.28 - Ensure passwordless authentication methods are considered
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; 5.28 - Ensure passwordless authentication methods are considered &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 5 - Identity Services &gt; Maximum Attestation Duration
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.01 - Configuring Diagnostic Settings
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.01 - Configuring Diagnostic Settings &gt; 6.01.01.01 - Ensure that a &apos;Diagnostic Setting&apos; exists for Subscription Activity Logs
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.01 - Configuring Diagnostic Settings &gt; 6.01.01.01 - Ensure that a &apos;Diagnostic Setting&apos; exists for Subscription Activity Logs &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.01 - Configuring Diagnostic Settings &gt; 6.01.01.02 - Ensure Diagnostic Setting captures appropriate categories
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.01 - Configuring Diagnostic Settings &gt; 6.01.01.03 - Ensure the storage account containing the container with activity logs is encrypted with customer-managed key (CMK)
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.01 - Configuring Diagnostic Settings &gt; 6.01.01.04 - Ensure that logging for Azure Key Vault is &apos;Enabled&apos;
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.01 - Configuring Diagnostic Settings &gt; 6.01.01.05 - Ensure that Network Security Group Flow logs are captured and sent to Log Analytics
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.01 - Configuring Diagnostic Settings &gt; 6.01.01.06 - Ensure that logging for Azure AppService &apos;HTTP logs&apos; is enabled
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.01 - Configuring Diagnostic Settings &gt; 6.01.01.07 - Ensure that virtual network flow logs are captured and sent to Log Analytics
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.01 - Configuring Diagnostic Settings &gt; 6.01.01.07 - Ensure that virtual network flow logs are captured and sent to Log Analytics &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.01 - Configuring Diagnostic Settings &gt; 6.01.01.08 - Ensure that a Microsoft Entra diagnostic setting exists to send Microsoft Graph activity logs to an appropriate destination
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.01 - Configuring Diagnostic Settings &gt; 6.01.01.08 - Ensure that a Microsoft Entra diagnostic setting exists to send Microsoft Graph activity logs to an appropriate destination &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.01 - Configuring Diagnostic Settings &gt; 6.01.01.09 - Ensure that a Microsoft Entra diagnostic setting exists to send Microsoft Entra activity logs to an appropriate destination
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.01 - Configuring Diagnostic Settings &gt; 6.01.01.09 - Ensure that a Microsoft Entra diagnostic setting exists to send Microsoft Entra activity logs to an appropriate destination &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.01 - Configuring Diagnostic Settings &gt; 6.01.01.10 - Ensure that Intune logs are captured and sent to Log Analytics
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.01 - Configuring Diagnostic Settings &gt; 6.01.01.10 - Ensure that Intune logs are captured and sent to Log Analytics &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.02 - Monitoring using Activity Log Alerts
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.02 - Monitoring using Activity Log Alerts &gt; 6.01.02.01 - Ensure that Activity Log Alert exists for Create Policy Assignment
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.02 - Monitoring using Activity Log Alerts &gt; 6.01.02.02 - Ensure that Activity Log Alert exists for Delete Policy Assignment
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.02 - Monitoring using Activity Log Alerts &gt; 6.01.02.03 - Ensure that Activity Log Alert exists for Create or Update Network Security Group
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.02 - Monitoring using Activity Log Alerts &gt; 6.01.02.04 - Ensure that Activity Log Alert exists for Delete Network Security Group
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.02 - Monitoring using Activity Log Alerts &gt; 6.01.02.05 - Ensure that Activity Log Alert exists for Create or Update Security Solution
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.02 - Monitoring using Activity Log Alerts &gt; 6.01.02.06 - Ensure that Activity Log Alert exists for Delete Security Solution
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.02 - Monitoring using Activity Log Alerts &gt; 6.01.02.07 - Ensure that Activity Log Alert exists for Create or Update SQL Server Firewall Rule
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.02 - Monitoring using Activity Log Alerts &gt; 6.01.02.08 - Ensure that Activity Log Alert exists for Delete SQL Server Firewall Rule
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.02 - Monitoring using Activity Log Alerts &gt; 6.01.02.09 - Ensure that Activity Log Alert exists for Create or Update Public IP Address rule
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.02 - Monitoring using Activity Log Alerts &gt; 6.01.02.10 - Ensure that Activity Log Alert exists for Delete Public IP Address rule
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.02 - Monitoring using Activity Log Alerts &gt; 6.01.02.11 - Ensure that an Activity Log Alert exists for Service Health
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.03 - Configuring Application Insights
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.03 - Configuring Application Insights &gt; 6.01.03.01 - Ensure Application Insights are Configured
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.04 - Ensure that Azure Monitor Resource Logging is Enabled for All Services that Support it
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.04 - Ensure that Azure Monitor Resource Logging is Enabled for All Services that Support it &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.01 - Logging and Monitoring &gt; 6.01.05 - Ensure that SKU Basic/Consumption is not used on artifacts that need to be monitored (Particularly for Production Workloads)
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.02 - Ensure that Resource Locks are set for Mission-Critical Azure Resources
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; 6.02 - Ensure that Resource Locks are set for Mission-Critical Azure Resources &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 6 - Management and Governance Services &gt; Maximum Attestation Duration
- Azure &gt; CIS v5.0 &gt; 7 - Networking Services
- Azure &gt; CIS v5.0 &gt; 7 - Networking Services &gt; Maximum Attestation Duration
- Azure &gt; CIS v5.0 &gt; 7 - Networking Services &gt; 7.01 - Ensure that RDP access from the Internet is evaluated and restricted
- Azure &gt; CIS v5.0 &gt; 7 - Networking Services &gt; 7.02 - Ensure that SSH access from the Internet is evaluated and restricted
- Azure &gt; CIS v5.0 &gt; 7 - Networking Services &gt; 7.03 - Ensure that UDP access from the Internet is evaluated and restricted
- Azure &gt; CIS v5.0 &gt; 7 - Networking Services &gt; 7.04 - Ensure that HTTP(S) access from the Internet is evaluated and restricted
- Azure &gt; CIS v5.0 &gt; 7 - Networking Services &gt; 7.05 - Ensure that network security group flow log retention days is set to greater than or equal to 90
- Azure &gt; CIS v5.0 &gt; 7 - Networking Services &gt; 7.06 - Ensure that Network Watcher is &apos;Enabled&apos; for Azure Regions that are in use
- Azure &gt; CIS v5.0 &gt; 7 - Networking Services &gt; 7.07 - Ensure that Public IP addresses are Evaluated on a Periodic Basis
- Azure &gt; CIS v5.0 &gt; 7 - Networking Services &gt; 7.07 - Ensure that Public IP addresses are Evaluated on a Periodic Basis &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 7 - Networking Services &gt; 7.08 - Ensure that virtual network flow log retention days is set to greater than or equal to 90
- Azure &gt; CIS v5.0 &gt; 7 - Networking Services &gt; 7.09 - Ensure &apos;Authentication type&apos; is set to &apos;Azure Active Directory&apos; only for Azure VPN Gateway point-to-site configuration
- Azure &gt; CIS v5.0 &gt; 7 - Networking Services &gt; 7.10 - Ensure Azure Web Application Firewall (WAF) is enabled on Azure Application Gateway
- Azure &gt; CIS v5.0 &gt; 7 - Networking Services &gt; 7.11 - Ensure subnets are associated with network security groups
- Azure &gt; CIS v5.0 &gt; 7 - Networking Services &gt; 7.12 - Ensure the SSL policy&apos;s &apos;Min protocol version&apos; is set to &apos;TLSv1_2&apos; or higher on Azure Application Gateway
- Azure &gt; CIS v5.0 &gt; 7 - Networking Services &gt; 7.13 - Ensure &apos;HTTP2&apos; is set to &apos;Enabled&apos; on Azure Application Gateway
- Azure &gt; CIS v5.0 &gt; 7 - Networking Services &gt; 7.14 - Ensure request body inspection is enabled in Azure Web Application Firewall policy on Azure Application Gateway
- Azure &gt; CIS v5.0 &gt; 7 - Networking Services &gt; 7.15 - Ensure bot protection is enabled in Azure Web Application Firewall policy on Azure Application Gateway
- Azure &gt; CIS v5.0 &gt; 7 - Networking Services &gt; 7.16 - Ensure Azure Network Security Perimeter is used to secure Azure platform-as-a-service resources
- Azure &gt; CIS v5.0 &gt; 7 - Networking Services &gt; 7.16 - Ensure Azure Network Security Perimeter is used to secure Azure platform-as-a-service resources &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 8 - Security Services
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.01 - Microsoft Cloud Security Posture Management (CSPM)
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.01 - Microsoft Cloud Security Posture Management (CSPM) &gt; 8.01.01.01 - Ensure Microsoft Defender CSPM is set to &apos;On&apos;
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.02 - Defender Plan: APIs
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.02 - Defender Plan: APIs &gt; 8.01.02.01 - Ensure Microsoft Defender for APIs is set to &apos;On&apos;
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.03 - Defender Plan: Servers
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.03 - Defender Plan: Servers &gt; 8.01.03.01 - Ensure that Defender for Servers is set to &apos;On&apos;
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.03 - Defender Plan: Servers &gt; 8.01.03.02 - Ensure that &apos;Vulnerability assessment for machines&apos; component status is set to &apos;On&apos;
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.03 - Defender Plan: Servers &gt; 8.01.03.02 - Ensure that &apos;Vulnerability assessment for machines&apos; component status is set to &apos;On&apos; &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.03 - Defender Plan: Servers &gt; 8.01.03.03 - Ensure that &apos;Endpoint protection&apos; component status is set to &apos;On&apos;
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.03 - Defender Plan: Servers &gt; 8.01.03.04 - Ensure that &apos;Agentless scanning for machines&apos; component status is set to &apos;On&apos;
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.03 - Defender Plan: Servers &gt; 8.01.03.04 - Ensure that &apos;Agentless scanning for machines&apos; component status is set to &apos;On&apos; &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.03 - Defender Plan: Servers &gt; 8.01.03.05 - Ensure that &apos;File Integrity Monitoring&apos; component status is set to &apos;On&apos;
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.03 - Defender Plan: Servers &gt; 8.01.03.05 - Ensure that &apos;File Integrity Monitoring&apos; component status is set to &apos;On&apos; &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.04 - Defender Plan: Containers
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.04 - Defender Plan: Containers &gt; 8.01.04.01 - Ensure That Microsoft Defender for Containers Is Set To &apos;On&apos;
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.05 - Defender Plan: Storage
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.05 - Defender Plan: Storage &gt; 8.01.05.01 - Ensure That Microsoft Defender for Storage Is Set To &apos;On&apos;
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.05 - Defender Plan: Storage &gt; 8.01.05.02 - Ensure Advanced Threat Protection Alerts for Storage Accounts Are Monitored
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.05 - Defender Plan: Storage &gt; 8.01.05.02 - Ensure Advanced Threat Protection Alerts for Storage Accounts Are Monitored &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.06 - Defender Plan: App Service
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.06 - Defender Plan: App Service &gt; 8.01.06.01 - Ensure That Microsoft Defender for App Services Is Set To &apos;On&apos;
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.07 - Defender Plan: Databases
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.07 - Defender Plan: Databases &gt; 8.01.07.01 - Ensure That Microsoft Defender for Azure Cosmos DB Is Set To &apos;On&apos;
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.07 - Defender Plan: Databases &gt; 8.01.07.02 - Ensure That Microsoft Defender for Open-Source Relational Databases Is Set To &apos;On&apos;
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.07 - Defender Plan: Databases &gt; 8.01.07.03 - Ensure That Microsoft Defender for (Managed Instance) Azure SQL Databases Is Set To &apos;On&apos;
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.07 - Defender Plan: Databases &gt; 8.01.07.04 - Ensure That Microsoft Defender for SQL Servers on Machines Is Set To &apos;On&apos;
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.08 - Defender Plan: Key Vault
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.08 - Defender Plan: Key Vault &gt; 8.01.08.01 - Ensure That Microsoft Defender for Key Vault Is Set To &apos;On&apos;
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.09 - Defender Plan: Resource Manager
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.09 - Defender Plan: Resource Manager &gt; 8.01.09.01 - Ensure That Microsoft Defender for Resource Manager Is Set To &apos;On&apos;
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.10 - Ensure that Microsoft Defender for Cloud is configured to check VM operating systems for updates
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.10 - Ensure that Microsoft Defender for Cloud is configured to check VM operating systems for updates &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.11 - Ensure That Microsoft Cloud Security Benchmark policies are not set to &apos;Disabled&apos;
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.11 - Ensure That Microsoft Cloud Security Benchmark policies are not set to &apos;Disabled&apos; &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.12 - Ensure That &apos;All users with the following roles&apos; is set to &apos;Owner&apos;
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.13 - Ensure &apos;Additional email addresses&apos; is Configured with a Security Contact Email
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.14 - Ensure that &apos;Notify about alerts with the following severity (or higher)&apos; is enabled
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.15 - Ensure that &apos;Notify about attack paths with the following risk level (or higher)&apos; is enabled
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.16 - Ensure that Microsoft Defender External Attack Surface Monitoring (EASM) is enabled
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.01 - Microsoft Defender for Cloud &gt; 8.01.16 - Ensure that Microsoft Defender External Attack Surface Monitoring (EASM) is enabled &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.02 - Microsoft Defender for IoT
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.02 - Microsoft Defender for IoT &gt; 8.02.01 - Ensure That Microsoft Defender for IoT Hub Is Set To &apos;On&apos;
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.02 - Microsoft Defender for IoT &gt; 8.02.01 - Ensure That Microsoft Defender for IoT Hub Is Set To &apos;On&apos; &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.03 - Key Vault
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.03 - Key Vault &gt; 8.03.01 - Ensure that the Expiration Date is set for all Keys in RBAC Key Vaults
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.03 - Key Vault &gt; 8.03.02 - Ensure that the Expiration Date is set for all Keys in Non-RBAC Key Vaults
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.03 - Key Vault &gt; 8.03.03 - Ensure that the Expiration Date is set for all Secrets in RBAC Key Vaults
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.03 - Key Vault &gt; 8.03.04 - Ensure that the Expiration Date is set for all Secrets in Non-RBAC Key Vaults
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.03 - Key Vault &gt; 8.03.05 - Ensure &apos;Purge protection&apos; is set to &apos;Enabled&apos;
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.03 - Key Vault &gt; 8.03.06 - Ensure that Role Based Access Control for Azure Key Vault is enabled
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.03 - Key Vault &gt; 8.03.07 - Ensure Public Network Access is Disabled
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.03 - Key Vault &gt; 8.03.08 - Ensure Private Endpoints are used to access Azure Key Vault
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.03 - Key Vault &gt; 8.03.09 - Ensure automatic key rotation is enabled within Azure Key Vault
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.03 - Key Vault &gt; 8.03.10 - Ensure that Azure Key Vault Managed HSM is used when required
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.03 - Key Vault &gt; 8.03.10 - Ensure that Azure Key Vault Managed HSM is used when required &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.03 - Key Vault &gt; 8.03.11 - Ensure certificate &apos;Validity Period (in months)&apos; is less than or equal to &apos;12&apos;
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.04 - Azure Bastion
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.04 - Azure Bastion &gt; 8.04.01 - Ensure an Azure Bastion Host Exists
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; 8.05 - Ensure Azure DDoS Network Protection is enabled on virtual networks
- Azure &gt; CIS v5.0 &gt; 8 - Security Services &gt; Maximum Attestation Duration
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.01 - Azure Files
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.01 - Azure Files &gt; 9.01.01 - Ensure soft delete for Azure File Shares is Enabled
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.01 - Azure Files &gt; 9.01.02 - Ensure &apos;SMB protocol version&apos; is set to &apos;SMB 3.1.1&apos; or higher for SMB file shares
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.01 - Azure Files &gt; 9.01.03 - Ensure &apos;SMB channel encryption&apos; is set to &apos;AES-256-GCM&apos; or higher for SMB file shares
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.02 - Azure Blob Storage
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.02 - Azure Blob Storage &gt; 9.02.01 - Ensure that soft delete for blobs on Azure Blob Storage storage accounts is Enabled
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.02 - Azure Blob Storage &gt; 9.02.02 - Ensure that soft delete for containers on Azure Blob Storage storage accounts is Enabled
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.02 - Azure Blob Storage &gt; 9.02.03 - Ensure &apos;Versioning&apos; is set to &apos;Enabled&apos; on Azure Blob Storage storage accounts
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.03 - Storage Accounts
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.03 - Storage Accounts &gt; 9.03.01 - Secrets and Keys
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.03 - Storage Accounts &gt; 9.03.01 - Secrets and Keys &gt; 9.03.01.01 - Ensure that &apos;Enable key rotation reminders&apos; is enabled for each Storage Account
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.03 - Storage Accounts &gt; 9.03.01 - Secrets and Keys &gt; 9.03.01.02 - Ensure that Storage Account Access Keys are Periodically Regenerated
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.03 - Storage Accounts &gt; 9.03.01 - Secrets and Keys &gt; 9.03.01.02 - Ensure that Storage Account Access Keys are Periodically Regenerated &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.03 - Storage Accounts &gt; 9.03.01 - Secrets and Keys &gt; 9.03.01.03 - Ensure &apos;Allow storage account key access&apos; for Azure Storage Accounts is &apos;Disabled&apos;
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.03 - Storage Accounts &gt; 9.03.02 - Networking
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.03 - Storage Accounts &gt; 9.03.02 - Networking &gt; 9.03.02.01 - Ensure Private Endpoints are used to access Storage Accounts
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.03 - Storage Accounts &gt; 9.03.02 - Networking &gt; 9.03.02.02 - Ensure that &apos;Public Network Access&apos; is &apos;Disabled&apos; for storage accounts
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.03 - Storage Accounts &gt; 9.03.02 - Networking &gt; 9.03.02.03 - Ensure default network access rule for storage accounts is set to deny
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.03 - Storage Accounts &gt; 9.03.03 - Identity and Access Management
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.03 - Storage Accounts &gt; 9.03.03 - Identity and Access Management &gt; 9.03.03.01 - Ensure that &apos;Default to Microsoft Entra authorization in the Azure portal&apos; is set to &apos;Enabled&apos;
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.03 - Storage Accounts &gt; 9.03.04 - Ensure that &apos;Secure transfer required&apos; is set to &apos;Enabled&apos;
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.03 - Storage Accounts &gt; 9.03.05 - Ensure &apos;Allow Azure services on the trusted services list to access this storage account&apos; is Enabled for Storage Account Access
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.03 - Storage Accounts &gt; 9.03.06 - Ensure the &apos;Minimum TLS version&apos; for storage accounts is set to &apos;Version 1.2&apos;
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.03 - Storage Accounts &gt; 9.03.07 - Ensure &apos;Cross Tenant Replication&apos; is not enabled
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.03 - Storage Accounts &gt; 9.03.08 - Ensure that &apos;Allow Blob Anonymous Access&apos; is set to &apos;Disabled&apos;
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.03 - Storage Accounts &gt; 9.03.09 - Ensure Azure Resource Manager Delete locks are applied to Azure Storage Accounts
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.03 - Storage Accounts &gt; 9.03.09 - Ensure Azure Resource Manager Delete locks are applied to Azure Storage Accounts &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.03 - Storage Accounts &gt; 9.03.10 - Ensure Azure Resource Manager ReadOnly locks are considered for Azure Storage Accounts
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.03 - Storage Accounts &gt; 9.03.10 - Ensure Azure Resource Manager ReadOnly locks are considered for Azure Storage Accounts &gt; Attestation
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; 9.03 - Storage Accounts &gt; 9.03.11 - Ensure Redundancy is set to &apos;geo-redundant storage (GRS)&apos; on critical Azure Storage Accounts
- Azure &gt; CIS v5.0 &gt; 9 - Storage Services &gt; Maximum Attestation Duration
- Azure &gt; CIS v5.0 &gt; Maximum Attestation Duration

_Note_

This mod requires `@turbot/azure-storage` v5.31.0 or higher for the Storage Services (Section 9) controls to function correctly.</description>
            <pubDate>Wed, 11 Feb 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-sns-v5-20-1</guid>
            <title>aws-sns v5.20.1 - Encryption at Rest control now correctly skips Guardrails-managed SNS topics</title>
            <link>https://turbot.com/guardrails/changelog/aws-sns-v5-20-1</link>
            <description>_Bug fixes_

- The `AWS &gt; SNS &gt; Topic &gt; Encryption at Rest` control now correctly skips Guardrails-managed SNS topics created by the Event Handlers stack. Previously, when encryption was set to Enforce, the control would repeatedly attempt to update the `KmsMasterKeyId` attribute on these topics, conflicting with the Event Handler stack and causing a loop of `SetTopicAttributes` CloudTrail events.</description>
            <pubDate>Wed, 11 Feb 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-pciv3-2-1-v5-1-2</guid>
            <title>aws-pciv3-2-1 v5.1.2 - Fixed mod installation failure and policy mappings in various control types</title>
            <link>https://turbot.com/guardrails/changelog/aws-pciv3-2-1-v5-1-2</link>
            <description>_Bug fixes_

- Fixed mod installation failure by adding `@turbot/aws-vpc-connect` peer dependency required by `aws-vpc-security 5.16.1`.
- Fixed policy mappings in various control types.</description>
            <pubDate>Wed, 11 Feb 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-cisv6-0-v5-0-1</guid>
            <title>aws-cisv6-0 v5.0.1 - Fixed mod installation failure by adding missing peer dependency</title>
            <link>https://turbot.com/guardrails/changelog/aws-cisv6-0-v5-0-1</link>
            <description>_Bug fixes_

- Fixed mod installation failure by adding `@turbot/aws-vpc-connect` peer dependency required by `aws-vpc-security 5.16.1`.</description>
            <pubDate>Wed, 11 Feb 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-cisv5-0-v5-0-1</guid>
            <title>aws-cisv5-0 v5.0.1 - Fixed mod installation failure by adding missing peer dependency</title>
            <link>https://turbot.com/guardrails/changelog/aws-cisv5-0-v5-0-1</link>
            <description>_Bug fixes_

- Fixed mod installation failure by adding `@turbot/aws-vpc-connect` peer dependency required by `aws-vpc-security 5.16.1`.</description>
            <pubDate>Wed, 11 Feb 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-cisv4-0-v5-0-1</guid>
            <title>aws-cisv4-0 v5.0.1 - Fixed mod installation failure by adding missing peer dependency</title>
            <link>https://turbot.com/guardrails/changelog/aws-cisv4-0-v5-0-1</link>
            <description>_Bug fixes_

- Fixed mod installation failure by adding `@turbot/aws-vpc-connect` peer dependency required by `aws-vpc-security 5.16.1`.</description>
            <pubDate>Wed, 11 Feb 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-cisv3-0-v5-0-9</guid>
            <title>aws-cisv3-0 v5.0.9 - Fixed mod installation failure by adding missing peer dependency</title>
            <link>https://turbot.com/guardrails/changelog/aws-cisv3-0-v5-0-9</link>
            <description>_Bug fixes_

- Fixed mod installation failure by adding `@turbot/aws-vpc-connect` peer dependency required by `aws-vpc-security 5.16.1`.</description>
            <pubDate>Wed, 11 Feb 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-cisv2-0-v5-0-7</guid>
            <title>aws-cisv2-0 v5.0.7 - Fixed mod installation failure by adding missing peer dependency</title>
            <link>https://turbot.com/guardrails/changelog/aws-cisv2-0-v5-0-7</link>
            <description>_Bug fixes_

- Fixed mod installation failure by adding `@turbot/aws-vpc-connect` peer dependency required by `aws-vpc-security 5.16.1`.</description>
            <pubDate>Wed, 11 Feb 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-cisv1-v5-0-12</guid>
            <title>aws-cisv1 v5.0.12 - Fixed mod installation failure by adding missing peer dependency</title>
            <link>https://turbot.com/guardrails/changelog/aws-cisv1-v5-0-12</link>
            <description>_Bug fixes_

- Fixed mod installation failure by adding `@turbot/aws-vpc-connect` peer dependency required by `aws-vpc-security 5.16.1`.</description>
            <pubDate>Wed, 11 Feb 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-cisv1-4-v5-0-11</guid>
            <title>aws-cisv1-4 v5.0.11 - Fixed mod installation failure by adding missing peer dependency</title>
            <link>https://turbot.com/guardrails/changelog/aws-cisv1-4-v5-0-11</link>
            <description>_Bug fixes_

- Fixed mod installation failure by adding `@turbot/aws-vpc-connect` peer dependency required by `aws-vpc-security 5.16.1`.</description>
            <pubDate>Wed, 11 Feb 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-57-0</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.57.0 - OCI tenancy import and automatic mod dependency resolution</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-57-0</link>
            <description>_What&apos;s new?_

- Server
  - Added support for importing OCI (Oracle Cloud Infrastructure) tenancies into Guardrails, including connectivity testing to validate credentials before import.
  - Added automatic dependency resolution for mod installation.

- UI
  - Added an OCI tenancy import wizard to the cloud services import flow, guiding users through credential configuration and connectivity testing.

_Requirements_

- Upgrade to `5.57.0` requires your workspace to be on `5.55.x`
- PostgreSQL (RDS engine): &gt;= 15
- TEF: 1.66.0
- TED: 1.37.0
- Mods:
  - @turbot/turbot: 5.57.0

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Mon, 09 Feb 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-cisv4-0-v5-0-1</guid>
            <title>azure-cisv4-0 v5.0.1 - Fixed various CIS v4.0 controls that were in error state or requiring manual attestation</title>
            <link>https://turbot.com/guardrails/changelog/azure-cisv4-0-v5-0-1</link>
            <description>_Bug fixes_

- The `Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.02 - Azure Blob Storage &gt; 10.02.01 - Ensure that soft delete for blobs on Azure Blob Storage storage accounts is enabled` control would go into an error state when the `blobDeleteRetentionPolicy` property was `null` for FileStorage accounts. This is now fixed.
- The `06.02.06`, `06.02.07`, and `06.26` controls now automatically evaluate compliance instead of requiring manual attestation. Their default policy values were corrected from `Check: Benchmark using attestation` to `Check: Benchmark`.</description>
            <pubDate>Mon, 09 Feb 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-v5-43-4</guid>
            <title>aws v5.43.4 - CMDB control for account now gracefully handles missing account credentials in organization imports</title>
            <link>https://turbot.com/guardrails/changelog/aws-v5-43-4</link>
            <description>_Bug fixes_

- The `AWS &gt; Account &gt; CMDB` control previously entered an error state for accounts upserted into the Guardrails CMDB as part of an AWS organization when Guardrails lacked permission to retrieve account-specific details. The control now gracefully handles missing account credentials by skipping account-specific API calls while still populating organization-level data. We recommend upgrading your workspace TE version to 5.57.0 or later to ensure this behavior works as expected.
- The `AWS &gt; Account &gt; Discovery` control previously entered an error state on workspaces running TE versions earlier than 5.56.0 due to incorrect GraphQL query dependencies. This issue has been resolved, and the control now works as expected.</description>
            <pubDate>Mon, 09 Feb 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ec2-v5-51-1</guid>
            <title>aws-ec2 v5.51.1 - AMI CMDB control will no longer enter an error state due to a missing AWS SDK dependency</title>
            <link>https://turbot.com/guardrails/changelog/aws-ec2-v5-51-1</link>
            <description>_Bug fixes_

- The `AWS &gt; EC2 &gt; AMI &gt; CMDB` control would go into an error state due to a missing AWS SDK dependency. This is now fixed.</description>
            <pubDate>Mon, 09 Feb 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-55-3</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.55.3 - Resolved hanging issue when attaching multiple policy packs</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-55-3</link>
            <description>_Bug fixes_

- Server
  - Fixed an issue that could cause policy pack attachments to hang when attaching multiple policy packs to a resource.

_Requirements_

- Upgrade to `5.55.3` requires your workspace to be on `5.54.x`
- PostgreSQL (RDS engine): &gt;= 15
- TEF: 1.66.0
- TED: 1.37.0
- Mods:
  - @turbot/turbot: 5.56.0

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Fri, 06 Feb 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-54-14</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.54.14 - Resolved hanging issue when attaching multiple policy packs</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-54-14</link>
            <description>_Bug fixes_

- Server
  - Fixed an issue that could cause policy pack attachments to hang when attaching multiple policy packs to a resource.

_Notes_

- Versions `5.54.15`, `5.54.16`, and `5.54.17` include version bumps only and contain no additional functional changes beyond those listed in `5.54.14`.

_Requirements_

- Upgrade to `5.54.12` requires your workspace to be on `5.53.x`
- PostgreSQL (RDS engine): &gt;= 15
- TEF: 1.66.0
- TED: 1.37.0
- Mods:
  - @turbot/turbot: 5.56.0

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Fri, 06 Feb 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-54-13</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.54.13 - Policy value mode materialization fix</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-54-13</link>
            <description>_Bug fixes_

- Server
  - Policy values now use the correct mode when they’re materialized.

_Requirements_

- Upgrade to `5.54.12` requires your workspace to be on `5.53.x`
- PostgreSQL (RDS engine): &gt;= 15
- TEF: 1.66.0
- TED: 1.37.0
- Mods:
  - @turbot/turbot: 5.56.0

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Fri, 06 Feb 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-cisv3-0-v5-0-3</guid>
            <title>azure-cisv3-0 v5.0.3 - Fixed various CIS v3.0 controls stuck in TBD state</title>
            <link>https://turbot.com/guardrails/changelog/azure-cisv3-0-v5-0-3</link>
            <description>_Bug fixes_

- The `Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.02 - Azure Database for PostgreSQL &gt; 05.02.02 - Ensure server parameter &apos;log_checkpoints&apos; is set to &apos;ON&apos; for PostgreSQL flexible server` control would get stuck in a TBD state. This is now fixed.
- The `Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.02 - Azure Database for PostgreSQL &gt; 05.02.05 - Ensure &apos;Allow public access from any Azure service within Azure to this server&apos; for PostgreSQL flexible server is disabled` control would get stuck in a TBD state. This is now fixed.
- The `Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.03 - Azure Database for MySQL &gt; 05.03.02 - Ensure server parameter &apos;tls_version&apos; is set to &apos;TLSv1.2&apos; (or higher) for MySQL flexible server` control would get stuck in a TBD state. This is now fixed.
- The `Azure &gt; CIS v3.0 &gt; 06 - Logging &amp; Monitoring &gt; 06.01 - Configuring Diagnostic Settings &gt; 06.01.04 - Ensure that logging for Azure Key Vault is &apos;Enabled&apos;` control would get stuck in a TBD state. This is now fixed.
- The `Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.02 - Azure Database for PostgreSQL &gt; 05.02.06 - [LEGACY] Ensure server parameter &apos;log_connections&apos; is set to &apos;ON&apos; for PostgreSQL single server` control would incorrectly target PostgreSQL Flexible Server. This is now fixed.
- The `Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.02 - Azure Database for PostgreSQL &gt; 05.02.07 - [LEGACY] Ensure server parameter &apos;log_disconnections&apos; is set to &apos;ON&apos; for PostgreSQL single server` control would incorrectly target PostgreSQL Flexible Server. This is now fixed.</description>
            <pubDate>Fri, 06 Feb 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-cisv2-0-v5-2-2</guid>
            <title>azure-cisv2-0 v5.2.2 - Fixed CIS v2.0 logging and monitoring control error when referenced storage account does not exist</title>
            <link>https://turbot.com/guardrails/changelog/azure-cisv2-0-v5-2-2</link>
            <description>_Bug fixes_

- The `Azure &gt; CIS v2.0 &gt; 05 - Logging and Monitoring &gt; 5.01.04 - Ensure the storage account containing the container with activity logs is encrypted with Customer Managed Key` control would go into an error state when the storage account referenced in the log profile did not exist. This is now fixed.</description>
            <pubDate>Fri, 06 Feb 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ec2-v5-51-0</guid>
            <title>aws-ec2 v5.51.0 - CMDB data for instances now includes AMI details</title>
            <link>https://turbot.com/guardrails/changelog/aws-ec2-v5-51-0</link>
            <description>_What&apos;s new?_

- CMDB data for instances now also includes details of the AMIs associated with those instances.</description>
            <pubDate>Fri, 06 Feb 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-55-2</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.55.2 - Policy value mode materialization fix</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-55-2</link>
            <description>_Bug fixes_

- Server
  - Policy values now use the correct mode when they&apos;re materialized.

_Requirements_

- Upgrade to `5.55.2` requires your workspace to be on `5.54.x`
- PostgreSQL (RDS engine): &gt;= 15
- TEF: 1.66.0
- TED: 1.37.0
- Mods:
  - @turbot/turbot: 5.56.0

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Thu, 05 Feb 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/oci-compute-v5-0-0</guid>
            <title>oci-compute v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/oci-compute-v5-0-0</link>
            <description>_Resource Types_

- OCI &gt; Compute
- OCI &gt; Compute &gt; Instance

_Control Types_

- OCI &gt; Compute &gt; Instance &gt; Allowed
- OCI &gt; Compute &gt; Instance &gt; Allowed &gt; Custom
- OCI &gt; Compute &gt; Instance &gt; Allowed &gt; Region
- OCI &gt; Compute &gt; Instance &gt; CMDB
- OCI &gt; Compute &gt; Instance &gt; Defined Tags
- OCI &gt; Compute &gt; Instance &gt; Discovery
- OCI &gt; Compute &gt; Instance &gt; Freeform Tags

_Policy Types_

- OCI &gt; Compute &gt; Allowed Regions [Default]
- OCI &gt; Compute &gt; Instance &gt; Allowed
- OCI &gt; Compute &gt; Instance &gt; Allowed &gt; Custom
- OCI &gt; Compute &gt; Instance &gt; Allowed &gt; Custom &gt; Rules
- OCI &gt; Compute &gt; Instance &gt; Allowed &gt; Region
- OCI &gt; Compute &gt; Instance &gt; Allowed &gt; Region &gt; Regions
- OCI &gt; Compute &gt; Instance &gt; CMDB
- OCI &gt; Compute &gt; Instance &gt; Defined Tags
- OCI &gt; Compute &gt; Instance &gt; Defined Tags &gt; Template
- OCI &gt; Compute &gt; Instance &gt; Freeform Tags
- OCI &gt; Compute &gt; Instance &gt; Freeform Tags &gt; Template
- OCI &gt; Compute &gt; Regions

_Action Types_

- OCI &gt; Compute &gt; Instance &gt; Router
- OCI &gt; Compute &gt; Instance &gt; Update Defined Tags
- OCI &gt; Compute &gt; Instance &gt; Update Freeform Tags

_Note_

To ensure compatibility and proper functioning of the mod, please upgrade TE to v5.57.0 or higher.</description>
            <pubDate>Thu, 05 Feb 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-v5-34-1</guid>
            <title>gcp v5.34.1 - CMDB control for project will no longer enter an error state for workspaces on TE v5.55.0 or lower</title>
            <link>https://turbot.com/guardrails/changelog/gcp-v5-34-1</link>
            <description>_Bug fixes_

- The `GCP &gt; Project &gt; CMDB` control entered an error state on workspaces running TE versions earlier than 5.56.0 due to an inadvertent bug in the GraphQL input query introduced in the previous version of the mod. This issue has been fixed, and the control now works as expected.</description>
            <pubDate>Thu, 05 Feb 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-v5-35-2</guid>
            <title>azure v5.35.2 - CMDB control for subscription will no longer enter an error state for workspaces on TE v5.55.0 or lower</title>
            <link>https://turbot.com/guardrails/changelog/azure-v5-35-2</link>
            <description>_Bug fixes_

- The `Azure &gt; Subscription &gt; CMDB` control entered an error state on workspaces running TE versions earlier than 5.56.0 due to an inadvertent bug in the GraphQL input query introduced in the previous version of the mod. This issue has been fixed, and the control now works as expected.</description>
            <pubDate>Thu, 05 Feb 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-v5-35-1</guid>
            <title>azure v5.35.1 - Fixed an issue where deleted Azure Resource Groups could still appear in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-v5-35-1</link>
            <description>_Bug fixes_

- Fixed an issue where deleted Azure Resource Groups could still appear in Guardrails. The `Azure &gt; Resource Group &gt; CMDB` control now automatically refreshes every 24 hours to ensure deleted resources are properly removed.</description>
            <pubDate>Thu, 05 Feb 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-v5-43-3</guid>
            <title>aws v5.43.3 - Deprecated the Organization CMDB Exclude policy</title>
            <link>https://turbot.com/guardrails/changelog/aws-v5-43-3</link>
            <description>_Policy Types_

_Renamed_

- `AWS &gt; Organization &gt; CMDB &gt; Exclude` to `AWS &gt; Organization &gt; CMDB &gt; Exclude [Deprecated]`</description>
            <pubDate>Thu, 05 Feb 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/oci-v5-0-0</guid>
            <title>oci v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/oci-v5-0-0</link>
            <description>_Resource Types_

- OCI
- OCI &gt; Compartment
- OCI &gt; Region
- OCI &gt; Tenancy

_Control Types_

- OCI &gt; Compartment &gt; CMDB
- OCI &gt; Compartment &gt; Defined Tags
- OCI &gt; Compartment &gt; Discovery
- OCI &gt; Compartment &gt; Freeform Tags
- OCI &gt; Region &gt; Discovery
- OCI &gt; Tenancy &gt; CMDB
- OCI &gt; Turbot
- OCI &gt; Turbot &gt; Event Poller

_Policy Types_

- OCI &gt; Compartment &gt; CMDB
- OCI &gt; Compartment &gt; Defined Tags
- OCI &gt; Compartment &gt; Defined Tags &gt; Template
- OCI &gt; Compartment &gt; Freeform Tags
- OCI &gt; Compartment &gt; Freeform Tags &gt; Template
- OCI &gt; Config
- OCI &gt; Config &gt; Fingerprint
- OCI &gt; Config &gt; Home Region
- OCI &gt; Config &gt; Private Key
- OCI &gt; Config &gt; Tenancy OCID
- OCI &gt; Config &gt; User OCID
- OCI &gt; Login Names
- OCI &gt; Region &gt; CMDB
- OCI &gt; Tenancy &gt; Allowed Regions [Default]
- OCI &gt; Tenancy &gt; CMDB
- OCI &gt; Tenancy &gt; Defined Tags Template [Default]
- OCI &gt; Tenancy &gt; Freeform Tags Template [Default]
- OCI &gt; Tenancy &gt; Regions
- OCI &gt; Tenancy &gt; Tags Template [Default]
- OCI &gt; Turbot
- OCI &gt; Turbot &gt; Event Poller
- OCI &gt; Turbot &gt; Event Poller &gt; Excluded Events
- OCI &gt; Turbot &gt; Event Poller &gt; Interval
- OCI &gt; Turbot &gt; Event Poller &gt; Window

_Action Types_

- OCI &gt; Compartment &gt; Router
- OCI &gt; Compartment &gt; Update Defined Tags
- OCI &gt; Compartment &gt; Update Freeform Tags
- OCI &gt; Tenancy &gt; Event Handler

_Note_

To ensure compatibility and proper functioning of the mod, please upgrade TE to v5.57.0 or higher.</description>
            <pubDate>Tue, 03 Feb 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/oci-storage-v5-0-0</guid>
            <title>oci-storage v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/oci-storage-v5-0-0</link>
            <description>_Resource Types_

- OCI &gt; Storage
- OCI &gt; Storage &gt; Block Volume
- OCI &gt; Storage &gt; Boot Volume
- OCI &gt; Storage &gt; Bucket
- OCI &gt; Storage &gt; File System
- OCI &gt; Storage &gt; Mount Target

_Control Types_

- OCI &gt; Storage &gt; Block Volume &gt; Allowed
- OCI &gt; Storage &gt; Block Volume &gt; Allowed &gt; Custom
- OCI &gt; Storage &gt; Block Volume &gt; Allowed &gt; Region
- OCI &gt; Storage &gt; Block Volume &gt; CMDB
- OCI &gt; Storage &gt; Block Volume &gt; Defined Tags
- OCI &gt; Storage &gt; Block Volume &gt; Discovery
- OCI &gt; Storage &gt; Block Volume &gt; Freeform Tags
- OCI &gt; Storage &gt; Boot Volume &gt; Allowed
- OCI &gt; Storage &gt; Boot Volume &gt; Allowed &gt; Custom
- OCI &gt; Storage &gt; Boot Volume &gt; Allowed &gt; Region
- OCI &gt; Storage &gt; Boot Volume &gt; CMDB
- OCI &gt; Storage &gt; Boot Volume &gt; Defined Tags
- OCI &gt; Storage &gt; Boot Volume &gt; Discovery
- OCI &gt; Storage &gt; Boot Volume &gt; Freeform Tags
- OCI &gt; Storage &gt; Bucket &gt; Allowed
- OCI &gt; Storage &gt; Bucket &gt; Allowed &gt; Custom
- OCI &gt; Storage &gt; Bucket &gt; Allowed &gt; Region
- OCI &gt; Storage &gt; Bucket &gt; CMDB
- OCI &gt; Storage &gt; Bucket &gt; Defined Tags
- OCI &gt; Storage &gt; Bucket &gt; Discovery
- OCI &gt; Storage &gt; Bucket &gt; Freeform Tags
- OCI &gt; Storage &gt; File System &gt; Allowed
- OCI &gt; Storage &gt; File System &gt; Allowed &gt; Custom
- OCI &gt; Storage &gt; File System &gt; Allowed &gt; Region
- OCI &gt; Storage &gt; File System &gt; CMDB
- OCI &gt; Storage &gt; File System &gt; Defined Tags
- OCI &gt; Storage &gt; File System &gt; Discovery
- OCI &gt; Storage &gt; File System &gt; Freeform Tags
- OCI &gt; Storage &gt; Mount Target &gt; Allowed
- OCI &gt; Storage &gt; Mount Target &gt; Allowed &gt; Custom
- OCI &gt; Storage &gt; Mount Target &gt; Allowed &gt; Region
- OCI &gt; Storage &gt; Mount Target &gt; CMDB
- OCI &gt; Storage &gt; Mount Target &gt; Defined Tags
- OCI &gt; Storage &gt; Mount Target &gt; Discovery
- OCI &gt; Storage &gt; Mount Target &gt; Freeform Tags

_Policy Types_

- OCI &gt; Storage &gt; Allowed Regions [Default]
- OCI &gt; Storage &gt; Block Volume &gt; Allowed
- OCI &gt; Storage &gt; Block Volume &gt; Allowed &gt; Custom
- OCI &gt; Storage &gt; Block Volume &gt; Allowed &gt; Custom &gt; Rules
- OCI &gt; Storage &gt; Block Volume &gt; Allowed &gt; Region
- OCI &gt; Storage &gt; Block Volume &gt; Allowed &gt; Region &gt; Regions
- OCI &gt; Storage &gt; Block Volume &gt; CMDB
- OCI &gt; Storage &gt; Block Volume &gt; Defined Tags
- OCI &gt; Storage &gt; Block Volume &gt; Defined Tags &gt; Template
- OCI &gt; Storage &gt; Block Volume &gt; Freeform Tags
- OCI &gt; Storage &gt; Block Volume &gt; Freeform Tags &gt; Template
- OCI &gt; Storage &gt; Boot Volume &gt; Allowed
- OCI &gt; Storage &gt; Boot Volume &gt; Allowed &gt; Custom
- OCI &gt; Storage &gt; Boot Volume &gt; Allowed &gt; Custom &gt; Rules
- OCI &gt; Storage &gt; Boot Volume &gt; Allowed &gt; Region
- OCI &gt; Storage &gt; Boot Volume &gt; Allowed &gt; Region &gt; Regions
- OCI &gt; Storage &gt; Boot Volume &gt; CMDB
- OCI &gt; Storage &gt; Boot Volume &gt; Defined Tags
- OCI &gt; Storage &gt; Boot Volume &gt; Defined Tags &gt; Template
- OCI &gt; Storage &gt; Boot Volume &gt; Freeform Tags
- OCI &gt; Storage &gt; Boot Volume &gt; Freeform Tags &gt; Template
- OCI &gt; Storage &gt; Bucket &gt; Allowed
- OCI &gt; Storage &gt; Bucket &gt; Allowed &gt; Custom
- OCI &gt; Storage &gt; Bucket &gt; Allowed &gt; Custom &gt; Rules
- OCI &gt; Storage &gt; Bucket &gt; Allowed &gt; Region
- OCI &gt; Storage &gt; Bucket &gt; Allowed &gt; Region &gt; Regions
- OCI &gt; Storage &gt; Bucket &gt; CMDB
- OCI &gt; Storage &gt; Bucket &gt; Defined Tags
- OCI &gt; Storage &gt; Bucket &gt; Defined Tags &gt; Template
- OCI &gt; Storage &gt; Bucket &gt; Freeform Tags
- OCI &gt; Storage &gt; Bucket &gt; Freeform Tags &gt; Template
- OCI &gt; Storage &gt; File System &gt; Allowed
- OCI &gt; Storage &gt; File System &gt; Allowed &gt; Custom
- OCI &gt; Storage &gt; File System &gt; Allowed &gt; Custom &gt; Rules
- OCI &gt; Storage &gt; File System &gt; Allowed &gt; Region
- OCI &gt; Storage &gt; File System &gt; Allowed &gt; Region &gt; Regions
- OCI &gt; Storage &gt; File System &gt; CMDB
- OCI &gt; Storage &gt; File System &gt; Defined Tags
- OCI &gt; Storage &gt; File System &gt; Defined Tags &gt; Template
- OCI &gt; Storage &gt; File System &gt; Freeform Tags
- OCI &gt; Storage &gt; File System &gt; Freeform Tags &gt; Template
- OCI &gt; Storage &gt; Mount Target &gt; Allowed
- OCI &gt; Storage &gt; Mount Target &gt; Allowed &gt; Custom
- OCI &gt; Storage &gt; Mount Target &gt; Allowed &gt; Custom &gt; Rules
- OCI &gt; Storage &gt; Mount Target &gt; Allowed &gt; Region
- OCI &gt; Storage &gt; Mount Target &gt; Allowed &gt; Region &gt; Regions
- OCI &gt; Storage &gt; Mount Target &gt; CMDB
- OCI &gt; Storage &gt; Mount Target &gt; Defined Tags
- OCI &gt; Storage &gt; Mount Target &gt; Defined Tags &gt; Template
- OCI &gt; Storage &gt; Mount Target &gt; Freeform Tags
- OCI &gt; Storage &gt; Mount Target &gt; Freeform Tags &gt; Template
- OCI &gt; Storage &gt; Regions

_Action Types_

- OCI &gt; Storage &gt; Block Volume &gt; Router
- OCI &gt; Storage &gt; Block Volume &gt; Update Defined Tags
- OCI &gt; Storage &gt; Block Volume &gt; Update Freeform Tags
- OCI &gt; Storage &gt; Boot Volume &gt; Router
- OCI &gt; Storage &gt; Boot Volume &gt; Update Defined Tags
- OCI &gt; Storage &gt; Boot Volume &gt; Update Freeform Tags
- OCI &gt; Storage &gt; Bucket &gt; Router
- OCI &gt; Storage &gt; Bucket &gt; Update Defined Tags
- OCI &gt; Storage &gt; Bucket &gt; Update Freeform Tags
- OCI &gt; Storage &gt; File System &gt; Router
- OCI &gt; Storage &gt; File System &gt; Update Defined Tags
- OCI &gt; Storage &gt; File System &gt; Update Freeform Tags
- OCI &gt; Storage &gt; Mount Target &gt; Router
- OCI &gt; Storage &gt; Mount Target &gt; Update Defined Tags
- OCI &gt; Storage &gt; Mount Target &gt; Update Freeform Tags

_Note_

To ensure compatibility and proper functioning of the mod, please upgrade TE to v5.57.0 or higher.</description>
            <pubDate>Tue, 03 Feb 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-cisv4-0-v5-0-0</guid>
            <title>azure-cisv4-0 v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/azure-cisv4-0-v5-0-0</link>
            <description>_Control Types_

- Azure &gt; CIS v4.0
- Azure &gt; CIS v4.0 &gt; 02 - Common Reference Recommendations
- Azure &gt; CIS v4.0 &gt; 02 - Common Reference Recommendations &gt; 02.01 - Secrets and Keys
- Azure &gt; CIS v4.0 &gt; 02 - Common Reference Recommendations &gt; 02.01 - Secrets and Keys &gt; 02.01.01 - Encryption Key Management
- Azure &gt; CIS v4.0 &gt; 02 - Common Reference Recommendations &gt; 02.01 - Secrets and Keys &gt; 02.01.01 - Encryption Key Management &gt; 02.01.01.01 - Microsoft Managed Keys (MMK)
- Azure &gt; CIS v4.0 &gt; 02 - Common Reference Recommendations &gt; 02.01 - Secrets and Keys &gt; 02.01.01 - Encryption Key Management &gt; 02.01.01.01 - Microsoft Managed Keys (MMK) &gt; 02.01.01.01.01 - Ensure Critical Data is Encrypted with Microsoft Managed Keys (MMK)
- Azure &gt; CIS v4.0 &gt; 02 - Common Reference Recommendations &gt; 02.01 - Secrets and Keys &gt; 02.01.01 - Encryption Key Management &gt; 02.01.01.02 - Customer Managed Keys (CMK)
- Azure &gt; CIS v4.0 &gt; 02 - Common Reference Recommendations &gt; 02.01 - Secrets and Keys &gt; 02.01.01 - Encryption Key Management &gt; 02.01.01.02 - Customer Managed Keys (CMK) &gt; 02.01.01.02.01 - Ensure Critical Data is Encrypted with Customer Managed Keys (CMK)
- Azure &gt; CIS v4.0 &gt; 02 - Common Reference Recommendations &gt; 02.02 - Networking
- Azure &gt; CIS v4.0 &gt; 02 - Common Reference Recommendations &gt; 02.02 - Networking &gt; 02.02.01 - Virtual Networks (VNets)
- Azure &gt; CIS v4.0 &gt; 02 - Common Reference Recommendations &gt; 02.02 - Networking &gt; 02.02.01 - Virtual Networks (VNets) &gt; 02.02.01.01 - Ensure public network access is Disabled
- Azure &gt; CIS v4.0 &gt; 02 - Common Reference Recommendations &gt; 02.02 - Networking &gt; 02.02.01 - Virtual Networks (VNets) &gt; 02.02.01.02 - Ensure Network Access Rules are set to Deny-by-default
- Azure &gt; CIS v4.0 &gt; 02 - Common Reference Recommendations &gt; 02.02 - Networking &gt; 02.02.02 - Private Endpoints
- Azure &gt; CIS v4.0 &gt; 02 - Common Reference Recommendations &gt; 02.02 - Networking &gt; 02.02.02 - Private Endpoints &gt; 02.02.02.01 - Ensure Private Endpoints are used to access {service}
- Azure &gt; CIS v4.0 &gt; 03 - Analytics Services
- Azure &gt; CIS v4.0 &gt; 03 - Analytics Services &gt; 03.01 - Azure Databricks
- Azure &gt; CIS v4.0 &gt; 03 - Analytics Services &gt; 03.01 - Azure Databricks &gt; 03.01.01 - Ensure that Azure Databricks is deployed in a customer-managed virtual network (VNet)
- Azure &gt; CIS v4.0 &gt; 03 - Analytics Services &gt; 03.01 - Azure Databricks &gt; 03.01.02 - Ensure that network security groups are configured for Databricks subnets
- Azure &gt; CIS v4.0 &gt; 03 - Analytics Services &gt; 03.01 - Azure Databricks &gt; 03.01.03 - Ensure that traffic is encrypted between cluster worker nodes
- Azure &gt; CIS v4.0 &gt; 03 - Analytics Services &gt; 03.01 - Azure Databricks &gt; 03.01.04 - Ensure that users and groups are synced from Microsoft Entra ID to Azure Databricks
- Azure &gt; CIS v4.0 &gt; 03 - Analytics Services &gt; 03.01 - Azure Databricks &gt; 03.01.05 - Ensure that Unity Catalog is configured for Azure Databricks
- Azure &gt; CIS v4.0 &gt; 03 - Analytics Services &gt; 03.01 - Azure Databricks &gt; 03.01.06 - Ensure that usage is restricted and expiry is enforced for Databricks personal access tokens
- Azure &gt; CIS v4.0 &gt; 03 - Analytics Services &gt; 03.01 - Azure Databricks &gt; 03.01.07 - Ensure that diagnostic log delivery is configured for Azure Databricks
- Azure &gt; CIS v4.0 &gt; 03 - Analytics Services &gt; 03.01 - Azure Databricks &gt; 03.01.08 - Ensure that data at rest and in transit is encrypted in Azure Databricks using customer managed keys (CMK)
- Azure &gt; CIS v4.0 &gt; 04 - Compute Services
- Azure &gt; CIS v4.0 &gt; 04 - Compute Services &gt; 04.01 - Virtual Machines
- Azure &gt; CIS v4.0 &gt; 04 - Compute Services &gt; 04.01 - Virtual Machines &gt; 04.01.01 - Ensure only MFA enabled identities can access privileged Virtual Machine
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.01 - Security Defaults (Per-User MFA)
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.01 - Security Defaults (Per-User MFA) &gt; 06.01.01 - Ensure that &apos;security defaults&apos; is enabled in Microsoft Entra ID
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.01 - Security Defaults (Per-User MFA) &gt; 06.01.02 - Ensure that &apos;multifactor authentication&apos; is &apos;enabled&apos; for all users
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.01 - Security Defaults (Per-User MFA) &gt; 06.01.03 - Ensure that &apos;Allow users to remember multifactor authentication on devices they trust&apos; is disabled
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.02 - Conditional Access
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.02 - Conditional Access &gt; 06.02.01 - Ensure that &apos;trusted locations&apos; are defined
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.02 - Conditional Access &gt; 06.02.02 - Ensure that an exclusionary geographic Conditional Access policy is considered
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.02 - Conditional Access &gt; 06.02.03 - Ensure that an exclusionary device code flow policy is considered
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.02 - Conditional Access &gt; 06.02.04 - Ensure that a multifactor authentication policy exists for all users
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.02 - Conditional Access &gt; 06.02.05 - Ensure that multifactor authentication is required for risky sign-ins
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.02 - Conditional Access &gt; 06.02.06 - Ensure that multifactor authentication is required for Windows Azure Service Management API
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.02 - Conditional Access &gt; 06.02.07 - Ensure that multifactor authentication is required to access Microsoft Admin Portals
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.03 - Periodic Identity Reviews
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.03 - Periodic Identity Reviews &gt; 06.03.01 - Ensure that Azure admin accounts are not used for daily operations
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.03 - Periodic Identity Reviews &gt; 06.03.02 - Ensure that guest users are reviewed on a regular basis
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.03 - Periodic Identity Reviews &gt; 06.03.03 - Ensure that use of the &apos;User Access Administrator&apos; role is restricted
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.03 - Periodic Identity Reviews &gt; 06.03.04 - Ensure that all &apos;privileged&apos; role assignments are periodically reviewed
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.04 - Ensure that &apos;Restrict non-admin users from creating tenants&apos; is set to &apos;Yes&apos;
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.05 - Ensure that &apos;Number of methods required to reset&apos; is set to &apos;2&apos;
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.06 - Ensure that account &apos;Lockout threshold&apos; is less than or equal to &apos;10&apos;
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.07 - Ensure that account &apos;Lockout duration in seconds&apos; is greater than or equal to &apos;60&apos;
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.08 - Ensure that a &apos;Custom banned password list&apos; is set to &apos;Enforce&apos;
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.09 - Ensure that &apos;Number of days before users are asked to re-confirm their authentication information&apos; is not set to &apos;0&apos;
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.10 - Ensure that &apos;Notify users on password resets?&apos; is set to &apos;Yes&apos;
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.11 - Ensure that &apos;Notify all admins when other admins reset their password?&apos; is set to &apos;Yes&apos;
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.12 - Ensure that &apos;User consent for applications&apos; is set to &apos;Do not allow user consent&apos;
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.13 - Ensure that &apos;User consent for applications&apos; is set to &apos;Allow user consent for apps from verified publishers, for selected permissions&apos;
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.14 - Ensure that &apos;Users can register applications&apos; is set to &apos;No&apos;
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.15 - Ensure that &apos;Guest users access restrictions&apos; is set to &apos;Guest user access is restricted to properties and memberships of their own directory objects&apos;
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.16 - Ensure that &apos;Guest invite restrictions&apos; is set to &apos;Only users assigned to specific admin roles can invite guest users&apos;
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.17 - Ensure that &apos;Restrict access to Microsoft Entra admin center&apos; is set to &apos;Yes&apos;
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.18 - Ensure that &apos;Restrict user ability to access groups features in My Groups&apos; is set to &apos;Yes&apos;
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.19 - Ensure that &apos;Users can create security groups in Azure portals, API or PowerShell&apos; is set to &apos;No&apos;
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.20 - Ensure that &apos;Owners can manage group membership requests in My Groups&apos; is set to &apos;No&apos;
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.21 - Ensure that &apos;Users can create Microsoft 365 groups in Azure portals, API or PowerShell&apos; is set to &apos;No&apos;
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.22 - Ensure that &apos;Require Multifactor Authentication to register or join devices with Microsoft Entra&apos; is set to &apos;Yes&apos;
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.23 - Ensure that no custom subscription administrator roles exist
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.24 - Ensure that a custom role is assigned permissions for administering resource locks
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.25 - Ensure that &apos;Subscription leaving Microsoft Entra tenant&apos; and &apos;Subscription entering Microsoft Entra tenant&apos; is set to &apos;Permit no one&apos;
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.26 - Ensure fewer than 5 users have global administrator assignment
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.01 - Configuring Diagnostic Settings
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.01 - Configuring Diagnostic Settings &gt; 07.01.01.01 - Ensure that a &apos;Diagnostic Setting&apos; exists for Subscription Activity Logs
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.01 - Configuring Diagnostic Settings &gt; 07.01.01.02 - Ensure Diagnostic Setting captures appropriate categories
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.01 - Configuring Diagnostic Settings &gt; 07.01.01.03 - Ensure the storage account containing the container with activity logs is encrypted with Customer Managed Key (CMK)
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.01 - Configuring Diagnostic Settings &gt; 07.01.01.04 - Ensure that logging for Azure Key Vault is &apos;Enabled&apos;
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.01 - Configuring Diagnostic Settings &gt; 07.01.01.05 - Ensure that Network Security Group Flow logs are captured and sent to Log Analytics
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.01 - Configuring Diagnostic Settings &gt; 07.01.01.06 - Ensure that logging for Azure AppService &apos;HTTP logs&apos; is enabled
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.01 - Configuring Diagnostic Settings &gt; 07.01.01.07 - Ensure that virtual network flow logs are captured and sent to Log Analytics
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.01 - Configuring Diagnostic Settings &gt; 07.01.01.08 - Ensure that a Microsoft Entra diagnostic setting exists to send Microsoft Graph activity logs to an appropriate destination
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.01 - Configuring Diagnostic Settings &gt; 07.01.01.09 - Ensure that a Microsoft Entra diagnostic setting exists to send Microsoft Entra activity logs to an appropriate destination
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.01 - Configuring Diagnostic Settings &gt; 07.01.01.10 - Ensure that Intune logs are captured and sent to Log Analytics
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.02 - Monitoring using Activity Log Alerts
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.02 - Monitoring using Activity Log Alerts &gt; 07.01.02.01 - Ensure that Activity Log Alert exists for Create Policy Assignment
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.02 - Monitoring using Activity Log Alerts &gt; 07.01.02.02 - Ensure that Activity Log Alert exists for Delete Policy Assignment
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.02 - Monitoring using Activity Log Alerts &gt; 07.01.02.03 - Ensure that Activity Log Alert exists for Create or Update Network Security Group
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.02 - Monitoring using Activity Log Alerts &gt; 07.01.02.04 - Ensure that Activity Log Alert exists for Delete Network Security Group
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.02 - Monitoring using Activity Log Alerts &gt; 07.01.02.05 - Ensure that Activity Log Alert exists for Create or Update Security Solution
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.02 - Monitoring using Activity Log Alerts &gt; 07.01.02.06 - Ensure that Activity Log Alert exists for Delete Security Solution
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.02 - Monitoring using Activity Log Alerts &gt; 07.01.02.07 - Ensure that Activity Log Alert exists for Create or Update SQL Server Firewall Rule
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.02 - Monitoring using Activity Log Alerts &gt; 07.01.02.08 - Ensure that Activity Log Alert exists for Delete SQL Server Firewall Rule
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.02 - Monitoring using Activity Log Alerts &gt; 07.01.02.09 - Ensure that Activity Log Alert exists for Create or Update Public IP Address rule
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.02 - Monitoring using Activity Log Alerts &gt; 07.01.02.10 - Ensure that Activity Log Alert exists for Delete Public IP Address rule
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.02 - Monitoring using Activity Log Alerts &gt; 07.01.02.11 - Ensure that Activity Log Alert exists for Service Health
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.03 - Configuring Application Insights
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.03 - Configuring Application Insights &gt; 07.01.03.01 - Ensure Application Insights are Configured
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.04 - Ensure that Azure Monitor Resource Logging is Enabled for All Services that Support it
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.05 - Ensure that SKU Basic/Consumption is not used on artifacts that need to be monitored (Particularly for Production Workloads)
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.02 - Ensure that Resource Locks are set for Mission-Critical Azure Resources
- Azure &gt; CIS v4.0 &gt; 08 - Networking
- Azure &gt; CIS v4.0 &gt; 08 - Networking &gt; 08.01 - Ensure that RDP access from the Internet is evaluated and restricted
- Azure &gt; CIS v4.0 &gt; 08 - Networking &gt; 08.02 - Ensure that SSH access from the Internet is evaluated and restricted
- Azure &gt; CIS v4.0 &gt; 08 - Networking &gt; 08.03 - Ensure that UDP access from the Internet is evaluated and restricted
- Azure &gt; CIS v4.0 &gt; 08 - Networking &gt; 08.04 - Ensure that HTTP(S) access from the Internet is evaluated and restricted
- Azure &gt; CIS v4.0 &gt; 08 - Networking &gt; 08.05 - Ensure that Network Security Group Flow Log retention period is &apos;greater than 90 days&apos;
- Azure &gt; CIS v4.0 &gt; 08 - Networking &gt; 08.06 - Ensure that Network Watcher is &apos;Enabled&apos; for Azure Regions that are in use
- Azure &gt; CIS v4.0 &gt; 08 - Networking &gt; 08.07 - Ensure that Public IP addresses are evaluated on a periodic basis
- Azure &gt; CIS v4.0 &gt; 08 - Networking &gt; 08.08 - Ensure that virtual network flow log retention days is set to greater than or equal to 90
- Azure &gt; CIS v4.0 &gt; 09 - Security Services
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.03 - Defender Plan: Servers
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.03 - Defender Plan: Servers &gt; 09.01.03.01 - Ensure that Defender for Servers is set to &apos;On&apos;
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.03 - Defender Plan: Servers &gt; 09.01.03.02 - Ensure that &apos;Vulnerability assessment for machines&apos; component status is set to &apos;On&apos;
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.03 - Defender Plan: Servers &gt; 09.01.03.03 - Ensure that &apos;Endpoint protection&apos; component status is set to &apos;On&apos;
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.03 - Defender Plan: Servers &gt; 09.01.03.04 - Ensure that &apos;Agentless scanning for machines&apos; component status is set to &apos;On&apos;
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.03 - Defender Plan: Servers &gt; 09.01.03.05 - Ensure that &apos;File Integrity Monitoring&apos; component status is set to &apos;On&apos;
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.04 - Defender Plan: Containers
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.04 - Defender Plan: Containers &gt; 09.01.04.01 - Ensure That Microsoft Defender for Containers Is Set To &apos;On&apos;
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.05 - Defender Plan: Storage
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.05 - Defender Plan: Storage &gt; 09.01.05.01 - Ensure That Microsoft Defender for Storage Is Set To &apos;On&apos;
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.06 - Defender Plan: App Service
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.06 - Defender Plan: App Service &gt; 09.01.06.01 - Ensure That Microsoft Defender for App Services Is Set To &apos;On&apos;
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.07 - Defender Plan: Databases
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.07 - Defender Plan: Databases &gt; 09.01.07.01 - Ensure That Microsoft Defender for Azure Cosmos DB Is Set To &apos;On&apos;
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.07 - Defender Plan: Databases &gt; 09.01.07.02 - Ensure That Microsoft Defender for Open-Source Relational Databases Is Set To &apos;On&apos;
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.07 - Defender Plan: Databases &gt; 09.01.07.03 - Ensure That Microsoft Defender for (Managed Instance) Azure SQL Databases Is Set To &apos;On&apos;
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.07 - Defender Plan: Databases &gt; 09.01.07.04 - Ensure That Microsoft Defender for SQL Servers on Machines Is Set To &apos;On&apos;
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.08 - Defender Plan: Key Vault
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.08 - Defender Plan: Key Vault &gt; 09.01.08.01 - Ensure That Microsoft Defender for Key Vault Is Set To &apos;On&apos;
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.09 - Defender Plan: Resource Manager
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.09 - Defender Plan: Resource Manager &gt; 09.01.09.01 - Ensure That Microsoft Defender for Resource Manager Is Set To &apos;On&apos;
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.10 - Ensure that Microsoft Defender for Cloud is configured to check VM operating systems for updates
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.11 - Ensure that Microsoft Cloud Security Benchmark policies are not set to &apos;Disabled&apos;
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.12 - Ensure That &apos;All users with the following roles&apos; is set to &apos;Owner&apos;
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.13 - Ensure &apos;Additional email addresses&apos; is Configured with a Security Contact Email
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.14 - Ensure that &apos;Notify about alerts with the following severity (or higher)&apos; is enabled
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.15 - Ensure that &apos;Notify about attack paths with the following risk level (or higher)&apos; is enabled
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.16 - Ensure that Microsoft Defender External Attack Surface Monitoring (EASM) is enabled
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.17 - [LEGACY] Ensure That Microsoft Defender for DNS Is Set To &apos;On&apos;
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.02 - Microsoft Defender for IoT
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.02 - Microsoft Defender for IoT &gt; 09.02.01 - Ensure That Microsoft Defender for IoT Hub Is Set To &apos;On&apos;
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.03 - Key Vault
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.03 - Key Vault &gt; 09.03.01 - Ensure that the Expiration Date is set for all Keys in RBAC Key Vaults
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.03 - Key Vault &gt; 09.03.02 - Ensure that the Expiration Date is set for all Keys in Non-RBAC Key Vaults
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.03 - Key Vault &gt; 09.03.03 - Ensure that the Expiration Date is set for all Secrets in RBAC Key Vaults
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.03 - Key Vault &gt; 09.03.04 - Ensure that the Expiration Date is set for all Secrets in Non-RBAC Key Vaults
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.03 - Key Vault &gt; 09.03.05 - Ensure the Key Vault is Recoverable
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.03 - Key Vault &gt; 09.03.06 - Ensure that Role Based Access Control for Azure Key Vault is enabled
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.03 - Key Vault &gt; 09.03.07 - Ensure that Public Network Access when using Private Endpoint is disabled
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.03 - Key Vault &gt; 09.03.08 - Ensure that Private Endpoints are Used for Azure Key Vault
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.03 - Key Vault &gt; 09.03.09 - Ensure automatic key rotation is enabled within Azure Key Vault
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.03 - Key Vault &gt; 09.03.10 - Ensure that Azure Key Vault Managed HSM is used when required
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.04 - Azure Bastion
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.04 - Azure Bastion &gt; 09.04.01 - Ensure an Azure Bastion Host Exists
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.01 - Azure Files
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.01 - Azure Files &gt; 10.01.01 - Ensure soft delete for Azure File Shares is Enabled
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.01 - Azure Files &gt; 10.01.02 - Ensure &apos;SMB protocol version&apos; is set to &apos;SMB 3.1.1&apos; or higher for SMB file shares
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.01 - Azure Files &gt; 10.01.03 - Ensure &apos;SMB channel encryption&apos; is set to &apos;AES-256-GCM&apos; or higher for SMB file shares
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.02 - Azure Blob Storage
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.02 - Azure Blob Storage &gt; 10.02.01 - Ensure that soft delete for blobs on Azure Blob Storage storage accounts is Enabled
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.02 - Azure Blob Storage &gt; 10.02.02 - Ensure &apos;Versioning&apos; is set to &apos;Enabled&apos; on Azure Blob Storage storage accounts
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.03 - Storage Accounts
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.03 - Storage Accounts &gt; 10.03.01 - Secrets and Keys
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.03 - Storage Accounts &gt; 10.03.01 - Secrets and Keys &gt; 10.03.01.01 - Ensure that &apos;Enable key rotation reminders&apos; is enabled for each Storage Account
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.03 - Storage Accounts &gt; 10.03.01 - Secrets and Keys &gt; 10.03.01.02 - Ensure that Storage Account access keys are periodically regenerated
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.03 - Storage Accounts &gt; 10.03.01 - Secrets and Keys &gt; 10.03.01.03 - Ensure &apos;Allow storage account key access&apos; for Azure Storage Accounts is &apos;Disabled&apos;
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.03 - Storage Accounts &gt; 10.03.02 - Networking
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.03 - Storage Accounts &gt; 10.03.02 - Networking &gt; 10.03.02.01 - Ensure Private Endpoints are used to access Storage Accounts
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.03 - Storage Accounts &gt; 10.03.02 - Networking &gt; 10.03.02.02 - Ensure that &apos;Public Network Access&apos; is &apos;Disabled&apos; for storage accounts
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.03 - Storage Accounts &gt; 10.03.02 - Networking &gt; 10.03.02.03 - Ensure default network access rule for storage accounts is set to deny
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.03 - Storage Accounts &gt; 10.03.03 - Identity and Access Management
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.03 - Storage Accounts &gt; 10.03.03 - Identity and Access Management &gt; 10.03.03.01 - Ensure that &apos;Default to Microsoft Entra authorization in the Azure portal&apos; is set to &apos;Enabled&apos;
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.03 - Storage Accounts &gt; 10.03.04 - Ensure that &apos;Secure transfer required&apos; is set to &apos;Enabled&apos;
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.03 - Storage Accounts &gt; 10.03.05 - Ensure &apos;Allow Azure services on the trusted services list to access this storage account&apos; is Enabled for Storage Account Access
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.03 - Storage Accounts &gt; 10.03.06 - Ensure Soft Delete is Enabled for Azure Containers and Blob Storage
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.03 - Storage Accounts &gt; 10.03.07 - Ensure the &apos;Minimum TLS version&apos; for storage accounts is set to &apos;Version 1.2&apos;
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.03 - Storage Accounts &gt; 10.03.08 - Ensure &apos;Cross Tenant Replication&apos; is not enabled
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.03 - Storage Accounts &gt; 10.03.09 - Ensure that &apos;Allow Blob Anonymous Access&apos; is set to &apos;Disabled&apos;
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.03 - Storage Accounts &gt; 10.03.10 - Ensure Azure Resource Manager Delete locks are applied to Azure Storage Accounts
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.03 - Storage Accounts &gt; 10.03.11 - Ensure Azure Resource Manager ReadOnly locks are considered for Azure Storage Accounts
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.03 - Storage Accounts &gt; 10.03.12 - Ensure Redundancy is set to &apos;geo-redundant storage (GRS)&apos; on critical Azure Storage Accounts

_Policy Types_

- Azure &gt; CIS v4.0
- Azure &gt; CIS v4.0 &gt; 02 - Common Reference Recommendations
- Azure &gt; CIS v4.0 &gt; 02 - Common Reference Recommendations &gt; 02.01 - Secrets and Keys
- Azure &gt; CIS v4.0 &gt; 02 - Common Reference Recommendations &gt; 02.01 - Secrets and Keys &gt; 02.01.01 - Encryption Key Management
- Azure &gt; CIS v4.0 &gt; 02 - Common Reference Recommendations &gt; 02.01 - Secrets and Keys &gt; 02.01.01 - Encryption Key Management &gt; 02.01.01.01 - Microsoft Managed Keys (MMK)
- Azure &gt; CIS v4.0 &gt; 02 - Common Reference Recommendations &gt; 02.01 - Secrets and Keys &gt; 02.01.01 - Encryption Key Management &gt; 02.01.01.01 - Microsoft Managed Keys (MMK) &gt; 02.01.01.01.01 - Ensure Critical Data is Encrypted with Microsoft Managed Keys (MMK)
- Azure &gt; CIS v4.0 &gt; 02 - Common Reference Recommendations &gt; 02.01 - Secrets and Keys &gt; 02.01.01 - Encryption Key Management &gt; 02.01.01.01 - Microsoft Managed Keys (MMK) &gt; 02.01.01.01.01 - Ensure Critical Data is Encrypted with Microsoft Managed Keys (MMK) &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 02 - Common Reference Recommendations &gt; 02.01 - Secrets and Keys &gt; 02.01.01 - Encryption Key Management &gt; 02.01.01.02 - Customer Managed Keys (CMK)
- Azure &gt; CIS v4.0 &gt; 02 - Common Reference Recommendations &gt; 02.01 - Secrets and Keys &gt; 02.01.01 - Encryption Key Management &gt; 02.01.01.02 - Customer Managed Keys (CMK) &gt; 02.01.01.02.01 - Ensure Critical Data is Encrypted with Customer Managed Keys (CMK)
- Azure &gt; CIS v4.0 &gt; 02 - Common Reference Recommendations &gt; 02.01 - Secrets and Keys &gt; 02.01.01 - Encryption Key Management &gt; 02.01.01.02 - Customer Managed Keys (CMK) &gt; 02.01.01.02.01 - Ensure Critical Data is Encrypted with Customer Managed Keys (CMK) &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 02 - Common Reference Recommendations &gt; 02.02 - Networking
- Azure &gt; CIS v4.0 &gt; 02 - Common Reference Recommendations &gt; 02.02 - Networking &gt; 02.02.01 - Virtual Networks (VNets)
- Azure &gt; CIS v4.0 &gt; 02 - Common Reference Recommendations &gt; 02.02 - Networking &gt; 02.02.01 - Virtual Networks (VNets) &gt; 02.02.01.01 - Ensure public network access is Disabled
- Azure &gt; CIS v4.0 &gt; 02 - Common Reference Recommendations &gt; 02.02 - Networking &gt; 02.02.01 - Virtual Networks (VNets) &gt; 02.02.01.01 - Ensure public network access is Disabled &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 02 - Common Reference Recommendations &gt; 02.02 - Networking &gt; 02.02.01 - Virtual Networks (VNets) &gt; 02.02.01.02 - Ensure Network Access Rules are set to Deny-by-default
- Azure &gt; CIS v4.0 &gt; 02 - Common Reference Recommendations &gt; 02.02 - Networking &gt; 02.02.01 - Virtual Networks (VNets) &gt; 02.02.01.02 - Ensure Network Access Rules are set to Deny-by-default &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 02 - Common Reference Recommendations &gt; 02.02 - Networking &gt; 02.02.02 - Private Endpoints
- Azure &gt; CIS v4.0 &gt; 02 - Common Reference Recommendations &gt; 02.02 - Networking &gt; 02.02.02 - Private Endpoints &gt; 02.02.02.01 - Ensure Private Endpoints are used to access {service}
- Azure &gt; CIS v4.0 &gt; 02 - Common Reference Recommendations &gt; 02.02 - Networking &gt; 02.02.02 - Private Endpoints &gt; 02.02.02.01 - Ensure Private Endpoints are used to access {service} &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 02 - Common Reference Recommendations &gt; Maximum Attestation Duration
- Azure &gt; CIS v4.0 &gt; 03 - Analytics Services
- Azure &gt; CIS v4.0 &gt; 03 - Analytics Services &gt; 03.01 - Azure Databricks
- Azure &gt; CIS v4.0 &gt; 03 - Analytics Services &gt; 03.01 - Azure Databricks &gt; 03.01.01 - Ensure that Azure Databricks is deployed in a customer-managed virtual network (VNet)
- Azure &gt; CIS v4.0 &gt; 03 - Analytics Services &gt; 03.01 - Azure Databricks &gt; 03.01.02 - Ensure that network security groups are configured for Databricks subnets
- Azure &gt; CIS v4.0 &gt; 03 - Analytics Services &gt; 03.01 - Azure Databricks &gt; 03.01.02 - Ensure that network security groups are configured for Databricks subnets &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 03 - Analytics Services &gt; 03.01 - Azure Databricks &gt; 03.01.03 - Ensure that traffic is encrypted between cluster worker nodes
- Azure &gt; CIS v4.0 &gt; 03 - Analytics Services &gt; 03.01 - Azure Databricks &gt; 03.01.03 - Ensure that traffic is encrypted between cluster worker nodes &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 03 - Analytics Services &gt; 03.01 - Azure Databricks &gt; 03.01.04 - Ensure that users and groups are synced from Microsoft Entra ID to Azure Databricks
- Azure &gt; CIS v4.0 &gt; 03 - Analytics Services &gt; 03.01 - Azure Databricks &gt; 03.01.04 - Ensure that users and groups are synced from Microsoft Entra ID to Azure Databricks &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 03 - Analytics Services &gt; 03.01 - Azure Databricks &gt; 03.01.05 - Ensure that Unity Catalog is configured for Azure Databricks
- Azure &gt; CIS v4.0 &gt; 03 - Analytics Services &gt; 03.01 - Azure Databricks &gt; 03.01.05 - Ensure that Unity Catalog is configured for Azure Databricks &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 03 - Analytics Services &gt; 03.01 - Azure Databricks &gt; 03.01.06 - Ensure that usage is restricted and expiry is enforced for Databricks personal access tokens
- Azure &gt; CIS v4.0 &gt; 03 - Analytics Services &gt; 03.01 - Azure Databricks &gt; 03.01.06 - Ensure that usage is restricted and expiry is enforced for Databricks personal access tokens &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 03 - Analytics Services &gt; 03.01 - Azure Databricks &gt; 03.01.07 - Ensure that diagnostic log delivery is configured for Azure Databricks
- Azure &gt; CIS v4.0 &gt; 03 - Analytics Services &gt; 03.01 - Azure Databricks &gt; 03.01.07 - Ensure that diagnostic log delivery is configured for Azure Databricks &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 03 - Analytics Services &gt; 03.01 - Azure Databricks &gt; 03.01.08 - Ensure that data at rest and in transit is encrypted in Azure Databricks using customer managed keys (CMK)
- Azure &gt; CIS v4.0 &gt; 03 - Analytics Services &gt; Maximum Attestation Duration
- Azure &gt; CIS v4.0 &gt; 04 - Compute Services
- Azure &gt; CIS v4.0 &gt; 04 - Compute Services &gt; 04.01 - Virtual Machines
- Azure &gt; CIS v4.0 &gt; 04 - Compute Services &gt; 04.01 - Virtual Machines &gt; 04.01.01 - Ensure only MFA enabled identities can access privileged Virtual Machine
- Azure &gt; CIS v4.0 &gt; 04 - Compute Services &gt; 04.01 - Virtual Machines &gt; 04.01.01 - Ensure only MFA enabled identities can access privileged Virtual Machine &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 04 - Compute Services &gt; Maximum Attestation Duration
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.01 - Security Defaults (Per-User MFA)
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.01 - Security Defaults (Per-User MFA) &gt; 06.01.01 - Ensure that &apos;security defaults&apos; is enabled in Microsoft Entra ID
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.01 - Security Defaults (Per-User MFA) &gt; 06.01.01 - Ensure that &apos;security defaults&apos; is enabled in Microsoft Entra ID &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.01 - Security Defaults (Per-User MFA) &gt; 06.01.02 - Ensure that &apos;multifactor authentication&apos; is &apos;enabled&apos; for all users
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.01 - Security Defaults (Per-User MFA) &gt; 06.01.02 - Ensure that &apos;multifactor authentication&apos; is &apos;enabled&apos; for all users &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.01 - Security Defaults (Per-User MFA) &gt; 06.01.03 - Ensure that &apos;Allow users to remember multifactor authentication on devices they trust&apos; is disabled
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.01 - Security Defaults (Per-User MFA) &gt; 06.01.03 - Ensure that &apos;Allow users to remember multifactor authentication on devices they trust&apos; is disabled &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.02 - Conditional Access
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.02 - Conditional Access &gt; 06.02.01 - Ensure that &apos;trusted locations&apos; are defined
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.02 - Conditional Access &gt; 06.02.01 - Ensure that &apos;trusted locations&apos; are defined &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.02 - Conditional Access &gt; 06.02.02 - Ensure that an exclusionary geographic Conditional Access policy is considered
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.02 - Conditional Access &gt; 06.02.02 - Ensure that an exclusionary geographic Conditional Access policy is considered &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.02 - Conditional Access &gt; 06.02.03 - Ensure exclusionary device code flow policy is considered
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.02 - Conditional Access &gt; 06.02.03 - Ensure exclusionary device code flow policy is considered &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.02 - Conditional Access &gt; 06.02.04 - Ensure that a multifactor authentication policy exists for all users
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.02 - Conditional Access &gt; 06.02.04 - Ensure that a multifactor authentication policy exists for all users &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.02 - Conditional Access &gt; 06.02.05 - Ensure that multifactor authentication is required for risky sign-ins
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.02 - Conditional Access &gt; 06.02.05 - Ensure that multifactor authentication is required for risky sign-ins &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.02 - Conditional Access &gt; 06.02.06 - Ensure that multifactor authentication is required for Windows Azure Service Management API
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.02 - Conditional Access &gt; 06.02.06 - Ensure that multifactor authentication is required for Windows Azure Service Management API &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.02 - Conditional Access &gt; 06.02.07 - Ensure that multifactor authentication is required to access Microsoft Admin Portals
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.02 - Conditional Access &gt; 06.02.07 - Ensure that multifactor authentication is required to access Microsoft Admin Portals &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.03 - Periodic Identity Reviews
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.03 - Periodic Identity Reviews &gt; 06.03.01 - Ensure that Azure admin accounts are not used for daily operations
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.03 - Periodic Identity Reviews &gt; 06.03.01 - Ensure that Azure admin accounts are not used for daily operations &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.03 - Periodic Identity Reviews &gt; 06.03.02 - Ensure that guest users are reviewed on a regular basis
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.03 - Periodic Identity Reviews &gt; 06.03.02 - Ensure that guest users are reviewed on a regular basis &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.03 - Periodic Identity Reviews &gt; 06.03.03 - Ensure that use of the &apos;User Access Administrator&apos; role is restricted
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.03 - Periodic Identity Reviews &gt; 06.03.04 - Ensure that all &apos;privileged&apos; role assignments are periodically reviewed
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.03 - Periodic Identity Reviews &gt; 06.03.04 - Ensure that all &apos;privileged&apos; role assignments are periodically reviewed &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.04 - Ensure &apos;Restrict non-admin users from creating tenants&apos; is set to &apos;Yes&apos;
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.04 - Ensure &apos;Restrict non-admin users from creating tenants&apos; is set to &apos;Yes&apos; &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.05 - Ensure &apos;Number of methods required to reset&apos; is set to &apos;2&apos;
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.05 - Ensure &apos;Number of methods required to reset&apos; is set to &apos;2&apos; &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.06 - Ensure account &apos;Lockout threshold&apos; is less than or equal to &apos;10&apos;
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.06 - Ensure account &apos;Lockout threshold&apos; is less than or equal to &apos;10&apos; &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.07 - Ensure &apos;Lockout duration in seconds&apos; is greater than or equal to &apos;60&apos;
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.07 - Ensure &apos;Lockout duration in seconds&apos; is greater than or equal to &apos;60&apos; &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.08 - Ensure &apos;Custom banned password list&apos; is set to &apos;Enforce&apos;
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.08 - Ensure &apos;Custom banned password list&apos; is set to &apos;Enforce&apos; &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.09 - Ensure &apos;Number of days before users are asked to re-confirm their authentication information&apos; is not set to &apos;0&apos;
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.09 - Ensure &apos;Number of days before users are asked to re-confirm their authentication information&apos; is not set to &apos;0&apos; &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.10 - Ensure &apos;Notify users on password resets?&apos; is set to &apos;Yes&apos;
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.10 - Ensure &apos;Notify users on password resets?&apos; is set to &apos;Yes&apos; &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.11 - Ensure &apos;Notify all admins when other admins reset their password?&apos; is set to &apos;Yes&apos;
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.11 - Ensure &apos;Notify all admins when other admins reset their password?&apos; is set to &apos;Yes&apos; &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.12 - Ensure &apos;User consent for applications&apos; is set to &apos;Do not allow user consent&apos;
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.12 - Ensure &apos;User consent for applications&apos; is set to &apos;Do not allow user consent&apos; &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.13 - Ensure user consent is &apos;Allow for verified publishers only&apos;
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.13 - Ensure user consent is &apos;Allow for verified publishers only&apos; &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.14 - Ensure &apos;Users can register applications&apos; is set to &apos;No&apos;
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.15 - Ensure &apos;Guest users access restrictions&apos; is properly configured
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.15 - Ensure &apos;Guest users access restrictions&apos; is properly configured &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.16 - Ensure &apos;Guest invite restrictions&apos; is set to &apos;Only users assigned to specific admin roles can invite guest users&apos;
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.16 - Ensure &apos;Guest invite restrictions&apos; is set to &apos;Only users assigned to specific admin roles can invite guest users&apos; &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.17 - Ensure &apos;Restrict access to Microsoft Entra admin center&apos; is set to &apos;Yes&apos;
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.17 - Ensure &apos;Restrict access to Microsoft Entra admin center&apos; is set to &apos;Yes&apos; &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.18 - Ensure &apos;Restrict user ability to access groups features&apos; is set to &apos;Yes&apos;
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.18 - Ensure &apos;Restrict user ability to access groups features&apos; is set to &apos;Yes&apos; &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.19 - Ensure &apos;Users can create security groups&apos; is set to &apos;No&apos;
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.19 - Ensure &apos;Users can create security groups&apos; is set to &apos;No&apos; &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.20 - Ensure &apos;Owners can manage group membership requests in My Groups&apos; is set to &apos;No&apos;
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.20 - Ensure &apos;Owners can manage group membership requests in My Groups&apos; is set to &apos;No&apos; &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.21 - Ensure &apos;Users can create M365 groups in Azure portals, API or PowerShell&apos; is set to &apos;No&apos;
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.21 - Ensure &apos;Users can create M365 groups in Azure portals, API or PowerShell&apos; is set to &apos;No&apos; &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.22 - Ensure &apos;Require Multifactor Authentication to register or join devices with Microsoft Entra&apos; is set to &apos;Yes&apos;
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.22 - Ensure &apos;Require Multifactor Authentication to register or join devices with Microsoft Entra&apos; is set to &apos;Yes&apos; &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.23 - Ensure no custom subscription administrator roles exist
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.24 - Ensure custom role is assigned permissions for administering resource locks
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.24 - Ensure custom role is assigned permissions for administering resource locks &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.25 - Ensure &apos;Subscription leaving Microsoft Entra tenant&apos; and &apos;Subscription entering Microsoft Entra tenant&apos; is set to &apos;Permit no one&apos;
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.25 - Ensure &apos;Subscription leaving Microsoft Entra tenant&apos; and &apos;Subscription entering Microsoft Entra tenant&apos; is set to &apos;Permit no one&apos; &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.26 - Ensure fewer than 5 users have global administrator assignment
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; 06.26 - Ensure fewer than 5 users have global administrator assignment &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 06 - Identity Services &gt; Maximum Attestation Duration
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.01 - Configuring Diagnostic Settings
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.01 - Configuring Diagnostic Settings &gt; 07.01.01.01 - Ensure that a &apos;Diagnostic Setting&apos; exists for Subscription Activity Logs
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.01 - Configuring Diagnostic Settings &gt; 07.01.01.01 - Ensure that a &apos;Diagnostic Setting&apos; exists for Subscription Activity Logs &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.01 - Configuring Diagnostic Settings &gt; 07.01.01.02 - Ensure Diagnostic Setting captures appropriate categories
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.01 - Configuring Diagnostic Settings &gt; 07.01.01.03 - Ensure the storage account containing the container with activity logs is encrypted with Customer Managed Key (CMK)
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.01 - Configuring Diagnostic Settings &gt; 07.01.01.04 - Ensure that logging for Azure Key Vault is &apos;Enabled&apos;
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.01 - Configuring Diagnostic Settings &gt; 07.01.01.05 - Ensure that Network Security Group Flow logs are captured and sent to Log Analytics
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.01 - Configuring Diagnostic Settings &gt; 07.01.01.06 - Ensure that logging for Azure AppService &apos;HTTP logs&apos; is enabled
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.01 - Configuring Diagnostic Settings &gt; 07.01.01.07 - Ensure that virtual network flow logs are captured and sent to Log Analytics
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.01 - Configuring Diagnostic Settings &gt; 07.01.01.07 - Ensure that virtual network flow logs are captured and sent to Log Analytics &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.01 - Configuring Diagnostic Settings &gt; 07.01.01.08 - Ensure that a Microsoft Entra diagnostic setting exists to send Microsoft Graph activity logs to an appropriate destination
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.01 - Configuring Diagnostic Settings &gt; 07.01.01.08 - Ensure that a Microsoft Entra diagnostic setting exists to send Microsoft Graph activity logs to an appropriate destination &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.01 - Configuring Diagnostic Settings &gt; 07.01.01.09 - Ensure that a Microsoft Entra diagnostic setting exists to send Microsoft Entra activity logs to an appropriate destination
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.01 - Configuring Diagnostic Settings &gt; 07.01.01.09 - Ensure that a Microsoft Entra diagnostic setting exists to send Microsoft Entra activity logs to an appropriate destination &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.01 - Configuring Diagnostic Settings &gt; 07.01.01.10 - Ensure that Intune logs are captured and sent to Log Analytics
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.01 - Configuring Diagnostic Settings &gt; 07.01.01.10 - Ensure that Intune logs are captured and sent to Log Analytics &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.02 - Monitoring using Activity Log Alerts
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.02 - Monitoring using Activity Log Alerts &gt; 07.01.02.01 - Ensure that Activity Log Alert exists for Create Policy Assignment
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.02 - Monitoring using Activity Log Alerts &gt; 07.01.02.02 - Ensure that Activity Log Alert exists for Delete Policy Assignment
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.02 - Monitoring using Activity Log Alerts &gt; 07.01.02.03 - Ensure that Activity Log Alert exists for Create or Update Network Security Group
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.02 - Monitoring using Activity Log Alerts &gt; 07.01.02.04 - Ensure that Activity Log Alert exists for Delete Network Security Group
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.02 - Monitoring using Activity Log Alerts &gt; 07.01.02.05 - Ensure that Activity Log Alert exists for Create or Update Security Solution
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.02 - Monitoring using Activity Log Alerts &gt; 07.01.02.06 - Ensure that Activity Log Alert exists for Delete Security Solution
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.02 - Monitoring using Activity Log Alerts &gt; 07.01.02.07 - Ensure that Activity Log Alert exists for Create or Update SQL Server Firewall Rule
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.02 - Monitoring using Activity Log Alerts &gt; 07.01.02.08 - Ensure that Activity Log Alert exists for Delete SQL Server Firewall Rule
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.02 - Monitoring using Activity Log Alerts &gt; 07.01.02.09 - Ensure that Activity Log Alert exists for Create or Update Public IP Address rule
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.02 - Monitoring using Activity Log Alerts &gt; 07.01.02.10 - Ensure that Activity Log Alert exists for Delete Public IP Address rule
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.02 - Monitoring using Activity Log Alerts &gt; 07.01.02.11 - Ensure that Activity Log Alert exists for Service Health
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.03 - Configuring Application Insights
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.03 - Configuring Application Insights &gt; 07.01.03.01 - Ensure Application Insights are Configured
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.04 - Ensure that Azure Monitor Resource Logging is Enabled for All Services that Support it
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.04 - Ensure that Azure Monitor Resource Logging is Enabled for All Services that Support it &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.05 - Ensure SKU Basic/Consumption is not used on artifacts that need to be monitored
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.01 - Logging and Monitoring &gt; 07.01.05 - Ensure SKU Basic/Consumption is not used on artifacts that need to be monitored &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.02 - Ensure that Resource Locks are set for Mission-Critical Azure Resources
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; 07.02 - Ensure that Resource Locks are set for Mission-Critical Azure Resources &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 07 - Management and Governance &gt; Maximum Attestation Duration
- Azure &gt; CIS v4.0 &gt; 08 - Networking
- Azure &gt; CIS v4.0 &gt; 08 - Networking &gt; 08.01 - Ensure that RDP access from the Internet is evaluated and restricted
- Azure &gt; CIS v4.0 &gt; 08 - Networking &gt; 08.02 - Ensure that SSH access from the Internet is evaluated and restricted
- Azure &gt; CIS v4.0 &gt; 08 - Networking &gt; 08.03 - Ensure that UDP access from the Internet is evaluated and restricted
- Azure &gt; CIS v4.0 &gt; 08 - Networking &gt; 08.04 - Ensure that HTTP(S) access from the Internet is evaluated and restricted
- Azure &gt; CIS v4.0 &gt; 08 - Networking &gt; 08.05 - Ensure that Network Security Group Flow Log retention period is &apos;greater than 90 days&apos;
- Azure &gt; CIS v4.0 &gt; 08 - Networking &gt; 08.06 - Ensure that Network Watcher is &apos;Enabled&apos; for Azure Regions that are in use
- Azure &gt; CIS v4.0 &gt; 08 - Networking &gt; 08.07 - Ensure that Public IP addresses are evaluated on a periodic basis
- Azure &gt; CIS v4.0 &gt; 08 - Networking &gt; 08.07 - Ensure that Public IP addresses are evaluated on a periodic basis &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 08 - Networking &gt; 08.08 - Ensure that virtual network flow log retention days is set to greater than or equal to 90
- Azure &gt; CIS v4.0 &gt; 08 - Networking &gt; Maximum Attestation Duration
- Azure &gt; CIS v4.0 &gt; 09 - Security Services
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.03 - Defender Plan: Servers
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.03 - Defender Plan: Servers &gt; 09.01.03.01 - Ensure that Defender for Servers is set to &apos;On&apos;
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.03 - Defender Plan: Servers &gt; 09.01.03.02 - Ensure that &apos;Vulnerability assessment for machines&apos; component status is set to &apos;On&apos;
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.03 - Defender Plan: Servers &gt; 09.01.03.02 - Ensure that &apos;Vulnerability assessment for machines&apos; component status is set to &apos;On&apos; &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.03 - Defender Plan: Servers &gt; 09.01.03.03 - Ensure that &apos;Endpoint protection&apos; component status is set to &apos;On&apos;
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.03 - Defender Plan: Servers &gt; 09.01.03.03 - Ensure that &apos;Endpoint protection&apos; component status is set to &apos;On&apos; &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.03 - Defender Plan: Servers &gt; 09.01.03.04 - Ensure that &apos;Agentless scanning for machines&apos; component status is set to &apos;On&apos;
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.03 - Defender Plan: Servers &gt; 09.01.03.04 - Ensure that &apos;Agentless scanning for machines&apos; component status is set to &apos;On&apos; &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.03 - Defender Plan: Servers &gt; 09.01.03.05 - Ensure that &apos;File Integrity Monitoring&apos; component status is set to &apos;On&apos;
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.03 - Defender Plan: Servers &gt; 09.01.03.05 - Ensure that &apos;File Integrity Monitoring&apos; component status is set to &apos;On&apos; &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.04 - Defender Plan: Containers
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.04 - Defender Plan: Containers &gt; 09.01.04.01 - Ensure That Microsoft Defender for Containers Is Set To &apos;On&apos;
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.05 - Defender Plan: Storage
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.05 - Defender Plan: Storage &gt; 09.01.05.01 - Ensure That Microsoft Defender for Storage Is Set To &apos;On&apos;
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.06 - Defender Plan: App Service
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.06 - Defender Plan: App Service &gt; 09.01.06.01 - Ensure That Microsoft Defender for App Services Is Set To &apos;On&apos;
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.07 - Defender Plan: Databases
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.07 - Defender Plan: Databases &gt; 09.01.07.01 - Ensure That Microsoft Defender for Azure Cosmos DB Is Set To &apos;On&apos;
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.07 - Defender Plan: Databases &gt; 09.01.07.02 - Ensure That Microsoft Defender for Open-Source Relational Databases Is Set To &apos;On&apos;
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.07 - Defender Plan: Databases &gt; 09.01.07.03 - Ensure That Microsoft Defender for (Managed Instance) Azure SQL Databases Is Set To &apos;On&apos;
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.07 - Defender Plan: Databases &gt; 09.01.07.04 - Ensure That Microsoft Defender for SQL Servers on Machines Is Set To &apos;On&apos;
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.08 - Defender Plan: Key Vault
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.08 - Defender Plan: Key Vault &gt; 09.01.08.01 - Ensure That Microsoft Defender for Key Vault Is Set To &apos;On&apos;
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.09 - Defender Plan: Resource Manager
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.09 - Defender Plan: Resource Manager &gt; 09.01.09.01 - Ensure That Microsoft Defender for Resource Manager Is Set To &apos;On&apos;
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.10 - Ensure that Microsoft Defender for Cloud is configured to check VM operating systems for updates
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.10 - Ensure that Microsoft Defender for Cloud is configured to check VM operating systems for updates &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.11 - Ensure that Microsoft Cloud Security Benchmark policies are not set to &apos;Disabled&apos;
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.11 - Ensure that Microsoft Cloud Security Benchmark policies are not set to &apos;Disabled&apos; &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.12 - Ensure That &apos;All users with the following roles&apos; is set to &apos;Owner&apos;
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.13 - Ensure &apos;Additional email addresses&apos; is Configured with a Security Contact Email
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.14 - Ensure that &apos;Notify about alerts with the following severity (or higher)&apos; is enabled
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.15 - Ensure that &apos;Notify about attack paths with the following risk level (or higher)&apos; is enabled
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.16 - Ensure that Microsoft Defender External Attack Surface Monitoring (EASM) is enabled
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.16 - Ensure that Microsoft Defender External Attack Surface Monitoring (EASM) is enabled &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.01 - Microsoft Defender for Cloud &gt; 09.01.17 - [LEGACY] Ensure That Microsoft Defender for DNS Is Set To &apos;On&apos;
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.02 - Microsoft Defender for IoT
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.02 - Microsoft Defender for IoT &gt; 09.02.01 - Ensure That Microsoft Defender for IoT Hub Is Set To &apos;On&apos;
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.02 - Microsoft Defender for IoT &gt; 09.02.01 - Ensure That Microsoft Defender for IoT Hub Is Set To &apos;On&apos; &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.03 - Key Vault
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.03 - Key Vault &gt; 09.03.01 - Ensure that the Expiration Date is set for all Keys in RBAC Key Vaults
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.03 - Key Vault &gt; 09.03.02 - Ensure that the Expiration Date is set for all Keys in Non-RBAC Key Vaults
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.03 - Key Vault &gt; 09.03.03 - Ensure that the Expiration Date is set for all Secrets in RBAC Key Vaults
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.03 - Key Vault &gt; 09.03.04 - Ensure that the Expiration Date is set for all Secrets in Non-RBAC Key Vaults
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.03 - Key Vault &gt; 09.03.05 - Ensure the Key Vault is Recoverable
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.03 - Key Vault &gt; 09.03.06 - Ensure that Role Based Access Control for Azure Key Vault is enabled
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.03 - Key Vault &gt; 09.03.07 - Ensure that Public Network Access when using Private Endpoint is disabled
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.03 - Key Vault &gt; 09.03.08 - Ensure that Private Endpoints are Used for Azure Key Vault
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.03 - Key Vault &gt; 09.03.09 - Ensure automatic key rotation is enabled within Azure Key Vault
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.03 - Key Vault &gt; 09.03.10 - Ensure that Azure Key Vault Managed HSM is used when required
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.03 - Key Vault &gt; 09.03.10 - Ensure that Azure Key Vault Managed HSM is used when required &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.04 - Azure Bastion
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; 09.04 - Azure Bastion &gt; 09.04.01 - Ensure an Azure Bastion Host Exists
- Azure &gt; CIS v4.0 &gt; 09 - Security Services &gt; Maximum Attestation Duration
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.01 - Azure Files
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.01 - Azure Files &gt; 10.01.01 - Ensure soft delete for Azure File Shares is Enabled
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.01 - Azure Files &gt; 10.01.02 - Ensure &apos;SMB protocol version&apos; is set to &apos;SMB 3.1.1&apos; or higher for SMB file shares
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.01 - Azure Files &gt; 10.01.03 - Ensure &apos;SMB channel encryption&apos; is set to &apos;AES-256-GCM&apos; or higher for SMB file shares
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.02 - Azure Blob Storage
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.02 - Azure Blob Storage &gt; 10.02.01 - Ensure that soft delete for blobs on Azure Blob Storage storage accounts is Enabled
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.02 - Azure Blob Storage &gt; 10.02.02 - Ensure &apos;Versioning&apos; is set to &apos;Enabled&apos; on Azure Blob Storage storage accounts
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.03 - Storage Accounts
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.03 - Storage Accounts &gt; 10.03.01 - Secrets and Keys
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.03 - Storage Accounts &gt; 10.03.01 - Secrets and Keys &gt; 10.03.01.01 - Ensure that &apos;Enable key rotation reminders&apos; is enabled for each Storage Account
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.03 - Storage Accounts &gt; 10.03.01 - Secrets and Keys &gt; 10.03.01.01 - Ensure that &apos;Enable key rotation reminders&apos; is enabled for each Storage Account &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.03 - Storage Accounts &gt; 10.03.01 - Secrets and Keys &gt; 10.03.01.02 - Ensure that Storage Account access keys are periodically regenerated
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.03 - Storage Accounts &gt; 10.03.01 - Secrets and Keys &gt; 10.03.01.02 - Ensure that Storage Account access keys are periodically regenerated &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.03 - Storage Accounts &gt; 10.03.01 - Secrets and Keys &gt; 10.03.01.03 - Ensure &apos;Allow storage account key access&apos; for Azure Storage Accounts is &apos;Disabled&apos;
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.03 - Storage Accounts &gt; 10.03.02 - Networking
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.03 - Storage Accounts &gt; 10.03.02 - Networking &gt; 10.03.02.01 - Ensure Private Endpoints are used to access Storage Accounts
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.03 - Storage Accounts &gt; 10.03.02 - Networking &gt; 10.03.02.02 - Ensure &apos;Public Network Access&apos; is &apos;Disabled&apos;
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.03 - Storage Accounts &gt; 10.03.02 - Networking &gt; 10.03.02.03 - Ensure default network access rule is set to deny
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.03 - Storage Accounts &gt; 10.03.03 - Identity and Access Management
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.03 - Storage Accounts &gt; 10.03.03 - Identity and Access Management &gt; 10.03.03.01 - Ensure &apos;Default to Microsoft Entra authorization&apos; is &apos;Enabled&apos;
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.03 - Storage Accounts &gt; 10.03.04 - Ensure &apos;Secure transfer required&apos; is set to &apos;Enabled&apos;
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.03 - Storage Accounts &gt; 10.03.05 - Ensure &apos;Allow Azure services on trusted services list&apos; is Enabled
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.03 - Storage Accounts &gt; 10.03.06 - Ensure Soft Delete is Enabled for Azure Containers and Blob Storage
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.03 - Storage Accounts &gt; 10.03.07 - Ensure &apos;Minimum TLS version&apos; is set to &apos;Version 1.2&apos;
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.03 - Storage Accounts &gt; 10.03.08 - Ensure &apos;Cross Tenant Replication&apos; is not enabled
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.03 - Storage Accounts &gt; 10.03.09 - Ensure &apos;Allow Blob Anonymous Access&apos; is set to &apos;Disabled&apos;
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.03 - Storage Accounts &gt; 10.03.10 - Ensure Azure Resource Manager Delete locks are applied
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.03 - Storage Accounts &gt; 10.03.10 - Ensure Azure Resource Manager Delete locks are applied &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.03 - Storage Accounts &gt; 10.03.11 - Ensure Azure Resource Manager ReadOnly locks are considered
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.03 - Storage Accounts &gt; 10.03.11 - Ensure Azure Resource Manager ReadOnly locks are considered &gt; Attestation
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; 10.03 - Storage Accounts &gt; 10.03.12 - Ensure Redundancy is set to &apos;geo-redundant storage (GRS)&apos; for critical accounts
- Azure &gt; CIS v4.0 &gt; 10 - Storage Services &gt; Maximum Attestation Duration
- Azure &gt; CIS v4.0 &gt; Maximum Attestation Duration

_Note_

To ensure compatibility and proper functioning of the Guardrails Azure CIS v4 mod, we recommend updating all dependent mods to their latest versions.</description>
            <pubDate>Tue, 03 Feb 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-neptune-v5-8-0</guid>
            <title>aws-neptune v5.8.0 - CMDB control for DB Cluster Snapshot will no longer enter an error state when processing certain API responses</title>
            <link>https://turbot.com/guardrails/changelog/aws-neptune-v5-8-0</link>
            <description>_Bug fixes_

- Fixed the `AWS &gt; Neptune &gt; DB Cluster Snapshot &gt; CMDB` control that would enter an error state due to internal metadata being incorrectly stored in the resource data. This is now fixed.

_Control Types_

- AWS &gt; Neptune &gt; DB Cluster &gt; Allowed
- AWS &gt; Neptune &gt; DB Cluster &gt; Allowed &gt; Custom
- AWS &gt; Neptune &gt; DB Cluster &gt; Allowed &gt; Region
- AWS &gt; Neptune &gt; DB Instance &gt; Allowed
- AWS &gt; Neptune &gt; DB Instance &gt; Allowed &gt; Custom
- AWS &gt; Neptune &gt; DB Instance &gt; Allowed &gt; Region

_Policy Types_

- AWS &gt; Neptune &gt; DB Cluster &gt; Allowed
- AWS &gt; Neptune &gt; DB Cluster &gt; Allowed &gt; Custom
- AWS &gt; Neptune &gt; DB Cluster &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; Neptune &gt; DB Cluster &gt; Allowed &gt; Region
- AWS &gt; Neptune &gt; DB Cluster &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; Neptune &gt; DB Instance &gt; Allowed
- AWS &gt; Neptune &gt; DB Instance &gt; Allowed &gt; Custom
- AWS &gt; Neptune &gt; DB Instance &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; Neptune &gt; DB Instance &gt; Allowed &gt; Region
- AWS &gt; Neptune &gt; DB Instance &gt; Allowed &gt; Region &gt; Regions</description>
            <pubDate>Tue, 03 Feb 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-apigateway-v5-16-1</guid>
            <title>aws-apigateway v5.16.1 - Tags control for API Gateway V2 resources will no longer fail due to invalid ARN error</title>
            <link>https://turbot.com/guardrails/changelog/aws-apigateway-v5-16-1</link>
            <description>_Bug fixes_

- The tags control previously failed for some API Gateway V2 resources due to an invalid ARN error, causing the control to remain in alarm even after tags were applied. This has now been fixed and the controls will work as expected.</description>
            <pubDate>Tue, 03 Feb 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-vpc-security-v5-16-1</guid>
            <title>aws-vpc-security v5.16.1 - Flow Log Discovery control will no longer fail when processing Flow Logs attached to Transit Gateways</title>
            <link>https://turbot.com/guardrails/changelog/aws-vpc-security-v5-16-1</link>
            <description>_Bug fixes_

- The `AWS &gt; VPC &gt; Flow Log &gt; Discovery` would go into an error state when processing Flow Logs attached to Transit Gateways or Transit Gateway Attachments. The control now correctly discovers Flow Logs attached to VPCs, Subnets, ENIs, Transit Gateways, and Transit Gateway Attachments.</description>
            <pubDate>Mon, 02 Feb 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-cisv4-0-v5-0-0</guid>
            <title>gcp-cisv4-0 v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/gcp-cisv4-0-v5-0-0</link>
            <description>_Control Types_

- GCP &gt; CIS v4.0
- GCP &gt; CIS v4.0 &gt; 1 - Identity and Access Management
- GCP &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.01 - Ensure that Corporate Login Credentials are Used
- GCP &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.02 - Ensure that Multi-Factor Authentication is &apos;Enabled&apos; for All Non-Service Accounts
- GCP &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.03 - Ensure that Security Key Enforcement is Enabled for All Admin Accounts
- GCP &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.04 - Ensure That There Are Only GCP-Managed Service Account Keys for Each Service Account
- GCP &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.05 - Ensure That Service Account Has No Admin Privileges
- GCP &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.06 - Ensure That IAM Users Are Not Assigned the Service Account User or Service Account Token Creator Roles at Project Level
- GCP &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.07 - Ensure User-Managed/External Keys for Service Accounts Are Rotated Every 90 Days or Fewer
- GCP &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.08 - Ensure That Separation of Duties Is Enforced While Assigning Service Account Related Roles to Users
- GCP &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.09 - Ensure That Cloud KMS Cryptokeys Are Not Anonymously or Publicly Accessible
- GCP &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.10 - Ensure KMS Encryption Keys Are Rotated Within a Period of 90 Days
- GCP &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.11 - Ensure That Separation of Duties Is Enforced While Assigning KMS Related Roles to Users
- GCP &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.12 - Ensure API Keys Only Exist for Active Services
- GCP &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.13 - Ensure API Keys Are Restricted To Use by Only Specified Hosts and Apps
- GCP &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.14 - Ensure API Keys Are Restricted to Only APIs That Application Needs Access
- GCP &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.15 - Ensure API Keys Are Rotated Every 90 Days
- GCP &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.16 - Ensure Essential Contacts is Configured for Organization
- GCP &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.17 - Ensure Secrets are Not Stored in Cloud Functions Environment Variables by Using Secret Manager
- GCP &gt; CIS v4.0 &gt; 2 - Logging and Monitoring
- GCP &gt; CIS v4.0 &gt; 2 - Logging and Monitoring &gt; 2.01 - Ensure That Cloud Audit Logging Is Configured Properly
- GCP &gt; CIS v4.0 &gt; 2 - Logging and Monitoring &gt; 2.02 - Ensure That Sinks Are Configured for All Log Entries
- GCP &gt; CIS v4.0 &gt; 2 - Logging and Monitoring &gt; 2.03 - Ensure That Retention Policies on Cloud Storage Buckets Used for Exporting Logs Are Configured Using Bucket Lock
- GCP &gt; CIS v4.0 &gt; 2 - Logging and Monitoring &gt; 2.04 - Ensure Log Metric Filter and Alerts Exist for Project Ownership Assignments/Changes
- GCP &gt; CIS v4.0 &gt; 2 - Logging and Monitoring &gt; 2.05 - Ensure That the Log Metric Filter and Alerts Exist for Audit Configuration Changes
- GCP &gt; CIS v4.0 &gt; 2 - Logging and Monitoring &gt; 2.06 - Ensure That the Log Metric Filter and Alerts Exist for Custom Role Changes
- GCP &gt; CIS v4.0 &gt; 2 - Logging and Monitoring &gt; 2.07 - Ensure That the Log Metric Filter and Alerts Exist for VPC Network Firewall Rule Changes
- GCP &gt; CIS v4.0 &gt; 2 - Logging and Monitoring &gt; 2.08 - Ensure That the Log Metric Filter and Alerts Exist for VPC Network Route Changes
- GCP &gt; CIS v4.0 &gt; 2 - Logging and Monitoring &gt; 2.09 - Ensure That the Log Metric Filter and Alerts Exist for VPC Network Changes
- GCP &gt; CIS v4.0 &gt; 2 - Logging and Monitoring &gt; 2.10 - Ensure That the Log Metric Filter and Alerts Exist for Cloud Storage IAM Permission Changes
- GCP &gt; CIS v4.0 &gt; 2 - Logging and Monitoring &gt; 2.11 - Ensure That the Log Metric Filter and Alerts Exist for SQL Instance Configuration Changes
- GCP &gt; CIS v4.0 &gt; 2 - Logging and Monitoring &gt; 2.12 - Ensure That Cloud DNS Logging Is Enabled for All VPC Networks
- GCP &gt; CIS v4.0 &gt; 2 - Logging and Monitoring &gt; 2.13 - Ensure Cloud Asset Inventory Is Enabled
- GCP &gt; CIS v4.0 &gt; 2 - Logging and Monitoring &gt; 2.14 - Ensure &apos;Access Transparency&apos; is &apos;Enabled&apos;
- GCP &gt; CIS v4.0 &gt; 2 - Logging and Monitoring &gt; 2.15 - Ensure &apos;Access Approval&apos; is &apos;Enabled&apos;
- GCP &gt; CIS v4.0 &gt; 2 - Logging and Monitoring &gt; 2.16 - Ensure Logging is enabled for HTTP(S) Load Balancer
- GCP &gt; CIS v4.0 &gt; 3 - Networking
- GCP &gt; CIS v4.0 &gt; 3 - Networking &gt; 3.01 - Ensure That the Default Network Does Not Exist in a Project
- GCP &gt; CIS v4.0 &gt; 3 - Networking &gt; 3.02 - Ensure Legacy Networks Do Not Exist for Older Projects
- GCP &gt; CIS v4.0 &gt; 3 - Networking &gt; 3.03 - Ensure That DNSSEC Is Enabled for Cloud DNS
- GCP &gt; CIS v4.0 &gt; 3 - Networking &gt; 3.04 - Ensure That RSASHA1 Is Not Used for the Key-Signing Key in Cloud DNS DNSSEC
- GCP &gt; CIS v4.0 &gt; 3 - Networking &gt; 3.05 - Ensure That RSASHA1 Is Not Used for the Zone-Signing Key in Cloud DNS DNSSEC
- GCP &gt; CIS v4.0 &gt; 3 - Networking &gt; 3.06 - Ensure That SSH Access Is Restricted From the Internet
- GCP &gt; CIS v4.0 &gt; 3 - Networking &gt; 3.07 - Ensure That RDP Access Is Restricted From the Internet
- GCP &gt; CIS v4.0 &gt; 3 - Networking &gt; 3.08 - Ensure that VPC Flow Logs is Enabled for Every Subnet in a VPC Network
- GCP &gt; CIS v4.0 &gt; 3 - Networking &gt; 3.09 - Ensure No HTTPS or SSL Proxy Load Balancers Permit SSL Policies With Weak Cipher Suites
- GCP &gt; CIS v4.0 &gt; 3 - Networking &gt; 3.10 - Use Identity Aware Proxy (IAP) to Ensure Only Traffic From Google IP Addresses are &apos;Allowed&apos;
- GCP &gt; CIS v4.0 &gt; 4 - Virtual Machines
- GCP &gt; CIS v4.0 &gt; 4 - Virtual Machines &gt; 4.01 - Ensure That Instances Are Not Configured To Use the Default Service Account
- GCP &gt; CIS v4.0 &gt; 4 - Virtual Machines &gt; 4.02 - Ensure That Instances Are Not Configured To Use the Default Service Account With Full Access to All Cloud APIs
- GCP &gt; CIS v4.0 &gt; 4 - Virtual Machines &gt; 4.03 - Ensure &quot;Block Project-Wide SSH Keys&quot; Is Enabled for VM Instances
- GCP &gt; CIS v4.0 &gt; 4 - Virtual Machines &gt; 4.04 - Ensure Oslogin Is Enabled for a Project
- GCP &gt; CIS v4.0 &gt; 4 - Virtual Machines &gt; 4.05 - Ensure &apos;Enable Connecting to Serial Ports&apos; Is Not Enabled for VM Instance
- GCP &gt; CIS v4.0 &gt; 4 - Virtual Machines &gt; 4.06 - Ensure That IP Forwarding Is Not Enabled on Instances
- GCP &gt; CIS v4.0 &gt; 4 - Virtual Machines &gt; 4.07 - Ensure VM Disks for Critical VMs Are Encrypted With Customer-Supplied Encryption Keys (CSEK)
- GCP &gt; CIS v4.0 &gt; 4 - Virtual Machines &gt; 4.08 - Ensure Compute Instances Are Launched With Shielded VM Enabled
- GCP &gt; CIS v4.0 &gt; 4 - Virtual Machines &gt; 4.09 - Ensure That Compute Instances Do Not Have Public IP Addresses
- GCP &gt; CIS v4.0 &gt; 4 - Virtual Machines &gt; 4.10 - Ensure That App Engine Applications Enforce HTTPS Connections
- GCP &gt; CIS v4.0 &gt; 4 - Virtual Machines &gt; 4.11 - Ensure That Compute Instances Have Confidential Computing Enabled
- GCP &gt; CIS v4.0 &gt; 4 - Virtual Machines &gt; 4.12 - Ensure the Latest Operating System Updates Are Installed On Your Virtual Machines in All Projects
- GCP &gt; CIS v4.0 &gt; 5 - Storage
- GCP &gt; CIS v4.0 &gt; 5 - Storage &gt; 5.01 - Ensure That Cloud Storage Bucket Is Not Anonymously or Publicly Accessible
- GCP &gt; CIS v4.0 &gt; 5 - Storage &gt; 5.02 - Ensure That Cloud Storage Buckets Have Uniform Bucket-Level Access Enabled
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.01 - MySQL Database
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.01 - MySQL Database &gt; 6.01.01 - Ensure That a MySQL Database Instance Does Not Allow Anyone To Connect With Administrative Privileges
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.01 - MySQL Database &gt; 6.01.02 - Ensure &apos;Skip_show_database&apos; Database Flag for Cloud SQL MySQL Instance Is Set to &apos;On&apos;
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.01 - MySQL Database &gt; 6.01.03 - Ensure That the &apos;Local_infile&apos; Database Flag for a Cloud SQL MySQL Instance Is Set to &apos;Off&apos;
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database &gt; 6.02.01 - Ensure &apos;Log_error_verbosity&apos; Database Flag for Cloud SQL PostgreSQL Instance Is Set to &apos;DEFAULT&apos; or Stricter
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database &gt; 6.02.02 - Ensure &apos;Log_connections&apos; Database Flag for Cloud SQL PostgreSQL Instance Is Set to &apos;On&apos;
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database &gt; 6.02.03 - Ensure &apos;Log_disconnections&apos; Database Flag for Cloud SQL PostgreSQL Instance Is Set to &apos;On&apos;
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database &gt; 6.02.04 - Ensure &apos;Log_statement&apos; Database Flag for Cloud SQL PostgreSQL Instance Is Set Appropriately
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database &gt; 6.02.05 - Ensure &apos;Log_min_messages&apos; Database Flag for Cloud SQL PostgreSQL Instance is set at minimum to &apos;Warning&apos;
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database &gt; 6.02.06 - Ensure &apos;Log_min_error_statement&apos; Database Flag for Cloud SQL PostgreSQL Instance Is Set to &apos;Error&apos; or Stricter
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database &gt; 6.02.07 - Ensure That the &apos;Log_min_duration_statement&apos; Database Flag for Cloud SQL PostgreSQL Instance Is Set to &apos;-1&apos;
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database &gt; 6.02.08 - Ensure That &apos;cloudsql.enable_pgaudit&apos; Database Flag for each Cloud Sql Postgresql Instance Is Set to &apos;on&apos; For Centralized Logging
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.03 - SQL Server
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.03 - SQL Server &gt; 6.03.01 - Ensure &apos;external scripts enabled&apos; database flag for Cloud SQL SQL Server instance is set to &apos;off&apos;
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.03 - SQL Server &gt; 6.03.02 - Ensure that the &apos;cross db ownership chaining&apos; database flag for Cloud SQL SQL Server instance is set to &apos;off&apos;
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.03 - SQL Server &gt; 6.03.03 - Ensure &apos;user Connections&apos; Database Flag for Cloud Sql Sql Server Instance Is Set to a Non-limiting Value
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.03 - SQL Server &gt; 6.03.04 - Ensure &apos;user options&apos; database flag for Cloud SQL SQL Server instance is not configured
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.03 - SQL Server &gt; 6.03.05 - Ensure &apos;remote access&apos; database flag for Cloud SQL SQL Server instance is set to &apos;off&apos;
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.03 - SQL Server &gt; 6.03.06 - Ensure &apos;3625 (trace flag)&apos; database flag for all Cloud SQL Server instances is set to &apos;on&apos;
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.03 - SQL Server &gt; 6.03.07 - Ensure that the &apos;contained database authentication&apos; database flag for Cloud SQL on the SQL Server instance is set to &apos;off&apos;
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.04 - Ensure That the Cloud SQL Database Instance Requires All Incoming Connections To Use SSL
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.05 - Ensure That Cloud SQL Database Instances Do Not Implicitly Whitelist All Public IP Addresses
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.06 - Ensure That Cloud SQL Database Instances Do Not Have Public IPs
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.07 - Ensure That Cloud SQL Database Instances Are Configured With Automated Backups
- GCP &gt; CIS v4.0 &gt; 7 - BigQuery
- GCP &gt; CIS v4.0 &gt; 7 - BigQuery &gt; 7.01 - Ensure That BigQuery Datasets Are Not Anonymously or Publicly Accessible
- GCP &gt; CIS v4.0 &gt; 7 - BigQuery &gt; 7.02 - Ensure That All BigQuery Tables Are Encrypted With Customer-Managed Encryption Key (CMEK)
- GCP &gt; CIS v4.0 &gt; 7 - BigQuery &gt; 7.03 - Ensure That a Default Customer-Managed Encryption Key (CMEK) Is Specified for All BigQuery Data Sets
- GCP &gt; CIS v4.0 &gt; 7 - BigQuery &gt; 7.04 - Ensure all data in BigQuery has been classified
- GCP &gt; CIS v4.0 &gt; 8 - Dataproc
- GCP &gt; CIS v4.0 &gt; 8 - Dataproc &gt; 8.01 - Ensure that Dataproc Cluster is encrypted using Customer-Managed Encryption Key

_Policy Types_

- GCP &gt; CIS v4.0
- GCP &gt; CIS v4.0 &gt; 1 - Identity and Access Management
- GCP &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.01 - Ensure that Corporate Login Credentials are Used
- GCP &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.01 - Ensure that Corporate Login Credentials are Used &gt; Attestation
- GCP &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.02 - Ensure that Multi-Factor Authentication is &apos;Enabled&apos; for All Non-Service Accounts
- GCP &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.02 - Ensure that Multi-Factor Authentication is &apos;Enabled&apos; for All Non-Service Accounts &gt; Attestation
- GCP &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.03 - Ensure that Security Key Enforcement is Enabled for All Admin Accounts
- GCP &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.03 - Ensure that Security Key Enforcement is Enabled for All Admin Accounts &gt; Attestation
- GCP &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.04 - Ensure That There Are Only GCP-Managed Service Account Keys for Each Service Account
- GCP &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.05 - Ensure That Service Account Has No Admin Privileges
- GCP &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.06 - Ensure That IAM Users Are Not Assigned the Service Account User or Service Account Token Creator Roles at Project Level
- GCP &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.07 - Ensure User-Managed/External Keys for Service Accounts Are Rotated Every 90 Days or Fewer
- GCP &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.08 - Ensure That Separation of Duties Is Enforced While Assigning Service Account Related Roles to Users
- GCP &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.09 - Ensure That Cloud KMS Cryptokeys Are Not Anonymously or Publicly Accessible
- GCP &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.10 - Ensure KMS Encryption Keys Are Rotated Within a Period of 90 Days
- GCP &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.11 - Ensure That Separation of Duties Is Enforced While Assigning KMS Related Roles to Users
- GCP &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.12 - Ensure API Keys Only Exist for Active Services
- GCP &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.13 - Ensure API Keys Are Restricted To Use by Only Specified Hosts and Apps
- GCP &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.13 - Ensure API Keys Are Restricted To Use by Only Specified Hosts and Apps &gt; Attestation
- GCP &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.14 - Ensure API Keys Are Restricted to Only APIs That Application Needs Access
- GCP &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.15 - Ensure API Keys Are Rotated Every 90 Days
- GCP &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.16 - Ensure Essential Contacts is Configured for Organization
- GCP &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.16 - Ensure Essential Contacts is Configured for Organization &gt; Attestation
- GCP &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.17 - Ensure Secrets are Not Stored in Cloud Functions Environment Variables by Using Secret Manager
- GCP &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.17 - Ensure Secrets are Not Stored in Cloud Functions Environment Variables by Using Secret Manager &gt; Attestation
- GCP &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; Maximum Attestation Duration
- GCP &gt; CIS v4.0 &gt; 2 - Logging and Monitoring
- GCP &gt; CIS v4.0 &gt; 2 - Logging and Monitoring &gt; 2.01 - Ensure That Cloud Audit Logging Is Configured Properly
- GCP &gt; CIS v4.0 &gt; 2 - Logging and Monitoring &gt; 2.02 - Ensure That Sinks Are Configured for All Log Entries
- GCP &gt; CIS v4.0 &gt; 2 - Logging and Monitoring &gt; 2.03 - Ensure That Retention Policies on Cloud Storage Buckets Used for Exporting Logs Are Configured Using Bucket Lock
- GCP &gt; CIS v4.0 &gt; 2 - Logging and Monitoring &gt; 2.04 - Ensure Log Metric Filter and Alerts Exist for Project Ownership Assignments/Changes
- GCP &gt; CIS v4.0 &gt; 2 - Logging and Monitoring &gt; 2.05 - Ensure That the Log Metric Filter and Alerts Exist for Audit Configuration Changes
- GCP &gt; CIS v4.0 &gt; 2 - Logging and Monitoring &gt; 2.06 - Ensure That the Log Metric Filter and Alerts Exist for Custom Role Changes
- GCP &gt; CIS v4.0 &gt; 2 - Logging and Monitoring &gt; 2.07 - Ensure That the Log Metric Filter and Alerts Exist for VPC Network Firewall Rule Changes
- GCP &gt; CIS v4.0 &gt; 2 - Logging and Monitoring &gt; 2.08 - Ensure That the Log Metric Filter and Alerts Exist for VPC Network Route Changes
- GCP &gt; CIS v4.0 &gt; 2 - Logging and Monitoring &gt; 2.09 - Ensure That the Log Metric Filter and Alerts Exist for VPC Network Changes
- GCP &gt; CIS v4.0 &gt; 2 - Logging and Monitoring &gt; 2.10 - Ensure That the Log Metric Filter and Alerts Exist for Cloud Storage IAM Permission Changes
- GCP &gt; CIS v4.0 &gt; 2 - Logging and Monitoring &gt; 2.11 - Ensure That the Log Metric Filter and Alerts Exist for SQL Instance Configuration Changes
- GCP &gt; CIS v4.0 &gt; 2 - Logging and Monitoring &gt; 2.12 - Ensure That Cloud DNS Logging Is Enabled for All VPC Networks
- GCP &gt; CIS v4.0 &gt; 2 - Logging and Monitoring &gt; 2.13 - Ensure Cloud Asset Inventory Is Enabled
- GCP &gt; CIS v4.0 &gt; 2 - Logging and Monitoring &gt; 2.14 - Ensure &apos;Access Transparency&apos; is &apos;Enabled&apos;
- GCP &gt; CIS v4.0 &gt; 2 - Logging and Monitoring &gt; 2.14 - Ensure &apos;Access Transparency&apos; is &apos;Enabled&apos; &gt; Attestation
- GCP &gt; CIS v4.0 &gt; 2 - Logging and Monitoring &gt; 2.15 - Ensure &apos;Access Approval&apos; is &apos;Enabled&apos;
- GCP &gt; CIS v4.0 &gt; 2 - Logging and Monitoring &gt; 2.16 - Ensure Logging is enabled for HTTP(S) Load Balancer
- GCP &gt; CIS v4.0 &gt; 2 - Logging and Monitoring &gt; Maximum Attestation Duration
- GCP &gt; CIS v4.0 &gt; 3 - Networking
- GCP &gt; CIS v4.0 &gt; 3 - Networking &gt; 3.01 - Ensure That the Default Network Does Not Exist in a Project
- GCP &gt; CIS v4.0 &gt; 3 - Networking &gt; 3.02 - Ensure Legacy Networks Do Not Exist for Older Projects
- GCP &gt; CIS v4.0 &gt; 3 - Networking &gt; 3.03 - Ensure That DNSSEC Is Enabled for Cloud DNS
- GCP &gt; CIS v4.0 &gt; 3 - Networking &gt; 3.04 - Ensure That RSASHA1 Is Not Used for the Key-Signing Key in Cloud DNS DNSSEC
- GCP &gt; CIS v4.0 &gt; 3 - Networking &gt; 3.05 - Ensure That RSASHA1 Is Not Used for the Zone-Signing Key in Cloud DNS DNSSEC
- GCP &gt; CIS v4.0 &gt; 3 - Networking &gt; 3.06 - Ensure That SSH Access Is Restricted From the Internet
- GCP &gt; CIS v4.0 &gt; 3 - Networking &gt; 3.07 - Ensure That RDP Access Is Restricted From the Internet
- GCP &gt; CIS v4.0 &gt; 3 - Networking &gt; 3.08 - Ensure that VPC Flow Logs is Enabled for Every Subnet in a VPC Network
- GCP &gt; CIS v4.0 &gt; 3 - Networking &gt; 3.09 - Ensure No HTTPS or SSL Proxy Load Balancers Permit SSL Policies With Weak Cipher Suites
- GCP &gt; CIS v4.0 &gt; 3 - Networking &gt; 3.09 - Ensure No HTTPS or SSL Proxy Load Balancers Permit SSL Policies With Weak Cipher Suites &gt; Attestation
- GCP &gt; CIS v4.0 &gt; 3 - Networking &gt; 3.10 - Use Identity Aware Proxy (IAP) to Ensure Only Traffic From Google IP Addresses are &apos;Allowed&apos;
- GCP &gt; CIS v4.0 &gt; 3 - Networking &gt; 3.10 - Use Identity Aware Proxy (IAP) to Ensure Only Traffic From Google IP Addresses are &apos;Allowed&apos; &gt; Attestation
- GCP &gt; CIS v4.0 &gt; 3 - Networking &gt; Maximum Attestation Duration
- GCP &gt; CIS v4.0 &gt; 4 - Virtual Machines
- GCP &gt; CIS v4.0 &gt; 4 - Virtual Machines &gt; 4.01 - Ensure That Instances Are Not Configured To Use the Default Service Account
- GCP &gt; CIS v4.0 &gt; 4 - Virtual Machines &gt; 4.02 - Ensure That Instances Are Not Configured To Use the Default Service Account With Full Access to All Cloud APIs
- GCP &gt; CIS v4.0 &gt; 4 - Virtual Machines &gt; 4.03 - Ensure &quot;Block Project-Wide SSH Keys&quot; Is Enabled for VM Instances
- GCP &gt; CIS v4.0 &gt; 4 - Virtual Machines &gt; 4.04 - Ensure Oslogin Is Enabled for a Project
- GCP &gt; CIS v4.0 &gt; 4 - Virtual Machines &gt; 4.05 - Ensure &apos;Enable Connecting to Serial Ports&apos; Is Not Enabled for VM Instance
- GCP &gt; CIS v4.0 &gt; 4 - Virtual Machines &gt; 4.06 - Ensure That IP Forwarding Is Not Enabled on Instances
- GCP &gt; CIS v4.0 &gt; 4 - Virtual Machines &gt; 4.07 - Ensure VM Disks for Critical VMs Are Encrypted With Customer-Supplied Encryption Keys (CSEK)
- GCP &gt; CIS v4.0 &gt; 4 - Virtual Machines &gt; 4.08 - Ensure Compute Instances Are Launched With Shielded VM Enabled
- GCP &gt; CIS v4.0 &gt; 4 - Virtual Machines &gt; 4.09 - Ensure That Compute Instances Do Not Have Public IP Addresses
- GCP &gt; CIS v4.0 &gt; 4 - Virtual Machines &gt; 4.10 - Ensure That App Engine Applications Enforce HTTPS Connections
- GCP &gt; CIS v4.0 &gt; 4 - Virtual Machines &gt; 4.10 - Ensure That App Engine Applications Enforce HTTPS Connections &gt; Attestation
- GCP &gt; CIS v4.0 &gt; 4 - Virtual Machines &gt; 4.11 - Ensure That Compute Instances Have Confidential Computing Enabled
- GCP &gt; CIS v4.0 &gt; 4 - Virtual Machines &gt; 4.12 - Ensure the Latest Operating System Updates Are Installed On Your Virtual Machines in All Projects
- GCP &gt; CIS v4.0 &gt; 4 - Virtual Machines &gt; 4.12 - Ensure the Latest Operating System Updates Are Installed On Your Virtual Machines in All Projects &gt; Attestation
- GCP &gt; CIS v4.0 &gt; 4 - Virtual Machines &gt; Maximum Attestation Duration
- GCP &gt; CIS v4.0 &gt; 5 - Storage
- GCP &gt; CIS v4.0 &gt; 5 - Storage &gt; 5.01 - Ensure That Cloud Storage Bucket Is Not Anonymously or Publicly Accessible
- GCP &gt; CIS v4.0 &gt; 5 - Storage &gt; 5.02 - Ensure That Cloud Storage Buckets Have Uniform Bucket-Level Access Enabled
- GCP &gt; CIS v4.0 &gt; 5 - Storage &gt; Maximum Attestation Duration
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.01 - MySQL Database
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.01 - MySQL Database &gt; 6.01.01 - Ensure That a MySQL Database Instance Does Not Allow Anyone To Connect With Administrative Privileges
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.01 - MySQL Database &gt; 6.01.01 - Ensure That a MySQL Database Instance Does Not Allow Anyone To Connect With Administrative Privileges &gt; Attestation
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.01 - MySQL Database &gt; 6.01.02 - Ensure &apos;Skip_show_database&apos; Database Flag for Cloud SQL MySQL Instance Is Set to &apos;On&apos;
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.01 - MySQL Database &gt; 6.01.03 - Ensure That the &apos;Local_infile&apos; Database Flag for a Cloud SQL MySQL Instance Is Set to &apos;Off&apos;
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.01 - MySQL Database &gt; Maximum Attestation Duration
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database &gt; 6.02.01 - Ensure &apos;Log_error_verbosity&apos; Database Flag for Cloud SQL PostgreSQL Instance Is Set to &apos;DEFAULT&apos; or Stricter
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database &gt; 6.02.02 - Ensure &apos;Log_connections&apos; Database Flag for Cloud SQL PostgreSQL Instance Is Set to &apos;On&apos;
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database &gt; 6.02.03 - Ensure &apos;Log_disconnections&apos; Database Flag for Cloud SQL PostgreSQL Instance Is Set to &apos;On&apos;
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database &gt; 6.02.04 - Ensure &apos;Log_statement&apos; Database Flag for Cloud SQL PostgreSQL Instance Is Set Appropriately
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database &gt; 6.02.05 - Ensure &apos;Log_min_messages&apos; Database Flag for Cloud SQL PostgreSQL Instance is set at minimum to &apos;Warning&apos;
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database &gt; 6.02.06 - Ensure &apos;Log_min_error_statement&apos; Database Flag for Cloud SQL PostgreSQL Instance Is Set to &apos;Error&apos; or Stricter
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database &gt; 6.02.07 - Ensure That the &apos;Log_min_duration_statement&apos; Database Flag for Cloud SQL PostgreSQL Instance Is Set to &apos;-1&apos;
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database &gt; 6.02.08 - Ensure That &apos;cloudsql.enable_pgaudit&apos; Database Flag for each Cloud Sql Postgresql Instance Is Set to &apos;on&apos; For Centralized Logging
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database &gt; Maximum Attestation Duration
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.03 - SQL Server
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.03 - SQL Server &gt; 6.03.01 - Ensure &apos;external scripts enabled&apos; database flag for Cloud SQL SQL Server instance is set to &apos;off&apos;
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.03 - SQL Server &gt; 6.03.02 - Ensure that the &apos;cross db ownership chaining&apos; database flag for Cloud SQL SQL Server instance is set to &apos;off&apos;
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.03 - SQL Server &gt; 6.03.03 - Ensure &apos;user Connections&apos; Database Flag for Cloud Sql Sql Server Instance Is Set to a Non-limiting Value
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.03 - SQL Server &gt; 6.03.04 - Ensure &apos;user options&apos; database flag for Cloud SQL SQL Server instance is not configured
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.03 - SQL Server &gt; 6.03.05 - Ensure &apos;remote access&apos; database flag for Cloud SQL SQL Server instance is set to &apos;off&apos;
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.03 - SQL Server &gt; 6.03.06 - Ensure &apos;3625 (trace flag)&apos; database flag for all Cloud SQL Server instances is set to &apos;on&apos;
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.03 - SQL Server &gt; 6.03.07 - Ensure that the &apos;contained database authentication&apos; database flag for Cloud SQL on the SQL Server instance is set to &apos;off&apos;
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.03 - SQL Server &gt; Maximum Attestation Duration
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.04 - Ensure That the Cloud SQL Database Instance Requires All Incoming Connections To Use SSL
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.05 - Ensure That Cloud SQL Database Instances Do Not Implicitly Whitelist All Public IP Addresses
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.06 - Ensure That Cloud SQL Database Instances Do Not Have Public IPs
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; 6.07 - Ensure That Cloud SQL Database Instances Are Configured With Automated Backups
- GCP &gt; CIS v4.0 &gt; 6 - Cloud SQL Database Services &gt; Maximum Attestation Duration
- GCP &gt; CIS v4.0 &gt; 7 - BigQuery
- GCP &gt; CIS v4.0 &gt; 7 - BigQuery &gt; 7.01 - Ensure That BigQuery Datasets Are Not Anonymously or Publicly Accessible
- GCP &gt; CIS v4.0 &gt; 7 - BigQuery &gt; 7.02 - Ensure That All BigQuery Tables Are Encrypted With Customer-Managed Encryption Key (CMEK)
- GCP &gt; CIS v4.0 &gt; 7 - BigQuery &gt; 7.03 - Ensure That a Default Customer-Managed Encryption Key (CMEK) Is Specified for All BigQuery Data Sets
- GCP &gt; CIS v4.0 &gt; 7 - BigQuery &gt; 7.04 - Ensure All Data in BigQuery Has Been Classified
- GCP &gt; CIS v4.0 &gt; 7 - BigQuery &gt; 7.04 - Ensure All Data in BigQuery Has Been Classified &gt; Attestation
- GCP &gt; CIS v4.0 &gt; 7 - BigQuery &gt; Maximum Attestation Duration
- GCP &gt; CIS v4.0 &gt; 8 - Dataproc
- GCP &gt; CIS v4.0 &gt; 8 - Dataproc &gt; 8.01 - Ensure that Dataproc Cluster is encrypted using Customer-Managed Encryption Key
- GCP &gt; CIS v4.0 &gt; 8 - Dataproc &gt; Maximum Attestation Duration
- GCP &gt; CIS v4.0 &gt; Maximum Attestation Duration</description>
            <pubDate>Fri, 30 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-storage-v5-31-0</guid>
            <title>azure-storage v5.31.0 - Protocol settings and versioning details now available in CMDB for storage accounts</title>
            <link>https://turbot.com/guardrails/changelog/azure-storage-v5-31-0</link>
            <description>_What&apos;s new?_

- Protocol settings and versioning details are now available in CMDB for storage accounts.

_Control Types_

- Azure &gt; Storage &gt; Container &gt; Allowed
- Azure &gt; Storage &gt; Container &gt; Allowed &gt; Custom
- Azure &gt; Storage &gt; FileShare &gt; Allowed
- Azure &gt; Storage &gt; FileShare &gt; Allowed &gt; Custom
- Azure &gt; Storage &gt; Storage Account &gt; Allowed
- Azure &gt; Storage &gt; Storage Account &gt; Allowed &gt; Custom
- Azure &gt; Storage &gt; Storage Account &gt; Allowed &gt; Region

_Policy Types_

- Azure &gt; Storage &gt; Allowed Regions [Default]
- Azure &gt; Storage &gt; Container &gt; Allowed
- Azure &gt; Storage &gt; Container &gt; Allowed &gt; Custom
- Azure &gt; Storage &gt; Container &gt; Allowed &gt; Custom &gt; Rules
- Azure &gt; Storage &gt; FileShare &gt; Allowed
- Azure &gt; Storage &gt; FileShare &gt; Allowed &gt; Custom
- Azure &gt; Storage &gt; FileShare &gt; Allowed &gt; Custom &gt; Rules
- Azure &gt; Storage &gt; Storage Account &gt; Allowed
- Azure &gt; Storage &gt; Storage Account &gt; Allowed &gt; Custom
- Azure &gt; Storage &gt; Storage Account &gt; Allowed &gt; Custom &gt; Rules
- Azure &gt; Storage &gt; Storage Account &gt; Allowed &gt; Region
- Azure &gt; Storage &gt; Storage Account &gt; Allowed &gt; Region &gt; Regions</description>
            <pubDate>Fri, 30 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-network-v5-29-1</guid>
            <title>azure-network v5.29.1 - Private Endpoints Tags control now updates tags correctly</title>
            <link>https://turbot.com/guardrails/changelog/azure-network-v5-29-1</link>
            <description>_Bug fixes_

- The `Azure &gt; Network &gt; Private Endpoints &gt; Tags` control previously failed to update tags. This has now been fixed and the control will work as expected.</description>
            <pubDate>Fri, 30 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-mq-v5-5-0</guid>
            <title>aws-mq v5.5.0 - Real-time event handlers now process tagging events for configuration resources</title>
            <link>https://turbot.com/guardrails/changelog/aws-mq-v5-5-0</link>
            <description>_What&apos;s new?_

- Real-time event handlers previously failed to process tagging and untagging events for configuration resources. This has now been fixed.

_Action Types_

- AWS &gt; Amazon MQ &gt; Configuration &gt; Router</description>
            <pubDate>Fri, 30 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/terraform-provider-v1-13-1</guid>
            <title>Terraform Provider v1.13.1 - Fixed `turbot_control` data source GraphQL query error</title>
            <link>https://turbot.com/guardrails/changelog/terraform-provider-v1-13-1</link>
            <description>_Bug fixes_

- Fixed a GraphQL syntax error when querying the `turbot_control` data source using control type and resource.</description>
            <pubDate>Thu, 29 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-cisv6-0-v5-0-0</guid>
            <title>aws-cisv6-0 v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/aws-cisv6-0-v5-0-0</link>
            <description>_Control Types_

- AWS &gt; CIS v6.0
- AWS &gt; CIS v6.0 &gt; 2 - Identity and Access Management
- AWS &gt; CIS v6.0 &gt; 2 - Identity and Access Management &gt; 2.01 - Maintain current contact details
- AWS &gt; CIS v6.0 &gt; 2 - Identity and Access Management &gt; 2.02 - Ensure security contact information is registered
- AWS &gt; CIS v6.0 &gt; 2 - Identity and Access Management &gt; 2.03 - Ensure no &apos;root&apos; user account access key exists
- AWS &gt; CIS v6.0 &gt; 2 - Identity and Access Management &gt; 2.04 - Ensure MFA is enabled for the &apos;root&apos; user account
- AWS &gt; CIS v6.0 &gt; 2 - Identity and Access Management &gt; 2.05 - Ensure hardware MFA is enabled for the &apos;root&apos; user account
- AWS &gt; CIS v6.0 &gt; 2 - Identity and Access Management &gt; 2.06 - Eliminate use of the &apos;root&apos; user for administrative and daily tasks
- AWS &gt; CIS v6.0 &gt; 2 - Identity and Access Management &gt; 2.07 - Ensure IAM password policy requires minimum length of 14 or greater
- AWS &gt; CIS v6.0 &gt; 2 - Identity and Access Management &gt; 2.08 - Ensure IAM password policy prevents password reuse
- AWS &gt; CIS v6.0 &gt; 2 - Identity and Access Management &gt; 2.09 - Ensure multi-factor authentication (MFA) is enabled for all IAM users that have a console password
- AWS &gt; CIS v6.0 &gt; 2 - Identity and Access Management &gt; 2.10 - Do not create access keys during initial setup for IAM users with a console password
- AWS &gt; CIS v6.0 &gt; 2 - Identity and Access Management &gt; 2.11 - Ensure credentials unused for 45 days or more are disabled
- AWS &gt; CIS v6.0 &gt; 2 - Identity and Access Management &gt; 2.12 - Ensure there is only one active access key for any single IAM user
- AWS &gt; CIS v6.0 &gt; 2 - Identity and Access Management &gt; 2.13 - Ensure access keys are rotated every 90 days or less
- AWS &gt; CIS v6.0 &gt; 2 - Identity and Access Management &gt; 2.14 - Ensure IAM users receive permissions only through groups
- AWS &gt; CIS v6.0 &gt; 2 - Identity and Access Management &gt; 2.15 - Ensure IAM policies that allow full &quot;_:_&quot; administrative privileges are not attached
- AWS &gt; CIS v6.0 &gt; 2 - Identity and Access Management &gt; 2.16 - Ensure a support role has been created to manage incidents with AWS Support
- AWS &gt; CIS v6.0 &gt; 2 - Identity and Access Management &gt; 2.17 - Ensure IAM instance roles are used for AWS resource access from instances
- AWS &gt; CIS v6.0 &gt; 2 - Identity and Access Management &gt; 2.18 - Ensure that all expired SSL/TLS certificates stored in AWS IAM are removed
- AWS &gt; CIS v6.0 &gt; 2 - Identity and Access Management &gt; 2.19 - Ensure that IAM External Access Analyzer is enabled for all regions
- AWS &gt; CIS v6.0 &gt; 2 - Identity and Access Management &gt; 2.20 - Ensure IAM users are managed centrally via identity federation or AWS Organizations for multi-account environments
- AWS &gt; CIS v6.0 &gt; 2 - Identity and Access Management &gt; 2.21 - Ensure access to AWSCloudShellFullAccess is restricted
- AWS &gt; CIS v6.0 &gt; 3 - Storage
- AWS &gt; CIS v6.0 &gt; 3 - Storage &gt; 3.01 - Simple Storage Service (S3)
- AWS &gt; CIS v6.0 &gt; 3 - Storage &gt; 3.01 - Simple Storage Service (S3) &gt; 3.01.01 - Ensure S3 Bucket Policy is set to deny HTTP requests
- AWS &gt; CIS v6.0 &gt; 3 - Storage &gt; 3.01 - Simple Storage Service (S3) &gt; 3.01.02 - Ensure MFA Delete is enabled on S3 buckets
- AWS &gt; CIS v6.0 &gt; 3 - Storage &gt; 3.01 - Simple Storage Service (S3) &gt; 3.01.03 - Ensure all data in Amazon S3 has been discovered, classified, and secured when necessary
- AWS &gt; CIS v6.0 &gt; 3 - Storage &gt; 3.01 - Simple Storage Service (S3) &gt; 3.01.04 - Ensure that S3 is configured with &apos;Block Public Access&apos; enabled
- AWS &gt; CIS v6.0 &gt; 3 - Storage &gt; 3.02 - Relational Database Service (RDS)
- AWS &gt; CIS v6.0 &gt; 3 - Storage &gt; 3.02 - Relational Database Service (RDS) &gt; 3.02.01 - Ensure that encryption-at-rest is enabled for RDS Instances
- AWS &gt; CIS v6.0 &gt; 3 - Storage &gt; 3.02 - Relational Database Service (RDS) &gt; 3.02.02 - Ensure the Auto Minor Version Upgrade feature is enabled for RDS instances
- AWS &gt; CIS v6.0 &gt; 3 - Storage &gt; 3.02 - Relational Database Service (RDS) &gt; 3.02.03 - Ensure that RDS instances are not publicly accessible
- AWS &gt; CIS v6.0 &gt; 3 - Storage &gt; 3.02 - Relational Database Service (RDS) &gt; 3.02.04 - Ensure Multi-AZ deployments are used for enhanced availability in Amazon RDS
- AWS &gt; CIS v6.0 &gt; 3 - Storage &gt; 3.03 - Elastic File System (EFS)
- AWS &gt; CIS v6.0 &gt; 3 - Storage &gt; 3.03 - Elastic File System (EFS) &gt; 3.03.01 - Ensure that encryption is enabled for EFS file systems
- AWS &gt; CIS v6.0 &gt; 4 - Logging
- AWS &gt; CIS v6.0 &gt; 4 - Logging &gt; 4.01 - Ensure CloudTrail is enabled in all regions
- AWS &gt; CIS v6.0 &gt; 4 - Logging &gt; 4.02 - Ensure CloudTrail log file validation is enabled
- AWS &gt; CIS v6.0 &gt; 4 - Logging &gt; 4.03 - Ensure AWS Config is enabled in all regions
- AWS &gt; CIS v6.0 &gt; 4 - Logging &gt; 4.04 - Ensure that server access logging is enabled on the CloudTrail S3 bucket
- AWS &gt; CIS v6.0 &gt; 4 - Logging &gt; 4.05 - Ensure CloudTrail logs are encrypted at rest using KMS CMKs
- AWS &gt; CIS v6.0 &gt; 4 - Logging &gt; 4.06 - Ensure rotation for customer-created symmetric CMKs is enabled
- AWS &gt; CIS v6.0 &gt; 4 - Logging &gt; 4.07 - Ensure VPC flow logging is enabled in all VPCs
- AWS &gt; CIS v6.0 &gt; 4 - Logging &gt; 4.08 - Ensure that object-level logging for write events is enabled for S3 buckets
- AWS &gt; CIS v6.0 &gt; 4 - Logging &gt; 4.09 - Ensure that object-level logging for read events is enabled for S3 buckets
- AWS &gt; CIS v6.0 &gt; 5 - Monitoring
- AWS &gt; CIS v6.0 &gt; 5 - Monitoring &gt; 5.01 - Ensure unauthorized API calls are monitored
- AWS &gt; CIS v6.0 &gt; 5 - Monitoring &gt; 5.02 - Ensure management console sign-in without MFA is monitored
- AWS &gt; CIS v6.0 &gt; 5 - Monitoring &gt; 5.03 - Ensure usage of the &apos;root&apos; account is monitored
- AWS &gt; CIS v6.0 &gt; 5 - Monitoring &gt; 5.04 - Ensure IAM policy changes are monitored
- AWS &gt; CIS v6.0 &gt; 5 - Monitoring &gt; 5.05 - Ensure CloudTrail configuration changes are monitored
- AWS &gt; CIS v6.0 &gt; 5 - Monitoring &gt; 5.06 - Ensure AWS Management Console authentication failures are monitored
- AWS &gt; CIS v6.0 &gt; 5 - Monitoring &gt; 5.07 - Ensure disabling or scheduled deletion of customer created CMKs is monitored
- AWS &gt; CIS v6.0 &gt; 5 - Monitoring &gt; 5.08 - Ensure S3 bucket policy changes are monitored
- AWS &gt; CIS v6.0 &gt; 5 - Monitoring &gt; 5.09 - Ensure AWS Config configuration changes are monitored
- AWS &gt; CIS v6.0 &gt; 5 - Monitoring &gt; 5.10 - Ensure security group changes are monitored
- AWS &gt; CIS v6.0 &gt; 5 - Monitoring &gt; 5.11 - Ensure Network Access Control List (NACL) changes are monitored
- AWS &gt; CIS v6.0 &gt; 5 - Monitoring &gt; 5.12 - Ensure changes to network gateways are monitored
- AWS &gt; CIS v6.0 &gt; 5 - Monitoring &gt; 5.13 - Ensure route table changes are monitored
- AWS &gt; CIS v6.0 &gt; 5 - Monitoring &gt; 5.14 - Ensure VPC changes are monitored
- AWS &gt; CIS v6.0 &gt; 5 - Monitoring &gt; 5.15 - Ensure AWS Organizations changes are monitored
- AWS &gt; CIS v6.0 &gt; 5 - Monitoring &gt; 5.16 - Ensure AWS Security Hub is enabled
- AWS &gt; CIS v6.0 &gt; 6 - Networking
- AWS &gt; CIS v6.0 &gt; 6 - Networking &gt; 6.01 - Elastic Compute Cloud (EC2)
- AWS &gt; CIS v6.0 &gt; 6 - Networking &gt; 6.01 - Elastic Compute Cloud (EC2) &gt; 6.01.01 - Ensure EBS volume encryption is enabled in all regions
- AWS &gt; CIS v6.0 &gt; 6 - Networking &gt; 6.01 - Elastic Compute Cloud (EC2) &gt; 6.01.02 - Ensure CIFS access is restricted to trusted networks to prevent unauthorized access
- AWS &gt; CIS v6.0 &gt; 6 - Networking &gt; 6.02 - Ensure no Network ACLs allow ingress from 0.0.0.0/0 to remote server administration ports
- AWS &gt; CIS v6.0 &gt; 6 - Networking &gt; 6.03 - Ensure no security groups allow ingress from 0.0.0.0/0 to remote server administration ports
- AWS &gt; CIS v6.0 &gt; 6 - Networking &gt; 6.04 - Ensure no security groups allow ingress from ::/0 to remote server administration ports
- AWS &gt; CIS v6.0 &gt; 6 - Networking &gt; 6.05 - Ensure the default security group of every VPC restricts all traffic
- AWS &gt; CIS v6.0 &gt; 6 - Networking &gt; 6.06 - Ensure routing tables for VPC peering are &apos;least access&apos;
- AWS &gt; CIS v6.0 &gt; 6 - Networking &gt; 6.07 - Ensure that the EC2 Metadata Service only allows IMDSv2

_Policy Types_

- AWS &gt; CIS v6.0
- AWS &gt; CIS v6.0 &gt; 2 - Identity and Access Management
- AWS &gt; CIS v6.0 &gt; 2 - Identity and Access Management &gt; 2.01 - Maintain current contact details
- AWS &gt; CIS v6.0 &gt; 2 - Identity and Access Management &gt; 2.01 - Maintain current contact details &gt; Attestation
- AWS &gt; CIS v6.0 &gt; 2 - Identity and Access Management &gt; 2.02 - Ensure security contact information is registered
- AWS &gt; CIS v6.0 &gt; 2 - Identity and Access Management &gt; 2.03 - Ensure no &apos;root&apos; user account access key exists
- AWS &gt; CIS v6.0 &gt; 2 - Identity and Access Management &gt; 2.04 - Ensure MFA is enabled for the &apos;root&apos; user account
- AWS &gt; CIS v6.0 &gt; 2 - Identity and Access Management &gt; 2.05 - Ensure hardware MFA is enabled for the &apos;root&apos; user account
- AWS &gt; CIS v6.0 &gt; 2 - Identity and Access Management &gt; 2.06 - Eliminate use of the &apos;root&apos; user for administrative and daily tasks
- AWS &gt; CIS v6.0 &gt; 2 - Identity and Access Management &gt; 2.07 - Ensure IAM password policy requires minimum length of 14 or greater
- AWS &gt; CIS v6.0 &gt; 2 - Identity and Access Management &gt; 2.08 - Ensure IAM password policy prevents password reuse
- AWS &gt; CIS v6.0 &gt; 2 - Identity and Access Management &gt; 2.09 - Ensure multi-factor authentication (MFA) is enabled for all IAM users that have a console password
- AWS &gt; CIS v6.0 &gt; 2 - Identity and Access Management &gt; 2.10 - Do not create access keys during initial setup for IAM users with a console password
- AWS &gt; CIS v6.0 &gt; 2 - Identity and Access Management &gt; 2.11 - Ensure credentials unused for 45 days or more are disabled
- AWS &gt; CIS v6.0 &gt; 2 - Identity and Access Management &gt; 2.12 - Ensure there is only one active access key for any single IAM user
- AWS &gt; CIS v6.0 &gt; 2 - Identity and Access Management &gt; 2.13 - Ensure access keys are rotated every 90 days or less
- AWS &gt; CIS v6.0 &gt; 2 - Identity and Access Management &gt; 2.14 - Ensure IAM users receive permissions only through groups
- AWS &gt; CIS v6.0 &gt; 2 - Identity and Access Management &gt; 2.15 - Ensure IAM policies that allow full &quot;_:_&quot; administrative privileges are not attached
- AWS &gt; CIS v6.0 &gt; 2 - Identity and Access Management &gt; 2.16 - Ensure a support role has been created to manage incidents with AWS Support
- AWS &gt; CIS v6.0 &gt; 2 - Identity and Access Management &gt; 2.17 - Ensure IAM instance roles are used for AWS resource access from instances
- AWS &gt; CIS v6.0 &gt; 2 - Identity and Access Management &gt; 2.18 - Ensure that all expired SSL/TLS certificates stored in AWS IAM are removed
- AWS &gt; CIS v6.0 &gt; 2 - Identity and Access Management &gt; 2.19 - Ensure that IAM External Access Analyzer is enabled for all regions
- AWS &gt; CIS v6.0 &gt; 2 - Identity and Access Management &gt; 2.20 - Ensure IAM users are managed centrally via identity federation or AWS Organizations for multi-account environments
- AWS &gt; CIS v6.0 &gt; 2 - Identity and Access Management &gt; 2.20 - Ensure IAM users are managed centrally via identity federation or AWS Organizations for multi-account environments &gt; Attestation
- AWS &gt; CIS v6.0 &gt; 2 - Identity and Access Management &gt; 2.21 - Ensure access to AWSCloudShellFullAccess is restricted
- AWS &gt; CIS v6.0 &gt; 2 - Identity and Access Management &gt; 2.21 - Ensure access to AWSCloudShellFullAccess is restricted &gt; Attestation
- AWS &gt; CIS v6.0 &gt; 2 - Identity and Access Management &gt; Maximum Attestation Duration
- AWS &gt; CIS v6.0 &gt; 3 - Storage
- AWS &gt; CIS v6.0 &gt; 3 - Storage &gt; 3.01 - Simple Storage Service (S3)
- AWS &gt; CIS v6.0 &gt; 3 - Storage &gt; 3.01 - Simple Storage Service (S3) &gt; 3.01.01 - Ensure S3 Bucket Policy is set to deny HTTP requests
- AWS &gt; CIS v6.0 &gt; 3 - Storage &gt; 3.01 - Simple Storage Service (S3) &gt; 3.01.02 - Ensure MFA Delete is enabled on S3 buckets
- AWS &gt; CIS v6.0 &gt; 3 - Storage &gt; 3.01 - Simple Storage Service (S3) &gt; 3.01.03 - Ensure all data in Amazon S3 has been discovered, classified, and secured when necessary
- AWS &gt; CIS v6.0 &gt; 3 - Storage &gt; 3.01 - Simple Storage Service (S3) &gt; 3.01.03 - Ensure all data in Amazon S3 has been discovered, classified, and secured when necessary &gt; Attestation
- AWS &gt; CIS v6.0 &gt; 3 - Storage &gt; 3.01 - Simple Storage Service (S3) &gt; 3.01.04 - Ensure that S3 is configured with &apos;Block Public Access&apos; enabled
- AWS &gt; CIS v6.0 &gt; 3 - Storage &gt; 3.02 - Relational Database Service (RDS)
- AWS &gt; CIS v6.0 &gt; 3 - Storage &gt; 3.02 - Relational Database Service (RDS) &gt; 3.02.01 - Ensure that encryption-at-rest is enabled for RDS Instances
- AWS &gt; CIS v6.0 &gt; 3 - Storage &gt; 3.02 - Relational Database Service (RDS) &gt; 3.02.02 - Ensure the Auto Minor Version Upgrade feature is enabled for RDS instances
- AWS &gt; CIS v6.0 &gt; 3 - Storage &gt; 3.02 - Relational Database Service (RDS) &gt; 3.02.03 - Ensure that RDS instances are not publicly accessible
- AWS &gt; CIS v6.0 &gt; 3 - Storage &gt; 3.02 - Relational Database Service (RDS) &gt; 3.02.04 - Ensure Multi-AZ deployments are used for enhanced availability in Amazon RDS
- AWS &gt; CIS v6.0 &gt; 3 - Storage &gt; 3.03 - Elastic File System (EFS)
- AWS &gt; CIS v6.0 &gt; 3 - Storage &gt; 3.03 - Elastic File System (EFS) &gt; 3.03.01 - Ensure that encryption is enabled for EFS file systems
- AWS &gt; CIS v6.0 &gt; 3 - Storage &gt; Maximum Attestation Duration
- AWS &gt; CIS v6.0 &gt; 4 - Logging
- AWS &gt; CIS v6.0 &gt; 4 - Logging &gt; 4.01 - Ensure CloudTrail is enabled in all regions
- AWS &gt; CIS v6.0 &gt; 4 - Logging &gt; 4.02 - Ensure CloudTrail log file validation is enabled
- AWS &gt; CIS v6.0 &gt; 4 - Logging &gt; 4.03 - Ensure AWS Config is enabled in all regions
- AWS &gt; CIS v6.0 &gt; 4 - Logging &gt; 4.04 - Ensure that server access logging is enabled on the CloudTrail S3 bucket
- AWS &gt; CIS v6.0 &gt; 4 - Logging &gt; 4.05 - Ensure CloudTrail logs are encrypted at rest using KMS CMKs
- AWS &gt; CIS v6.0 &gt; 4 - Logging &gt; 4.06 - Ensure rotation for customer-created symmetric CMKs is enabled
- AWS &gt; CIS v6.0 &gt; 4 - Logging &gt; 4.07 - Ensure VPC flow logging is enabled in all VPCs
- AWS &gt; CIS v6.0 &gt; 4 - Logging &gt; 4.08 - Ensure that object-level logging for write events is enabled for S3 buckets
- AWS &gt; CIS v6.0 &gt; 4 - Logging &gt; 4.09 - Ensure that object-level logging for read events is enabled for S3 buckets
- AWS &gt; CIS v6.0 &gt; 4 - Logging &gt; Maximum Attestation Duration
- AWS &gt; CIS v6.0 &gt; 5 - Monitoring
- AWS &gt; CIS v6.0 &gt; 5 - Monitoring &gt; 5.01 - Ensure unauthorized API calls are monitored
- AWS &gt; CIS v6.0 &gt; 5 - Monitoring &gt; 5.02 - Ensure management console sign-in without MFA is monitored
- AWS &gt; CIS v6.0 &gt; 5 - Monitoring &gt; 5.03 - Ensure usage of the &apos;root&apos; account is monitored
- AWS &gt; CIS v6.0 &gt; 5 - Monitoring &gt; 5.04 - Ensure IAM policy changes are monitored
- AWS &gt; CIS v6.0 &gt; 5 - Monitoring &gt; 5.05 - Ensure CloudTrail configuration changes are monitored
- AWS &gt; CIS v6.0 &gt; 5 - Monitoring &gt; 5.06 - Ensure AWS Management Console authentication failures are monitored
- AWS &gt; CIS v6.0 &gt; 5 - Monitoring &gt; 5.07 - Ensure disabling or scheduled deletion of customer created CMKs is monitored
- AWS &gt; CIS v6.0 &gt; 5 - Monitoring &gt; 5.08 - Ensure S3 bucket policy changes are monitored
- AWS &gt; CIS v6.0 &gt; 5 - Monitoring &gt; 5.09 - Ensure AWS Config configuration changes are monitored
- AWS &gt; CIS v6.0 &gt; 5 - Monitoring &gt; 5.10 - Ensure security group changes are monitored
- AWS &gt; CIS v6.0 &gt; 5 - Monitoring &gt; 5.11 - Ensure Network Access Control List (NACL) changes are monitored
- AWS &gt; CIS v6.0 &gt; 5 - Monitoring &gt; 5.12 - Ensure changes to network gateways are monitored
- AWS &gt; CIS v6.0 &gt; 5 - Monitoring &gt; 5.13 - Ensure route table changes are monitored
- AWS &gt; CIS v6.0 &gt; 5 - Monitoring &gt; 5.14 - Ensure VPC changes are monitored
- AWS &gt; CIS v6.0 &gt; 5 - Monitoring &gt; 5.15 - Ensure AWS Organizations changes are monitored
- AWS &gt; CIS v6.0 &gt; 5 - Monitoring &gt; 5.16 - Ensure AWS Security Hub is enabled
- AWS &gt; CIS v6.0 &gt; 5 - Monitoring &gt; Maximum Attestation Duration
- AWS &gt; CIS v6.0 &gt; 6 - Networking
- AWS &gt; CIS v6.0 &gt; 6 - Networking &gt; 6.01 - Elastic Compute Cloud (EC2)
- AWS &gt; CIS v6.0 &gt; 6 - Networking &gt; 6.01 - Elastic Compute Cloud (EC2) &gt; 6.01.01 - Ensure EBS volume encryption is enabled in all regions
- AWS &gt; CIS v6.0 &gt; 6 - Networking &gt; 6.01 - Elastic Compute Cloud (EC2) &gt; 6.01.02 - Ensure CIFS access is restricted to trusted networks to prevent unauthorized access
- AWS &gt; CIS v6.0 &gt; 6 - Networking &gt; 6.02 - Ensure no Network ACLs allow ingress from 0.0.0.0/0 to remote server administration ports
- AWS &gt; CIS v6.0 &gt; 6 - Networking &gt; 6.03 - Ensure no security groups allow ingress from 0.0.0.0/0 to remote server administration ports
- AWS &gt; CIS v6.0 &gt; 6 - Networking &gt; 6.04 - Ensure no security groups allow ingress from ::/0 to remote server administration ports
- AWS &gt; CIS v6.0 &gt; 6 - Networking &gt; 6.05 - Ensure the default security group of every VPC restricts all traffic
- AWS &gt; CIS v6.0 &gt; 6 - Networking &gt; 6.06 - Ensure routing tables for VPC peering are &apos;least access&apos;
- AWS &gt; CIS v6.0 &gt; 6 - Networking &gt; 6.06 - Ensure routing tables for VPC peering are &apos;least access&apos; &gt; Attestation
- AWS &gt; CIS v6.0 &gt; 6 - Networking &gt; 6.07 - Ensure that the EC2 Metadata Service only allows IMDSv2
- AWS &gt; CIS v6.0 &gt; 6 - Networking &gt; Maximum Attestation Duration
- AWS &gt; CIS v6.0 &gt; Maximum Attestation Duration</description>
            <pubDate>Thu, 29 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-54-12</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.54.12 - Version bump to align with deployment requirements</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-54-12</link>
            <description>Version bump to align with deployment requirements.

_Requirements_

- Upgrade to `5.54.12` requires your workspace to be on `5.53.x`
- PostgreSQL (RDS engine): &gt;= 15
- TEF: 1.66.0
- TED: 1.37.0
- Mods:
  - @turbot/turbot: 5.56.0

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Wed, 28 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-cisv3-0-v5-0-0</guid>
            <title>gcp-cisv3-0 v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/gcp-cisv3-0-v5-0-0</link>
            <description>_Control Types_

- GCP &gt; CIS v3.0
- GCP &gt; CIS v3.0 &gt; 1 - Identity and Access Management
- GCP &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.01 - Ensure that Corporate Login Credentials are Used
- GCP &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.02 - Ensure that Multi-Factor Authentication is &apos;Enabled&apos; for All Non-Service Accounts
- GCP &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.03 - Ensure that Security Key Enforcement is Enabled for All Admin Accounts
- GCP &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.04 - Ensure That There Are Only GCP-Managed Service Account Keys for Each Service Account
- GCP &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.05 - Ensure That Service Account Has No Admin Privileges
- GCP &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.06 - Ensure That IAM Users Are Not Assigned the Service Account User or Service Account Token Creator Roles at Project Level
- GCP &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.07 - Ensure User-Managed/External Keys for Service Accounts Are Rotated Every 90 Days or Fewer
- GCP &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.08 - Ensure That Separation of Duties Is Enforced While Assigning Service Account Related Roles to Users
- GCP &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.09 - Ensure That Cloud KMS Cryptokeys Are Not Anonymously or Publicly Accessible
- GCP &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.10 - Ensure KMS Encryption Keys Are Rotated Within a Period of 90 Days
- GCP &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.11 - Ensure That Separation of Duties Is Enforced While Assigning KMS Related Roles to Users
- GCP &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.12 - Ensure API Keys Only Exist for Active Services
- GCP &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.13 - Ensure API Keys Are Restricted To Use by Only Specified Hosts and Apps
- GCP &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.14 - Ensure API Keys Are Restricted to Only APIs That Application Needs Access
- GCP &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.15 - Ensure API Keys Are Rotated Every 90 Days
- GCP &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.16 - Ensure Essential Contacts is Configured for Organization
- GCP &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.17 - Ensure that Dataproc Cluster is encrypted using Customer-Managed Encryption Key
- GCP &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.18 - Ensure Secrets are Not Stored in Cloud Functions Environment Variables by Using Secret Manager
- GCP &gt; CIS v3.0 &gt; 2 - Logging and Monitoring
- GCP &gt; CIS v3.0 &gt; 2 - Logging and Monitoring &gt; 2.01 - Ensure That Cloud Audit Logging Is Configured Properly
- GCP &gt; CIS v3.0 &gt; 2 - Logging and Monitoring &gt; 2.02 - Ensure That Sinks Are Configured for All Log Entries
- GCP &gt; CIS v3.0 &gt; 2 - Logging and Monitoring &gt; 2.03 - Ensure That Retention Policies on Cloud Storage Buckets Used for Exporting Logs Are Configured Using Bucket Lock
- GCP &gt; CIS v3.0 &gt; 2 - Logging and Monitoring &gt; 2.04 - Ensure Log Metric Filter and Alerts Exist for Project Ownership Assignments/Changes
- GCP &gt; CIS v3.0 &gt; 2 - Logging and Monitoring &gt; 2.05 - Ensure That the Log Metric Filter and Alerts Exist for Audit Configuration Changes
- GCP &gt; CIS v3.0 &gt; 2 - Logging and Monitoring &gt; 2.06 - Ensure That the Log Metric Filter and Alerts Exist for Custom Role Changes
- GCP &gt; CIS v3.0 &gt; 2 - Logging and Monitoring &gt; 2.07 - Ensure That the Log Metric Filter and Alerts Exist for VPC Network Firewall Rule Changes
- GCP &gt; CIS v3.0 &gt; 2 - Logging and Monitoring &gt; 2.08 - Ensure That the Log Metric Filter and Alerts Exist for VPC Network Route Changes
- GCP &gt; CIS v3.0 &gt; 2 - Logging and Monitoring &gt; 2.09 - Ensure That the Log Metric Filter and Alerts Exist for VPC Network Changes
- GCP &gt; CIS v3.0 &gt; 2 - Logging and Monitoring &gt; 2.10 - Ensure That the Log Metric Filter and Alerts Exist for Cloud Storage IAM Permission Changes
- GCP &gt; CIS v3.0 &gt; 2 - Logging and Monitoring &gt; 2.11 - Ensure That the Log Metric Filter and Alerts Exist for SQL Instance Configuration Changes
- GCP &gt; CIS v3.0 &gt; 2 - Logging and Monitoring &gt; 2.12 - Ensure That Cloud DNS Logging Is Enabled for All VPC Networks
- GCP &gt; CIS v3.0 &gt; 2 - Logging and Monitoring &gt; 2.13 - Ensure Cloud Asset Inventory Is Enabled
- GCP &gt; CIS v3.0 &gt; 2 - Logging and Monitoring &gt; 2.14 - Ensure &apos;Access Transparency&apos; is &apos;Enabled&apos;
- GCP &gt; CIS v3.0 &gt; 2 - Logging and Monitoring &gt; 2.15 - Ensure &apos;Access Approval&apos; is &apos;Enabled&apos;
- GCP &gt; CIS v3.0 &gt; 2 - Logging and Monitoring &gt; 2.16 - Ensure Logging is enabled for HTTP(S) Load Balancer
- GCP &gt; CIS v3.0 &gt; 3 - Networking
- GCP &gt; CIS v3.0 &gt; 3 - Networking &gt; 3.01 - Ensure That the Default Network Does Not Exist in a Project
- GCP &gt; CIS v3.0 &gt; 3 - Networking &gt; 3.02 - Ensure Legacy Networks Do Not Exist for Older Projects
- GCP &gt; CIS v3.0 &gt; 3 - Networking &gt; 3.03 - Ensure That DNSSEC Is Enabled for Cloud DNS
- GCP &gt; CIS v3.0 &gt; 3 - Networking &gt; 3.04 - Ensure That RSASHA1 Is Not Used for the Key-Signing Key in Cloud DNS DNSSEC
- GCP &gt; CIS v3.0 &gt; 3 - Networking &gt; 3.05 - Ensure That RSASHA1 Is Not Used for the Zone-Signing Key in Cloud DNS DNSSEC
- GCP &gt; CIS v3.0 &gt; 3 - Networking &gt; 3.06 - Ensure That SSH Access Is Restricted From the Internet
- GCP &gt; CIS v3.0 &gt; 3 - Networking &gt; 3.07 - Ensure That RDP Access Is Restricted From the Internet
- GCP &gt; CIS v3.0 &gt; 3 - Networking &gt; 3.08 - Ensure that VPC Flow Logs is Enabled for Every Subnet in a VPC Network
- GCP &gt; CIS v3.0 &gt; 3 - Networking &gt; 3.09 - Ensure No HTTPS or SSL Proxy Load Balancers Permit SSL Policies With Weak Cipher Suites
- GCP &gt; CIS v3.0 &gt; 3 - Networking &gt; 3.10 - Use Identity Aware Proxy (IAP) to Ensure Only Traffic From Google IP Addresses are &apos;Allowed&apos;
- GCP &gt; CIS v3.0 &gt; 4 - Virtual Machines
- GCP &gt; CIS v3.0 &gt; 4 - Virtual Machines &gt; 4.01 - Ensure That Instances Are Not Configured To Use the Default Service Account
- GCP &gt; CIS v3.0 &gt; 4 - Virtual Machines &gt; 4.02 - Ensure That Instances Are Not Configured To Use the Default Service Account With Full Access to All Cloud APIs
- GCP &gt; CIS v3.0 &gt; 4 - Virtual Machines &gt; 4.03 - Ensure &quot;Block Project-Wide SSH Keys&quot; Is Enabled for VM Instances
- GCP &gt; CIS v3.0 &gt; 4 - Virtual Machines &gt; 4.04 - Ensure Oslogin Is Enabled for a Project
- GCP &gt; CIS v3.0 &gt; 4 - Virtual Machines &gt; 4.05 - Ensure &apos;Enable Connecting to Serial Ports&apos; Is Not Enabled for VM Instance
- GCP &gt; CIS v3.0 &gt; 4 - Virtual Machines &gt; 4.06 - Ensure That IP Forwarding Is Not Enabled on Instances
- GCP &gt; CIS v3.0 &gt; 4 - Virtual Machines &gt; 4.07 - Ensure VM Disks for Critical VMs Are Encrypted With Customer-Supplied Encryption Keys (CSEK)
- GCP &gt; CIS v3.0 &gt; 4 - Virtual Machines &gt; 4.08 - Ensure Compute Instances Are Launched With Shielded VM Enabled
- GCP &gt; CIS v3.0 &gt; 4 - Virtual Machines &gt; 4.09 - Ensure That Compute Instances Do Not Have Public IP Addresses
- GCP &gt; CIS v3.0 &gt; 4 - Virtual Machines &gt; 4.10 - Ensure That App Engine Applications Enforce HTTPS Connections
- GCP &gt; CIS v3.0 &gt; 4 - Virtual Machines &gt; 4.11 - Ensure That Compute Instances Have Confidential Computing Enabled
- GCP &gt; CIS v3.0 &gt; 4 - Virtual Machines &gt; 4.12 - Ensure the Latest Operating System Updates Are Installed On Your Virtual Machines in All Projects
- GCP &gt; CIS v3.0 &gt; 5 - Storage
- GCP &gt; CIS v3.0 &gt; 5 - Storage &gt; 5.01 - Ensure That Cloud Storage Bucket Is Not Anonymously or Publicly Accessible
- GCP &gt; CIS v3.0 &gt; 5 - Storage &gt; 5.02 - Ensure That Cloud Storage Buckets Have Uniform Bucket-Level Access Enabled
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services &gt; 6.01 - MySQL Database
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services &gt; 6.01 - MySQL Database &gt; 6.01.01 - Ensure That a MySQL Database Instance Does Not Allow Anyone To Connect With Administrative Privileges
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services &gt; 6.01 - MySQL Database &gt; 6.01.02 - Ensure &apos;Skip_show_database&apos; Database Flag for Cloud SQL MySQL Instance Is Set to &apos;On&apos;
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services &gt; 6.01 - MySQL Database &gt; 6.01.03 - Ensure That the &apos;Local_infile&apos; Database Flag for a Cloud SQL MySQL Instance Is Set to &apos;Off&apos;
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database &gt; 6.02.01 - Ensure &apos;Log_error_verbosity&apos; Database Flag for Cloud SQL PostgreSQL Instance Is Set to &apos;DEFAULT&apos; or Stricter
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database &gt; 6.02.02 - Ensure &apos;Log_connections&apos; Database Flag for Cloud SQL PostgreSQL Instance Is Set to &apos;On&apos;
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database &gt; 6.02.03 - Ensure &apos;Log_disconnections&apos; Database Flag for Cloud SQL PostgreSQL Instance Is Set to &apos;On&apos;
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database &gt; 6.02.04 - Ensure &apos;Log_statement&apos; Database Flag for Cloud SQL PostgreSQL Instance Is Set Appropriately
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database &gt; 6.02.05 - Ensure &apos;Log_min_messages&apos; Database Flag for Cloud SQL PostgreSQL Instance is set at minimum to &apos;Warning&apos;
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database &gt; 6.02.06 - Ensure &apos;Log_min_error_statement&apos; Database Flag for Cloud SQL PostgreSQL Instance Is Set to &apos;Error&apos; or Stricter
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database &gt; 6.02.07 - Ensure That the &apos;Log_min_duration_statement&apos; Database Flag for Cloud SQL PostgreSQL Instance Is Set to &apos;-1&apos;
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database &gt; 6.02.08 - Ensure That &apos;cloudsql.enable_pgaudit&apos; Database Flag for each Cloud Sql Postgresql Instance Is Set to &apos;on&apos; For Centralized Logging
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services &gt; 6.03 - SQL Server
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services &gt; 6.03 - SQL Server &gt; 6.03.01 - Ensure &apos;external scripts enabled&apos; database flag for Cloud SQL SQL Server instance is set to &apos;off&apos;
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services &gt; 6.03 - SQL Server &gt; 6.03.02 - Ensure that the &apos;cross db ownership chaining&apos; database flag for Cloud SQL SQL Server instance is set to &apos;off&apos;
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services &gt; 6.03 - SQL Server &gt; 6.03.03 - Ensure &apos;user Connections&apos; Database Flag for Cloud Sql Sql Server Instance Is Set to a Non-limiting Value
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services &gt; 6.03 - SQL Server &gt; 6.03.04 - Ensure &apos;user options&apos; database flag for Cloud SQL SQL Server instance is not configured
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services &gt; 6.03 - SQL Server &gt; 6.03.05 - Ensure &apos;remote access&apos; database flag for Cloud SQL SQL Server instance is set to &apos;off&apos;
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services &gt; 6.03 - SQL Server &gt; 6.03.06 - Ensure &apos;3625 (trace flag)&apos; database flag for all Cloud SQL Server instances is set to &apos;on&apos;
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services &gt; 6.03 - SQL Server &gt; 6.03.07 - Ensure that the &apos;contained database authentication&apos; database flag for Cloud SQL on the SQL Server instance is set to &apos;off&apos;
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services &gt; 6.04 - Ensure That the Cloud SQL Database Instance Requires All Incoming Connections To Use SSL
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services &gt; 6.05 - Ensure That Cloud SQL Database Instances Do Not Implicitly Whitelist All Public IP Addresses
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services &gt; 6.06 - Ensure That Cloud SQL Database Instances Do Not Have Public IPs
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services &gt; 6.07 - Ensure That Cloud SQL Database Instances Are Configured With Automated Backups
- GCP &gt; CIS v3.0 &gt; 7 - BigQuery
- GCP &gt; CIS v3.0 &gt; 7 - BigQuery &gt; 7.01 - Ensure That BigQuery Datasets Are Not Anonymously or Publicly Accessible
- GCP &gt; CIS v3.0 &gt; 7 - BigQuery &gt; 7.02 - Ensure That All BigQuery Tables Are Encrypted With Customer-Managed Encryption Key (CMEK)
- GCP &gt; CIS v3.0 &gt; 7 - BigQuery &gt; 7.03 - Ensure That a Default Customer-Managed Encryption Key (CMEK) Is Specified for All BigQuery Data Sets
- GCP &gt; CIS v3.0 &gt; 7 - BigQuery &gt; 7.04 - Ensure all data in BigQuery has been classified
- GCP &gt; CIS v3.0 &gt; 8 - Dataproc
- GCP &gt; CIS v3.0 &gt; 8 - Dataproc &gt; 8.1 - Ensure that Dataproc Cluster is encrypted using Customer-Managed Encryption Key

_Policy Types_

- GCP &gt; CIS v3.0
- GCP &gt; CIS v3.0 &gt; 1 - Identity and Access Management
- GCP &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.01 - Ensure that Corporate Login Credentials are Used
- GCP &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.01 - Ensure that Corporate Login Credentials are Used &gt; Attestation
- GCP &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.02 - Ensure that Multi-Factor Authentication is &apos;Enabled&apos; for All Non-Service Accounts
- GCP &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.02 - Ensure that Multi-Factor Authentication is &apos;Enabled&apos; for All Non-Service Accounts &gt; Attestation
- GCP &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.03 - Ensure that Security Key Enforcement is Enabled for All Admin Accounts
- GCP &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.03 - Ensure that Security Key Enforcement is Enabled for All Admin Accounts &gt; Attestation
- GCP &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.04 - Ensure That There Are Only GCP-Managed Service Account Keys for Each Service Account
- GCP &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.05 - Ensure That Service Account Has No Admin Privileges
- GCP &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.06 - Ensure That IAM Users Are Not Assigned the Service Account User or Service Account Token Creator Roles at Project Level
- GCP &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.07 - Ensure User-Managed/External Keys for Service Accounts Are Rotated Every 90 Days or Fewer
- GCP &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.08 - Ensure That Separation of Duties Is Enforced While Assigning Service Account Related Roles to Users
- GCP &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.09 - Ensure That Cloud KMS Cryptokeys Are Not Anonymously or Publicly Accessible
- GCP &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.10 - Ensure KMS Encryption Keys Are Rotated Within a Period of 90 Days
- GCP &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.11 - Ensure That Separation of Duties Is Enforced While Assigning KMS Related Roles to Users
- GCP &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.12 - Ensure API Keys Only Exist for Active Services
- GCP &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.13 - Ensure API Keys Are Restricted To Use by Only Specified Hosts and Apps
- GCP &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.14 - Ensure API Keys Are Restricted to Only APIs That Application Needs Access
- GCP &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.15 - Ensure API Keys Are Rotated Every 90 Days
- GCP &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.16 - Ensure Essential Contacts is Configured for Organization
- GCP &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.16 - Ensure Essential Contacts is Configured for Organization &gt; Attestation
- GCP &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.17 - Ensure that Dataproc Cluster is encrypted using Customer-Managed Encryption Key
- GCP &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.18 - Ensure Secrets are Not Stored in Cloud Functions Environment Variables by Using Secret Manager
- GCP &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.18 - Ensure Secrets are Not Stored in Cloud Functions Environment Variables by Using Secret Manager &gt; Attestation
- GCP &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; Maximum Attestation Duration
- GCP &gt; CIS v3.0 &gt; 2 - Logging and Monitoring
- GCP &gt; CIS v3.0 &gt; 2 - Logging and Monitoring &gt; 2.01 - Ensure That Cloud Audit Logging Is Configured Properly
- GCP &gt; CIS v3.0 &gt; 2 - Logging and Monitoring &gt; 2.02 - Ensure That Sinks Are Configured for All Log Entries
- GCP &gt; CIS v3.0 &gt; 2 - Logging and Monitoring &gt; 2.03 - Ensure That Retention Policies on Cloud Storage Buckets Used for Exporting Logs Are Configured Using Bucket Lock
- GCP &gt; CIS v3.0 &gt; 2 - Logging and Monitoring &gt; 2.04 - Ensure Log Metric Filter and Alerts Exist for Project Ownership Assignments/Changes
- GCP &gt; CIS v3.0 &gt; 2 - Logging and Monitoring &gt; 2.05 - Ensure That the Log Metric Filter and Alerts Exist for Audit Configuration Changes
- GCP &gt; CIS v3.0 &gt; 2 - Logging and Monitoring &gt; 2.06 - Ensure That the Log Metric Filter and Alerts Exist for Custom Role Changes
- GCP &gt; CIS v3.0 &gt; 2 - Logging and Monitoring &gt; 2.07 - Ensure That the Log Metric Filter and Alerts Exist for VPC Network Firewall Rule Changes
- GCP &gt; CIS v3.0 &gt; 2 - Logging and Monitoring &gt; 2.08 - Ensure That the Log Metric Filter and Alerts Exist for VPC Network Route Changes
- GCP &gt; CIS v3.0 &gt; 2 - Logging and Monitoring &gt; 2.09 - Ensure That the Log Metric Filter and Alerts Exist for VPC Network Changes
- GCP &gt; CIS v3.0 &gt; 2 - Logging and Monitoring &gt; 2.10 - Ensure That the Log Metric Filter and Alerts Exist for Cloud Storage IAM Permission Changes
- GCP &gt; CIS v3.0 &gt; 2 - Logging and Monitoring &gt; 2.11 - Ensure That the Log Metric Filter and Alerts Exist for SQL Instance Configuration Changes
- GCP &gt; CIS v3.0 &gt; 2 - Logging and Monitoring &gt; 2.12 - Ensure That Cloud DNS Logging Is Enabled for All VPC Networks
- GCP &gt; CIS v3.0 &gt; 2 - Logging and Monitoring &gt; 2.13 - Ensure Cloud Asset Inventory Is Enabled
- GCP &gt; CIS v3.0 &gt; 2 - Logging and Monitoring &gt; 2.14 - Ensure &apos;Access Transparency&apos; is &apos;Enabled&apos;
- GCP &gt; CIS v3.0 &gt; 2 - Logging and Monitoring &gt; 2.14 - Ensure &apos;Access Transparency&apos; is &apos;Enabled&apos; &gt; Attestation
- GCP &gt; CIS v3.0 &gt; 2 - Logging and Monitoring &gt; 2.15 - Ensure &apos;Access Approval&apos; is &apos;Enabled&apos;
- GCP &gt; CIS v3.0 &gt; 2 - Logging and Monitoring &gt; 2.16 - Ensure Logging is enabled for HTTP(S) Load Balancer
- GCP &gt; CIS v3.0 &gt; 2 - Logging and Monitoring &gt; Maximum Attestation Duration
- GCP &gt; CIS v3.0 &gt; 3 - Networking
- GCP &gt; CIS v3.0 &gt; 3 - Networking &gt; 3.01 - Ensure That the Default Network Does Not Exist in a Project
- GCP &gt; CIS v3.0 &gt; 3 - Networking &gt; 3.02 - Ensure Legacy Networks Do Not Exist for Older Projects
- GCP &gt; CIS v3.0 &gt; 3 - Networking &gt; 3.03 - Ensure That DNSSEC Is Enabled for Cloud DNS
- GCP &gt; CIS v3.0 &gt; 3 - Networking &gt; 3.04 - Ensure That RSASHA1 Is Not Used for the Key-Signing Key in Cloud DNS DNSSEC
- GCP &gt; CIS v3.0 &gt; 3 - Networking &gt; 3.05 - Ensure That RSASHA1 Is Not Used for the Zone-Signing Key in Cloud DNS DNSSEC
- GCP &gt; CIS v3.0 &gt; 3 - Networking &gt; 3.06 - Ensure That SSH Access Is Restricted From the Internet
- GCP &gt; CIS v3.0 &gt; 3 - Networking &gt; 3.07 - Ensure That RDP Access Is Restricted From the Internet
- GCP &gt; CIS v3.0 &gt; 3 - Networking &gt; 3.08 - Ensure that VPC Flow Logs is Enabled for Every Subnet in a VPC Network
- GCP &gt; CIS v3.0 &gt; 3 - Networking &gt; 3.09 - Ensure No HTTPS or SSL Proxy Load Balancers Permit SSL Policies With Weak Cipher Suites
- GCP &gt; CIS v3.0 &gt; 3 - Networking &gt; 3.10 - Use Identity Aware Proxy (IAP) to Ensure Only Traffic From Google IP Addresses are &apos;Allowed&apos;
- GCP &gt; CIS v3.0 &gt; 3 - Networking &gt; Maximum Attestation Duration
- GCP &gt; CIS v3.0 &gt; 4 - Virtual Machines
- GCP &gt; CIS v3.0 &gt; 4 - Virtual Machines &gt; 4.01 - Ensure That Instances Are Not Configured To Use the Default Service Account
- GCP &gt; CIS v3.0 &gt; 4 - Virtual Machines &gt; 4.02 - Ensure That Instances Are Not Configured To Use the Default Service Account With Full Access to All Cloud APIs
- GCP &gt; CIS v3.0 &gt; 4 - Virtual Machines &gt; 4.03 - Ensure &quot;Block Project-Wide SSH Keys&quot; Is Enabled for VM Instances
- GCP &gt; CIS v3.0 &gt; 4 - Virtual Machines &gt; 4.04 - Ensure Oslogin Is Enabled for a Project
- GCP &gt; CIS v3.0 &gt; 4 - Virtual Machines &gt; 4.05 - Ensure &apos;Enable Connecting to Serial Ports&apos; Is Not Enabled for VM Instance
- GCP &gt; CIS v3.0 &gt; 4 - Virtual Machines &gt; 4.06 - Ensure That IP Forwarding Is Not Enabled on Instances
- GCP &gt; CIS v3.0 &gt; 4 - Virtual Machines &gt; 4.07 - Ensure VM Disks for Critical VMs Are Encrypted With Customer-Supplied Encryption Keys
- GCP &gt; CIS v3.0 &gt; 4 - Virtual Machines &gt; 4.08 - Ensure Compute Instances Are Launched With Shielded VM Enabled
- GCP &gt; CIS v3.0 &gt; 4 - Virtual Machines &gt; 4.09 - Ensure That Compute Instances Do Not Have Public IP Addresses
- GCP &gt; CIS v3.0 &gt; 4 - Virtual Machines &gt; 4.10 - Ensure That App Engine Applications Enforce HTTPS Connections
- GCP &gt; CIS v3.0 &gt; 4 - Virtual Machines &gt; 4.10 - Ensure That App Engine Applications Enforce HTTPS Connections &gt; Attestation
- GCP &gt; CIS v3.0 &gt; 4 - Virtual Machines &gt; 4.11 - Ensure That Compute Instances Have Confidential Computing Enabled
- GCP &gt; CIS v3.0 &gt; 4 - Virtual Machines &gt; 4.12 - Ensure the Latest Operating System Updates Are Installed On Your Virtual Machines in All Projects
- GCP &gt; CIS v3.0 &gt; 4 - Virtual Machines &gt; 4.12 - Ensure the Latest Operating System Updates Are Installed On Your Virtual Machines in All Projects &gt; Attestation
- GCP &gt; CIS v3.0 &gt; 4 - Virtual Machines &gt; Maximum Attestation Duration
- GCP &gt; CIS v3.0 &gt; 5 - Storage
- GCP &gt; CIS v3.0 &gt; 5 - Storage &gt; 5.01 - Ensure That Cloud Storage Bucket Is Not Anonymously or Publicly Accessible
- GCP &gt; CIS v3.0 &gt; 5 - Storage &gt; 5.02 - Ensure That Cloud Storage Buckets Have Uniform Bucket-Level Access Enabled
- GCP &gt; CIS v3.0 &gt; 5 - Storage &gt; Maximum Attestation Duration
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services &gt; 6.01 - MySQL Database
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services &gt; 6.01 - MySQL Database &gt; 6.01.01 - Ensure That a MySQL Database Instance Does Not Allow Anyone To Connect With Administrative Privileges
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services &gt; 6.01 - MySQL Database &gt; 6.01.01 - Ensure That a MySQL Database Instance Does Not Allow Anyone To Connect With Administrative Privileges &gt; Attestation
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services &gt; 6.01 - MySQL Database &gt; 6.01.02 - Ensure &apos;Skip_show_database&apos; Database Flag for Cloud SQL MySQL Instance Is Set to &apos;On&apos;
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services &gt; 6.01 - MySQL Database &gt; 6.01.03 - Ensure That the &apos;Local_infile&apos; Database Flag for a Cloud SQL MySQL Instance Is Set to &apos;Off&apos;
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database &gt; 6.02.01 - Ensure &apos;Log_error_verbosity&apos; Database Flag for Cloud SQL PostgreSQL Instance Is Set to &apos;DEFAULT&apos; or Stricter
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database &gt; 6.02.02 - Ensure That the &apos;Log_connections&apos; Database Flag for Cloud SQL PostgreSQL Instance Is Set to &apos;On&apos;
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database &gt; 6.02.03 - Ensure That the &apos;Log_disconnections&apos; Database Flag for Cloud SQL PostgreSQL Instance Is Set to &apos;On&apos;
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database &gt; 6.02.04 - Ensure &apos;Log_statement&apos; Database Flag for Cloud SQL PostgreSQL Instance Is Set Appropriately
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database &gt; 6.02.05 - Ensure that the &apos;Log_min_Messages&apos; Flag for a Cloud SQL PostgreSQL Instance is set at minimum to &apos;Warning&apos;
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database &gt; 6.02.06 - Ensure &apos;Log_min_error_statement&apos; Database Flag for Cloud SQL PostgreSQL Instance Is Set to &apos;Error&apos; or Stricter
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database &gt; 6.02.07 - Ensure That the &apos;Log_min_duration_statement&apos; Database Flag for Cloud SQL PostgreSQL Instance Is Set to &apos;-1&apos;
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database &gt; 6.02.08 - Ensure That &apos;cloudsql.enable_pgaudit&apos; Database Flag for each Cloud Sql Postgresql Instance Is Set to &apos;on&apos; For Centralized Logging
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services &gt; 6.03 - SQL Server
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services &gt; 6.03 - SQL Server &gt; 6.03.01 - Ensure &apos;external scripts enabled&apos; database flag for Cloud SQL SQL Server instance is set to &apos;off&apos;
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services &gt; 6.03 - SQL Server &gt; 6.03.02 - Ensure that the &apos;cross db ownership chaining&apos; database flag for Cloud SQL SQL Server instance is set to &apos;off&apos;
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services &gt; 6.03 - SQL Server &gt; 6.03.03 - Ensure &apos;user Connections&apos; Database Flag for Cloud Sql Sql Server Instance Is Set to a Non-limiting Value
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services &gt; 6.03 - SQL Server &gt; 6.03.04 - Ensure &apos;user options&apos; database flag for Cloud SQL SQL Server instance is not configured
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services &gt; 6.03 - SQL Server &gt; 6.03.05 - Ensure &apos;remote access&apos; database flag for Cloud SQL SQL Server instance is set to &apos;off&apos;
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services &gt; 6.03 - SQL Server &gt; 6.03.06 - Ensure &apos;3625 (trace flag)&apos; database flag for all Cloud SQL Server instances is set to &apos;on&apos;
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services &gt; 6.03 - SQL Server &gt; 6.03.07 - Ensure that the &apos;contained database authentication&apos; database flag for Cloud SQL on the SQL Server instance is set to &apos;off&apos;
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services &gt; 6.04 - Ensure That the Cloud SQL Database Instance Requires All Incoming Connections To Use SSL
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services &gt; 6.05 - Ensure That Cloud SQL Database Instances Do Not Implicitly Whitelist All Public IP Addresses
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services &gt; 6.06 - Ensure That Cloud SQL Database Instances Do Not Have Public IPs
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services &gt; 6.07 - Ensure That Cloud SQL Database Instances Are Configured With Automated Backups
- GCP &gt; CIS v3.0 &gt; 6 - Cloud SQL Database Services &gt; Maximum Attestation Duration
- GCP &gt; CIS v3.0 &gt; 7 - BigQuery
- GCP &gt; CIS v3.0 &gt; 7 - BigQuery &gt; 7.01 - Ensure That BigQuery Datasets Are Not Anonymously or Publicly Accessible
- GCP &gt; CIS v3.0 &gt; 7 - BigQuery &gt; 7.02 - Ensure That All BigQuery Tables Are Encrypted With Customer-Managed Encryption Key (CMEK)
- GCP &gt; CIS v3.0 &gt; 7 - BigQuery &gt; 7.03 - Ensure That a Default Customer-Managed Encryption Key (CMEK) Is Specified for All BigQuery Data Sets
- GCP &gt; CIS v3.0 &gt; 7 - BigQuery &gt; 7.04 - Ensure all data in BigQuery has been classified
- GCP &gt; CIS v3.0 &gt; 7 - BigQuery &gt; 7.04 - Ensure all data in BigQuery has been classified &gt; Attestation
- GCP &gt; CIS v3.0 &gt; 7 - BigQuery &gt; Maximum Attestation Duration
- GCP &gt; CIS v3.0 &gt; 8 - Dataproc
- GCP &gt; CIS v3.0 &gt; 8 - Dataproc &gt; 8.1 - Ensure that Dataproc Cluster is encrypted using Customer-Managed Encryption Key
- GCP &gt; CIS v3.0 &gt; 8 - Dataproc &gt; Maximum Attestation Duration
- GCP &gt; CIS v3.0 &gt; Maximum Attestation Duration</description>
            <pubDate>Wed, 28 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-logs-v5-17-1</guid>
            <title>aws-logs v5.17.1 - The metric filter discovery control will no longer end up in the DLQ</title>
            <link>https://turbot.com/guardrails/changelog/aws-logs-v5-17-1</link>
            <description>_Bug fixes_

- The `AWS &gt; Logs &gt; Metric Filter &gt; Discovery` control was ending up in the DLQ for some metric filters. This has now been fixed, and the control works as expected.</description>
            <pubDate>Wed, 28 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ec2-v5-50-2</guid>
            <title>aws-ec2 v5.50.2 - The CMDB control for AMIs will no longer fail due to missing `GetImageAncestry` API support</title>
            <link>https://turbot.com/guardrails/changelog/aws-ec2-v5-50-2</link>
            <description>_Bug fixes_

- Fixed the `AWS &gt; EC2 &gt; AMI &gt; CMDB` control that was failing due to missing support for the `GetImageAncestry` API in the AWS SDK. This is now fixed.</description>
            <pubDate>Tue, 27 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-cisv5-0-v5-0-0</guid>
            <title>aws-cisv5-0 v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/aws-cisv5-0-v5-0-0</link>
            <description>_Control Types_

- AWS &gt; CIS v5.0
- AWS &gt; CIS v5.0 &gt; 1 - Identity and Access Management
- AWS &gt; CIS v5.0 &gt; 1 - Identity and Access Management &gt; 1.01 - Maintain current contact details
- AWS &gt; CIS v5.0 &gt; 1 - Identity and Access Management &gt; 1.02 - Ensure security contact information is registered
- AWS &gt; CIS v5.0 &gt; 1 - Identity and Access Management &gt; 1.03 - Ensure no &apos;root&apos; user account access key exists
- AWS &gt; CIS v5.0 &gt; 1 - Identity and Access Management &gt; 1.04 - Ensure MFA is enabled for the &apos;root&apos; user account
- AWS &gt; CIS v5.0 &gt; 1 - Identity and Access Management &gt; 1.05 - Ensure hardware MFA is enabled for the &apos;root&apos; user account
- AWS &gt; CIS v5.0 &gt; 1 - Identity and Access Management &gt; 1.06 - Eliminate use of the &apos;root&apos; user for administrative and daily tasks
- AWS &gt; CIS v5.0 &gt; 1 - Identity and Access Management &gt; 1.07 - Ensure IAM password policy requires minimum length of 14 or greater
- AWS &gt; CIS v5.0 &gt; 1 - Identity and Access Management &gt; 1.08 - Ensure IAM password policy prevents password reuse
- AWS &gt; CIS v5.0 &gt; 1 - Identity and Access Management &gt; 1.09 - Ensure multi-factor authentication (MFA) is enabled for all IAM users that have a console password
- AWS &gt; CIS v5.0 &gt; 1 - Identity and Access Management &gt; 1.10 - Do not create access keys during initial setup for IAM users with a console password
- AWS &gt; CIS v5.0 &gt; 1 - Identity and Access Management &gt; 1.11 - Ensure credentials unused for 45 days or more are disabled
- AWS &gt; CIS v5.0 &gt; 1 - Identity and Access Management &gt; 1.12 - Ensure there is only one active access key for any single IAM user
- AWS &gt; CIS v5.0 &gt; 1 - Identity and Access Management &gt; 1.13 - Ensure access keys are rotated every 90 days or less
- AWS &gt; CIS v5.0 &gt; 1 - Identity and Access Management &gt; 1.14 - Ensure IAM Users Receive Permissions Only Through Groups
- AWS &gt; CIS v5.0 &gt; 1 - Identity and Access Management &gt; 1.15 - Ensure IAM policies that allow full &quot;_:_&quot; administrative privileges are not attached
- AWS &gt; CIS v5.0 &gt; 1 - Identity and Access Management &gt; 1.16 - Ensure a support role has been created to manage incidents with AWS Support
- AWS &gt; CIS v5.0 &gt; 1 - Identity and Access Management &gt; 1.17 - Ensure IAM instance roles are used for AWS resource access from instances
- AWS &gt; CIS v5.0 &gt; 1 - Identity and Access Management &gt; 1.18 - Ensure that all expired SSL/TLS certificates stored in AWS IAM are removed
- AWS &gt; CIS v5.0 &gt; 1 - Identity and Access Management &gt; 1.19 - Ensure that IAM External Access Analyzer is enabled for all regions
- AWS &gt; CIS v5.0 &gt; 1 - Identity and Access Management &gt; 1.20 - Ensure IAM users are managed centrally via identity federation or AWS Organizations for multi-account environments
- AWS &gt; CIS v5.0 &gt; 1 - Identity and Access Management &gt; 1.21 - Ensure access to AWSCloudShellFullAccess is restricted
- AWS &gt; CIS v5.0 &gt; 2 - Storage
- AWS &gt; CIS v5.0 &gt; 2 - Storage &gt; 2.01 - Simple Storage Service (S3)
- AWS &gt; CIS v5.0 &gt; 2 - Storage &gt; 2.01 - Simple Storage Service (S3) &gt; 2.01.01 - Ensure S3 Bucket Policy is set to deny HTTP requests
- AWS &gt; CIS v5.0 &gt; 2 - Storage &gt; 2.01 - Simple Storage Service (S3) &gt; 2.01.02 - Ensure MFA Delete is enabled on S3 buckets
- AWS &gt; CIS v5.0 &gt; 2 - Storage &gt; 2.01 - Simple Storage Service (S3) &gt; 2.01.03 - Ensure all data in Amazon S3 has been discovered, classified, and secured when necessary
- AWS &gt; CIS v5.0 &gt; 2 - Storage &gt; 2.01 - Simple Storage Service (S3) &gt; 2.01.04 - Ensure that S3 is configured with &apos;Block Public Access&apos; enabled
- AWS &gt; CIS v5.0 &gt; 2 - Storage &gt; 2.02 - Relational Database Service (RDS)
- AWS &gt; CIS v5.0 &gt; 2 - Storage &gt; 2.02 - Relational Database Service (RDS) &gt; 2.02.01 - Ensure that encryption-at-rest is enabled for RDS Instances
- AWS &gt; CIS v5.0 &gt; 2 - Storage &gt; 2.02 - Relational Database Service (RDS) &gt; 2.02.02 - Ensure the Auto Minor Version Upgrade feature is enabled for RDS instances
- AWS &gt; CIS v5.0 &gt; 2 - Storage &gt; 2.02 - Relational Database Service (RDS) &gt; 2.02.03 - Ensure that RDS instances are not publicly accessible
- AWS &gt; CIS v5.0 &gt; 2 - Storage &gt; 2.02 - Relational Database Service (RDS) &gt; 2.02.04 - Ensure Multi-AZ deployments are used for enhanced availability in Amazon RDS
- AWS &gt; CIS v5.0 &gt; 2 - Storage &gt; 2.03 - Elastic File System (EFS)
- AWS &gt; CIS v5.0 &gt; 2 - Storage &gt; 2.03 - Elastic File System (EFS) &gt; 2.03.01 - Ensure that encryption is enabled for EFS file systems
- AWS &gt; CIS v5.0 &gt; 3 - Logging
- AWS &gt; CIS v5.0 &gt; 3 - Logging &gt; 3.01 - Ensure CloudTrail is enabled in all regions
- AWS &gt; CIS v5.0 &gt; 3 - Logging &gt; 3.02 - Ensure CloudTrail log file validation is enabled
- AWS &gt; CIS v5.0 &gt; 3 - Logging &gt; 3.03 - Ensure AWS Config is enabled in all regions
- AWS &gt; CIS v5.0 &gt; 3 - Logging &gt; 3.04 - Ensure that server access logging is enabled on the CloudTrail S3 bucket
- AWS &gt; CIS v5.0 &gt; 3 - Logging &gt; 3.05 - Ensure CloudTrail logs are encrypted at rest using KMS CMKs
- AWS &gt; CIS v5.0 &gt; 3 - Logging &gt; 3.06 - Ensure rotation for customer-created symmetric CMKs is enabled
- AWS &gt; CIS v5.0 &gt; 3 - Logging &gt; 3.07 - Ensure that VPC flow logging is enabled in all VPCs
- AWS &gt; CIS v5.0 &gt; 3 - Logging &gt; 3.08 - Ensure that object-level logging for write events is enabled for S3 buckets
- AWS &gt; CIS v5.0 &gt; 3 - Logging &gt; 3.09 - Ensure that object-level logging for read events is enabled for S3 buckets
- AWS &gt; CIS v5.0 &gt; 4 - Monitoring
- AWS &gt; CIS v5.0 &gt; 4 - Monitoring &gt; 4.01 - Ensure unauthorized API calls are monitored
- AWS &gt; CIS v5.0 &gt; 4 - Monitoring &gt; 4.02 - Ensure management console sign-in without MFA is monitored
- AWS &gt; CIS v5.0 &gt; 4 - Monitoring &gt; 4.03 - Ensure usage of the &apos;root&apos; account is monitored
- AWS &gt; CIS v5.0 &gt; 4 - Monitoring &gt; 4.04 - Ensure IAM policy changes are monitored
- AWS &gt; CIS v5.0 &gt; 4 - Monitoring &gt; 4.05 - Ensure CloudTrail configuration changes are monitored
- AWS &gt; CIS v5.0 &gt; 4 - Monitoring &gt; 4.06 - Ensure AWS Management Console authentication failures are monitored
- AWS &gt; CIS v5.0 &gt; 4 - Monitoring &gt; 4.07 - Ensure disabling or scheduled deletion of customer created CMKs is monitored
- AWS &gt; CIS v5.0 &gt; 4 - Monitoring &gt; 4.08 - Ensure S3 bucket policy changes are monitored
- AWS &gt; CIS v5.0 &gt; 4 - Monitoring &gt; 4.09 - Ensure AWS Config configuration changes are monitored
- AWS &gt; CIS v5.0 &gt; 4 - Monitoring &gt; 4.10 - Ensure security group changes are monitored
- AWS &gt; CIS v5.0 &gt; 4 - Monitoring &gt; 4.11 - Ensure Network Access Control List (NACL) changes are monitored
- AWS &gt; CIS v5.0 &gt; 4 - Monitoring &gt; 4.12 - Ensure changes to network gateways are monitored
- AWS &gt; CIS v5.0 &gt; 4 - Monitoring &gt; 4.13 - Ensure route table changes are monitored
- AWS &gt; CIS v5.0 &gt; 4 - Monitoring &gt; 4.14 - Ensure VPC changes are monitored
- AWS &gt; CIS v5.0 &gt; 4 - Monitoring &gt; 4.15 - Ensure AWS Organizations changes are monitored
- AWS &gt; CIS v5.0 &gt; 4 - Monitoring &gt; 4.16 - Ensure AWS Security Hub is enabled
- AWS &gt; CIS v5.0 &gt; 5 - Networking
- AWS &gt; CIS v5.0 &gt; 5 - Networking &gt; 5.01 - EC2
- AWS &gt; CIS v5.0 &gt; 5 - Networking &gt; 5.01 - EC2 &gt; 5.01.01 - Ensure EBS Volume Encryption is Enabled in all Regions
- AWS &gt; CIS v5.0 &gt; 5 - Networking &gt; 5.01 - EC2 &gt; 5.01.02 - Ensure CIFS access is restricted to trusted networks to prevent unauthorized access
- AWS &gt; CIS v5.0 &gt; 5 - Networking &gt; 5.02 - Ensure no Network ACLs allow ingress from 0.0.0.0/0 to remote server administration ports
- AWS &gt; CIS v5.0 &gt; 5 - Networking &gt; 5.03 - Ensure no security groups allow ingress from 0.0.0.0/0 to remote server administration ports
- AWS &gt; CIS v5.0 &gt; 5 - Networking &gt; 5.04 - Ensure no security groups allow ingress from ::/0 to remote server administration ports
- AWS &gt; CIS v5.0 &gt; 5 - Networking &gt; 5.05 - Ensure the default security group of every VPC restricts all traffic
- AWS &gt; CIS v5.0 &gt; 5 - Networking &gt; 5.06 - Ensure routing tables for VPC peering are &apos;least access&apos;
- AWS &gt; CIS v5.0 &gt; 5 - Networking &gt; 5.07 - Ensure that the EC2 Metadata Service only allows IMDSv2

_Policy Types_

- AWS &gt; CIS v5.0
- AWS &gt; CIS v5.0 &gt; 1 - Identity and Access Management
- AWS &gt; CIS v5.0 &gt; 1 - Identity and Access Management &gt; 1.01 - Maintain current contact details
- AWS &gt; CIS v5.0 &gt; 1 - Identity and Access Management &gt; 1.01 - Maintain current contact details &gt; Attestation
- AWS &gt; CIS v5.0 &gt; 1 - Identity and Access Management &gt; 1.02 - Ensure security contact information is registered
- AWS &gt; CIS v5.0 &gt; 1 - Identity and Access Management &gt; 1.03 - Ensure no &apos;root&apos; user account access key exists
- AWS &gt; CIS v5.0 &gt; 1 - Identity and Access Management &gt; 1.04 - Ensure MFA is enabled for the &apos;root&apos; user account
- AWS &gt; CIS v5.0 &gt; 1 - Identity and Access Management &gt; 1.05 - Ensure hardware MFA is enabled for the &apos;root&apos; user account
- AWS &gt; CIS v5.0 &gt; 1 - Identity and Access Management &gt; 1.06 - Eliminate use of the &apos;root&apos; user for administrative and daily tasks
- AWS &gt; CIS v5.0 &gt; 1 - Identity and Access Management &gt; 1.07 - Ensure IAM password policy requires minimum length of 14 or greater
- AWS &gt; CIS v5.0 &gt; 1 - Identity and Access Management &gt; 1.08 - Ensure IAM password policy prevents password reuse
- AWS &gt; CIS v5.0 &gt; 1 - Identity and Access Management &gt; 1.09 - Ensure multi-factor authentication (MFA) is enabled for all IAM users that have a console password
- AWS &gt; CIS v5.0 &gt; 1 - Identity and Access Management &gt; 1.10 - Do not create access keys during initial setup for IAM users with a console password
- AWS &gt; CIS v5.0 &gt; 1 - Identity and Access Management &gt; 1.11 - Ensure credentials unused for 45 days or more are disabled
- AWS &gt; CIS v5.0 &gt; 1 - Identity and Access Management &gt; 1.12 - Ensure there is only one active access key for any single IAM user
- AWS &gt; CIS v5.0 &gt; 1 - Identity and Access Management &gt; 1.13 - Ensure access keys are rotated every 90 days or less
- AWS &gt; CIS v5.0 &gt; 1 - Identity and Access Management &gt; 1.14 - Ensure IAM Users Receive Permissions Only Through Groups
- AWS &gt; CIS v5.0 &gt; 1 - Identity and Access Management &gt; 1.15 - Ensure IAM policies that allow full &quot;_:_&quot; administrative privileges are not attached
- AWS &gt; CIS v5.0 &gt; 1 - Identity and Access Management &gt; 1.16 - Ensure a support role has been created to manage incidents with AWS Support
- AWS &gt; CIS v5.0 &gt; 1 - Identity and Access Management &gt; 1.17 - Ensure IAM instance roles are used for AWS resource access from instances
- AWS &gt; CIS v5.0 &gt; 1 - Identity and Access Management &gt; 1.18 - Ensure that all expired SSL/TLS certificates stored in AWS IAM are removed
- AWS &gt; CIS v5.0 &gt; 1 - Identity and Access Management &gt; 1.19 - Ensure that IAM External Access Analyzer is enabled for all regions
- AWS &gt; CIS v5.0 &gt; 1 - Identity and Access Management &gt; 1.20 - Ensure IAM users are managed centrally via identity federation or AWS Organizations for multi-account environments
- AWS &gt; CIS v5.0 &gt; 1 - Identity and Access Management &gt; 1.20 - Ensure IAM users are managed centrally via identity federation or AWS Organizations for multi-account environments &gt; Attestation
- AWS &gt; CIS v5.0 &gt; 1 - Identity and Access Management &gt; 1.21 - Ensure access to AWSCloudShellFullAccess is restricted
- AWS &gt; CIS v5.0 &gt; 1 - Identity and Access Management &gt; 1.21 - Ensure access to AWSCloudShellFullAccess is restricted &gt; Attestation
- AWS &gt; CIS v5.0 &gt; 1 - Identity and Access Management &gt; Maximum Attestation Duration
- AWS &gt; CIS v5.0 &gt; 2 - Storage
- AWS &gt; CIS v5.0 &gt; 2 - Storage &gt; 2.01 - Simple Storage Service (S3)
- AWS &gt; CIS v5.0 &gt; 2 - Storage &gt; 2.01 - Simple Storage Service (S3) &gt; 2.01.01 - Ensure S3 Bucket Policy is set to deny HTTP requests
- AWS &gt; CIS v5.0 &gt; 2 - Storage &gt; 2.01 - Simple Storage Service (S3) &gt; 2.01.02 - Ensure MFA Delete is enable on S3 buckets
- AWS &gt; CIS v5.0 &gt; 2 - Storage &gt; 2.01 - Simple Storage Service (S3) &gt; 2.01.03 - Ensure all data in Amazon S3 has been discovered, classified, and secured when necessary
- AWS &gt; CIS v5.0 &gt; 2 - Storage &gt; 2.01 - Simple Storage Service (S3) &gt; 2.01.03 - Ensure all data in Amazon S3 has been discovered, classified, and secured when necessary &gt; Attestation
- AWS &gt; CIS v5.0 &gt; 2 - Storage &gt; 2.01 - Simple Storage Service (S3) &gt; 2.01.04 - Ensure that S3 is configured with &apos;Block Public Access&apos; enabled
- AWS &gt; CIS v5.0 &gt; 2 - Storage &gt; 2.02 - Relational Database Service (RDS)
- AWS &gt; CIS v5.0 &gt; 2 - Storage &gt; 2.02 - Relational Database Service (RDS) &gt; 2.02.01 - Ensure that encryption-at-rest is enabled for RDS Instances
- AWS &gt; CIS v5.0 &gt; 2 - Storage &gt; 2.02 - Relational Database Service (RDS) &gt; 2.02.02 - Ensure the Auto Minor Version Upgrade feature is enabled for RDS instances
- AWS &gt; CIS v5.0 &gt; 2 - Storage &gt; 2.02 - Relational Database Service (RDS) &gt; 2.02.03 - Ensure that RDS instances are not publicly accessible
- AWS &gt; CIS v5.0 &gt; 2 - Storage &gt; 2.02 - Relational Database Service (RDS) &gt; 2.02.04 - Ensure Multi-AZ deployments are used for enhanced availability in Amazon RDS
- AWS &gt; CIS v5.0 &gt; 2 - Storage &gt; 2.03 - Elastic File System (EFS)
- AWS &gt; CIS v5.0 &gt; 2 - Storage &gt; 2.03 - Elastic File System (EFS) &gt; 2.03.01 - Ensure that encryption is enabled for EFS file systems
- AWS &gt; CIS v5.0 &gt; 2 - Storage &gt; Maximum Attestation Duration
- AWS &gt; CIS v5.0 &gt; 3 - Logging
- AWS &gt; CIS v5.0 &gt; 3 - Logging &gt; 3.01 - Ensure CloudTrail is enabled in all regions
- AWS &gt; CIS v5.0 &gt; 3 - Logging &gt; 3.02 - Ensure CloudTrail log file validation is enabled
- AWS &gt; CIS v5.0 &gt; 3 - Logging &gt; 3.03 - Ensure AWS Config is enabled in all regions
- AWS &gt; CIS v5.0 &gt; 3 - Logging &gt; 3.04 - Ensure that server access logging is enabled on the CloudTrail S3 bucket
- AWS &gt; CIS v5.0 &gt; 3 - Logging &gt; 3.05 - Ensure CloudTrail logs are encrypted at rest using KMS CMKs
- AWS &gt; CIS v5.0 &gt; 3 - Logging &gt; 3.06 - Ensure rotation for customer-created symmetric CMKs is enabled
- AWS &gt; CIS v5.0 &gt; 3 - Logging &gt; 3.07 - Ensure VPC flow logging is enabled in all VPCs
- AWS &gt; CIS v5.0 &gt; 3 - Logging &gt; 3.08 - Ensure that Object-level logging for write events is enabled for S3 bucket
- AWS &gt; CIS v5.0 &gt; 3 - Logging &gt; 3.09 - Ensure that object-level logging for read events is enabled for S3 buckets
- AWS &gt; CIS v5.0 &gt; 3 - Logging &gt; Maximum Attestation Duration
- AWS &gt; CIS v5.0 &gt; 4 - Monitoring
- AWS &gt; CIS v5.0 &gt; 4 - Monitoring &gt; 4.01 - Ensure unauthorized API calls are monitored
- AWS &gt; CIS v5.0 &gt; 4 - Monitoring &gt; 4.02 - Ensure management console sign-in without MFA is monitored
- AWS &gt; CIS v5.0 &gt; 4 - Monitoring &gt; 4.03 - Ensure usage of the &apos;root&apos; account is monitored
- AWS &gt; CIS v5.0 &gt; 4 - Monitoring &gt; 4.04 - Ensure IAM policy changes are monitored
- AWS &gt; CIS v5.0 &gt; 4 - Monitoring &gt; 4.05 - Ensure CloudTrail configuration changes are monitored
- AWS &gt; CIS v5.0 &gt; 4 - Monitoring &gt; 4.06 - Ensure AWS Management Console authentication failures are monitored
- AWS &gt; CIS v5.0 &gt; 4 - Monitoring &gt; 4.07 - Ensure disabling or scheduled deletion of customer created CMKs is monitored
- AWS &gt; CIS v5.0 &gt; 4 - Monitoring &gt; 4.08 - Ensure S3 bucket policy changes are monitored
- AWS &gt; CIS v5.0 &gt; 4 - Monitoring &gt; 4.09 - Ensure AWS Config configuration changes are monitored
- AWS &gt; CIS v5.0 &gt; 4 - Monitoring &gt; 4.10 - Ensure security group changes are monitored
- AWS &gt; CIS v5.0 &gt; 4 - Monitoring &gt; 4.11 - Ensure Network Access Control List (NACL) changes are monitored
- AWS &gt; CIS v5.0 &gt; 4 - Monitoring &gt; 4.12 - Ensure changes to network gateways are monitored
- AWS &gt; CIS v5.0 &gt; 4 - Monitoring &gt; 4.13 - Ensure route table changes are monitored
- AWS &gt; CIS v5.0 &gt; 4 - Monitoring &gt; 4.14 - Ensure VPC changes are monitored
- AWS &gt; CIS v5.0 &gt; 4 - Monitoring &gt; 4.15 - Ensure AWS Organizations changes are monitored
- AWS &gt; CIS v5.0 &gt; 4 - Monitoring &gt; 4.16 - Ensure AWS Security Hub is enabled
- AWS &gt; CIS v5.0 &gt; 4 - Monitoring &gt; Maximum Attestation Duration
- AWS &gt; CIS v5.0 &gt; 5 - Networking
- AWS &gt; CIS v5.0 &gt; 5 - Networking &gt; 5.01 - EC2
- AWS &gt; CIS v5.0 &gt; 5 - Networking &gt; 5.01 - EC2 &gt; 5.01.01 - Ensure EBS Volume Encryption is Enabled in all Regions
- AWS &gt; CIS v5.0 &gt; 5 - Networking &gt; 5.01 - EC2 &gt; 5.01.02 - Ensure CIFS access is restricted to trusted networks to prevent unauthorized access
- AWS &gt; CIS v5.0 &gt; 5 - Networking &gt; 5.02 - Ensure no Network ACLs allow ingress from 0.0.0.0/0 to remote server administration ports
- AWS &gt; CIS v5.0 &gt; 5 - Networking &gt; 5.03 - Ensure no security groups allow ingress from 0.0.0.0/0 to remote server administration ports
- AWS &gt; CIS v5.0 &gt; 5 - Networking &gt; 5.04 - Ensure no security groups allow ingress from ::/0 to remote server administration ports
- AWS &gt; CIS v5.0 &gt; 5 - Networking &gt; 5.05 - Default SG Restricts All Traffic &gt; Attestation
- AWS &gt; CIS v5.0 &gt; 5 - Networking &gt; 5.05 - Ensure the default security group of every VPC restricts all traffic
- AWS &gt; CIS v5.0 &gt; 5 - Networking &gt; 5.06 - Ensure routing tables for VPC peering are &apos;least access&apos;
- AWS &gt; CIS v5.0 &gt; 5 - Networking &gt; 5.06 - Ensure routing tables for VPC peering are &apos;least access&apos; &gt; 5.06 - VPC Peering Routes Least Access &gt; Attestation
- AWS &gt; CIS v5.0 &gt; 5 - Networking &gt; 5.07 - Ensure that the EC2 Metadata Service only allows IMDSv2
- AWS &gt; CIS v5.0 &gt; 5 - Networking &gt; Maximum Attestation Duration
- AWS &gt; CIS v5.0 &gt; Maximum Attestation Duration</description>
            <pubDate>Tue, 27 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-network-v5-29-0</guid>
            <title>azure-network v5.29.0 - Track and manage web application firewall policy resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-network-v5-29-0</link>
            <description>_Resource Types_

- Azure &gt; Network &gt; Web Application Firewall Policy

_Control Types_

- Azure &gt; Network &gt; Web Application Firewall Policy &gt; Active
- Azure &gt; Network &gt; Web Application Firewall Policy &gt; Allowed
- Azure &gt; Network &gt; Web Application Firewall Policy &gt; Allowed &gt; Custom
- Azure &gt; Network &gt; Web Application Firewall Policy &gt; Allowed &gt; Region
- Azure &gt; Network &gt; Web Application Firewall Policy &gt; CMDB
- Azure &gt; Network &gt; Web Application Firewall Policy &gt; Discovery
- Azure &gt; Network &gt; Web Application Firewall Policy &gt; Tags

_Policy Types_

- Azure &gt; Network &gt; Web Application Firewall Policy &gt; Active
- Azure &gt; Network &gt; Web Application Firewall Policy &gt; Active &gt; Age
- Azure &gt; Network &gt; Web Application Firewall Policy &gt; Active &gt; Last Modified
- Azure &gt; Network &gt; Web Application Firewall Policy &gt; Allowed
- Azure &gt; Network &gt; Web Application Firewall Policy &gt; Allowed &gt; Custom
- Azure &gt; Network &gt; Web Application Firewall Policy &gt; Allowed &gt; Custom &gt; Rules
- Azure &gt; Network &gt; Web Application Firewall Policy &gt; Allowed &gt; Region
- Azure &gt; Network &gt; Web Application Firewall Policy &gt; Allowed &gt; Region &gt; Regions
- Azure &gt; Network &gt; Web Application Firewall Policy &gt; CMDB
- Azure &gt; Network &gt; Web Application Firewall Policy &gt; Regions
- Azure &gt; Network &gt; Web Application Firewall Policy &gt; Tags
- Azure &gt; Network &gt; Web Application Firewall Policy &gt; Tags &gt; Template

_Action Types_

- Azure &gt; Network &gt; Web Application Firewall Policy &gt; Delete
- Azure &gt; Network &gt; Web Application Firewall Policy &gt; Router
- Azure &gt; Network &gt; Web Application Firewall Policy &gt; Set Tags</description>
            <pubDate>Mon, 26 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-keyvault-v5-20-0</guid>
            <title>azure-keyvault v5.20.0 - Track and manage certificate resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-keyvault-v5-20-0</link>
            <description>_Resource Types_

- Azure &gt; Key Vault &gt; Certificate

_Control Types_

- Azure &gt; Key Vault &gt; Certificate &gt; Active
- Azure &gt; Key Vault &gt; Certificate &gt; Allowed
- Azure &gt; Key Vault &gt; Certificate &gt; Allowed &gt; Custom
- Azure &gt; Key Vault &gt; Certificate &gt; Allowed &gt; Region
- Azure &gt; Key Vault &gt; Certificate &gt; CMDB
- Azure &gt; Key Vault &gt; Certificate &gt; Discovery
- Azure &gt; Key Vault &gt; Key &gt; Allowed
- Azure &gt; Key Vault &gt; Key &gt; Allowed &gt; Custom
- Azure &gt; Key Vault &gt; Key &gt; Allowed &gt; Region
- Azure &gt; Key Vault &gt; Secret &gt; Allowed
- Azure &gt; Key Vault &gt; Secret &gt; Allowed &gt; Custom
- Azure &gt; Key Vault &gt; Secret &gt; Allowed &gt; Region
- Azure &gt; Key Vault &gt; Vault &gt; Allowed
- Azure &gt; Key Vault &gt; Vault &gt; Allowed &gt; Custom
- Azure &gt; Key Vault &gt; Vault &gt; Allowed &gt; Region

_Policy Types_

- Azure &gt; Key Vault &gt; Allowed Regions [Default]
- Azure &gt; Key Vault &gt; Certificate &gt; Active
- Azure &gt; Key Vault &gt; Certificate &gt; Active &gt; Age
- Azure &gt; Key Vault &gt; Certificate &gt; Active &gt; Last Modified
- Azure &gt; Key Vault &gt; Certificate &gt; Allowed
- Azure &gt; Key Vault &gt; Certificate &gt; Allowed &gt; Custom
- Azure &gt; Key Vault &gt; Certificate &gt; Allowed &gt; Custom &gt; Rules
- Azure &gt; Key Vault &gt; Certificate &gt; Allowed &gt; Region
- Azure &gt; Key Vault &gt; Certificate &gt; Allowed &gt; Region &gt; Regions
- Azure &gt; Key Vault &gt; Certificate &gt; CMDB
- Azure &gt; Key Vault &gt; Certificate &gt; Regions
- Azure &gt; Key Vault &gt; Key &gt; Allowed
- Azure &gt; Key Vault &gt; Key &gt; Allowed &gt; Custom
- Azure &gt; Key Vault &gt; Key &gt; Allowed &gt; Custom &gt; Rules
- Azure &gt; Key Vault &gt; Key &gt; Allowed &gt; Region
- Azure &gt; Key Vault &gt; Key &gt; Allowed &gt; Region &gt; Regions
- Azure &gt; Key Vault &gt; Secret &gt; Allowed
- Azure &gt; Key Vault &gt; Secret &gt; Allowed &gt; Custom
- Azure &gt; Key Vault &gt; Secret &gt; Allowed &gt; Custom &gt; Rules
- Azure &gt; Key Vault &gt; Secret &gt; Allowed &gt; Region
- Azure &gt; Key Vault &gt; Secret &gt; Allowed &gt; Region &gt; Regions
- Azure &gt; Key Vault &gt; Vault &gt; Allowed
- Azure &gt; Key Vault &gt; Vault &gt; Allowed &gt; Custom
- Azure &gt; Key Vault &gt; Vault &gt; Allowed &gt; Custom &gt; Rules
- Azure &gt; Key Vault &gt; Vault &gt; Allowed &gt; Region
- Azure &gt; Key Vault &gt; Vault &gt; Allowed &gt; Region &gt; Regions

_Action Types_

- Azure &gt; Key Vault &gt; Certificate &gt; Delete</description>
            <pubDate>Mon, 26 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-cisv4-0-v5-0-0</guid>
            <title>aws-cisv4-0 v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/aws-cisv4-0-v5-0-0</link>
            <description>_Control Types_

- AWS &gt; CIS v4.0
- AWS &gt; CIS v4.0 &gt; 1 - Identity and Access Management
- AWS &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.01 - Maintain current contact details
- AWS &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.02 - Ensure security contact information is registered
- AWS &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.03 - Ensure security questions are registered in the AWS account
- AWS &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.04 - Ensure no &apos;root&apos; user account access key exists
- AWS &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.05 - Ensure MFA is enabled for the &apos;root&apos; user account
- AWS &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.06 - Ensure hardware MFA is enabled for the &apos;root&apos; user account
- AWS &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.07 - Eliminate use of the &apos;root&apos; user for administrative and daily tasks
- AWS &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.08 - Ensure IAM password policy requires minimum length of 14 or greater
- AWS &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.09 - Ensure IAM password policy prevents password reuse
- AWS &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.10 - Ensure multi-factor authentication (MFA) is enabled for all IAM users that have a console password
- AWS &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.11 - Do not create access keys during initial setup for IAM users with a console password
- AWS &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.12 - Ensure credentials unused for 45 days or more are disabled
- AWS &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.13 - Ensure there is only one active access key for any single IAM user
- AWS &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.14 - Ensure access keys are rotated every 90 days or less
- AWS &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.15 - Ensure IAM users receive permissions only through groups
- AWS &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.16 - Ensure IAM policies that allow full &quot;_:_&quot; administrative privileges are not attached
- AWS &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.17 - Ensure a support role has been created to manage incidents with AWS Support
- AWS &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.18 - Ensure IAM instance roles are used for AWS resource access from instances
- AWS &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.19 - Ensure that all expired SSL/TLS certificates stored in AWS IAM are removed
- AWS &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.20 - Ensure that IAM Access analyzer is enabled for all regions
- AWS &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.21 - Ensure IAM users are managed centrally via identity federation or AWS Organizations for multi-account environments
- AWS &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.22 - Ensure access to AWSCloudShellFullAccess is restricted
- AWS &gt; CIS v4.0 &gt; 2 - Storage
- AWS &gt; CIS v4.0 &gt; 2 - Storage &gt; 2.01 - Simple Storage Service (S3)
- AWS &gt; CIS v4.0 &gt; 2 - Storage &gt; 2.01 - Simple Storage Service (S3) &gt; 2.01.01 - Ensure S3 Bucket Policy is set to deny HTTP requests
- AWS &gt; CIS v4.0 &gt; 2 - Storage &gt; 2.01 - Simple Storage Service (S3) &gt; 2.01.02 - Ensure MFA Delete is enabled on S3 buckets
- AWS &gt; CIS v4.0 &gt; 2 - Storage &gt; 2.01 - Simple Storage Service (S3) &gt; 2.01.03 - Ensure all data in Amazon S3 has been discovered, classified, and secured when necessary
- AWS &gt; CIS v4.0 &gt; 2 - Storage &gt; 2.01 - Simple Storage Service (S3) &gt; 2.01.04 - Ensure that S3 is configured with &apos;Block Public Access&apos; enabled
- AWS &gt; CIS v4.0 &gt; 2 - Storage &gt; 2.02 - Relational Database Service (RDS)
- AWS &gt; CIS v4.0 &gt; 2 - Storage &gt; 2.02 - Relational Database Service (RDS) &gt; 2.02.01 - Ensure that encryption-at-rest is enabled for RDS Instances
- AWS &gt; CIS v4.0 &gt; 2 - Storage &gt; 2.02 - Relational Database Service (RDS) &gt; 2.02.02 - Ensure the Auto Minor Version Upgrade feature is enabled for RDS instances
- AWS &gt; CIS v4.0 &gt; 2 - Storage &gt; 2.02 - Relational Database Service (RDS) &gt; 2.02.03 - Ensure that RDS instances are not publicly accessible
- AWS &gt; CIS v4.0 &gt; 2 - Storage &gt; 2.02 - Relational Database Service (RDS) &gt; 2.02.04 - Ensure Multi-AZ deployments are used for enhanced availability in Amazon RDS
- AWS &gt; CIS v4.0 &gt; 2 - Storage &gt; 2.03 - Elastic File System (EFS)
- AWS &gt; CIS v4.0 &gt; 2 - Storage &gt; 2.03 - Elastic File System (EFS) &gt; 2.03.01 - Ensure that encryption is enabled for EFS file systems
- AWS &gt; CIS v4.0 &gt; 3 - Logging
- AWS &gt; CIS v4.0 &gt; 3 - Logging &gt; 3.01 - Ensure CloudTrail is enabled in all regions
- AWS &gt; CIS v4.0 &gt; 3 - Logging &gt; 3.02 - Ensure CloudTrail log file validation is enabled
- AWS &gt; CIS v4.0 &gt; 3 - Logging &gt; 3.03 - Ensure AWS Config is enabled in all regions
- AWS &gt; CIS v4.0 &gt; 3 - Logging &gt; 3.04 - Ensure that server access logging is enabled on the CloudTrail S3 bucket
- AWS &gt; CIS v4.0 &gt; 3 - Logging &gt; 3.05 - Ensure CloudTrail logs are encrypted at rest using KMS CMKs
- AWS &gt; CIS v4.0 &gt; 3 - Logging &gt; 3.06 - Ensure rotation for customer-created symmetric CMKs is enabled
- AWS &gt; CIS v4.0 &gt; 3 - Logging &gt; 3.07 - Ensure VPC flow logging is enabled in all VPCs
- AWS &gt; CIS v4.0 &gt; 3 - Logging &gt; 3.08 - Ensure that Object-level logging for write events is enabled for S3 bucket
- AWS &gt; CIS v4.0 &gt; 3 - Logging &gt; 3.09 - Ensure that object-level logging for read events is enabled for S3 buckets
- AWS &gt; CIS v4.0 &gt; 4 - Monitoring
- AWS &gt; CIS v4.0 &gt; 4 - Monitoring &gt; 4.01 - Ensure unauthorized API calls are monitored
- AWS &gt; CIS v4.0 &gt; 4 - Monitoring &gt; 4.02 - Ensure management console sign-in without MFA is monitored
- AWS &gt; CIS v4.0 &gt; 4 - Monitoring &gt; 4.03 - Ensure usage of the &apos;root&apos; account is monitored
- AWS &gt; CIS v4.0 &gt; 4 - Monitoring &gt; 4.04 - Ensure IAM policy changes are monitored
- AWS &gt; CIS v4.0 &gt; 4 - Monitoring &gt; 4.05 - Ensure CloudTrail configuration changes are monitored
- AWS &gt; CIS v4.0 &gt; 4 - Monitoring &gt; 4.06 - Ensure AWS Management Console authentication failures are monitored
- AWS &gt; CIS v4.0 &gt; 4 - Monitoring &gt; 4.07 - Ensure disabling or scheduled deletion of customer created CMKs is monitored
- AWS &gt; CIS v4.0 &gt; 4 - Monitoring &gt; 4.08 - Ensure S3 bucket policy changes are monitored
- AWS &gt; CIS v4.0 &gt; 4 - Monitoring &gt; 4.09 - Ensure AWS Config configuration changes are monitored
- AWS &gt; CIS v4.0 &gt; 4 - Monitoring &gt; 4.10 - Ensure security group changes are monitored
- AWS &gt; CIS v4.0 &gt; 4 - Monitoring &gt; 4.11 - Ensure Network Access Control List (NACL) changes are monitored
- AWS &gt; CIS v4.0 &gt; 4 - Monitoring &gt; 4.12 - Ensure changes to network gateways are monitored
- AWS &gt; CIS v4.0 &gt; 4 - Monitoring &gt; 4.13 - Ensure route table changes are monitored
- AWS &gt; CIS v4.0 &gt; 4 - Monitoring &gt; 4.14 - Ensure VPC changes are monitored
- AWS &gt; CIS v4.0 &gt; 4 - Monitoring &gt; 4.15 - Ensure AWS Organizations changes are monitored
- AWS &gt; CIS v4.0 &gt; 4 - Monitoring &gt; 4.16 - Ensure AWS Security Hub is enabled
- AWS &gt; CIS v4.0 &gt; 5 - Networking
- AWS &gt; CIS v4.0 &gt; 5 - Networking &gt; 5.01 - Elastic Compute Cloud (EC2)
- AWS &gt; CIS v4.0 &gt; 5 - Networking &gt; 5.01 - Elastic Compute Cloud (EC2) &gt; 5.01.01 - Ensure EBS Volume Encryption is Enabled in all Regions
- AWS &gt; CIS v4.0 &gt; 5 - Networking &gt; 5.01 - Elastic Compute Cloud (EC2) &gt; 5.01.02 - Ensure CIFS access is restricted to trusted networks to prevent unauthorized access
- AWS &gt; CIS v4.0 &gt; 5 - Networking &gt; 5.02 - Ensure no Network ACLs allow ingress from 0.0.0.0/0 to remote server administration ports
- AWS &gt; CIS v4.0 &gt; 5 - Networking &gt; 5.03 - Ensure no security groups allow ingress from 0.0.0.0/0 to remote server administration ports
- AWS &gt; CIS v4.0 &gt; 5 - Networking &gt; 5.04 - Ensure no security groups allow ingress from ::/0 to remote server administration ports
- AWS &gt; CIS v4.0 &gt; 5 - Networking &gt; 5.05 - Ensure the default security group of every VPC restricts all traffic
- AWS &gt; CIS v4.0 &gt; 5 - Networking &gt; 5.06 - Ensure routing tables for VPC peering are &quot;least access&quot;
- AWS &gt; CIS v4.0 &gt; 5 - Networking &gt; 5.07 - Ensure that the EC2 Metadata Service only allows IMDSv2

_Policy Types_

- AWS &gt; CIS v4.0
- AWS &gt; CIS v4.0 &gt; 1 - Identity and Access Management
- AWS &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.01 - Maintain current contact details
- AWS &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.01 - Maintain current contact details &gt; Attestation
- AWS &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.02 - Ensure security contact information is registered
- AWS &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.03 - Ensure security questions are registered in the AWS account
- AWS &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.03 - Ensure security questions are registered in the AWS account &gt; Attestation
- AWS &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.04 - Ensure no &apos;root&apos; user account access key exists
- AWS &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.05 - Ensure MFA is enabled for the &apos;root&apos; user account
- AWS &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.06 - Ensure hardware MFA is enabled for the &apos;root&apos; user account
- AWS &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.07 - Eliminate use of the &apos;root&apos; user for administrative and daily tasks
- AWS &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.08 - Ensure IAM password policy requires minimum length of 14 or greater
- AWS &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.09 - Ensure IAM password policy prevents password reuse
- AWS &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.10 - Ensure multi-factor authentication (MFA) is enabled for all IAM users that have a console password
- AWS &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.11 - Do not setup access keys during initial user setup for all IAM users that have a console password
- AWS &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.12 - Ensure credentials unused for 45 days or greater are disabled
- AWS &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.13 - Ensure there is only one active access key available for any single IAM user
- AWS &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.14 - Ensure access keys are rotated every 90 days or less
- AWS &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.15 - Ensure IAM Users Receive Permissions Only Through Groups
- AWS &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.16 - Ensure IAM policies that allow full &quot;_:_&quot; administrative privileges are not attached
- AWS &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.17 - Ensure a support role has been created to manage incidents with AWS Support
- AWS &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.18 - Ensure IAM instance roles are used for AWS resource access from instances
- AWS &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.19 - Ensure that all the expired SSL/TLS certificates stored in AWS IAM are removed
- AWS &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.20 - Ensure that IAM Access analyzer is enabled for all regions
- AWS &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.21 - Ensure IAM users are managed centrally via identity federation or AWS Organizations for multi-account environments
- AWS &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.21 - Ensure IAM users are managed centrally via identity federation or AWS Organizations for multi-account environments &gt; Attestation
- AWS &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.22 - Ensure access to AWSCloudShellFullAccess is restricted
- AWS &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; 1.22 - Ensure access to AWSCloudShellFullAccess is restricted &gt; Attestation
- AWS &gt; CIS v4.0 &gt; 1 - Identity and Access Management &gt; Maximum Attestation Duration
- AWS &gt; CIS v4.0 &gt; 2 - Storage
- AWS &gt; CIS v4.0 &gt; 2 - Storage &gt; 2.01 - Simple Storage Service (S3)
- AWS &gt; CIS v4.0 &gt; 2 - Storage &gt; 2.01 - Simple Storage Service (S3) &gt; 2.01.01 - Ensure S3 Bucket Policy is set to deny HTTP requests
- AWS &gt; CIS v4.0 &gt; 2 - Storage &gt; 2.01 - Simple Storage Service (S3) &gt; 2.01.02 - Ensure MFA Delete is enable on S3 buckets
- AWS &gt; CIS v4.0 &gt; 2 - Storage &gt; 2.01 - Simple Storage Service (S3) &gt; 2.01.03 - Ensure all data in Amazon S3 has been discovered, classified and secured when required
- AWS &gt; CIS v4.0 &gt; 2 - Storage &gt; 2.01 - Simple Storage Service (S3) &gt; 2.01.03 - Ensure all data in Amazon S3 has been discovered, classified and secured when required &gt; Attestation
- AWS &gt; CIS v4.0 &gt; 2 - Storage &gt; 2.01 - Simple Storage Service (S3) &gt; 2.01.04 - Ensure that S3 Buckets are configured with &apos;Block public access (bucket settings)&apos;
- AWS &gt; CIS v4.0 &gt; 2 - Storage &gt; 2.02 - Relational Database Service (RDS)
- AWS &gt; CIS v4.0 &gt; 2 - Storage &gt; 2.02 - Relational Database Service (RDS) &gt; 2.02.01 - Ensure that encryption-at-rest is enabled for RDS Instances
- AWS &gt; CIS v4.0 &gt; 2 - Storage &gt; 2.02 - Relational Database Service (RDS) &gt; 2.02.02 - Ensure Auto Minor Version Upgrade feature is Enabled for RDS Instances
- AWS &gt; CIS v4.0 &gt; 2 - Storage &gt; 2.02 - Relational Database Service (RDS) &gt; 2.02.03 - Ensure that public access is not given to RDS Instance
- AWS &gt; CIS v4.0 &gt; 2 - Storage &gt; 2.02 - Relational Database Service (RDS) &gt; 2.02.04 - Ensure Multi-AZ deployments are used for enhanced availability in Amazon RDS
- AWS &gt; CIS v4.0 &gt; 2 - Storage &gt; 2.03 - Elastic File System (EFS)
- AWS &gt; CIS v4.0 &gt; 2 - Storage &gt; 2.03 - Elastic File System (EFS) &gt; 2.03.01 - Ensure that encryption is enabled for EFS file systems
- AWS &gt; CIS v4.0 &gt; 2 - Storage &gt; Maximum Attestation Duration
- AWS &gt; CIS v4.0 &gt; 3 - Logging
- AWS &gt; CIS v4.0 &gt; 3 - Logging &gt; 3.01 - Ensure CloudTrail is enabled in all regions
- AWS &gt; CIS v4.0 &gt; 3 - Logging &gt; 3.02 - Ensure CloudTrail log file validation is enabled
- AWS &gt; CIS v4.0 &gt; 3 - Logging &gt; 3.03 - Ensure AWS Config is enabled in all regions
- AWS &gt; CIS v4.0 &gt; 3 - Logging &gt; 3.04 - Ensure that server access logging is enabled on the CloudTrail S3 bucket
- AWS &gt; CIS v4.0 &gt; 3 - Logging &gt; 3.05 - Ensure CloudTrail logs are encrypted at rest using KMS CMKs
- AWS &gt; CIS v4.0 &gt; 3 - Logging &gt; 3.06 - Ensure rotation for customer-created symmetric CMKs is enabled
- AWS &gt; CIS v4.0 &gt; 3 - Logging &gt; 3.07 - Ensure VPC flow logging is enabled in all VPCs
- AWS &gt; CIS v4.0 &gt; 3 - Logging &gt; 3.08 - Ensure that Object-level logging for write events is enabled for S3 bucket
- AWS &gt; CIS v4.0 &gt; 3 - Logging &gt; 3.09 - Ensure that object-level logging for read events is enabled for S3 buckets
- AWS &gt; CIS v4.0 &gt; 3 - Logging &gt; Maximum Attestation Duration
- AWS &gt; CIS v4.0 &gt; 4 - Monitoring
- AWS &gt; CIS v4.0 &gt; 4 - Monitoring &gt; 4.01 - Ensure unauthorized API calls are monitored
- AWS &gt; CIS v4.0 &gt; 4 - Monitoring &gt; 4.02 - Ensure management console sign-in without MFA is monitored
- AWS &gt; CIS v4.0 &gt; 4 - Monitoring &gt; 4.03 - Ensure usage of &apos;root&apos; account is monitored
- AWS &gt; CIS v4.0 &gt; 4 - Monitoring &gt; 4.04 - Ensure IAM policy changes are monitored
- AWS &gt; CIS v4.0 &gt; 4 - Monitoring &gt; 4.05 - Ensure CloudTrail configuration changes are monitored
- AWS &gt; CIS v4.0 &gt; 4 - Monitoring &gt; 4.06 - Ensure AWS Management Console authentication failures are monitored
- AWS &gt; CIS v4.0 &gt; 4 - Monitoring &gt; 4.07 - Ensure disabling or scheduled deletion of customer created CMKs is monitored
- AWS &gt; CIS v4.0 &gt; 4 - Monitoring &gt; 4.08 - Ensure S3 bucket policy changes are monitored
- AWS &gt; CIS v4.0 &gt; 4 - Monitoring &gt; 4.09 - Ensure AWS Config configuration changes are monitored
- AWS &gt; CIS v4.0 &gt; 4 - Monitoring &gt; 4.10 - Ensure security group changes are monitored
- AWS &gt; CIS v4.0 &gt; 4 - Monitoring &gt; 4.11 - Ensure Network Access Control Lists (NACL) changes are monitored
- AWS &gt; CIS v4.0 &gt; 4 - Monitoring &gt; 4.12 - Ensure changes to network gateways are monitored
- AWS &gt; CIS v4.0 &gt; 4 - Monitoring &gt; 4.13 - Ensure route table changes are monitored
- AWS &gt; CIS v4.0 &gt; 4 - Monitoring &gt; 4.14 - Ensure VPC changes are monitored
- AWS &gt; CIS v4.0 &gt; 4 - Monitoring &gt; 4.15 - Ensure AWS Organizations changes are monitored
- AWS &gt; CIS v4.0 &gt; 4 - Monitoring &gt; 4.16 - Ensure AWS Security Hub is enabled
- AWS &gt; CIS v4.0 &gt; 4 - Monitoring &gt; Maximum Attestation Duration
- AWS &gt; CIS v4.0 &gt; 5 - Networking
- AWS &gt; CIS v4.0 &gt; 5 - Networking &gt; 5.01 - Elastic Compute Cloud (EC2)
- AWS &gt; CIS v4.0 &gt; 5 - Networking &gt; 5.01 - Elastic Compute Cloud (EC2) &gt; 5.01.01 - Ensure EBS Volume Encryption is Enabled in all Regions
- AWS &gt; CIS v4.0 &gt; 5 - Networking &gt; 5.01 - Elastic Compute Cloud (EC2) &gt; 5.01.02 - Ensure CIFS access is restricted to trusted networks to prevent unauthorized access
- AWS &gt; CIS v4.0 &gt; 5 - Networking &gt; 5.02 - Ensure no Network ACLs allow ingress from 0.0.0.0/0 to remote server administration ports
- AWS &gt; CIS v4.0 &gt; 5 - Networking &gt; 5.03 - Ensure no security groups allow ingress from 0.0.0.0/0 to remote server administration ports
- AWS &gt; CIS v4.0 &gt; 5 - Networking &gt; 5.04 - Ensure no security groups allow ingress from ::/0 to remote server administration ports
- AWS &gt; CIS v4.0 &gt; 5 - Networking &gt; 5.05 - Ensure the default security group of every VPC restricts all traffic
- AWS &gt; CIS v4.0 &gt; 5 - Networking &gt; 5.06 - Ensure routing tables for VPC peering are &apos;least access&apos;
- AWS &gt; CIS v4.0 &gt; 5 - Networking &gt; 5.06 - Ensure routing tables for VPC peering are &apos;least access&apos; &gt; 5.06 - VPC Peering Routes Least Access &gt; Attestation
- AWS &gt; CIS v4.0 &gt; 5 - Networking &gt; 5.07 - Ensure that EC2 Metadata Service only allows IMDSv2
- AWS &gt; CIS v4.0 &gt; 5 - Networking &gt; Maximum Attestation Duration
- AWS &gt; CIS v4.0 &gt; Maximum Attestation Duration</description>
            <pubDate>Mon, 26 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-v5-34-0</guid>
            <title>gcp v5.34.0 - Added support for `Discovery Level` and `Cloud Parent` for organization, folder and project resource types</title>
            <link>https://turbot.com/guardrails/changelog/gcp-v5-34-0</link>
            <description>_What&apos;s new?_

- Added support for `Discovery Level` and `Cloud Parent` for Organization, Folder and Project resource types.

_Policy Types_

- GCP &gt; Organization &gt; Discovery Level
- Turbot &gt; Discovery Level &gt; Materialization Exceptions &gt; @turbot/gcp</description>
            <pubDate>Fri, 23 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-v5-35-0</guid>
            <title>azure v5.35.0 - Added support for `Discovery Level` and `Cloud Parent` for tenant, management group and subscription resource types</title>
            <link>https://turbot.com/guardrails/changelog/azure-v5-35-0</link>
            <description>_What&apos;s new?_

- Added support for `Discovery Level` and `Cloud Parent` for Tenant, Management Group and Subscription resource types.

_Policy Types_

- Azure &gt; Tenant &gt; Discovery Level
- Turbot &gt; Discovery Level &gt; Materialization Exceptions &gt; @turbot/azure</description>
            <pubDate>Fri, 23 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ec2-v5-50-1</guid>
            <title>aws-ec2 v5.50.1 - The CMDB control for instances will update IAM instance profile when it is detached from the instance</title>
            <link>https://turbot.com/guardrails/changelog/aws-ec2-v5-50-1</link>
            <description>_Bug fixes_

- The `AWS &gt; EC2 &gt; Instance &gt; CMDB` control would fail to update IAM instance profile when it was detached from an instance. This is now fixed.
- Fixed the `AWS &gt; EC2 &gt; Instance &gt; Instance Profile` control to check CMDB state before execution, ensuring complete instance data is available.</description>
            <pubDate>Fri, 23 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-55-1</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.55.1 - Enforced PostgreSQL 15+ and policy pack optimization</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-55-1</link>
            <description>_What&apos;s new?_

- Server
  - Workspace creation and upgrade are now blocked if the RDS PostgreSQL version is lower than 15.

_Bug fixes_

- Server
  - Prevent policy pack summary control from querying AI credentials when the summary policy is disabled.

_Requirements_

- Upgrade to `5.55.1` requires your workspace to be on `5.54.x`
- PostgreSQL (RDS engine): &gt;= 15
- TEF: 1.66.0
- TED: 1.37.0
- Mods:
  - @turbot/turbot: 5.56.0

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Thu, 22 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-cisv2-0-v5-1-2</guid>
            <title>gcp-cisv2-0 v5.1.2 - Fixed policy mappings in various control types</title>
            <link>https://turbot.com/guardrails/changelog/gcp-cisv2-0-v5-1-2</link>
            <description>_Bug fixes_

- Fixed policy mappings in various control types.</description>
            <pubDate>Thu, 22 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-cisv1-v5-0-2</guid>
            <title>gcp-cisv1 v5.0.2 - Fixed policy mappings in various control types</title>
            <link>https://turbot.com/guardrails/changelog/gcp-cisv1-v5-0-2</link>
            <description>_Bug fixes_

- Fixed policy mappings in various control types.</description>
            <pubDate>Thu, 22 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-cisv3-0-v5-0-2</guid>
            <title>azure-cisv3-0 v5.0.2 - Fixed policy mappings in various control types</title>
            <link>https://turbot.com/guardrails/changelog/azure-cisv3-0-v5-0-2</link>
            <description>_Bug fixes_

- Fixed policy mappings in various control types.</description>
            <pubDate>Thu, 22 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-cisv2-0-v5-2-1</guid>
            <title>azure-cisv2-0 v5.2.1 - Fixed policy mappings in various control types</title>
            <link>https://turbot.com/guardrails/changelog/azure-cisv2-0-v5-2-1</link>
            <description>_Bug fixes_

- Fixed policy mappings in various control types.</description>
            <pubDate>Thu, 22 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-cisv1-v5-1-8</guid>
            <title>azure-cisv1 v5.1.8 - Fixed policy mappings in various control types</title>
            <link>https://turbot.com/guardrails/changelog/azure-cisv1-v5-1-8</link>
            <description>_Bug fixes_

- Fixed policy mappings in various control types.</description>
            <pubDate>Thu, 22 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-cisv1-2-v5-0-1</guid>
            <title>azure-cisv1-2 v5.0.1 - Fixed policy mappings in various control types</title>
            <link>https://turbot.com/guardrails/changelog/azure-cisv1-2-v5-0-1</link>
            <description>_Bug fixes_

- Fixed policy mappings in various control types.</description>
            <pubDate>Thu, 22 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-cisv3-0-v5-0-8</guid>
            <title>aws-cisv3-0 v5.0.8 - Fixed policy mappings in various control types</title>
            <link>https://turbot.com/guardrails/changelog/aws-cisv3-0-v5-0-8</link>
            <description>_Bug fixes_

- Fixed policy mappings in various control types.</description>
            <pubDate>Thu, 22 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-cisv2-0-v5-0-6</guid>
            <title>aws-cisv2-0 v5.0.6 - Fixed policy mappings in various control types</title>
            <link>https://turbot.com/guardrails/changelog/aws-cisv2-0-v5-0-6</link>
            <description>_Bug fixes_

- Fixed policy mappings in various control types.</description>
            <pubDate>Thu, 22 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-cisv1-v5-0-11</guid>
            <title>aws-cisv1 v5.0.11 - Fixed policy mappings in various control types</title>
            <link>https://turbot.com/guardrails/changelog/aws-cisv1-v5-0-11</link>
            <description>_Bug fixes_

- Fixed policy mappings in various control types.</description>
            <pubDate>Thu, 22 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-cisv1-4-v5-0-10</guid>
            <title>aws-cisv1-4 v5.0.10 - Fixed policy mappings in various control types</title>
            <link>https://turbot.com/guardrails/changelog/aws-cisv1-4-v5-0-10</link>
            <description>_Bug fixes_

- Fixed policy mappings in various control types.</description>
            <pubDate>Thu, 22 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-sagemaker-v5-14-0</guid>
            <title>aws-sagemaker v5.14.0 - Various new resource types for Sagemaker are now available</title>
            <link>https://turbot.com/guardrails/changelog/aws-sagemaker-v5-14-0</link>
            <description>_What&apos;s new?_

- Resource Types:
  - AWS &gt; SageMaker &gt; App
  - AWS &gt; SageMaker &gt; Cluster
  - AWS &gt; SageMaker &gt; Image
  - AWS &gt; SageMaker &gt; Pipeline
  - AWS &gt; SageMaker &gt; Processing Job
  - AWS &gt; SageMaker &gt; Project
  - AWS &gt; SageMaker &gt; Studio Lifecycle Config
  - AWS &gt; SageMaker &gt; User Profile

- Control Types:
  - AWS &gt; SageMaker &gt; App &gt; Active
  - AWS &gt; SageMaker &gt; App &gt; Allowed
  - AWS &gt; SageMaker &gt; App &gt; Allowed &gt; Custom
  - AWS &gt; SageMaker &gt; App &gt; Allowed &gt; Region
  - AWS &gt; SageMaker &gt; App &gt; CMDB
  - AWS &gt; SageMaker &gt; App &gt; Discovery
  - AWS &gt; SageMaker &gt; App &gt; Tags
  - AWS &gt; SageMaker &gt; Cluster &gt; Active
  - AWS &gt; SageMaker &gt; Cluster &gt; Allowed
  - AWS &gt; SageMaker &gt; Cluster &gt; Allowed &gt; Custom
  - AWS &gt; SageMaker &gt; Cluster &gt; Allowed &gt; Region
  - AWS &gt; SageMaker &gt; Cluster &gt; CMDB
  - AWS &gt; SageMaker &gt; Cluster &gt; Discovery
  - AWS &gt; SageMaker &gt; Cluster &gt; Tags
  - AWS &gt; SageMaker &gt; Image &gt; Active
  - AWS &gt; SageMaker &gt; Image &gt; Allowed
  - AWS &gt; SageMaker &gt; Image &gt; Allowed &gt; Custom
  - AWS &gt; SageMaker &gt; Image &gt; Allowed &gt; Region
  - AWS &gt; SageMaker &gt; Image &gt; CMDB
  - AWS &gt; SageMaker &gt; Image &gt; Discovery
  - AWS &gt; SageMaker &gt; Image &gt; Tags
  - AWS &gt; SageMaker &gt; Pipeline &gt; Active
  - AWS &gt; SageMaker &gt; Pipeline &gt; Allowed
  - AWS &gt; SageMaker &gt; Pipeline &gt; Allowed &gt; Custom
  - AWS &gt; SageMaker &gt; Pipeline &gt; Allowed &gt; Region
  - AWS &gt; SageMaker &gt; Pipeline &gt; CMDB
  - AWS &gt; SageMaker &gt; Pipeline &gt; Discovery
  - AWS &gt; SageMaker &gt; Pipeline &gt; Tags
  - AWS &gt; SageMaker &gt; Processing Job &gt; Active
  - AWS &gt; SageMaker &gt; Processing Job &gt; Allowed
  - AWS &gt; SageMaker &gt; Processing Job &gt; Allowed &gt; Custom
  - AWS &gt; SageMaker &gt; Processing Job &gt; Allowed &gt; Region
  - AWS &gt; SageMaker &gt; Processing Job &gt; CMDB
  - AWS &gt; SageMaker &gt; Processing Job &gt; Discovery
  - AWS &gt; SageMaker &gt; Processing Job &gt; Tags
  - AWS &gt; SageMaker &gt; Project &gt; Active
  - AWS &gt; SageMaker &gt; Project &gt; Allowed
  - AWS &gt; SageMaker &gt; Project &gt; Allowed &gt; Custom
  - AWS &gt; SageMaker &gt; Project &gt; Allowed &gt; Region
  - AWS &gt; SageMaker &gt; Project &gt; CMDB
  - AWS &gt; SageMaker &gt; Project &gt; Discovery
  - AWS &gt; SageMaker &gt; Project &gt; Tags
  - AWS &gt; SageMaker &gt; Project &gt; Usage
  - AWS &gt; SageMaker &gt; Studio Lifecycle Config &gt; Active
  - AWS &gt; SageMaker &gt; Studio Lifecycle Config &gt; Allowed
  - AWS &gt; SageMaker &gt; Studio Lifecycle Config &gt; Allowed &gt; Custom
  - AWS &gt; SageMaker &gt; Studio Lifecycle Config &gt; Allowed &gt; Region
  - AWS &gt; SageMaker &gt; Studio Lifecycle Config &gt; CMDB
  - AWS &gt; SageMaker &gt; Studio Lifecycle Config &gt; Discovery
  - AWS &gt; SageMaker &gt; Studio Lifecycle Config &gt; Tags
  - AWS &gt; SageMaker &gt; User Profile &gt; Active
  - AWS &gt; SageMaker &gt; User Profile &gt; Allowed
  - AWS &gt; SageMaker &gt; User Profile &gt; Allowed &gt; Custom
  - AWS &gt; SageMaker &gt; User Profile &gt; Allowed &gt; Region
  - AWS &gt; SageMaker &gt; User Profile &gt; CMDB
  - AWS &gt; SageMaker &gt; User Profile &gt; Discovery
  - AWS &gt; SageMaker &gt; User Profile &gt; Tags

- Policy Types:
  - AWS &gt; SageMaker &gt; Allowed Regions [Default]
  - AWS &gt; SageMaker &gt; App &gt; Active
  - AWS &gt; SageMaker &gt; App &gt; Active &gt; Age
  - AWS &gt; SageMaker &gt; App &gt; Active &gt; Last Modified
  - AWS &gt; SageMaker &gt; App &gt; Allowed
  - AWS &gt; SageMaker &gt; App &gt; Allowed &gt; Custom
  - AWS &gt; SageMaker &gt; App &gt; Allowed &gt; Custom &gt; Rules
  - AWS &gt; SageMaker &gt; App &gt; Allowed &gt; Region
  - AWS &gt; SageMaker &gt; App &gt; Allowed &gt; Region &gt; Regions
  - AWS &gt; SageMaker &gt; App &gt; CMDB
  - AWS &gt; SageMaker &gt; App &gt; Regions
  - AWS &gt; SageMaker &gt; App &gt; Tags
  - AWS &gt; SageMaker &gt; App &gt; Tags &gt; Template
  - AWS &gt; SageMaker &gt; Cluster &gt; Active
  - AWS &gt; SageMaker &gt; Cluster &gt; Active &gt; Age
  - AWS &gt; SageMaker &gt; Cluster &gt; Active &gt; Last Modified
  - AWS &gt; SageMaker &gt; Cluster &gt; Allowed
  - AWS &gt; SageMaker &gt; Cluster &gt; Allowed &gt; Custom
  - AWS &gt; SageMaker &gt; Cluster &gt; Allowed &gt; Custom &gt; Rules
  - AWS &gt; SageMaker &gt; Cluster &gt; Allowed &gt; Region
  - AWS &gt; SageMaker &gt; Cluster &gt; Allowed &gt; Region &gt; Regions
  - AWS &gt; SageMaker &gt; Cluster &gt; CMDB
  - AWS &gt; SageMaker &gt; Cluster &gt; Regions
  - AWS &gt; SageMaker &gt; Cluster &gt; Tags
  - AWS &gt; SageMaker &gt; Cluster &gt; Tags &gt; Template
  - AWS &gt; SageMaker &gt; Image &gt; Active
  - AWS &gt; SageMaker &gt; Image &gt; Active &gt; Age
  - AWS &gt; SageMaker &gt; Image &gt; Active &gt; Last Modified
  - AWS &gt; SageMaker &gt; Image &gt; Allowed
  - AWS &gt; SageMaker &gt; Image &gt; Allowed &gt; Custom
  - AWS &gt; SageMaker &gt; Image &gt; Allowed &gt; Custom &gt; Rules
  - AWS &gt; SageMaker &gt; Image &gt; Allowed &gt; Region
  - AWS &gt; SageMaker &gt; Image &gt; Allowed &gt; Region &gt; Regions
  - AWS &gt; SageMaker &gt; Image &gt; CMDB
  - AWS &gt; SageMaker &gt; Image &gt; Regions
  - AWS &gt; SageMaker &gt; Image &gt; Tags
  - AWS &gt; SageMaker &gt; Image &gt; Tags &gt; Template
  - AWS &gt; SageMaker &gt; Pipeline &gt; Active
  - AWS &gt; SageMaker &gt; Pipeline &gt; Active &gt; Age
  - AWS &gt; SageMaker &gt; Pipeline &gt; Active &gt; Last Modified
  - AWS &gt; SageMaker &gt; Pipeline &gt; Allowed
  - AWS &gt; SageMaker &gt; Pipeline &gt; Allowed &gt; Custom
  - AWS &gt; SageMaker &gt; Pipeline &gt; Allowed &gt; Custom &gt; Rules
  - AWS &gt; SageMaker &gt; Pipeline &gt; Allowed &gt; Region
  - AWS &gt; SageMaker &gt; Pipeline &gt; Allowed &gt; Region &gt; Regions
  - AWS &gt; SageMaker &gt; Pipeline &gt; CMDB
  - AWS &gt; SageMaker &gt; Pipeline &gt; Regions
  - AWS &gt; SageMaker &gt; Pipeline &gt; Tags
  - AWS &gt; SageMaker &gt; Pipeline &gt; Tags &gt; Template
  - AWS &gt; SageMaker &gt; Processing Job &gt; Active
  - AWS &gt; SageMaker &gt; Processing Job &gt; Active &gt; Age
  - AWS &gt; SageMaker &gt; Processing Job &gt; Active &gt; Last Modified
  - AWS &gt; SageMaker &gt; Processing Job &gt; Allowed
  - AWS &gt; SageMaker &gt; Processing Job &gt; Allowed &gt; Custom
  - AWS &gt; SageMaker &gt; Processing Job &gt; Allowed &gt; Custom &gt; Rules
  - AWS &gt; SageMaker &gt; Processing Job &gt; Allowed &gt; Region
  - AWS &gt; SageMaker &gt; Processing Job &gt; Allowed &gt; Region &gt; Regions
  - AWS &gt; SageMaker &gt; Processing Job &gt; CMDB
  - AWS &gt; SageMaker &gt; Processing Job &gt; Regions
  - AWS &gt; SageMaker &gt; Processing Job &gt; Tags
  - AWS &gt; SageMaker &gt; Processing Job &gt; Tags &gt; Template
  - AWS &gt; SageMaker &gt; Project &gt; Active
  - AWS &gt; SageMaker &gt; Project &gt; Active &gt; Age
  - AWS &gt; SageMaker &gt; Project &gt; Active &gt; Last Modified
  - AWS &gt; SageMaker &gt; Project &gt; Allowed
  - AWS &gt; SageMaker &gt; Project &gt; Allowed &gt; Custom
  - AWS &gt; SageMaker &gt; Project &gt; Allowed &gt; Custom &gt; Rules
  - AWS &gt; SageMaker &gt; Project &gt; Allowed &gt; Region
  - AWS &gt; SageMaker &gt; Project &gt; Allowed &gt; Region &gt; Regions
  - AWS &gt; SageMaker &gt; Project &gt; CMDB
  - AWS &gt; SageMaker &gt; Project &gt; Regions
  - AWS &gt; SageMaker &gt; Project &gt; Tags
  - AWS &gt; SageMaker &gt; Project &gt; Tags &gt; Template
  - AWS &gt; SageMaker &gt; Project &gt; Usage
  - AWS &gt; SageMaker &gt; Project &gt; Usage &gt; Limit
  - AWS &gt; SageMaker &gt; Studio Lifecycle Config &gt; Active
  - AWS &gt; SageMaker &gt; Studio Lifecycle Config &gt; Active &gt; Age
  - AWS &gt; SageMaker &gt; Studio Lifecycle Config &gt; Active &gt; Last Modified
  - AWS &gt; SageMaker &gt; Studio Lifecycle Config &gt; Allowed
  - AWS &gt; SageMaker &gt; Studio Lifecycle Config &gt; Allowed &gt; Custom
  - AWS &gt; SageMaker &gt; Studio Lifecycle Config &gt; Allowed &gt; Custom &gt; Rules
  - AWS &gt; SageMaker &gt; Studio Lifecycle Config &gt; Allowed &gt; Region
  - AWS &gt; SageMaker &gt; Studio Lifecycle Config &gt; Allowed &gt; Region &gt; Regions
  - AWS &gt; SageMaker &gt; Studio Lifecycle Config &gt; CMDB
  - AWS &gt; SageMaker &gt; Studio Lifecycle Config &gt; Regions
  - AWS &gt; SageMaker &gt; Studio Lifecycle Config &gt; Tags
  - AWS &gt; SageMaker &gt; Studio Lifecycle Config &gt; Tags &gt; Template
  - AWS &gt; SageMaker &gt; User Profile &gt; Active
  - AWS &gt; SageMaker &gt; User Profile &gt; Active &gt; Age
  - AWS &gt; SageMaker &gt; User Profile &gt; Active &gt; Last Modified
  - AWS &gt; SageMaker &gt; User Profile &gt; Allowed
  - AWS &gt; SageMaker &gt; User Profile &gt; Allowed &gt; Custom
  - AWS &gt; SageMaker &gt; User Profile &gt; Allowed &gt; Custom &gt; Rules
  - AWS &gt; SageMaker &gt; User Profile &gt; Allowed &gt; Region
  - AWS &gt; SageMaker &gt; User Profile &gt; Allowed &gt; Region &gt; Regions
  - AWS &gt; SageMaker &gt; User Profile &gt; CMDB
  - AWS &gt; SageMaker &gt; User Profile &gt; Regions
  - AWS &gt; SageMaker &gt; User Profile &gt; Tags
  - AWS &gt; SageMaker &gt; User Profile &gt; Tags &gt; Template

- Action Types:
  - AWS &gt; SageMaker &gt; App &gt; Delete
  - AWS &gt; SageMaker &gt; App &gt; Delete from AWS
  - AWS &gt; SageMaker &gt; App &gt; Router
  - AWS &gt; SageMaker &gt; App &gt; Set Tags
  - AWS &gt; SageMaker &gt; App &gt; Skip alarm for Active control
  - AWS &gt; SageMaker &gt; App &gt; Skip alarm for Active control [90 days]
  - AWS &gt; SageMaker &gt; App &gt; Skip alarm for Tags control
  - AWS &gt; SageMaker &gt; App &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; SageMaker &gt; App &gt; Update Tags
  - AWS &gt; SageMaker &gt; Cluster &gt; Delete
  - AWS &gt; SageMaker &gt; Cluster &gt; Delete from AWS
  - AWS &gt; SageMaker &gt; Cluster &gt; Router
  - AWS &gt; SageMaker &gt; Cluster &gt; Set Tags
  - AWS &gt; SageMaker &gt; Cluster &gt; Skip alarm for Active control
  - AWS &gt; SageMaker &gt; Cluster &gt; Skip alarm for Active control [90 days]
  - AWS &gt; SageMaker &gt; Cluster &gt; Skip alarm for Tags control
  - AWS &gt; SageMaker &gt; Cluster &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; SageMaker &gt; Cluster &gt; Update Tags
  - AWS &gt; SageMaker &gt; Image &gt; Delete
  - AWS &gt; SageMaker &gt; Image &gt; Delete from AWS
  - AWS &gt; SageMaker &gt; Image &gt; Router
  - AWS &gt; SageMaker &gt; Image &gt; Set Tags
  - AWS &gt; SageMaker &gt; Image &gt; Skip alarm for Active control
  - AWS &gt; SageMaker &gt; Image &gt; Skip alarm for Active control [90 days]
  - AWS &gt; SageMaker &gt; Image &gt; Skip alarm for Tags control
  - AWS &gt; SageMaker &gt; Image &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; SageMaker &gt; Image &gt; Update Tags
  - AWS &gt; SageMaker &gt; Pipeline &gt; Delete
  - AWS &gt; SageMaker &gt; Pipeline &gt; Delete from AWS
  - AWS &gt; SageMaker &gt; Pipeline &gt; Router
  - AWS &gt; SageMaker &gt; Pipeline &gt; Set Tags
  - AWS &gt; SageMaker &gt; Pipeline &gt; Skip alarm for Active control
  - AWS &gt; SageMaker &gt; Pipeline &gt; Skip alarm for Active control [90 days]
  - AWS &gt; SageMaker &gt; Pipeline &gt; Skip alarm for Approved control
  - AWS &gt; SageMaker &gt; Pipeline &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; SageMaker &gt; Pipeline &gt; Skip alarm for Tags control
  - AWS &gt; SageMaker &gt; Pipeline &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; SageMaker &gt; Pipeline &gt; Update Tags
  - AWS &gt; SageMaker &gt; Processing Job &gt; Delete
  - AWS &gt; SageMaker &gt; Processing Job &gt; Delete from AWS
  - AWS &gt; SageMaker &gt; Processing Job &gt; Router
  - AWS &gt; SageMaker &gt; Processing Job &gt; Set Tags
  - AWS &gt; SageMaker &gt; Processing Job &gt; Skip alarm for Active control
  - AWS &gt; SageMaker &gt; Processing Job &gt; Skip alarm for Active control [90 days]
  - AWS &gt; SageMaker &gt; Processing Job &gt; Skip alarm for Approved control
  - AWS &gt; SageMaker &gt; Processing Job &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; SageMaker &gt; Processing Job &gt; Skip alarm for Tags control
  - AWS &gt; SageMaker &gt; Processing Job &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; SageMaker &gt; Processing Job &gt; Update Tags
  - AWS &gt; SageMaker &gt; Project &gt; Delete
  - AWS &gt; SageMaker &gt; Project &gt; Delete from AWS
  - AWS &gt; SageMaker &gt; Project &gt; Router
  - AWS &gt; SageMaker &gt; Project &gt; Set Tags
  - AWS &gt; SageMaker &gt; Project &gt; Skip alarm for Active control
  - AWS &gt; SageMaker &gt; Project &gt; Skip alarm for Active control [90 days]
  - AWS &gt; SageMaker &gt; Project &gt; Skip alarm for Tags control
  - AWS &gt; SageMaker &gt; Project &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; SageMaker &gt; Project &gt; Update Tags
  - AWS &gt; SageMaker &gt; Studio Lifecycle Config &gt; Delete
  - AWS &gt; SageMaker &gt; Studio Lifecycle Config &gt; Delete from AWS
  - AWS &gt; SageMaker &gt; Studio Lifecycle Config &gt; Router
  - AWS &gt; SageMaker &gt; Studio Lifecycle Config &gt; Set Tags
  - AWS &gt; SageMaker &gt; Studio Lifecycle Config &gt; Skip alarm for Active control
  - AWS &gt; SageMaker &gt; Studio Lifecycle Config &gt; Skip alarm for Active control [90 days]
  - AWS &gt; SageMaker &gt; Studio Lifecycle Config &gt; Skip alarm for Tags control
  - AWS &gt; SageMaker &gt; Studio Lifecycle Config &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; SageMaker &gt; Studio Lifecycle Config &gt; Update Tags
  - AWS &gt; SageMaker &gt; User Profile &gt; Delete
  - AWS &gt; SageMaker &gt; User Profile &gt; Delete from AWS
  - AWS &gt; SageMaker &gt; User Profile &gt; Router
  - AWS &gt; SageMaker &gt; User Profile &gt; Set Tags
  - AWS &gt; SageMaker &gt; User Profile &gt; Skip alarm for Active control
  - AWS &gt; SageMaker &gt; User Profile &gt; Skip alarm for Active control [90 days]
  - AWS &gt; SageMaker &gt; User Profile &gt; Skip alarm for Tags control
  - AWS &gt; SageMaker &gt; User Profile &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; SageMaker &gt; User Profile &gt; Update Tags</description>
            <pubDate>Wed, 21 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/turbot-guardrails-cli-v1-31-1</guid>
            <title>Turbot Guardrails CLI v1.31.1 - Stability improvements and enhanced inspection</title>
            <link>https://turbot.com/guardrails/changelog/turbot-guardrails-cli-v1-31-1</link>
            <description>_What&apos;s new?_

- Added `--verbose` flag to `turbot inspect` command to **display full prevention details**, providing deeper visibility into policy enforcement and prevention actions.
- Renamed CLI binary from `turbot-macos*` to `turbot` for **consistent cross-platform experience** and simplified installation.

_Bug fixes_

- Fixed CLI failures on macOS after extended inactivity caused by temporary directory cleanup, improving **long-running session stability**.
- Resolved whitespace formatting issues in `turbot inspect` command output for improved readability.</description>
            <pubDate>Wed, 21 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-54-11</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.54.11 - Version bump to align with deployment requirements</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-54-11</link>
            <description>Version bump to align with deployment requirements.

_Requirements_

- Upgrade to `5.54.11` requires your workspace to be on `5.53.x`
- PostgreSQL (RDS engine): &gt;= 15
- TEF: 1.66.0
- TED: 1.37.0
- Mods:
  - @turbot/turbot: 5.56.0

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Mon, 19 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-54-10</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.54.10 - Version bump to align with deployment requirements</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-54-10</link>
            <description>Version bump to align with deployment requirements.

_Requirements_

- Upgrade to `5.54.10` requires your workspace to be on `5.53.x`
- PostgreSQL (RDS engine): &gt;= 15
- TEF: 1.66.0
- TED: 1.37.0
- Mods:
  - @turbot/turbot: 5.56.0

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Mon, 19 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-mskconnect-v5-0-0</guid>
            <title>aws-mskconnect v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/aws-mskconnect-v5-0-0</link>
            <description>_What&apos;s new?_

- Resource Types:

  - AWS &gt; MSK Connect
  - AWS &gt; MSK Connect &gt; Connector

- Control Types:

  - AWS &gt; MSK Connect &gt; Connector &gt; Allowed
  - AWS &gt; MSK Connect &gt; Connector &gt; Allowed &gt; Custom
  - AWS &gt; MSK Connect &gt; Connector &gt; Allowed &gt; Region
  - AWS &gt; MSK Connect &gt; Connector &gt; CMDB
  - AWS &gt; MSK Connect &gt; Connector &gt; Discovery
  - AWS &gt; MSK Connect &gt; Connector &gt; Tags

- Policy Types:

  - AWS &gt; MSK Connect &gt; API Enabled
  - AWS &gt; MSK Connect &gt; Allowed Regions [Default]
  - AWS &gt; MSK Connect &gt; Approved Regions [Default]
  - AWS &gt; MSK Connect &gt; Connector &gt; Allowed
  - AWS &gt; MSK Connect &gt; Connector &gt; Allowed &gt; Custom
  - AWS &gt; MSK Connect &gt; Connector &gt; Allowed &gt; Custom &gt; Rules
  - AWS &gt; MSK Connect &gt; Connector &gt; Allowed &gt; Region
  - AWS &gt; MSK Connect &gt; Connector &gt; Allowed &gt; Region &gt; Regions
  - AWS &gt; MSK Connect &gt; Connector &gt; CMDB
  - AWS &gt; MSK Connect &gt; Connector &gt; Regions
  - AWS &gt; MSK Connect &gt; Connector &gt; Tags
  - AWS &gt; MSK Connect &gt; Connector &gt; Tags &gt; Template
  - AWS &gt; MSK Connect &gt; Enabled
  - AWS &gt; MSK Connect &gt; Permissions
  - AWS &gt; MSK Connect &gt; Permissions &gt; Levels
  - AWS &gt; MSK Connect &gt; Permissions &gt; Levels &gt; Modifiers
  - AWS &gt; MSK Connect &gt; Permissions &gt; Lockdown
  - AWS &gt; MSK Connect &gt; Permissions &gt; Lockdown &gt; API Boundary
  - AWS &gt; MSK Connect &gt; Regions
  - AWS &gt; MSK Connect &gt; Tags Template [Default]
  - AWS &gt; Turbot &gt; Event Handlers &gt; Events &gt; Rules &gt; Event Sources &gt; @turbot/aws-mskconnect
  - AWS &gt; Turbot &gt; Permissions &gt; Compiled &gt; API Boundary &gt; @turbot/aws-mskconnect
  - AWS &gt; Turbot &gt; Permissions &gt; Compiled &gt; Levels &gt; @turbot/aws-mskconnect
  - AWS &gt; Turbot &gt; Permissions &gt; Compiled &gt; Service Permissions &gt; @turbot/aws-mskconnect

- Action Types:

  - AWS &gt; MSK Connect &gt; Connector &gt; Delete
  - AWS &gt; MSK Connect &gt; Connector &gt; Delete from AWS
  - AWS &gt; MSK Connect &gt; Connector &gt; Router
  - AWS &gt; MSK Connect &gt; Connector &gt; Set Tags
  - AWS &gt; MSK Connect &gt; Connector &gt; Skip alarm for Tags control
  - AWS &gt; MSK Connect &gt; Connector &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; MSK Connect &gt; Connector &gt; Update Tags</description>
            <pubDate>Mon, 19 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-apigateway-v5-16-0</guid>
            <title>aws-apigateway v5.16.0 - Track and manage VPC link V2 resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/aws-apigateway-v5-16-0</link>
            <description>_What&apos;s new?_

- Resource Types:

  - AWS &gt; API Gateway &gt; VPC Link V2

- Control Types:

  - AWS &gt; API Gateway &gt; VPC Link V2 &gt; Active
  - AWS &gt; API Gateway &gt; VPC Link V2 &gt; Allowed
  - AWS &gt; API Gateway &gt; VPC Link V2 &gt; Allowed &gt; Custom
  - AWS &gt; API Gateway &gt; VPC Link V2 &gt; Allowed &gt; Region
  - AWS &gt; API Gateway &gt; VPC Link V2 &gt; CMDB
  - AWS &gt; API Gateway &gt; VPC Link V2 &gt; Discovery
  - AWS &gt; API Gateway &gt; VPC Link V2 &gt; Tags
  - AWS &gt; API Gateway &gt; VPC Link V2 &gt; Usage

- Policy Types:

  - AWS &gt; API Gateway &gt; VPC Link V2 &gt; Active
  - AWS &gt; API Gateway &gt; VPC Link V2 &gt; Active &gt; Age
  - AWS &gt; API Gateway &gt; VPC Link V2 &gt; Active &gt; Last Modified
  - AWS &gt; API Gateway &gt; VPC Link V2 &gt; Allowed
  - AWS &gt; API Gateway &gt; VPC Link V2 &gt; Allowed &gt; Custom
  - AWS &gt; API Gateway &gt; VPC Link V2 &gt; Allowed &gt; Custom &gt; Rules
  - AWS &gt; API Gateway &gt; VPC Link V2 &gt; Allowed &gt; Region
  - AWS &gt; API Gateway &gt; VPC Link V2 &gt; Allowed &gt; Region &gt; Regions
  - AWS &gt; API Gateway &gt; VPC Link V2 &gt; CMDB
  - AWS &gt; API Gateway &gt; VPC Link V2 &gt; Regions
  - AWS &gt; API Gateway &gt; VPC Link V2 &gt; Tags
  - AWS &gt; API Gateway &gt; VPC Link V2 &gt; Tags &gt; Template
  - AWS &gt; API Gateway &gt; VPC Link V2 &gt; Usage
  - AWS &gt; API Gateway &gt; VPC Link V2 &gt; Usage &gt; Limit

- Action Types:

  - AWS &gt; API Gateway &gt; VPC Link V2 &gt; Delete
  - AWS &gt; API Gateway &gt; VPC Link V2 &gt; Delete from AWS
  - AWS &gt; API Gateway &gt; VPC Link V2 &gt; Router
  - AWS &gt; API Gateway &gt; VPC Link V2 &gt; Set Tags
  - AWS &gt; API Gateway &gt; VPC Link V2 &gt; Skip alarm for Active control
  - AWS &gt; API Gateway &gt; VPC Link V2 &gt; Skip alarm for Active control [90 days]
  - AWS &gt; API Gateway &gt; VPC Link V2 &gt; Skip alarm for Tags control
  - AWS &gt; API Gateway &gt; VPC Link V2 &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; API Gateway &gt; VPC Link V2 &gt; Update Tags</description>
            <pubDate>Mon, 19 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-54-9</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.54.9 - Fixed policy setting creation deadlock</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-54-9</link>
            <description>_Bug fixes_

- Server
  - Fixed an issue where policy setting creation was causing a JS deadlock while waiting for a transaction in the connection pool.

_Requirements_

- Upgrade to `5.54.9` requires your workspace to be on `5.53.x`
- PostgreSQL (RDS engine): &gt;= 15
- TEF: 1.66.0
- TED: 1.37.0
- Mods:
  - @turbot/turbot: 5.56.0

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Fri, 16 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-v5-43-2</guid>
            <title>aws v5.43.2 - Organization Discovery Level policy will now run in the priority queue</title>
            <link>https://turbot.com/guardrails/changelog/aws-v5-43-2</link>
            <description>_Bug fixes_

- The `AWS &gt; Organization &gt; Discovery Level` policy will now run in the priority queue.</description>
            <pubDate>Fri, 16 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-transfer-v5-3-0</guid>
            <title>aws-transfer v5.3.0 - Track and manage server and connector resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/aws-transfer-v5-3-0</link>
            <description>_What&apos;s new?_

- Resource Types:

  - AWS &gt; Transfer for SFTP &gt; Connector
  - AWS &gt; Transfer for SFTP &gt; Server

- Control Types:

  - AWS &gt; Transfer for SFTP &gt; Connector &gt; Active
  - AWS &gt; Transfer for SFTP &gt; Connector &gt; Allowed
  - AWS &gt; Transfer for SFTP &gt; Connector &gt; Allowed &gt; Custom
  - AWS &gt; Transfer for SFTP &gt; Connector &gt; Allowed &gt; Region
  - AWS &gt; Transfer for SFTP &gt; Connector &gt; CMDB
  - AWS &gt; Transfer for SFTP &gt; Connector &gt; Discovery
  - AWS &gt; Transfer for SFTP &gt; Connector &gt; Tags
  - AWS &gt; Transfer for SFTP &gt; Server &gt; Active
  - AWS &gt; Transfer for SFTP &gt; Server &gt; Allowed
  - AWS &gt; Transfer for SFTP &gt; Server &gt; Allowed &gt; Custom
  - AWS &gt; Transfer for SFTP &gt; Server &gt; Allowed &gt; Region
  - AWS &gt; Transfer for SFTP &gt; Server &gt; CMDB
  - AWS &gt; Transfer for SFTP &gt; Server &gt; Discovery
  - AWS &gt; Transfer for SFTP &gt; Server &gt; Tags

- Policy Types:

  - AWS &gt; Transfer for SFTP &gt; Allowed Regions [Default]
  - AWS &gt; Transfer for SFTP &gt; Connector &gt; Active
  - AWS &gt; Transfer for SFTP &gt; Connector &gt; Active &gt; Age
  - AWS &gt; Transfer for SFTP &gt; Connector &gt; Active &gt; Last Modified
  - AWS &gt; Transfer for SFTP &gt; Connector &gt; Allowed
  - AWS &gt; Transfer for SFTP &gt; Connector &gt; Allowed &gt; Custom
  - AWS &gt; Transfer for SFTP &gt; Connector &gt; Allowed &gt; Custom &gt; Rules
  - AWS &gt; Transfer for SFTP &gt; Connector &gt; Allowed &gt; Region
  - AWS &gt; Transfer for SFTP &gt; Connector &gt; Allowed &gt; Region &gt; Regions
  - AWS &gt; Transfer for SFTP &gt; Connector &gt; CMDB
  - AWS &gt; Transfer for SFTP &gt; Connector &gt; Regions
  - AWS &gt; Transfer for SFTP &gt; Connector &gt; Tags
  - AWS &gt; Transfer for SFTP &gt; Connector &gt; Tags &gt; Template
  - AWS &gt; Transfer for SFTP &gt; Server &gt; Active
  - AWS &gt; Transfer for SFTP &gt; Server &gt; Active &gt; Age
  - AWS &gt; Transfer for SFTP &gt; Server &gt; Active &gt; Last Modified
  - AWS &gt; Transfer for SFTP &gt; Server &gt; Allowed
  - AWS &gt; Transfer for SFTP &gt; Server &gt; Allowed &gt; Custom
  - AWS &gt; Transfer for SFTP &gt; Server &gt; Allowed &gt; Custom &gt; Rules
  - AWS &gt; Transfer for SFTP &gt; Server &gt; Allowed &gt; Region
  - AWS &gt; Transfer for SFTP &gt; Server &gt; Allowed &gt; Region &gt; Regions
  - AWS &gt; Transfer for SFTP &gt; Server &gt; CMDB
  - AWS &gt; Transfer for SFTP &gt; Server &gt; Regions
  - AWS &gt; Transfer for SFTP &gt; Server &gt; Tags
  - AWS &gt; Transfer for SFTP &gt; Server &gt; Tags &gt; Template

- Action Types:

  - AWS &gt; Transfer for SFTP &gt; Connector &gt; Delete
  - AWS &gt; Transfer for SFTP &gt; Connector &gt; Delete from AWS
  - AWS &gt; Transfer for SFTP &gt; Connector &gt; Router
  - AWS &gt; Transfer for SFTP &gt; Connector &gt; Set Tags
  - AWS &gt; Transfer for SFTP &gt; Connector &gt; Skip alarm for Active control
  - AWS &gt; Transfer for SFTP &gt; Connector &gt; Skip alarm for Active control [90 days]
  - AWS &gt; Transfer for SFTP &gt; Connector &gt; Skip alarm for Tags control
  - AWS &gt; Transfer for SFTP &gt; Connector &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; Transfer for SFTP &gt; Connector &gt; Update Tags
  - AWS &gt; Transfer for SFTP &gt; Server &gt; Delete
  - AWS &gt; Transfer for SFTP &gt; Server &gt; Delete from AWS
  - AWS &gt; Transfer for SFTP &gt; Server &gt; Router
  - AWS &gt; Transfer for SFTP &gt; Server &gt; Set Tags
  - AWS &gt; Transfer for SFTP &gt; Server &gt; Skip alarm for Active control
  - AWS &gt; Transfer for SFTP &gt; Server &gt; Skip alarm for Active control [90 days]
  - AWS &gt; Transfer for SFTP &gt; Server &gt; Skip alarm for Tags control
  - AWS &gt; Transfer for SFTP &gt; Server &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; Transfer for SFTP &gt; Server &gt; Update Tags</description>
            <pubDate>Fri, 16 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-rds-v5-34-0</guid>
            <title>aws-rds v5.34.0 - Identify and remove unallowed resources from CMDB</title>
            <link>https://turbot.com/guardrails/changelog/aws-rds-v5-34-0</link>
            <description>_What&apos;s new?_

_Control Types_

- AWS &gt; RDS &gt; DB Cluster &gt; Allowed
- AWS &gt; RDS &gt; DB Cluster &gt; Allowed &gt; Custom
- AWS &gt; RDS &gt; DB Cluster &gt; Allowed &gt; Encryption at Rest
- AWS &gt; RDS &gt; DB Cluster &gt; Allowed &gt; Region
- AWS &gt; RDS &gt; DB Cluster Parameter Group &gt; Allowed
- AWS &gt; RDS &gt; DB Cluster Parameter Group &gt; Allowed &gt; Custom
- AWS &gt; RDS &gt; DB Cluster Parameter Group &gt; Allowed &gt; Region
- AWS &gt; RDS &gt; DB Cluster Snapshot [Manual] &gt; Allowed
- AWS &gt; RDS &gt; DB Cluster Snapshot [Manual] &gt; Allowed &gt; Custom
- AWS &gt; RDS &gt; DB Cluster Snapshot [Manual] &gt; Allowed &gt; Region
- AWS &gt; RDS &gt; DB Instance &gt; Allowed
- AWS &gt; RDS &gt; DB Instance &gt; Allowed &gt; Custom
- AWS &gt; RDS &gt; DB Instance &gt; Allowed &gt; Database Engine
- AWS &gt; RDS &gt; DB Instance &gt; Allowed &gt; Encryption at Rest
- AWS &gt; RDS &gt; DB Instance &gt; Allowed &gt; Instance Class
- AWS &gt; RDS &gt; DB Instance &gt; Allowed &gt; Region
- AWS &gt; RDS &gt; DB Parameter Group &gt; Allowed
- AWS &gt; RDS &gt; DB Parameter Group &gt; Allowed &gt; Custom
- AWS &gt; RDS &gt; DB Parameter Group &gt; Allowed &gt; Region
- AWS &gt; RDS &gt; DB Snapshot [Manual] &gt; Allowed
- AWS &gt; RDS &gt; DB Snapshot [Manual] &gt; Allowed &gt; Custom
- AWS &gt; RDS &gt; DB Snapshot [Manual] &gt; Allowed &gt; Encryption at Rest
- AWS &gt; RDS &gt; DB Snapshot [Manual] &gt; Allowed &gt; Region
- AWS &gt; RDS &gt; Global Cluster &gt; Allowed
- AWS &gt; RDS &gt; Global Cluster &gt; Allowed &gt; Custom
- AWS &gt; RDS &gt; Option Group &gt; Allowed
- AWS &gt; RDS &gt; Option Group &gt; Allowed &gt; Custom
- AWS &gt; RDS &gt; Option Group &gt; Allowed &gt; Region
- AWS &gt; RDS &gt; Subnet Group &gt; Allowed
- AWS &gt; RDS &gt; Subnet Group &gt; Allowed &gt; Custom
- AWS &gt; RDS &gt; Subnet Group &gt; Allowed &gt; Region

_Policy Types_

- AWS &gt; RDS &gt; Allowed Regions [Default]
- AWS &gt; RDS &gt; DB Cluster &gt; Allowed
- AWS &gt; RDS &gt; DB Cluster &gt; Allowed &gt; Custom
- AWS &gt; RDS &gt; DB Cluster &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; RDS &gt; DB Cluster &gt; Allowed &gt; Encryption at Rest
- AWS &gt; RDS &gt; DB Cluster &gt; Allowed &gt; Encryption at Rest &gt; Level
- AWS &gt; RDS &gt; DB Cluster &gt; Allowed &gt; Encryption at Rest &gt; Level &gt; Customer Managed Key
- AWS &gt; RDS &gt; DB Cluster &gt; Allowed &gt; Region
- AWS &gt; RDS &gt; DB Cluster &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; RDS &gt; DB Cluster Parameter Group &gt; Allowed
- AWS &gt; RDS &gt; DB Cluster Parameter Group &gt; Allowed &gt; Custom
- AWS &gt; RDS &gt; DB Cluster Parameter Group &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; RDS &gt; DB Cluster Parameter Group &gt; Allowed &gt; Region
- AWS &gt; RDS &gt; DB Cluster Parameter Group &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; RDS &gt; DB Cluster Snapshot [Manual] &gt; Allowed
- AWS &gt; RDS &gt; DB Cluster Snapshot [Manual] &gt; Allowed &gt; Custom
- AWS &gt; RDS &gt; DB Cluster Snapshot [Manual] &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; RDS &gt; DB Cluster Snapshot [Manual] &gt; Allowed &gt; Region
- AWS &gt; RDS &gt; DB Cluster Snapshot [Manual] &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; RDS &gt; DB Instance &gt; Allowed
- AWS &gt; RDS &gt; DB Instance &gt; Allowed &gt; Custom
- AWS &gt; RDS &gt; DB Instance &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; RDS &gt; DB Instance &gt; Allowed &gt; Database Engine
- AWS &gt; RDS &gt; DB Instance &gt; Allowed &gt; Database Engine &gt; Engines
- AWS &gt; RDS &gt; DB Instance &gt; Allowed &gt; Encryption at Rest
- AWS &gt; RDS &gt; DB Instance &gt; Allowed &gt; Encryption at Rest &gt; Level
- AWS &gt; RDS &gt; DB Instance &gt; Allowed &gt; Encryption at Rest &gt; Level &gt; Customer Managed Key
- AWS &gt; RDS &gt; DB Instance &gt; Allowed &gt; Instance Class
- AWS &gt; RDS &gt; DB Instance &gt; Allowed &gt; Instance Class &gt; Classes
- AWS &gt; RDS &gt; DB Instance &gt; Allowed &gt; Region
- AWS &gt; RDS &gt; DB Instance &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; RDS &gt; DB Parameter Group &gt; Allowed
- AWS &gt; RDS &gt; DB Parameter Group &gt; Allowed &gt; Custom
- AWS &gt; RDS &gt; DB Parameter Group &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; RDS &gt; DB Parameter Group &gt; Allowed &gt; Region
- AWS &gt; RDS &gt; DB Parameter Group &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; RDS &gt; DB Snapshot [Manual] &gt; Allowed
- AWS &gt; RDS &gt; DB Snapshot [Manual] &gt; Allowed &gt; Custom
- AWS &gt; RDS &gt; DB Snapshot [Manual] &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; RDS &gt; DB Snapshot [Manual] &gt; Allowed &gt; Encryption at Rest
- AWS &gt; RDS &gt; DB Snapshot [Manual] &gt; Allowed &gt; Encryption at Rest &gt; Level
- AWS &gt; RDS &gt; DB Snapshot [Manual] &gt; Allowed &gt; Encryption at Rest &gt; Level &gt; Customer Managed Key
- AWS &gt; RDS &gt; DB Snapshot [Manual] &gt; Allowed &gt; Region
- AWS &gt; RDS &gt; DB Snapshot [Manual] &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; RDS &gt; Global Cluster &gt; Allowed
- AWS &gt; RDS &gt; Global Cluster &gt; Allowed &gt; Custom
- AWS &gt; RDS &gt; Global Cluster &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; RDS &gt; Option Group &gt; Allowed
- AWS &gt; RDS &gt; Option Group &gt; Allowed &gt; Custom
- AWS &gt; RDS &gt; Option Group &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; RDS &gt; Option Group &gt; Allowed &gt; Region
- AWS &gt; RDS &gt; Option Group &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; RDS &gt; Subnet Group &gt; Allowed
- AWS &gt; RDS &gt; Subnet Group &gt; Allowed &gt; Custom
- AWS &gt; RDS &gt; Subnet Group &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; RDS &gt; Subnet Group &gt; Allowed &gt; Region
- AWS &gt; RDS &gt; Subnet Group &gt; Allowed &gt; Region &gt; Regions

_Bug fixes_

- The `AWS &gt; RDS &gt; DB Instance &gt; Approved` control previously entered an alarm state when validating encryption at rest for DB instances encrypted with customer managed keys, particularly when validating against KMS key aliases. The control has been updated to correctly handle both data structure formats, ensuring accurate encryption validation in all cases.</description>
            <pubDate>Fri, 16 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-comprehend-v5-4-0</guid>
            <title>aws-comprehend v5.4.0 - Track and manage document classifier and flywheel resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/aws-comprehend-v5-4-0</link>
            <description>_What&apos;s new?_

- Resource Types:

  - AWS &gt; Comprehend &gt; Document Classifier
  - AWS &gt; Comprehend &gt; Flywheel

- Control Types:

  - AWS &gt; Comprehend &gt; Document Classifier &gt; Active
  - AWS &gt; Comprehend &gt; Document Classifier &gt; Allowed
  - AWS &gt; Comprehend &gt; Document Classifier &gt; Allowed &gt; Custom
  - AWS &gt; Comprehend &gt; Document Classifier &gt; Allowed &gt; Region
  - AWS &gt; Comprehend &gt; Document Classifier &gt; CMDB
  - AWS &gt; Comprehend &gt; Document Classifier &gt; Discovery
  - AWS &gt; Comprehend &gt; Document Classifier &gt; Tags
  - AWS &gt; Comprehend &gt; Document Classifier &gt; Usage
  - AWS &gt; Comprehend &gt; Flywheel &gt; Active
  - AWS &gt; Comprehend &gt; Flywheel &gt; CMDB
  - AWS &gt; Comprehend &gt; Flywheel &gt; Discovery
  - AWS &gt; Comprehend &gt; Flywheel &gt; Tags

- Policy Types:

  - AWS &gt; Comprehend &gt; Document Classifier &gt; Active
  - AWS &gt; Comprehend &gt; Document Classifier &gt; Active &gt; Age
  - AWS &gt; Comprehend &gt; Document Classifier &gt; Active &gt; Last Modified
  - AWS &gt; Comprehend &gt; Document Classifier &gt; Allowed
  - AWS &gt; Comprehend &gt; Document Classifier &gt; Allowed &gt; Custom
  - AWS &gt; Comprehend &gt; Document Classifier &gt; Allowed &gt; Custom &gt; Rules
  - AWS &gt; Comprehend &gt; Document Classifier &gt; Allowed &gt; Region
  - AWS &gt; Comprehend &gt; Document Classifier &gt; Allowed &gt; Region &gt; Regions
  - AWS &gt; Comprehend &gt; Document Classifier &gt; CMDB
  - AWS &gt; Comprehend &gt; Document Classifier &gt; Regions
  - AWS &gt; Comprehend &gt; Document Classifier &gt; Tags
  - AWS &gt; Comprehend &gt; Document Classifier &gt; Tags &gt; Template
  - AWS &gt; Comprehend &gt; Document Classifier &gt; Usage
  - AWS &gt; Comprehend &gt; Document Classifier &gt; Usage &gt; Limit
  - AWS &gt; Comprehend &gt; Flywheel &gt; Active
  - AWS &gt; Comprehend &gt; Flywheel &gt; Active &gt; Age
  - AWS &gt; Comprehend &gt; Flywheel &gt; Active &gt; Last Modified
  - AWS &gt; Comprehend &gt; Flywheel &gt; CMDB
  - AWS &gt; Comprehend &gt; Flywheel &gt; Regions
  - AWS &gt; Comprehend &gt; Flywheel &gt; Tags
  - AWS &gt; Comprehend &gt; Flywheel &gt; Tags &gt; Template
  - AWS &gt; Turbot &gt; Event Handlers &gt; Events &gt; Rules &gt; Custom Event Patterns &gt; @turbot/aws-comprehend

- Action Types:

  - AWS &gt; Comprehend &gt; Document Classifier &gt; Delete
  - AWS &gt; Comprehend &gt; Document Classifier &gt; Delete from AWS
  - AWS &gt; Comprehend &gt; Document Classifier &gt; Router
  - AWS &gt; Comprehend &gt; Document Classifier &gt; Set Tags
  - AWS &gt; Comprehend &gt; Document Classifier &gt; Skip alarm for Active control
  - AWS &gt; Comprehend &gt; Document Classifier &gt; Skip alarm for Active control [90 days]
  - AWS &gt; Comprehend &gt; Document Classifier &gt; Skip alarm for Tags control
  - AWS &gt; Comprehend &gt; Document Classifier &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; Comprehend &gt; Document Classifier &gt; Update Tags
  - AWS &gt; Comprehend &gt; Flywheel &gt; Delete
  - AWS &gt; Comprehend &gt; Flywheel &gt; Delete from AWS
  - AWS &gt; Comprehend &gt; Flywheel &gt; Router
  - AWS &gt; Comprehend &gt; Flywheel &gt; Set Tags
  - AWS &gt; Comprehend &gt; Flywheel &gt; Skip alarm for Active control
  - AWS &gt; Comprehend &gt; Flywheel &gt; Skip alarm for Active control [90 days]
  - AWS &gt; Comprehend &gt; Flywheel &gt; Skip alarm for Tags control
  - AWS &gt; Comprehend &gt; Flywheel &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; Comprehend &gt; Flywheel &gt; Update Tags</description>
            <pubDate>Fri, 16 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-56-0</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.56.0 - Introducing Preventive Security Posture Management (PSPM)</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-56-0</link>
            <description>_What&apos;s new?_

This release introduces Preventive Security Posture Management, a new approach to cloud security that shifts from reactive detection to proactive prevention. Rather than discovering misconfigurations after deployment, Guardrails now helps you block risky changes before they reach your cloud environments.

Key capabilities include:

- **Visualize** your preventive posture across AWS, Azure, and GCP with dashboards that highlight gaps and anomalies.
- **Assess** prevention maturity against industry benchmarks like CIS and NIST, with scoring from Level 0 (no prevention) to Level 5 (defense in depth).
- **Simulate** policy impact by testing against real CloudTrail data before enforcement, so you can see affected accounts and resources without production risk.
- **Deploy** controls with prescriptive recommendations, ready-to-use policy JSON, and tailored guidance while tracking effectiveness over time.

Read more at [turbot.com/blog/2025/12/pspm-announcement](https://turbot.com/blog/2025/12/pspm-announcement).

_Requirements_

- Upgrade to `5.56.0` requires your workspace to be on `5.55.x`
- PostgreSQL (RDS engine): &gt;= 15
- TEF: 1.66.0
- TED: 1.37.0
- Mods:
  - @turbot/turbot: 5.57.0

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Wed, 14 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-v5-43-1</guid>
            <title>aws v5.43.1 - CMDB control for account will no longer enter an error state for workspaces on TE v5.55.0 or lower</title>
            <link>https://turbot.com/guardrails/changelog/aws-v5-43-1</link>
            <description>_Bug fixes_

- The `AWS &gt; Account &gt; CMDB` control entered an error state in workspaces on TE versions 5.55.0 or earlier due to incorrect metadata dependencies. This issue has now been fixed.</description>
            <pubDate>Wed, 14 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-msk-v5-8-1</guid>
            <title>aws-msk v5.8.1 - Fixed incorrect target references in serverless cluster usage control and policies</title>
            <link>https://turbot.com/guardrails/changelog/aws-msk-v5-8-1</link>
            <description>_Bug fixes_

- Fixed incorrect target references in `AWS &gt; MSK &gt; Serverless Cluster &gt; Usage` control and `AWS &gt; MSK &gt; Serverless Cluster &gt; Usage &gt; *` policies.

_Action Types_

_Renamed_

- AWS &gt; MSK &gt; Serverless Cluster &gt; Skip Active alarm to AWS &gt; MSK &gt; Serverless Cluster &gt; Skip alarm for Active control
- AWS &gt; MSK &gt; Serverless Cluster &gt; Skip Active alarm for 90 days to AWS &gt; MSK &gt; Serverless Cluster &gt; Skip alarm for Active control [90 days]</description>
            <pubDate>Wed, 14 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-54-8</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.54.8 - Version bump to align with deployment requirements</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-54-8</link>
            <description>Version bump to align with deployment requirements.

_Requirements_

- Upgrade to `5.54.8` requires your workspace to be on `5.53.x`
- PostgreSQL (RDS engine): &gt;= 15
- TEF: 1.66.0
- TED: 1.37.0
- Mods:
  - @turbot/turbot: 5.56.0

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Tue, 13 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-54-7</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.54.7 - Version bump to align with deployment requirements</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-54-7</link>
            <description>Version bump to align with deployment requirements.

_Requirements_

- Upgrade to `5.54.7` requires your workspace to be on `5.53.x`
- PostgreSQL (RDS engine): &gt;= 15
- TEF: 1.66.0
- TED: 1.37.0
- Mods:
  - @turbot/turbot: 5.56.0

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Tue, 13 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-v5-43-0</guid>
            <title>aws v5.43.0 - CMDB control for organization will no longer enter an error state for workspaces on TE v5.55.0 or lower</title>
            <link>https://turbot.com/guardrails/changelog/aws-v5-43-0</link>
            <description>_Bug fixes_

- The `AWS &gt; Organization &gt; CMDB` control previously entered an error state in workspaces running TE versions earlier than 5.56.0. This issue has now been resolved.
- Added support for `Discovery Level` for Root and Organization Unit resource types.

_What&apos;s new?_

_Policy Types_

- Turbot &gt; Discovery Level &gt; Materialization Exceptions &gt; @turbot/aws</description>
            <pubDate>Tue, 13 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-msk-v5-8-0</guid>
            <title>aws-msk v5.8.0 - Track and manage serverless cluster and VPC connection resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/aws-msk-v5-8-0</link>
            <description>_What&apos;s new?_

- Resource Types:

  - AWS &gt; MSK &gt; Serverless Cluster
  - AWS &gt; MSK &gt; VPC Connection

- Control Types:

  - AWS &gt; MSK &gt; Serverless Cluster &gt; Active
  - AWS &gt; MSK &gt; Serverless Cluster &gt; Allowed
  - AWS &gt; MSK &gt; Serverless Cluster &gt; Allowed &gt; Custom
  - AWS &gt; MSK &gt; Serverless Cluster &gt; Allowed &gt; Region
  - AWS &gt; MSK &gt; Serverless Cluster &gt; CMDB
  - AWS &gt; MSK &gt; Serverless Cluster &gt; Discovery
  - AWS &gt; MSK &gt; Serverless Cluster &gt; Tags
  - AWS &gt; MSK &gt; Serverless Cluster &gt; Usage
  - AWS &gt; MSK &gt; VPC Connection &gt; Active
  - AWS &gt; MSK &gt; VPC Connection &gt; Allowed
  - AWS &gt; MSK &gt; VPC Connection &gt; Allowed &gt; Custom
  - AWS &gt; MSK &gt; VPC Connection &gt; Allowed &gt; Region
  - AWS &gt; MSK &gt; VPC Connection &gt; CMDB
  - AWS &gt; MSK &gt; VPC Connection &gt; Discovery
  - AWS &gt; MSK &gt; VPC Connection &gt; Tags

- Policy Types:

  - AWS &gt; MSK &gt; Serverless Cluster &gt; Active
  - AWS &gt; MSK &gt; Serverless Cluster &gt; Active &gt; Age
  - AWS &gt; MSK &gt; Serverless Cluster &gt; Active &gt; Budget
  - AWS &gt; MSK &gt; Serverless Cluster &gt; Active &gt; Last Modified
  - AWS &gt; MSK &gt; Serverless Cluster &gt; Allowed
  - AWS &gt; MSK &gt; Serverless Cluster &gt; Allowed &gt; Custom
  - AWS &gt; MSK &gt; Serverless Cluster &gt; Allowed &gt; Custom &gt; Rules
  - AWS &gt; MSK &gt; Serverless Cluster &gt; Allowed &gt; Region
  - AWS &gt; MSK &gt; Serverless Cluster &gt; Allowed &gt; Region &gt; Regions
  - AWS &gt; MSK &gt; Serverless Cluster &gt; CMDB
  - AWS &gt; MSK &gt; Serverless Cluster &gt; Regions
  - AWS &gt; MSK &gt; Serverless Cluster &gt; Tags
  - AWS &gt; MSK &gt; Serverless Cluster &gt; Tags &gt; Template
  - AWS &gt; MSK &gt; Serverless Cluster &gt; Usage
  - AWS &gt; MSK &gt; Serverless Cluster &gt; Usage &gt; Limit
  - AWS &gt; MSK &gt; VPC Connection &gt; Active
  - AWS &gt; MSK &gt; VPC Connection &gt; Active &gt; Age
  - AWS &gt; MSK &gt; VPC Connection &gt; Active &gt; Last Modified
  - AWS &gt; MSK &gt; VPC Connection &gt; Allowed
  - AWS &gt; MSK &gt; VPC Connection &gt; Allowed &gt; Custom
  - AWS &gt; MSK &gt; VPC Connection &gt; Allowed &gt; Custom &gt; Rules
  - AWS &gt; MSK &gt; VPC Connection &gt; Allowed &gt; Region
  - AWS &gt; MSK &gt; VPC Connection &gt; Allowed &gt; Region &gt; Regions
  - AWS &gt; MSK &gt; VPC Connection &gt; CMDB
  - AWS &gt; MSK &gt; VPC Connection &gt; Regions
  - AWS &gt; MSK &gt; VPC Connection &gt; Tags
  - AWS &gt; MSK &gt; VPC Connection &gt; Tags &gt; Template

- Action Types:

  - AWS &gt; MSK &gt; Serverless Cluster &gt; Delete
  - AWS &gt; MSK &gt; Serverless Cluster &gt; Delete from AWS
  - AWS &gt; MSK &gt; Serverless Cluster &gt; Router
  - AWS &gt; MSK &gt; Serverless Cluster &gt; Set Tags
  - AWS &gt; MSK &gt; Serverless Cluster &gt; Skip Active alarm
  - AWS &gt; MSK &gt; Serverless Cluster &gt; Skip Active alarm for 90 days
  - AWS &gt; MSK &gt; Serverless Cluster &gt; Skip alarm for Tags control
  - AWS &gt; MSK &gt; Serverless Cluster &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; MSK &gt; Serverless Cluster &gt; Update Tags
  - AWS &gt; MSK &gt; VPC Connection &gt; Delete
  - AWS &gt; MSK &gt; VPC Connection &gt; Delete from AWS
  - AWS &gt; MSK &gt; VPC Connection &gt; Router
  - AWS &gt; MSK &gt; VPC Connection &gt; Set Tags
  - AWS &gt; MSK &gt; VPC Connection &gt; Skip alarm for Active control
  - AWS &gt; MSK &gt; VPC Connection &gt; Skip alarm for Active control [90 days]
  - AWS &gt; MSK &gt; VPC Connection &gt; Skip alarm for Tags control
  - AWS &gt; MSK &gt; VPC Connection &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; MSK &gt; VPC Connection &gt; Update Tags</description>
            <pubDate>Tue, 13 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/turbot-v5-57-1</guid>
            <title>turbot v5.57.1 - Fixed issues on Policy Pack Summary control</title>
            <link>https://turbot.com/guardrails/changelog/turbot-v5-57-1</link>
            <description>_Bug fixes_

- The `Turbot &gt; Policy Pack &gt; Summary` control would go into an error state due to incorrect policy type dependencies. This is now fixed.</description>
            <pubDate>Mon, 12 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/guardrails-prevention-v5-0-0</guid>
            <title>guardrails-prevention v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/guardrails-prevention-v5-0-0</link>
            <description>_What&apos;s new?_

_Control Types_

- Turbot &gt; Control Prevention
- Turbot &gt; Control Prevention &gt; Discovery</description>
            <pubDate>Mon, 12 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-prevention-v5-0-0</guid>
            <title>aws-prevention v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/aws-prevention-v5-0-0</link>
            <description>_What&apos;s new?_

_Control Types_

- AWS &gt; CloudFormation &gt; Hook &gt; Prevention
- AWS &gt; CloudFormation &gt; Hook &gt; Prevention &gt; Discovery
- AWS &gt; Control Tower &gt; Enabled Control &gt; Prevention
- AWS &gt; Control Tower &gt; Enabled Control &gt; Prevention &gt; Discovery
- AWS &gt; EC2 &gt; Account Attributes &gt; Prevention
- AWS &gt; EC2 &gt; Account Attributes &gt; Prevention &gt; Discovery
- AWS &gt; IAM &gt; Account Password Policy &gt; Prevention
- AWS &gt; IAM &gt; Account Password Policy &gt; Prevention &gt; Discovery
- AWS &gt; Organizations &gt; Resource Control Policy &gt; Deny Statement Prevention
- AWS &gt; Organizations &gt; Resource Control Policy &gt; Deny Statement Prevention &gt; Discovery
- AWS &gt; Organizations &gt; Service Control Policy &gt; Allow Boundary Prevention
- AWS &gt; Organizations &gt; Service Control Policy &gt; Allow Boundary Prevention &gt; Discovery
- AWS &gt; Organizations &gt; Service Control Policy &gt; Deny Statement Prevention
- AWS &gt; Organizations &gt; Service Control Policy &gt; Deny Statement Prevention &gt; Discovery
- AWS &gt; S3 &gt; Account &gt; Prevention
- AWS &gt; S3 &gt; Account &gt; Prevention &gt; Discovery

_Prevention Types_

- AWS CloudFormation Hook
- AWS Control Tower Preventive Control
- AWS Control Tower Proactive Control
- AWS EC2 Account Attribute
- AWS IAM Account Password Policy
- AWS RCP Deny Statement
- AWS S3 Account
- AWS SCP Allow Boundary
- AWS SCP Deny Statement

_Prevention Benchmarks_

- AWS CIS v6.0.0
- AWS NIST 800-53 Rev 5
- AWS P1 Preventions
- AWS PCI DSS v4</description>
            <pubDate>Mon, 12 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-fsx-v5-7-0</guid>
            <title>aws-fsx v5.7.0 - Track and manage volume and storage virtual machine resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/aws-fsx-v5-7-0</link>
            <description>_What&apos;s new?_

- Resource Types:

  - AWS &gt; FSx &gt; Storage Virtual Machine
  - AWS &gt; FSx &gt; Volume

- Control Types:

  - AWS &gt; FSx &gt; Storage Virtual Machine &gt; Active
  - AWS &gt; FSx &gt; Storage Virtual Machine &gt; Allowed
  - AWS &gt; FSx &gt; Storage Virtual Machine &gt; Allowed &gt; Custom
  - AWS &gt; FSx &gt; Storage Virtual Machine &gt; Allowed &gt; Region
  - AWS &gt; FSx &gt; Storage Virtual Machine &gt; CMDB
  - AWS &gt; FSx &gt; Storage Virtual Machine &gt; Discovery
  - AWS &gt; FSx &gt; Storage Virtual Machine &gt; Tags
  - AWS &gt; FSx &gt; Volume &gt; Active
  - AWS &gt; FSx &gt; Volume &gt; Allowed
  - AWS &gt; FSx &gt; Volume &gt; Allowed &gt; Custom
  - AWS &gt; FSx &gt; Volume &gt; Allowed &gt; Region
  - AWS &gt; FSx &gt; Volume &gt; CMDB
  - AWS &gt; FSx &gt; Volume &gt; Discovery
  - AWS &gt; FSx &gt; Volume &gt; Tags

- Policy Types:

  - AWS &gt; FSx &gt; Storage Virtual Machine &gt; Active
  - AWS &gt; FSx &gt; Storage Virtual Machine &gt; Active &gt; Age
  - AWS &gt; FSx &gt; Storage Virtual Machine &gt; Active &gt; Budget
  - AWS &gt; FSx &gt; Storage Virtual Machine &gt; Active &gt; Last Modified
  - AWS &gt; FSx &gt; Storage Virtual Machine &gt; Allowed
  - AWS &gt; FSx &gt; Storage Virtual Machine &gt; Allowed &gt; Custom
  - AWS &gt; FSx &gt; Storage Virtual Machine &gt; Allowed &gt; Custom &gt; Rules
  - AWS &gt; FSx &gt; Storage Virtual Machine &gt; Allowed &gt; Region
  - AWS &gt; FSx &gt; Storage Virtual Machine &gt; Allowed &gt; Region &gt; Regions
  - AWS &gt; FSx &gt; Storage Virtual Machine &gt; CMDB
  - AWS &gt; FSx &gt; Storage Virtual Machine &gt; Regions
  - AWS &gt; FSx &gt; Storage Virtual Machine &gt; Tags
  - AWS &gt; FSx &gt; Storage Virtual Machine &gt; Tags &gt; Template
  - AWS &gt; FSx &gt; Volume &gt; Active
  - AWS &gt; FSx &gt; Volume &gt; Active &gt; Age
  - AWS &gt; FSx &gt; Volume &gt; Active &gt; Budget
  - AWS &gt; FSx &gt; Volume &gt; Active &gt; Last Modified
  - AWS &gt; FSx &gt; Volume &gt; Allowed
  - AWS &gt; FSx &gt; Volume &gt; Allowed &gt; Custom
  - AWS &gt; FSx &gt; Volume &gt; Allowed &gt; Custom &gt; Rules
  - AWS &gt; FSx &gt; Volume &gt; Allowed &gt; Region
  - AWS &gt; FSx &gt; Volume &gt; Allowed &gt; Region &gt; Regions
  - AWS &gt; FSx &gt; Volume &gt; CMDB
  - AWS &gt; FSx &gt; Volume &gt; Regions
  - AWS &gt; FSx &gt; Volume &gt; Tags
  - AWS &gt; FSx &gt; Volume &gt; Tags &gt; Template

- Action Types:

  - AWS &gt; FSx &gt; Storage Virtual Machine &gt; Delete
  - AWS &gt; FSx &gt; Storage Virtual Machine &gt; Delete from AWS
  - AWS &gt; FSx &gt; Storage Virtual Machine &gt; Router
  - AWS &gt; FSx &gt; Storage Virtual Machine &gt; Set Tags
  - AWS &gt; FSx &gt; Storage Virtual Machine &gt; Skip alarm for Active control
  - AWS &gt; FSx &gt; Storage Virtual Machine &gt; Skip alarm for Active control [90 days]
  - AWS &gt; FSx &gt; Storage Virtual Machine &gt; Skip alarm for Tags control
  - AWS &gt; FSx &gt; Storage Virtual Machine &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; FSx &gt; Storage Virtual Machine &gt; Update Tags
  - AWS &gt; FSx &gt; Volume &gt; Delete
  - AWS &gt; FSx &gt; Volume &gt; Delete from AWS
  - AWS &gt; FSx &gt; Volume &gt; Router
  - AWS &gt; FSx &gt; Volume &gt; Set Tags
  - AWS &gt; FSx &gt; Volume &gt; Skip alarm for Active control
  - AWS &gt; FSx &gt; Volume &gt; Skip alarm for Active control [90 days]
  - AWS &gt; FSx &gt; Volume &gt; Skip alarm for Tags control
  - AWS &gt; FSx &gt; Volume &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; FSx &gt; Volume &gt; Update Tags</description>
            <pubDate>Mon, 12 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-datasync-v5-2-0</guid>
            <title>aws-datasync v5.2.0 - Track and manage agent resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/aws-datasync-v5-2-0</link>
            <description>_What&apos;s new?_

- Resource Types:

  - AWS &gt; DataSync &gt; Agent

- Control Types:

  - AWS &gt; DataSync &gt; Agent &gt; Active
  - AWS &gt; DataSync &gt; Agent &gt; Allowed
  - AWS &gt; DataSync &gt; Agent &gt; Allowed &gt; Custom
  - AWS &gt; DataSync &gt; Agent &gt; Allowed &gt; Region
  - AWS &gt; DataSync &gt; Agent &gt; CMDB
  - AWS &gt; DataSync &gt; Agent &gt; Discovery
  - AWS &gt; DataSync &gt; Agent &gt; Router
  - AWS &gt; DataSync &gt; Agent &gt; Tags

- Policy Types:

  - AWS &gt; DataSync &gt; Agent &gt; Active
  - AWS &gt; DataSync &gt; Agent &gt; Active &gt; Age
  - AWS &gt; DataSync &gt; Agent &gt; Active &gt; Budget
  - AWS &gt; DataSync &gt; Agent &gt; Active &gt; Last Modified
  - AWS &gt; DataSync &gt; Agent &gt; Allowed
  - AWS &gt; DataSync &gt; Agent &gt; Allowed &gt; Custom
  - AWS &gt; DataSync &gt; Agent &gt; Allowed &gt; Custom &gt; Rules
  - AWS &gt; DataSync &gt; Agent &gt; Allowed &gt; Region
  - AWS &gt; DataSync &gt; Agent &gt; Allowed &gt; Region &gt; Regions
  - AWS &gt; DataSync &gt; Agent &gt; CMDB
  - AWS &gt; DataSync &gt; Agent &gt; Regions
  - AWS &gt; DataSync &gt; Agent &gt; Tags
  - AWS &gt; DataSync &gt; Agent &gt; Tags &gt; Template
  - AWS &gt; DataSync &gt; Allowed Regions [Default]
  - AWS &gt; Turbot &gt; Event Handlers &gt; Events &gt; Rules &gt; Event Sources &gt; @turbot/aws-datasync

- Action Types:

  - AWS &gt; DataSync &gt; Agent &gt; Delete
  - AWS &gt; DataSync &gt; Agent &gt; Delete from AWS
  - AWS &gt; DataSync &gt; Agent &gt; Set Tags
  - AWS &gt; DataSync &gt; Agent &gt; Skip alarm for Active control
  - AWS &gt; DataSync &gt; Agent &gt; Skip alarm for Active control [90 days]
  - AWS &gt; DataSync &gt; Agent &gt; Skip alarm for Tags control
  - AWS &gt; DataSync &gt; Agent &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; DataSync &gt; Agent &gt; Update Tags</description>
            <pubDate>Mon, 12 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/turbot-guardrails-cli-v1-31-0</guid>
            <title>Turbot Guardrails CLI v1.31.0 - Enhanced mod development with control and resource commands</title>
            <link>https://turbot.com/guardrails/changelog/turbot-guardrails-cli-v1-31-0</link>
            <description>_What&apos;s new?_

- Added `turbot control` and `turbot resource` commands for **streamlined mod development workflows**, making it easier to test and validate controls and resources during development.
- Improved `turbot up` performance with **incremental compose**, reducing deployment times for iterative development.
- Enhanced testing capabilities with new `--runnable` and `--resource` flags for control and policy input queries, enabling more precise testing scenarios.

_Bug fixes_

- Fixed missing `flattenBenchmarks` filter in `turbot inspect` command for accurate benchmark analysis.</description>
            <pubDate>Mon, 12 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-quicksight-v5-4-0</guid>
            <title>aws-quicksight v5.4.0 - Various new resource types for QuickSight are now available</title>
            <link>https://turbot.com/guardrails/changelog/aws-quicksight-v5-4-0</link>
            <description>_What&apos;s new?_

- Resource Types:

  - AWS &gt; QuickSight &gt; Analysis
  - AWS &gt; QuickSight &gt; Dashboard
  - AWS &gt; QuickSight &gt; Data Set
  - AWS &gt; QuickSight &gt; Data Source
  - AWS &gt; QuickSight &gt; VPC Connection

- Control Types:

  - AWS &gt; QuickSight &gt; Analysis &gt; Active
  - AWS &gt; QuickSight &gt; Analysis &gt; Allowed
  - AWS &gt; QuickSight &gt; Analysis &gt; Allowed &gt; Custom
  - AWS &gt; QuickSight &gt; Analysis &gt; Allowed &gt; Region
  - AWS &gt; QuickSight &gt; Analysis &gt; CMDB
  - AWS &gt; QuickSight &gt; Analysis &gt; Discovery
  - AWS &gt; QuickSight &gt; Analysis &gt; Tags
  - AWS &gt; QuickSight &gt; Dashboard &gt; Active
  - AWS &gt; QuickSight &gt; Dashboard &gt; Allowed
  - AWS &gt; QuickSight &gt; Dashboard &gt; Allowed &gt; Custom
  - AWS &gt; QuickSight &gt; Dashboard &gt; Allowed &gt; Region
  - AWS &gt; QuickSight &gt; Dashboard &gt; CMDB
  - AWS &gt; QuickSight &gt; Dashboard &gt; Discovery
  - AWS &gt; QuickSight &gt; Dashboard &gt; Tags
  - AWS &gt; QuickSight &gt; Data Set &gt; Active
  - AWS &gt; QuickSight &gt; Data Set &gt; Allowed
  - AWS &gt; QuickSight &gt; Data Set &gt; Allowed &gt; Custom
  - AWS &gt; QuickSight &gt; Data Set &gt; Allowed &gt; Region
  - AWS &gt; QuickSight &gt; Data Set &gt; CMDB
  - AWS &gt; QuickSight &gt; Data Set &gt; Discovery
  - AWS &gt; QuickSight &gt; Data Set &gt; Tags
  - AWS &gt; QuickSight &gt; Data Source &gt; Active
  - AWS &gt; QuickSight &gt; Data Source &gt; Allowed
  - AWS &gt; QuickSight &gt; Data Source &gt; Allowed &gt; Custom
  - AWS &gt; QuickSight &gt; Data Source &gt; Allowed &gt; Region
  - AWS &gt; QuickSight &gt; Data Source &gt; CMDB
  - AWS &gt; QuickSight &gt; Data Source &gt; Discovery
  - AWS &gt; QuickSight &gt; Data Source &gt; Tags
  - AWS &gt; QuickSight &gt; VPC Connection &gt; Active
  - AWS &gt; QuickSight &gt; VPC Connection &gt; Allowed
  - AWS &gt; QuickSight &gt; VPC Connection &gt; Allowed &gt; Custom
  - AWS &gt; QuickSight &gt; VPC Connection &gt; Allowed &gt; Region
  - AWS &gt; QuickSight &gt; VPC Connection &gt; CMDB
  - AWS &gt; QuickSight &gt; VPC Connection &gt; Discovery
  - AWS &gt; QuickSight &gt; VPC Connection &gt; Tags

- Policy Types:

  - AWS &gt; QuickSight &gt; Allowed Regions [Default]
  - AWS &gt; QuickSight &gt; Analysis &gt; Active
  - AWS &gt; QuickSight &gt; Analysis &gt; Active &gt; Age
  - AWS &gt; QuickSight &gt; Analysis &gt; Active &gt; Last Modified
  - AWS &gt; QuickSight &gt; Analysis &gt; Allowed
  - AWS &gt; QuickSight &gt; Analysis &gt; Allowed &gt; Custom
  - AWS &gt; QuickSight &gt; Analysis &gt; Allowed &gt; Custom &gt; Rules
  - AWS &gt; QuickSight &gt; Analysis &gt; Allowed &gt; Region
  - AWS &gt; QuickSight &gt; Analysis &gt; Allowed &gt; Region &gt; Regions
  - AWS &gt; QuickSight &gt; Analysis &gt; CMDB
  - AWS &gt; QuickSight &gt; Analysis &gt; Regions
  - AWS &gt; QuickSight &gt; Analysis &gt; Tags
  - AWS &gt; QuickSight &gt; Analysis &gt; Tags &gt; Template
  - AWS &gt; QuickSight &gt; Dashboard &gt; Active
  - AWS &gt; QuickSight &gt; Dashboard &gt; Active &gt; Age
  - AWS &gt; QuickSight &gt; Dashboard &gt; Active &gt; Last Modified
  - AWS &gt; QuickSight &gt; Dashboard &gt; Allowed
  - AWS &gt; QuickSight &gt; Dashboard &gt; Allowed &gt; Custom
  - AWS &gt; QuickSight &gt; Dashboard &gt; Allowed &gt; Custom &gt; Rules
  - AWS &gt; QuickSight &gt; Dashboard &gt; Allowed &gt; Region
  - AWS &gt; QuickSight &gt; Dashboard &gt; Allowed &gt; Region &gt; Regions
  - AWS &gt; QuickSight &gt; Dashboard &gt; CMDB
  - AWS &gt; QuickSight &gt; Dashboard &gt; Regions
  - AWS &gt; QuickSight &gt; Dashboard &gt; Tags
  - AWS &gt; QuickSight &gt; Dashboard &gt; Tags &gt; Template
  - AWS &gt; QuickSight &gt; Data Set &gt; Active
  - AWS &gt; QuickSight &gt; Data Set &gt; Active &gt; Age
  - AWS &gt; QuickSight &gt; Data Set &gt; Active &gt; Last Modified
  - AWS &gt; QuickSight &gt; Data Set &gt; Allowed
  - AWS &gt; QuickSight &gt; Data Set &gt; Allowed &gt; Custom
  - AWS &gt; QuickSight &gt; Data Set &gt; Allowed &gt; Custom &gt; Rules
  - AWS &gt; QuickSight &gt; Data Set &gt; Allowed &gt; Region
  - AWS &gt; QuickSight &gt; Data Set &gt; Allowed &gt; Region &gt; Regions
  - AWS &gt; QuickSight &gt; Data Set &gt; CMDB
  - AWS &gt; QuickSight &gt; Data Set &gt; Regions
  - AWS &gt; QuickSight &gt; Data Set &gt; Tags
  - AWS &gt; QuickSight &gt; Data Set &gt; Tags &gt; Template
  - AWS &gt; QuickSight &gt; Data Source &gt; Active
  - AWS &gt; QuickSight &gt; Data Source &gt; Active &gt; Age
  - AWS &gt; QuickSight &gt; Data Source &gt; Active &gt; Last Modified
  - AWS &gt; QuickSight &gt; Data Source &gt; Allowed
  - AWS &gt; QuickSight &gt; Data Source &gt; Allowed &gt; Custom
  - AWS &gt; QuickSight &gt; Data Source &gt; Allowed &gt; Custom &gt; Rules
  - AWS &gt; QuickSight &gt; Data Source &gt; Allowed &gt; Region
  - AWS &gt; QuickSight &gt; Data Source &gt; Allowed &gt; Region &gt; Regions
  - AWS &gt; QuickSight &gt; Data Source &gt; CMDB
  - AWS &gt; QuickSight &gt; Data Source &gt; Regions
  - AWS &gt; QuickSight &gt; Data Source &gt; Tags
  - AWS &gt; QuickSight &gt; Data Source &gt; Tags &gt; Template
  - AWS &gt; QuickSight &gt; VPC Connection &gt; Active
  - AWS &gt; QuickSight &gt; VPC Connection &gt; Active &gt; Age
  - AWS &gt; QuickSight &gt; VPC Connection &gt; Active &gt; Last Modified
  - AWS &gt; QuickSight &gt; VPC Connection &gt; Allowed
  - AWS &gt; QuickSight &gt; VPC Connection &gt; Allowed &gt; Custom
  - AWS &gt; QuickSight &gt; VPC Connection &gt; Allowed &gt; Custom &gt; Rules
  - AWS &gt; QuickSight &gt; VPC Connection &gt; Allowed &gt; Region
  - AWS &gt; QuickSight &gt; VPC Connection &gt; Allowed &gt; Region &gt; Regions
  - AWS &gt; QuickSight &gt; VPC Connection &gt; CMDB
  - AWS &gt; QuickSight &gt; VPC Connection &gt; Regions
  - AWS &gt; QuickSight &gt; VPC Connection &gt; Tags
  - AWS &gt; QuickSight &gt; VPC Connection &gt; Tags &gt; Template

- Action Types:

  - AWS &gt; QuickSight &gt; Analysis &gt; Delete
  - AWS &gt; QuickSight &gt; Analysis &gt; Delete from AWS
  - AWS &gt; QuickSight &gt; Analysis &gt; Router
  - AWS &gt; QuickSight &gt; Analysis &gt; Set Tags
  - AWS &gt; QuickSight &gt; Analysis &gt; Skip alarm for Active control
  - AWS &gt; QuickSight &gt; Analysis &gt; Skip alarm for Active control [90 days]
  - AWS &gt; QuickSight &gt; Analysis &gt; Skip alarm for Tags control
  - AWS &gt; QuickSight &gt; Analysis &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; QuickSight &gt; Analysis &gt; Update Tags
  - AWS &gt; QuickSight &gt; Dashboard &gt; Delete
  - AWS &gt; QuickSight &gt; Dashboard &gt; Delete from AWS
  - AWS &gt; QuickSight &gt; Dashboard &gt; Router
  - AWS &gt; QuickSight &gt; Dashboard &gt; Set Tags
  - AWS &gt; QuickSight &gt; Dashboard &gt; Skip alarm for Active control
  - AWS &gt; QuickSight &gt; Dashboard &gt; Skip alarm for Active control [90 days]
  - AWS &gt; QuickSight &gt; Dashboard &gt; Skip alarm for Tags control
  - AWS &gt; QuickSight &gt; Dashboard &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; QuickSight &gt; Dashboard &gt; Update Tags
  - AWS &gt; QuickSight &gt; Data Set &gt; Delete
  - AWS &gt; QuickSight &gt; Data Set &gt; Delete from AWS
  - AWS &gt; QuickSight &gt; Data Set &gt; Router
  - AWS &gt; QuickSight &gt; Data Set &gt; Set Tags
  - AWS &gt; QuickSight &gt; Data Set &gt; Skip alarm for Active control
  - AWS &gt; QuickSight &gt; Data Set &gt; Skip alarm for Active control [90 days]
  - AWS &gt; QuickSight &gt; Data Set &gt; Skip alarm for Tags control
  - AWS &gt; QuickSight &gt; Data Set &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; QuickSight &gt; Data Set &gt; Update Tags
  - AWS &gt; QuickSight &gt; Data Source &gt; Delete
  - AWS &gt; QuickSight &gt; Data Source &gt; Delete from AWS
  - AWS &gt; QuickSight &gt; Data Source &gt; Router
  - AWS &gt; QuickSight &gt; Data Source &gt; Set Tags
  - AWS &gt; QuickSight &gt; Data Source &gt; Skip alarm for Active control
  - AWS &gt; QuickSight &gt; Data Source &gt; Skip alarm for Active control [90 days]
  - AWS &gt; QuickSight &gt; Data Source &gt; Skip alarm for Tags control
  - AWS &gt; QuickSight &gt; Data Source &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; QuickSight &gt; Data Source &gt; Update Tags
  - AWS &gt; QuickSight &gt; VPC Connection &gt; Delete
  - AWS &gt; QuickSight &gt; VPC Connection &gt; Delete from AWS
  - AWS &gt; QuickSight &gt; VPC Connection &gt; Router
  - AWS &gt; QuickSight &gt; VPC Connection &gt; Set Tags
  - AWS &gt; QuickSight &gt; VPC Connection &gt; Skip alarm for Active control
  - AWS &gt; QuickSight &gt; VPC Connection &gt; Skip alarm for Active control [90 days]
  - AWS &gt; QuickSight &gt; VPC Connection &gt; Skip alarm for Tags control
  - AWS &gt; QuickSight &gt; VPC Connection &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; QuickSight &gt; VPC Connection &gt; Update Tags</description>
            <pubDate>Fri, 09 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/turbot-v5-57-0</guid>
            <title>turbot v5.57.0 - Configure AI features using AWS Bedrock and Azure OpenAI credentials</title>
            <link>https://turbot.com/guardrails/changelog/turbot-v5-57-0</link>
            <description>_What&apos;s new?_

- Added support for AWS Bedrock and Azure OpenAI to enable AI-powered features across Guardrails.
- Added the `Turbot &gt; Discovery Level &gt; Materialization` control and `Turbot &gt; Discovery Level &gt; Materialization Exceptions` policy to manage discovery level materialization behavior.

_Policy Types_

- Turbot &gt; Discovery Level &gt; Materialization Exceptions
- Turbot &gt; AI
- Turbot &gt; AI &gt; Configuration
- Turbot &gt; AI &gt; Configuration &gt; Provider [Default]
- Turbot &gt; AI &gt; Features &gt; Enabled [Default]
- Turbot &gt; AI &gt; Configuration &gt; AWS
- Turbot &gt; AI &gt; Configuration &gt; AWS &gt; Bedrock
- Turbot &gt; AI &gt; Configuration &gt; AWS &gt; Bedrock &gt; Inference Profile ARN
- Turbot &gt; AI &gt; Configuration &gt; AWS &gt; Bedrock &gt; Long-Term API Key
- Turbot &gt; AI &gt; Configuration &gt; Anthropic
- Turbot &gt; AI &gt; Configuration &gt; Anthropic &gt; API Key
- Turbot &gt; AI &gt; Configuration &gt; Anthropic &gt; Model
- Turbot &gt; AI &gt; Configuration &gt; Azure
- Turbot &gt; AI &gt; Configuration &gt; Azure &gt; OpenAI
- Turbot &gt; AI &gt; Configuration &gt; Azure &gt; OpenAI &gt; API Key
- Turbot &gt; AI &gt; Configuration &gt; Azure &gt; OpenAI &gt; Deployment
- Turbot &gt; AI &gt; Configuration &gt; Azure &gt; OpenAI &gt; Resource Name
- Turbot &gt; AI &gt; Configuration &gt; OpenAI
- Turbot &gt; AI &gt; Configuration &gt; OpenAI &gt; API Key
- Turbot &gt; AI &gt; Configuration &gt; OpenAI &gt; Model

_Control Types_

- Turbot &gt; Discovery Level &gt; Materialization</description>
            <pubDate>Wed, 07 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ses-v5-7-0</guid>
            <title>aws-ses v5.7.0 - Identify and remove unallowed resources from CMDB</title>
            <link>https://turbot.com/guardrails/changelog/aws-ses-v5-7-0</link>
            <description>_What&apos;s new?_

_Control Types_

- AWS &gt; SES &gt; Identity &gt; Allowed
- AWS &gt; SES &gt; Identity &gt; Allowed &gt; Custom
- AWS &gt; SES &gt; Identity &gt; Allowed &gt; Region

_Policy Types_

- AWS &gt; SES &gt; Allowed Regions [Default]
- AWS &gt; SES &gt; Identity &gt; Allowed
- AWS &gt; SES &gt; Identity &gt; Allowed &gt; Custom
- AWS &gt; SES &gt; Identity &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; SES &gt; Identity &gt; Allowed &gt; Region
- AWS &gt; SES &gt; Identity &gt; Allowed &gt; Region &gt; Regions</description>
            <pubDate>Wed, 07 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-cloudfront-v5-9-0</guid>
            <title>aws-cloudfront v5.9.0 - Identify and remove unallowed resources from CMDB</title>
            <link>https://turbot.com/guardrails/changelog/aws-cloudfront-v5-9-0</link>
            <description>_What&apos;s new?_

_Control Types_

- AWS &gt; CloudFront &gt; CloudFront Origin Access Identity &gt; Allowed
- AWS &gt; CloudFront &gt; CloudFront Origin Access Identity &gt; Allowed &gt; Custom
- AWS &gt; CloudFront &gt; Distribution &gt; Allowed
- AWS &gt; CloudFront &gt; Distribution &gt; Allowed &gt; Custom
- AWS &gt; CloudFront &gt; Streaming Distribution &gt; Allowed
- AWS &gt; CloudFront &gt; Streaming Distribution &gt; Allowed &gt; Custom
- AWS &gt; CloudFront &gt; Streaming Distribution &gt; Allowed &gt; Region

_Policy Types_

- AWS &gt; CloudFront &gt; Allowed Regions [Default]
- AWS &gt; CloudFront &gt; Approved Regions [Default]
- AWS &gt; CloudFront &gt; CloudFront Origin Access Identity &gt; Allowed
- AWS &gt; CloudFront &gt; CloudFront Origin Access Identity &gt; Allowed &gt; Custom
- AWS &gt; CloudFront &gt; CloudFront Origin Access Identity &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; CloudFront &gt; Distribution &gt; Allowed
- AWS &gt; CloudFront &gt; Distribution &gt; Allowed &gt; Custom
- AWS &gt; CloudFront &gt; Distribution &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; CloudFront &gt; Regions
- AWS &gt; CloudFront &gt; Streaming Distribution &gt; Allowed
- AWS &gt; CloudFront &gt; Streaming Distribution &gt; Allowed &gt; Custom
- AWS &gt; CloudFront &gt; Streaming Distribution &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; CloudFront &gt; Streaming Distribution &gt; Allowed &gt; Region
- AWS &gt; CloudFront &gt; Streaming Distribution &gt; Allowed &gt; Region &gt; Regions</description>
            <pubDate>Wed, 07 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-appstream-v5-6-0</guid>
            <title>aws-appstream v5.6.0 - Identify and remove unallowed resources from CMDB</title>
            <link>https://turbot.com/guardrails/changelog/aws-appstream-v5-6-0</link>
            <description>_What&apos;s new?_

_Control Types_

- AWS &gt; AppStream &gt; Fleet &gt; Allowed
- AWS &gt; AppStream &gt; Fleet &gt; Allowed &gt; Custom
- AWS &gt; AppStream &gt; Fleet &gt; Allowed &gt; Region
- AWS &gt; AppStream &gt; Image &gt; Allowed
- AWS &gt; AppStream &gt; Image &gt; Allowed &gt; Custom
- AWS &gt; AppStream &gt; Image &gt; Allowed &gt; Region
- AWS &gt; AppStream &gt; Image Builder &gt; Allowed
- AWS &gt; AppStream &gt; Image Builder &gt; Allowed &gt; Custom
- AWS &gt; AppStream &gt; Image Builder &gt; Allowed &gt; Region
- AWS &gt; AppStream &gt; User &gt; Allowed
- AWS &gt; AppStream &gt; User &gt; Allowed &gt; Custom
- AWS &gt; AppStream &gt; User &gt; Allowed &gt; Region

_Policy Types_

- AWS &gt; AppStream &gt; Allowed Regions [Default]
- AWS &gt; AppStream &gt; Fleet &gt; Allowed
- AWS &gt; AppStream &gt; Fleet &gt; Allowed &gt; Custom
- AWS &gt; AppStream &gt; Fleet &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; AppStream &gt; Fleet &gt; Allowed &gt; Region
- AWS &gt; AppStream &gt; Fleet &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; AppStream &gt; Image &gt; Allowed
- AWS &gt; AppStream &gt; Image &gt; Allowed &gt; Custom
- AWS &gt; AppStream &gt; Image &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; AppStream &gt; Image &gt; Allowed &gt; Region
- AWS &gt; AppStream &gt; Image &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; AppStream &gt; Image Builder &gt; Allowed
- AWS &gt; AppStream &gt; Image Builder &gt; Allowed &gt; Custom
- AWS &gt; AppStream &gt; Image Builder &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; AppStream &gt; Image Builder &gt; Allowed &gt; Region
- AWS &gt; AppStream &gt; Image Builder &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; AppStream &gt; User &gt; Allowed
- AWS &gt; AppStream &gt; User &gt; Allowed &gt; Custom
- AWS &gt; AppStream &gt; User &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; AppStream &gt; User &gt; Allowed &gt; Region
- AWS &gt; AppStream &gt; User &gt; Allowed &gt; Region &gt; Regions</description>
            <pubDate>Wed, 07 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/ted-v1-52-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.52.0 - Added support for PostgreSQL versions 15.14, 16.10, 16.11, 17.6 and 17.7</title>
            <link>https://turbot.com/guardrails/changelog/ted-v1-52-0</link>
            <description>_What&apos;s new?_

- Added support for PostgreSQL version 15.14, 16.10, 16.11, 17.6 and 17.7.
- Added support for Valkey cache v8.1 and v8.2.</description>
            <pubDate>Tue, 06 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-vpc-security-v5-16-0</guid>
            <title>aws-vpc-security v5.16.0 - Identify and remove unallowed resources from CMDB</title>
            <link>https://turbot.com/guardrails/changelog/aws-vpc-security-v5-16-0</link>
            <description>_What&apos;s new?_

_Control Types_

- AWS &gt; VPC &gt; Flow Log &gt; Allowed
- AWS &gt; VPC &gt; Flow Log &gt; Allowed &gt; Custom
- AWS &gt; VPC &gt; Flow Log &gt; Allowed &gt; Region
- AWS &gt; VPC &gt; Network ACL &gt; Allowed
- AWS &gt; VPC &gt; Network ACL &gt; Allowed &gt; Custom
- AWS &gt; VPC &gt; Network ACL &gt; Allowed &gt; Region
- AWS &gt; VPC &gt; Security Group &gt; Allowed
- AWS &gt; VPC &gt; Security Group &gt; Allowed &gt; Custom
- AWS &gt; VPC &gt; Security Group &gt; Allowed &gt; Region

_Policy Types_

- AWS &gt; VPC &gt; Flow Log &gt; Allowed
- AWS &gt; VPC &gt; Flow Log &gt; Allowed &gt; Custom
- AWS &gt; VPC &gt; Flow Log &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; VPC &gt; Flow Log &gt; Allowed &gt; Region
- AWS &gt; VPC &gt; Flow Log &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; VPC &gt; Network ACL &gt; Allowed
- AWS &gt; VPC &gt; Network ACL &gt; Allowed &gt; Custom
- AWS &gt; VPC &gt; Network ACL &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; VPC &gt; Network ACL &gt; Allowed &gt; Region
- AWS &gt; VPC &gt; Network ACL &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; VPC &gt; Security Group &gt; Allowed
- AWS &gt; VPC &gt; Security Group &gt; Allowed &gt; Custom
- AWS &gt; VPC &gt; Security Group &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; VPC &gt; Security Group &gt; Allowed &gt; Region
- AWS &gt; VPC &gt; Security Group &gt; Allowed &gt; Region &gt; Regions</description>
            <pubDate>Tue, 06 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-vpc-core-v5-24-0</guid>
            <title>aws-vpc-core v5.24.0 - Identify and remove unallowed resources from CMDB</title>
            <link>https://turbot.com/guardrails/changelog/aws-vpc-core-v5-24-0</link>
            <description>_What&apos;s new?_

_Control Types_

- AWS &gt; VPC &gt; DHCP Options &gt; Allowed
- AWS &gt; VPC &gt; DHCP Options &gt; Allowed &gt; Custom
- AWS &gt; VPC &gt; DHCP Options &gt; Allowed &gt; Region
- AWS &gt; VPC &gt; Route Table &gt; Allowed
- AWS &gt; VPC &gt; Route Table &gt; Allowed &gt; Custom
- AWS &gt; VPC &gt; Route Table &gt; Allowed &gt; Region
- AWS &gt; VPC &gt; Subnet &gt; Allowed
- AWS &gt; VPC &gt; Subnet &gt; Allowed &gt; Custom
- AWS &gt; VPC &gt; Subnet &gt; Allowed &gt; Region
- AWS &gt; VPC &gt; VPC &gt; Allowed
- AWS &gt; VPC &gt; VPC &gt; Allowed &gt; Custom
- AWS &gt; VPC &gt; VPC &gt; Allowed &gt; Region

_Policy Types_

- AWS &gt; VPC &gt; Allowed Regions [Default]
- AWS &gt; VPC &gt; DHCP Options &gt; Allowed
- AWS &gt; VPC &gt; DHCP Options &gt; Allowed &gt; Custom
- AWS &gt; VPC &gt; DHCP Options &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; VPC &gt; DHCP Options &gt; Allowed &gt; Region
- AWS &gt; VPC &gt; DHCP Options &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; VPC &gt; Route Table &gt; Allowed
- AWS &gt; VPC &gt; Route Table &gt; Allowed &gt; Custom
- AWS &gt; VPC &gt; Route Table &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; VPC &gt; Route Table &gt; Allowed &gt; Region
- AWS &gt; VPC &gt; Route Table &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; VPC &gt; Subnet &gt; Allowed
- AWS &gt; VPC &gt; Subnet &gt; Allowed &gt; Custom
- AWS &gt; VPC &gt; Subnet &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; VPC &gt; Subnet &gt; Allowed &gt; Region
- AWS &gt; VPC &gt; Subnet &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; VPC &gt; VPC &gt; Allowed
- AWS &gt; VPC &gt; VPC &gt; Allowed &gt; Custom
- AWS &gt; VPC &gt; VPC &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; VPC &gt; VPC &gt; Allowed &gt; Region
- AWS &gt; VPC &gt; VPC &gt; Allowed &gt; Region &gt; Regions</description>
            <pubDate>Tue, 06 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-stepfunctions-v5-9-0</guid>
            <title>aws-stepfunctions v5.9.0 - Identify and remove unallowed resources from CMDB</title>
            <link>https://turbot.com/guardrails/changelog/aws-stepfunctions-v5-9-0</link>
            <description>_What&apos;s new?_

_Control Types_

- AWS &gt; Step Functions &gt; State Machine &gt; Allowed
- AWS &gt; Step Functions &gt; State Machine &gt; Allowed &gt; Custom
- AWS &gt; Step Functions &gt; State Machine &gt; Allowed &gt; Region

_Policy Types_

- AWS &gt; Step Functions &gt; Allowed Regions [Default]
- AWS &gt; Step Functions &gt; State Machine &gt; Allowed
- AWS &gt; Step Functions &gt; State Machine &gt; Allowed &gt; Custom
- AWS &gt; Step Functions &gt; State Machine &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; Step Functions &gt; State Machine &gt; Allowed &gt; Region
- AWS &gt; Step Functions &gt; State Machine &gt; Allowed &gt; Region &gt; Regions</description>
            <pubDate>Tue, 06 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-eks-v5-10-0</guid>
            <title>aws-eks v5.10.0 - Identify and remove unallowed resources from CMDB</title>
            <link>https://turbot.com/guardrails/changelog/aws-eks-v5-10-0</link>
            <description>_What&apos;s new?_

_Control Types_

- AWS &gt; EKS &gt; Cluster &gt; Allowed
- AWS &gt; EKS &gt; Cluster &gt; Allowed &gt; Custom
- AWS &gt; EKS &gt; Cluster &gt; Allowed &gt; Region
- AWS &gt; EKS &gt; Node Group &gt; Allowed
- AWS &gt; EKS &gt; Node Group &gt; Allowed &gt; AMI Type
- AWS &gt; EKS &gt; Node Group &gt; Allowed &gt; Custom
- AWS &gt; EKS &gt; Node Group &gt; Allowed &gt; Instance Type
- AWS &gt; EKS &gt; Node Group &gt; Allowed &gt; Region

_Policy Types_

- AWS &gt; EKS &gt; Allowed Regions [Default]
- AWS &gt; EKS &gt; Cluster &gt; Allowed
- AWS &gt; EKS &gt; Cluster &gt; Allowed &gt; Custom
- AWS &gt; EKS &gt; Cluster &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; EKS &gt; Cluster &gt; Allowed &gt; Region
- AWS &gt; EKS &gt; Cluster &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; EKS &gt; Node Group &gt; Allowed
- AWS &gt; EKS &gt; Node Group &gt; Allowed &gt; AMI Type
- AWS &gt; EKS &gt; Node Group &gt; Allowed &gt; AMI Type &gt; AMI Types
- AWS &gt; EKS &gt; Node Group &gt; Allowed &gt; Custom
- AWS &gt; EKS &gt; Node Group &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; EKS &gt; Node Group &gt; Allowed &gt; Instance Type
- AWS &gt; EKS &gt; Node Group &gt; Allowed &gt; Instance Type &gt; Instance Types
- AWS &gt; EKS &gt; Node Group &gt; Allowed &gt; Region
- AWS &gt; EKS &gt; Node Group &gt; Allowed &gt; Region &gt; Regions</description>
            <pubDate>Tue, 06 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-bedrock-v5-4-0</guid>
            <title>aws-bedrock v5.4.0 - Identify and remove unallowed resources from CMDB</title>
            <link>https://turbot.com/guardrails/changelog/aws-bedrock-v5-4-0</link>
            <description>_What&apos;s new?_

_Control Types_

- AWS &gt; Bedrock &gt; Agent &gt; Allowed
- AWS &gt; Bedrock &gt; Agent &gt; Allowed &gt; Custom
- AWS &gt; Bedrock &gt; Agent &gt; Allowed &gt; Encryption at Rest
- AWS &gt; Bedrock &gt; Agent &gt; Allowed &gt; Region
- AWS &gt; Bedrock &gt; Custom Model &gt; Allowed
- AWS &gt; Bedrock &gt; Custom Model &gt; Allowed &gt; Custom
- AWS &gt; Bedrock &gt; Custom Model &gt; Allowed &gt; Region
- AWS &gt; Bedrock &gt; Imported Model &gt; Allowed
- AWS &gt; Bedrock &gt; Imported Model &gt; Allowed &gt; Custom
- AWS &gt; Bedrock &gt; Imported Model &gt; Allowed &gt; Region
- AWS &gt; Bedrock &gt; Knowledge Base &gt; Allowed
- AWS &gt; Bedrock &gt; Knowledge Base &gt; Allowed &gt; Custom
- AWS &gt; Bedrock &gt; Knowledge Base &gt; Allowed &gt; Region

_Policy Types_

- AWS &gt; Bedrock &gt; Agent &gt; Allowed
- AWS &gt; Bedrock &gt; Agent &gt; Allowed &gt; Custom
- AWS &gt; Bedrock &gt; Agent &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; Bedrock &gt; Agent &gt; Allowed &gt; Encryption at Rest
- AWS &gt; Bedrock &gt; Agent &gt; Allowed &gt; Encryption at Rest &gt; Level
- AWS &gt; Bedrock &gt; Agent &gt; Allowed &gt; Encryption at Rest &gt; Level &gt; Customer Managed Key
- AWS &gt; Bedrock &gt; Agent &gt; Allowed &gt; Region
- AWS &gt; Bedrock &gt; Agent &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; Bedrock &gt; Allowed Regions [Default]
- AWS &gt; Bedrock &gt; Custom Model &gt; Allowed
- AWS &gt; Bedrock &gt; Custom Model &gt; Allowed &gt; Custom
- AWS &gt; Bedrock &gt; Custom Model &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; Bedrock &gt; Custom Model &gt; Allowed &gt; Region
- AWS &gt; Bedrock &gt; Custom Model &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; Bedrock &gt; Imported Model &gt; Allowed
- AWS &gt; Bedrock &gt; Imported Model &gt; Allowed &gt; Custom
- AWS &gt; Bedrock &gt; Imported Model &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; Bedrock &gt; Imported Model &gt; Allowed &gt; Region
- AWS &gt; Bedrock &gt; Imported Model &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; Bedrock &gt; Knowledge Base &gt; Allowed
- AWS &gt; Bedrock &gt; Knowledge Base &gt; Allowed &gt; Custom
- AWS &gt; Bedrock &gt; Knowledge Base &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; Bedrock &gt; Knowledge Base &gt; Allowed &gt; Region
- AWS &gt; Bedrock &gt; Knowledge Base &gt; Allowed &gt; Region &gt; Regions</description>
            <pubDate>Tue, 06 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-apigateway-v5-15-0</guid>
            <title>aws-apigateway v5.15.0 - Track and manage VPC link resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/aws-apigateway-v5-15-0</link>
            <description>_Resource Types_

- AWS &gt; API Gateway &gt; VPC Link

_Control Types_

- AWS &gt; API Gateway &gt; VPC Link &gt; Active
- AWS &gt; API Gateway &gt; VPC Link &gt; Allowed
- AWS &gt; API Gateway &gt; VPC Link &gt; Allowed &gt; Custom
- AWS &gt; API Gateway &gt; VPC Link &gt; Allowed &gt; Region
- AWS &gt; API Gateway &gt; VPC Link &gt; CMDB
- AWS &gt; API Gateway &gt; VPC Link &gt; Discovery
- AWS &gt; API Gateway &gt; VPC Link &gt; Tags

_Policy Types_

- AWS &gt; API Gateway &gt; VPC Link &gt; Active
- AWS &gt; API Gateway &gt; VPC Link &gt; Active &gt; Age
- AWS &gt; API Gateway &gt; VPC Link &gt; Active &gt; Last Modified
- AWS &gt; API Gateway &gt; VPC Link &gt; Allowed
- AWS &gt; API Gateway &gt; VPC Link &gt; Allowed &gt; Custom
- AWS &gt; API Gateway &gt; VPC Link &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; API Gateway &gt; VPC Link &gt; Allowed &gt; Region
- AWS &gt; API Gateway &gt; VPC Link &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; API Gateway &gt; VPC Link &gt; CMDB
- AWS &gt; API Gateway &gt; VPC Link &gt; Regions
- AWS &gt; API Gateway &gt; VPC Link &gt; Tags
- AWS &gt; API Gateway &gt; VPC Link &gt; Tags &gt; Template

_Action Types_

- AWS &gt; API Gateway &gt; VPC Link &gt; Delete
- AWS &gt; API Gateway &gt; VPC Link &gt; Delete from AWS
- AWS &gt; API Gateway &gt; VPC Link &gt; Router
- AWS &gt; API Gateway &gt; VPC Link &gt; Set Tags
- AWS &gt; API Gateway &gt; VPC Link &gt; Skip alarm for Active control
- AWS &gt; API Gateway &gt; VPC Link &gt; Skip alarm for Active control [90 days]
- AWS &gt; API Gateway &gt; VPC Link &gt; Skip alarm for Tags control
- AWS &gt; API Gateway &gt; VPC Link &gt; Skip alarm for Tags control [90 days]
- AWS &gt; API Gateway &gt; VPC Link &gt; Update Tags</description>
            <pubDate>Tue, 06 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-wafregional-v5-7-0</guid>
            <title>aws-wafregional v5.7.0 - Identify and remove unallowed resources from CMDB</title>
            <link>https://turbot.com/guardrails/changelog/aws-wafregional-v5-7-0</link>
            <description>_What&apos;s new?_

_Control Types_

- AWS &gt; WAF Regional &gt; Rule &gt; Allowed
- AWS &gt; WAF Regional &gt; Rule &gt; Allowed &gt; Custom
- AWS &gt; WAF Regional &gt; Rule &gt; Allowed &gt; Region

_Policy Types_

- AWS &gt; WAF Regional &gt; Allowed Regions [Default]
- AWS &gt; WAF Regional &gt; Rule &gt; Allowed
- AWS &gt; WAF Regional &gt; Rule &gt; Allowed &gt; Custom
- AWS &gt; WAF Regional &gt; Rule &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; WAF Regional &gt; Rule &gt; Allowed &gt; Region
- AWS &gt; WAF Regional &gt; Rule &gt; Allowed &gt; Region &gt; Regions</description>
            <pubDate>Mon, 05 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-s3-v5-34-0</guid>
            <title>aws-s3 v5.34.0 - Identify and remove unallowed resources from CMDB</title>
            <link>https://turbot.com/guardrails/changelog/aws-s3-v5-34-0</link>
            <description>_What&apos;s new?_

_Control Types_

- AWS &gt; S3 &gt; Bucket &gt; Allowed
- AWS &gt; S3 &gt; Bucket &gt; Allowed &gt; Custom
- AWS &gt; S3 &gt; Bucket &gt; Allowed &gt; Region

_Policy Types_

- AWS &gt; S3 &gt; Allowed Regions [Default]
- AWS &gt; S3 &gt; Bucket &gt; Allowed
- AWS &gt; S3 &gt; Bucket &gt; Allowed &gt; Custom
- AWS &gt; S3 &gt; Bucket &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; S3 &gt; Bucket &gt; Allowed &gt; Region
- AWS &gt; S3 &gt; Bucket &gt; Allowed &gt; Region &gt; Regions</description>
            <pubDate>Mon, 05 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-opensearch-v5-4-0</guid>
            <title>aws-opensearch v5.4.0 - Identify and remove unallowed resources from CMDB</title>
            <link>https://turbot.com/guardrails/changelog/aws-opensearch-v5-4-0</link>
            <description>_What&apos;s new?_

_Control Types_

- AWS &gt; OpenSearch &gt; Domain &gt; Allowed
- AWS &gt; OpenSearch &gt; Domain &gt; Allowed &gt; Custom
- AWS &gt; OpenSearch &gt; Domain &gt; Allowed &gt; Region

_Policy Types_

- AWS &gt; OpenSearch &gt; Allowed Regions [Default]
- AWS &gt; OpenSearch &gt; Domain &gt; Allowed
- AWS &gt; OpenSearch &gt; Domain &gt; Allowed &gt; Custom
- AWS &gt; OpenSearch &gt; Domain &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; OpenSearch &gt; Domain &gt; Allowed &gt; Region
- AWS &gt; OpenSearch &gt; Domain &gt; Allowed &gt; Region &gt; Regions</description>
            <pubDate>Mon, 05 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-fsx-v5-6-0</guid>
            <title>aws-fsx v5.6.0 - Identify and remove unallowed resources from CMDB</title>
            <link>https://turbot.com/guardrails/changelog/aws-fsx-v5-6-0</link>
            <description>_What&apos;s new?_

_Control Types_

- AWS &gt; FSx &gt; Backup &gt; Allowed
- AWS &gt; FSx &gt; Backup &gt; Allowed &gt; Custom
- AWS &gt; FSx &gt; Backup &gt; Allowed &gt; Region
- AWS &gt; FSx &gt; File System &gt; Allowed
- AWS &gt; FSx &gt; File System &gt; Allowed &gt; Custom
- AWS &gt; FSx &gt; File System &gt; Allowed &gt; Region

_Policy Types_

- AWS &gt; FSx &gt; Allowed Regions [Default]
- AWS &gt; FSx &gt; Backup &gt; Allowed
- AWS &gt; FSx &gt; Backup &gt; Allowed &gt; Custom
- AWS &gt; FSx &gt; Backup &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; FSx &gt; Backup &gt; Allowed &gt; Region
- AWS &gt; FSx &gt; Backup &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; FSx &gt; File System &gt; Allowed
- AWS &gt; FSx &gt; File System &gt; Allowed &gt; Custom
- AWS &gt; FSx &gt; File System &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; FSx &gt; File System &gt; Allowed &gt; Region
- AWS &gt; FSx &gt; File System &gt; Allowed &gt; Region &gt; Regions</description>
            <pubDate>Mon, 05 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-elasticache-v5-13-0</guid>
            <title>aws-elasticache v5.13.0 - Identify and remove unallowed resources from CMDB</title>
            <link>https://turbot.com/guardrails/changelog/aws-elasticache-v5-13-0</link>
            <description>_What&apos;s new?_

_Control Types_

- AWS &gt; ElastiCache &gt; Cache Cluster &gt; Allowed
- AWS &gt; ElastiCache &gt; Cache Cluster &gt; Allowed &gt; Custom
- AWS &gt; ElastiCache &gt; Cache Cluster &gt; Allowed &gt; Engines
- AWS &gt; ElastiCache &gt; Cache Cluster &gt; Allowed &gt; Region
- AWS &gt; ElastiCache &gt; Cache Parameter Group &gt; Allowed
- AWS &gt; ElastiCache &gt; Cache Parameter Group &gt; Allowed &gt; Custom
- AWS &gt; ElastiCache &gt; Cache Parameter Group &gt; Allowed &gt; Region
- AWS &gt; ElastiCache &gt; Replication Group &gt; Allowed
- AWS &gt; ElastiCache &gt; Replication Group &gt; Allowed &gt; Custom
- AWS &gt; ElastiCache &gt; Replication Group &gt; Allowed &gt; Region
- AWS &gt; ElastiCache &gt; Snapshot &gt; Allowed
- AWS &gt; ElastiCache &gt; Snapshot &gt; Allowed &gt; Custom
- AWS &gt; ElastiCache &gt; Snapshot &gt; Allowed &gt; Region

_Policy Types_

- AWS &gt; ElastiCache &gt; Allowed Regions [Default]
- AWS &gt; ElastiCache &gt; Cache Cluster &gt; Allowed
- AWS &gt; ElastiCache &gt; Cache Cluster &gt; Allowed &gt; Custom
- AWS &gt; ElastiCache &gt; Cache Cluster &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; ElastiCache &gt; Cache Cluster &gt; Allowed &gt; Engines
- AWS &gt; ElastiCache &gt; Cache Cluster &gt; Allowed &gt; Engines &gt; Engines
- AWS &gt; ElastiCache &gt; Cache Cluster &gt; Allowed &gt; Region
- AWS &gt; ElastiCache &gt; Cache Cluster &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; ElastiCache &gt; Cache Parameter Group &gt; Allowed
- AWS &gt; ElastiCache &gt; Cache Parameter Group &gt; Allowed &gt; Custom
- AWS &gt; ElastiCache &gt; Cache Parameter Group &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; ElastiCache &gt; Cache Parameter Group &gt; Allowed &gt; Region
- AWS &gt; ElastiCache &gt; Cache Parameter Group &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; ElastiCache &gt; Replication Group &gt; Allowed
- AWS &gt; ElastiCache &gt; Replication Group &gt; Allowed &gt; Custom
- AWS &gt; ElastiCache &gt; Replication Group &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; ElastiCache &gt; Replication Group &gt; Allowed &gt; Region
- AWS &gt; ElastiCache &gt; Replication Group &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; ElastiCache &gt; Snapshot &gt; Allowed
- AWS &gt; ElastiCache &gt; Snapshot &gt; Allowed &gt; Custom
- AWS &gt; ElastiCache &gt; Snapshot &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; ElastiCache &gt; Snapshot &gt; Allowed &gt; Region
- AWS &gt; ElastiCache &gt; Snapshot &gt; Allowed &gt; Region &gt; Regions</description>
            <pubDate>Mon, 05 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-efs-v5-12-0</guid>
            <title>aws-efs v5.12.0 - Identify and remove unallowed resources from CMDB</title>
            <link>https://turbot.com/guardrails/changelog/aws-efs-v5-12-0</link>
            <description>_What&apos;s new?_

_Control Types_

- AWS &gt; EFS &gt; FileSystem &gt; Allowed
- AWS &gt; EFS &gt; FileSystem &gt; Allowed &gt; Custom
- AWS &gt; EFS &gt; FileSystem &gt; Allowed &gt; Encryption at Rest
- AWS &gt; EFS &gt; FileSystem &gt; Allowed &gt; Region
- AWS &gt; EFS &gt; Mount Target &gt; Allowed
- AWS &gt; EFS &gt; Mount Target &gt; Allowed &gt; Custom
- AWS &gt; EFS &gt; Mount Target &gt; Allowed &gt; Region

_Policy Types_

- AWS &gt; EFS &gt; Allowed Regions [Default]
- AWS &gt; EFS &gt; FileSystem &gt; Allowed
- AWS &gt; EFS &gt; FileSystem &gt; Allowed &gt; Custom
- AWS &gt; EFS &gt; FileSystem &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; EFS &gt; FileSystem &gt; Allowed &gt; Encryption at Rest
- AWS &gt; EFS &gt; FileSystem &gt; Allowed &gt; Encryption at Rest &gt; Level
- AWS &gt; EFS &gt; FileSystem &gt; Allowed &gt; Encryption at Rest &gt; Level &gt; Customer Managed Key
- AWS &gt; EFS &gt; FileSystem &gt; Allowed &gt; Region
- AWS &gt; EFS &gt; FileSystem &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; EFS &gt; Mount Target &gt; Allowed
- AWS &gt; EFS &gt; Mount Target &gt; Allowed &gt; Custom
- AWS &gt; EFS &gt; Mount Target &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; EFS &gt; Mount Target &gt; Allowed &gt; Region
- AWS &gt; EFS &gt; Mount Target &gt; Allowed &gt; Region &gt; Regions</description>
            <pubDate>Mon, 05 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ecs-v5-11-0</guid>
            <title>aws-ecs v5.11.0 - Identify and remove unallowed resources from CMDB</title>
            <link>https://turbot.com/guardrails/changelog/aws-ecs-v5-11-0</link>
            <description>_What&apos;s new?_

_Control Types_

- AWS &gt; ECS &gt; Cluster &gt; Allowed
- AWS &gt; ECS &gt; Cluster &gt; Allowed &gt; Custom
- AWS &gt; ECS &gt; Cluster &gt; Allowed &gt; Region
- AWS &gt; ECS &gt; Container Instance &gt; Allowed
- AWS &gt; ECS &gt; Container Instance &gt; Allowed &gt; Custom
- AWS &gt; ECS &gt; Container Instance &gt; Allowed &gt; Region
- AWS &gt; ECS &gt; Service &gt; Allowed
- AWS &gt; ECS &gt; Service &gt; Allowed &gt; Custom
- AWS &gt; ECS &gt; Service &gt; Allowed &gt; Region
- AWS &gt; ECS &gt; Task Definition &gt; Allowed
- AWS &gt; ECS &gt; Task Definition &gt; Allowed &gt; Custom
- AWS &gt; ECS &gt; Task Definition &gt; Allowed &gt; Region

_Policy Types_

- AWS &gt; ECS &gt; Allowed Regions [Default]
- AWS &gt; ECS &gt; Cluster &gt; Allowed
- AWS &gt; ECS &gt; Cluster &gt; Allowed &gt; Custom
- AWS &gt; ECS &gt; Cluster &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; ECS &gt; Cluster &gt; Allowed &gt; Region
- AWS &gt; ECS &gt; Cluster &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; ECS &gt; Container Instance &gt; Allowed
- AWS &gt; ECS &gt; Container Instance &gt; Allowed &gt; Custom
- AWS &gt; ECS &gt; Container Instance &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; ECS &gt; Container Instance &gt; Allowed &gt; Region
- AWS &gt; ECS &gt; Container Instance &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; ECS &gt; Service &gt; Allowed
- AWS &gt; ECS &gt; Service &gt; Allowed &gt; Custom
- AWS &gt; ECS &gt; Service &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; ECS &gt; Service &gt; Allowed &gt; Region
- AWS &gt; ECS &gt; Service &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; ECS &gt; Task Definition &gt; Allowed
- AWS &gt; ECS &gt; Task Definition &gt; Allowed &gt; Custom
- AWS &gt; ECS &gt; Task Definition &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; ECS &gt; Task Definition &gt; Allowed &gt; Region
- AWS &gt; ECS &gt; Task Definition &gt; Allowed &gt; Region &gt; Regions</description>
            <pubDate>Mon, 05 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ecr-v5-16-0</guid>
            <title>aws-ecr v5.16.0 - Identify and remove unallowed resources from CMDB</title>
            <link>https://turbot.com/guardrails/changelog/aws-ecr-v5-16-0</link>
            <description>_What&apos;s new?_

_Control Types_

- AWS &gt; ECR &gt; Image &gt; Allowed
- AWS &gt; ECR &gt; Image &gt; Allowed &gt; Custom
- AWS &gt; ECR &gt; Image &gt; Allowed &gt; Region
- AWS &gt; ECR &gt; Public Repository &gt; Allowed
- AWS &gt; ECR &gt; Public Repository &gt; Allowed &gt; Custom
- AWS &gt; ECR &gt; Repository &gt; Allowed
- AWS &gt; ECR &gt; Repository &gt; Allowed &gt; Custom
- AWS &gt; ECR &gt; Repository &gt; Allowed &gt; Encryption at Rest
- AWS &gt; ECR &gt; Repository &gt; Allowed &gt; Region

_Policy Types_

- AWS &gt; ECR &gt; Allowed Regions [Default]
- AWS &gt; ECR &gt; Image &gt; Allowed
- AWS &gt; ECR &gt; Image &gt; Allowed &gt; Custom
- AWS &gt; ECR &gt; Image &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; ECR &gt; Image &gt; Allowed &gt; Region
- AWS &gt; ECR &gt; Image &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; ECR &gt; Public Repository &gt; Allowed
- AWS &gt; ECR &gt; Public Repository &gt; Allowed &gt; Custom
- AWS &gt; ECR &gt; Public Repository &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; ECR &gt; Repository &gt; Allowed
- AWS &gt; ECR &gt; Repository &gt; Allowed &gt; Custom
- AWS &gt; ECR &gt; Repository &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; ECR &gt; Repository &gt; Allowed &gt; Encryption at Rest
- AWS &gt; ECR &gt; Repository &gt; Allowed &gt; Encryption at Rest &gt; Level
- AWS &gt; ECR &gt; Repository &gt; Allowed &gt; Encryption at Rest &gt; Level &gt; Customer Managed Key
- AWS &gt; ECR &gt; Repository &gt; Allowed &gt; Region
- AWS &gt; ECR &gt; Repository &gt; Allowed &gt; Region &gt; Regions</description>
            <pubDate>Mon, 05 Jan 2026 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-network-v5-28-0</guid>
            <title>azure-network v5.28.0 - Track and manage NAT Gateway resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-network-v5-28-0</link>
            <description>_Resource Types_

- Azure &gt; Network &gt; NAT Gateway

_Control Types_

- Azure &gt; Network &gt; NAT Gateway &gt; Active
- Azure &gt; Network &gt; NAT Gateway &gt; Allowed
- Azure &gt; Network &gt; NAT Gateway &gt; Allowed &gt; Custom
- Azure &gt; Network &gt; NAT Gateway &gt; Allowed &gt; Region
- Azure &gt; Network &gt; NAT Gateway &gt; CMDB
- Azure &gt; Network &gt; NAT Gateway &gt; Discovery
- Azure &gt; Network &gt; NAT Gateway &gt; Tags

_Policy Types_

- Azure &gt; Network &gt; NAT Gateway &gt; Active
- Azure &gt; Network &gt; NAT Gateway &gt; Active &gt; Age
- Azure &gt; Network &gt; NAT Gateway &gt; Active &gt; Last Modified
- Azure &gt; Network &gt; NAT Gateway &gt; Allowed
- Azure &gt; Network &gt; NAT Gateway &gt; Allowed &gt; Custom
- Azure &gt; Network &gt; NAT Gateway &gt; Allowed &gt; Custom &gt; Rules
- Azure &gt; Network &gt; NAT Gateway &gt; Allowed &gt; Region
- Azure &gt; Network &gt; NAT Gateway &gt; Allowed &gt; Region &gt; Regions
- Azure &gt; Network &gt; NAT Gateway &gt; CMDB
- Azure &gt; Network &gt; NAT Gateway &gt; Regions
- Azure &gt; Network &gt; NAT Gateway &gt; Tags
- Azure &gt; Network &gt; NAT Gateway &gt; Tags &gt; Template

_Action Types_

- Azure &gt; Network &gt; NAT Gateway &gt; Delete
- Azure &gt; Network &gt; NAT Gateway &gt; Router
- Azure &gt; Network &gt; NAT Gateway &gt; Set Tags</description>
            <pubDate>Wed, 24 Dec 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ec2-v5-50-0</guid>
            <title>aws-ec2 v5.50.0 - Improve AMI lineage discovery using native AWS API</title>
            <link>https://turbot.com/guardrails/changelog/aws-ec2-v5-50-0</link>
            <description>_What&apos;s new?_

- The `AWS &gt; EC2 &gt; AMI &gt; CMDB` control now uses AWS&apos;s native `GetImageAncestry` API to track AMI lineage. This provides complete ancestry information beyond the previous three-level limitation, offering improved accuracy and visibility into AMI lineage across accounts and regions. The previous manual parent AMI hierarchy tracking (limited to parent, grandparent, and great-grandparent) has been replaced with this more comprehensive API-based approach.</description>
            <pubDate>Tue, 23 Dec 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-cisv3-0-v5-0-7</guid>
            <title>aws-cisv3-0 v5.0.7 - Controls now correctly resolve to Skipped state when dependent CMDB controls are Skipped or TBD</title>
            <link>https://turbot.com/guardrails/changelog/aws-cisv3-0-v5-0-7</link>
            <description>_Bug fixes_

- Fixed an issue where controls could incorrectly enter an Invalid or TBD state when dependent CMDB controls were Skipped or TBD, even when the corresponding policies were set to Skip. Controls now correctly resolve to a Skipped state in these scenarios.</description>
            <pubDate>Tue, 23 Dec 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-sqs-v5-20-0</guid>
            <title>aws-sqs v5.20.0 - Identify and remove unallowed resources from CMDB</title>
            <link>https://turbot.com/guardrails/changelog/aws-sqs-v5-20-0</link>
            <description>_What&apos;s new?_

_Control Types_

- AWS &gt; SQS &gt; Queue &gt; Allowed
- AWS &gt; SQS &gt; Queue &gt; Allowed &gt; Custom
- AWS &gt; SQS &gt; Queue &gt; Allowed &gt; Region

_Policy Types_

- AWS &gt; SQS &gt; Allowed Regions [Default]
- AWS &gt; SQS &gt; Queue &gt; Allowed
- AWS &gt; SQS &gt; Queue &gt; Allowed &gt; Custom
- AWS &gt; SQS &gt; Queue &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; SQS &gt; Queue &gt; Allowed &gt; Region
- AWS &gt; SQS &gt; Queue &gt; Allowed &gt; Region &gt; Regions</description>
            <pubDate>Mon, 22 Dec 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-sns-v5-20-0</guid>
            <title>aws-sns v5.20.0 - Identify and remove unallowed resources from CMDB</title>
            <link>https://turbot.com/guardrails/changelog/aws-sns-v5-20-0</link>
            <description>_What&apos;s new?_

_Control Types_

- AWS &gt; SNS &gt; Subscription &gt; Allowed
- AWS &gt; SNS &gt; Subscription &gt; Allowed &gt; Custom
- AWS &gt; SNS &gt; Subscription &gt; Allowed &gt; Region
- AWS &gt; SNS &gt; Topic &gt; Allowed
- AWS &gt; SNS &gt; Topic &gt; Allowed &gt; Custom
- AWS &gt; SNS &gt; Topic &gt; Allowed &gt; Region

_Policy Types_

- AWS &gt; SNS &gt; Allowed Regions [Default]
- AWS &gt; SNS &gt; Subscription &gt; Allowed
- AWS &gt; SNS &gt; Subscription &gt; Allowed &gt; Custom
- AWS &gt; SNS &gt; Subscription &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; SNS &gt; Subscription &gt; Allowed &gt; Region
- AWS &gt; SNS &gt; Subscription &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; SNS &gt; Topic &gt; Allowed
- AWS &gt; SNS &gt; Topic &gt; Allowed &gt; Custom
- AWS &gt; SNS &gt; Topic &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; SNS &gt; Topic &gt; Allowed &gt; Region
- AWS &gt; SNS &gt; Topic &gt; Allowed &gt; Region &gt; Regions</description>
            <pubDate>Mon, 22 Dec 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-v5-42-0</guid>
            <title>aws v5.42.0 - Track and Manage Organization Policies in CMDB</title>
            <link>https://turbot.com/guardrails/changelog/aws-v5-42-0</link>
            <description>_What&apos;s new?_

- You can now track and manage AWS Organizations policies in CMDB, including AI Services Opt-Out Policy, Backup Policy, Chatbot Policy, Declarative Policy EC2, Resource Control Policy, Service Control Policy, and Tag Policy.
- Account CMDB data now includes details about account regions, effective organization policies, and attached organization policies.

_Resource Types_

- AWS &gt; Organizations
- AWS &gt; Organizations &gt; AI Services Opt-Out Policy
- AWS &gt; Organizations &gt; Backup Policy
- AWS &gt; Organizations &gt; Chatbot Policy
- AWS &gt; Organizations &gt; Declarative Policy EC2
- AWS &gt; Organizations &gt; Resource Control Policy
- AWS &gt; Organizations &gt; Service Control Policy
- AWS &gt; Organizations &gt; Tag Policy

_Policy Types_

- AWS &gt; Organization &gt; Discovery Level
- AWS &gt; Organizations &gt; AI Services Opt-Out Policy &gt; CMDB
- AWS &gt; Organizations &gt; Backup Policy &gt; CMDB
- AWS &gt; Organizations &gt; Chatbot Policy &gt; CMDB
- AWS &gt; Organizations &gt; Declarative Policy EC2 &gt; CMDB
- AWS &gt; Organizations &gt; Resource Control Policy &gt; CMDB
- AWS &gt; Organizations &gt; Service Control Policy &gt; CMDB
- AWS &gt; Organizations &gt; Tag Policy &gt; CMDB

_Control Types_

- AWS &gt; Organizations &gt; AI Services Opt-Out Policy &gt; CMDB
- AWS &gt; Organizations &gt; AI Services Opt-Out Policy &gt; Discovery
- AWS &gt; Organizations &gt; Backup Policy &gt; CMDB
- AWS &gt; Organizations &gt; Backup Policy &gt; Discovery
- AWS &gt; Organizations &gt; Chatbot Policy &gt; CMDB
- AWS &gt; Organizations &gt; Chatbot Policy &gt; Discovery
- AWS &gt; Organizations &gt; Declarative Policy EC2 &gt; CMDB
- AWS &gt; Organizations &gt; Declarative Policy EC2 &gt; Discovery
- AWS &gt; Organizations &gt; Resource Control Policy &gt; CMDB
- AWS &gt; Organizations &gt; Resource Control Policy &gt; Discovery
- AWS &gt; Organizations &gt; Service Control Policy &gt; CMDB
- AWS &gt; Organizations &gt; Service Control Policy &gt; Discovery
- AWS &gt; Organizations &gt; Tag Policy &gt; CMDB
- AWS &gt; Organizations &gt; Tag Policy &gt; Discovery

_Action Types_

- AWS &gt; Organizations &gt; AI Services Opt-Out Policy &gt; Router
- AWS &gt; Organizations &gt; Backup Policy &gt; Router
- AWS &gt; Organizations &gt; Chatbot Policy &gt; Router
- AWS &gt; Organizations &gt; Declarative Policy EC2 &gt; Router
- AWS &gt; Organizations &gt; Resource Control Policy &gt; Router
- AWS &gt; Organizations &gt; Service Control Policy &gt; Router
- AWS &gt; Organizations &gt; Tag Policy &gt; Router</description>
            <pubDate>Fri, 19 Dec 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-organizations-v5-7-0</guid>
            <title>aws-organizations v5.7.0 - Organizations service resource type is now deprecated</title>
            <link>https://turbot.com/guardrails/changelog/aws-organizations-v5-7-0</link>
            <description>_What&apos;s new?_

- Deprecated the `AWS &gt; Organizations` service resource type to help differentiate it from the latest `AWS &gt; Organizations` resource type in the `aws` mod.

_Resource Types_

_Renamed_

- AWS &gt; Organizations to AWS &gt; Organizations [Deprecated]
- AWS &gt; Organizations &gt; Organization to AWS &gt; Organizations [Deprecated] &gt; Organization
- AWS &gt; Organizations &gt; Organization Root to AWS &gt; Organizations [Deprecated] &gt; Organization Root
- AWS &gt; Organizations &gt; Organizational Account to AWS &gt; Organizations [Deprecated] &gt; Organizational Account
- AWS &gt; Organizations &gt; Organizational Unit to AWS &gt; Organizations [Deprecated] &gt; Organizational Unit

_Control Types_

_Renamed_

- AWS &gt; Organizations &gt; Organization &gt; CMDB to AWS &gt; Organizations [Deprecated] &gt; Organization &gt; CMDB
- AWS &gt; Organizations &gt; Organization &gt; Discovery to AWS &gt; Organizations [Deprecated] &gt; Organization &gt; Discovery
- AWS &gt; Organizations &gt; Organization &gt; Intelligent Assessment to AWS &gt; Organizations [Deprecated] &gt; Organization &gt; Intelligent Assessment
- AWS &gt; Organizations &gt; Organization Root &gt; Active to AWS &gt; Organizations [Deprecated] &gt; Organization Root &gt; Active
- AWS &gt; Organizations &gt; Organization Root &gt; Approved to AWS &gt; Organizations [Deprecated] &gt; Organization Root &gt; Approved
- AWS &gt; Organizations &gt; Organization Root &gt; CMDB to AWS &gt; Organizations [Deprecated] &gt; Organization Root &gt; CMDB
- AWS &gt; Organizations &gt; Organization Root &gt; Discovery to AWS &gt; Organizations [Deprecated] &gt; Organization Root &gt; Discovery
- AWS &gt; Organizations &gt; Organization Root &gt; Intelligent Assessment to AWS &gt; Organizations [Deprecated] &gt; Organization Root &gt; Intelligent Assessment
- AWS &gt; Organizations &gt; Organizational Account &gt; Active to AWS &gt; Organizations [Deprecated] &gt; Organizational Account &gt; Active
- AWS &gt; Organizations &gt; Organizational Account &gt; Approved to AWS &gt; Organizations [Deprecated] &gt; Organizational Account &gt; Approved
- AWS &gt; Organizations &gt; Organizational Account &gt; CMDB to AWS &gt; Organizations [Deprecated] &gt; Organizational Account &gt; CMDB
- AWS &gt; Organizations &gt; Organizational Account &gt; Discovery to AWS &gt; Organizations [Deprecated] &gt; Organizational Account &gt; Discovery
- AWS &gt; Organizations &gt; Organizational Account &gt; Intelligent Assessment to AWS &gt; Organizations [Deprecated] &gt; Organizational Account &gt; Intelligent Assessment
- AWS &gt; Organizations &gt; Organizational Unit &gt; CMDB to AWS &gt; Organizations [Deprecated] &gt; Organizational Unit &gt; CMDB
- AWS &gt; Organizations &gt; Organizational Unit &gt; Discovery to AWS &gt; Organizations [Deprecated] &gt; Organizational Unit &gt; Discovery
- AWS &gt; Organizations &gt; Organizational Unit &gt; Intelligent Assessment to AWS &gt; Organizations [Deprecated] &gt; Organizational Unit &gt; Intelligent Assessment

_Policy Types_

_Renamed_

- AWS &gt; Organizations &gt; API Enabled to AWS &gt; Organizations [Deprecated] &gt; API Enabled
- AWS &gt; Organizations &gt; Enabled to AWS &gt; Organizations [Deprecated] &gt; Enabled
- AWS &gt; Organizations &gt; Organization &gt; CMDB to AWS &gt; Organizations [Deprecated] &gt; Organization &gt; CMDB
- AWS &gt; Organizations &gt; Organization &gt; Intelligent Assessment to AWS &gt; Organizations [Deprecated] &gt; Organization &gt; Intelligent Assessment
- AWS &gt; Organizations &gt; Organization &gt; Intelligent Assessment &gt; Context to AWS &gt; Organizations [Deprecated] &gt; Organization &gt; Intelligent Assessment &gt; Context
- AWS &gt; Organizations &gt; Organization &gt; Intelligent Assessment &gt; User Prompt to AWS &gt; Organizations [Deprecated] &gt; Organization &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; Organizations &gt; Organization Root &gt; Active to AWS &gt; Organizations [Deprecated] &gt; Organization Root &gt; Active
- AWS &gt; Organizations &gt; Organization Root &gt; Active &gt; Age to AWS &gt; Organizations [Deprecated] &gt; Organization Root &gt; Active &gt; Age
- AWS &gt; Organizations &gt; Organization Root &gt; Active &gt; Last Modified to AWS &gt; Organizations [Deprecated] &gt; Organization Root &gt; Active &gt; Last Modified
- AWS &gt; Organizations &gt; Organization Root &gt; Approved to AWS &gt; Organizations [Deprecated] &gt; Organization Root &gt; Approved
- AWS &gt; Organizations &gt; Organization Root &gt; Approved &gt; Custom to AWS &gt; Organizations [Deprecated] &gt; Organization Root &gt; Approved &gt; Custom
- AWS &gt; Organizations &gt; Organization Root &gt; Approved &gt; Usage to AWS &gt; Organizations [Deprecated] &gt; Organization Root &gt; Approved &gt; Usage
- AWS &gt; Organizations &gt; Organization Root &gt; CMDB to AWS &gt; Organizations [Deprecated] &gt; Organization Root &gt; CMDB
- AWS &gt; Organizations &gt; Organization Root &gt; Intelligent Assessment to AWS &gt; Organizations [Deprecated] &gt; Organization Root &gt; Intelligent Assessment
- AWS &gt; Organizations &gt; Organization Root &gt; Intelligent Assessment &gt; Context to AWS &gt; Organizations [Deprecated] &gt; Organization Root &gt; Intelligent Assessment &gt; Context
- AWS &gt; Organizations &gt; Organization Root &gt; Intelligent Assessment &gt; User Prompt to AWS &gt; Organizations [Deprecated] &gt; Organization Root &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; Organizations &gt; Organizational Account &gt; Active to AWS &gt; Organizations [Deprecated] &gt; Organizational Account &gt; Active
- AWS &gt; Organizations &gt; Organizational Account &gt; Active &gt; Age to AWS &gt; Organizations [Deprecated] &gt; Organizational Account &gt; Active &gt; Age
- AWS &gt; Organizations &gt; Organizational Account &gt; Active &gt; Last Modified to AWS &gt; Organizations [Deprecated] &gt; Organizational Account &gt; Active &gt; Last Modified
- AWS &gt; Organizations &gt; Organizational Account &gt; Approved to AWS &gt; Organizations [Deprecated] &gt; Organizational Account &gt; Approved
- AWS &gt; Organizations &gt; Organizational Account &gt; Approved &gt; Custom to AWS &gt; Organizations [Deprecated] &gt; Organizational Account &gt; Approved &gt; Custom
- AWS &gt; Organizations &gt; Organizational Account &gt; Approved &gt; Usage to AWS &gt; Organizations [Deprecated] &gt; Organizational Account &gt; Approved &gt; Usage
- AWS &gt; Organizations &gt; Organizational Account &gt; CMDB to AWS &gt; Organizations [Deprecated] &gt; Organizational Account &gt; CMDB
- AWS &gt; Organizations &gt; Organizational Account &gt; Intelligent Assessment to AWS &gt; Organizations [Deprecated] &gt; Organizational Account &gt; Intelligent Assessment
- AWS &gt; Organizations &gt; Organizational Account &gt; Intelligent Assessment &gt; Context to AWS &gt; Organizations [Deprecated] &gt; Organizational Account &gt; Intelligent Assessment &gt; Context
- AWS &gt; Organizations &gt; Organizational Account &gt; Intelligent Assessment &gt; User Prompt to AWS &gt; Organizations [Deprecated] &gt; Organizational Account &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; Organizations &gt; Organizational Unit &gt; CMDB to AWS &gt; Organizations [Deprecated] &gt; Organizational Unit &gt; CMDB
- AWS &gt; Organizations &gt; Organizational Unit &gt; Intelligent Assessment to AWS &gt; Organizations [Deprecated] &gt; Organizational Unit &gt; Intelligent Assessment
- AWS &gt; Organizations &gt; Organizational Unit &gt; Intelligent Assessment &gt; Context to AWS &gt; Organizations [Deprecated] &gt; Organizational Unit &gt; Intelligent Assessment &gt; Context
- AWS &gt; Organizations &gt; Organizational Unit &gt; Intelligent Assessment &gt; User Prompt to AWS &gt; Organizations [Deprecated] &gt; Organizational Unit &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; Organizations &gt; Permissions to AWS &gt; Organizations [Deprecated] &gt; Permissions
- AWS &gt; Organizations &gt; Permissions &gt; Levels to AWS &gt; Organizations [Deprecated] &gt; Permissions &gt; Levels
- AWS &gt; Organizations &gt; Permissions &gt; Levels &gt; Modifiers to AWS &gt; Organizations [Deprecated] &gt; Permissions &gt; Levels &gt; Modifiers
- AWS &gt; Organizations &gt; Permissions &gt; Lockdown to AWS &gt; Organizations [Deprecated] &gt; Permissions &gt; Lockdown
- AWS &gt; Organizations &gt; Permissions &gt; Lockdown &gt; API Boundary to AWS &gt; Organizations [Deprecated] &gt; Permissions &gt; Lockdown &gt; API Boundary

_Action Types_

_Renamed_

- AWS &gt; Organizations &gt; Organization Root &gt; Router to AWS &gt; Organizations [Deprecated] &gt; Organization Root &gt; Router
- AWS &gt; Organizations &gt; Organization Root &gt; Skip alarm for Active control to AWS &gt; Organizations [Deprecated] &gt; Organization Root &gt; Skip alarm for Active control
- AWS &gt; Organizations &gt; Organization Root &gt; Skip alarm for Active control [90 days] to AWS &gt; Organizations [Deprecated] &gt; Organization Root &gt; Skip alarm for Active control [90 days]
- AWS &gt; Organizations &gt; Organization Root &gt; Skip alarm for Approved control to AWS &gt; Organizations [Deprecated] &gt; Organization Root &gt; Skip alarm for Approved control
- AWS &gt; Organizations &gt; Organization Root &gt; Skip alarm for Approved control [90 days] to AWS &gt; Organizations [Deprecated] &gt; Organization Root &gt; Skip alarm for Approved control [90 days]
- AWS &gt; Organizations &gt; Organizational Account &gt; Router to AWS &gt; Organizations [Deprecated] &gt; Organizational Account &gt; Router
- AWS &gt; Organizations &gt; Organizational Account &gt; Skip alarm for Active control to AWS &gt; Organizations [Deprecated] &gt; Organizational Account &gt; Skip alarm for Active control
- AWS &gt; Organizations &gt; Organizational Account &gt; Skip alarm for Active control [90 days] to AWS &gt; Organizations [Deprecated] &gt; Organizational Account &gt; Skip alarm for Active control [90 days]
- AWS &gt; Organizations &gt; Organizational Account &gt; Skip alarm for Approved control to AWS &gt; Organizations [Deprecated] &gt; Organizational Account &gt; Skip alarm for Approved control
- AWS &gt; Organizations &gt; Organizational Account &gt; Skip alarm for Approved control [90 days] to AWS &gt; Organizations [Deprecated] &gt; Organizational Account &gt; Skip alarm for Approved control [90 days]
- AWS &gt; Organizations &gt; Organizational Unit &gt; Router to AWS &gt; Organizations [Deprecated] &gt; Organizational Unit &gt; Router</description>
            <pubDate>Fri, 19 Dec 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-msk-v5-7-0</guid>
            <title>aws-msk v5.7.0 - Identify and remove unallowed resources from CMDB</title>
            <link>https://turbot.com/guardrails/changelog/aws-msk-v5-7-0</link>
            <description>_What&apos;s new?_

_Control Types_

- AWS &gt; MSK &gt; Cluster &gt; Allowed
- AWS &gt; MSK &gt; Cluster &gt; Allowed &gt; Custom
- AWS &gt; MSK &gt; Cluster &gt; Allowed &gt; Instance Type
- AWS &gt; MSK &gt; Cluster &gt; Allowed &gt; Region

_Policy Types_

- AWS &gt; MSK &gt; Allowed Regions [Default]
- AWS &gt; MSK &gt; Cluster &gt; Allowed
- AWS &gt; MSK &gt; Cluster &gt; Allowed &gt; Custom
- AWS &gt; MSK &gt; Cluster &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; MSK &gt; Cluster &gt; Allowed &gt; Instance Type
- AWS &gt; MSK &gt; Cluster &gt; Allowed &gt; Instance Type &gt; Instance Types
- AWS &gt; MSK &gt; Cluster &gt; Allowed &gt; Region
- AWS &gt; MSK &gt; Cluster &gt; Allowed &gt; Region &gt; Regions</description>
            <pubDate>Fri, 19 Dec 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-events-v5-17-0</guid>
            <title>aws-events v5.17.0 - Identify and remove unallowed resources from CMDB</title>
            <link>https://turbot.com/guardrails/changelog/aws-events-v5-17-0</link>
            <description>_What&apos;s new?_

_Control Types_

- AWS &gt; Events &gt; Event Bus &gt; Allowed
- AWS &gt; Events &gt; Event Bus &gt; Allowed &gt; Custom
- AWS &gt; Events &gt; Event Bus &gt; Allowed &gt; Region
- AWS &gt; Events &gt; Rule &gt; Allowed
- AWS &gt; Events &gt; Rule &gt; Allowed &gt; Custom
- AWS &gt; Events &gt; Rule &gt; Allowed &gt; Region
- AWS &gt; Events &gt; Target &gt; Allowed
- AWS &gt; Events &gt; Target &gt; Allowed &gt; Custom
- AWS &gt; Events &gt; Target &gt; Allowed &gt; Region

_Policy Types_

- AWS &gt; Events &gt; Allowed Regions [Default]
- AWS &gt; Events &gt; Event Bus &gt; Allowed
- AWS &gt; Events &gt; Event Bus &gt; Allowed &gt; Custom
- AWS &gt; Events &gt; Event Bus &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; Events &gt; Event Bus &gt; Allowed &gt; Region
- AWS &gt; Events &gt; Event Bus &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; Events &gt; Rule &gt; Allowed
- AWS &gt; Events &gt; Rule &gt; Allowed &gt; Custom
- AWS &gt; Events &gt; Rule &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; Events &gt; Rule &gt; Allowed &gt; Region
- AWS &gt; Events &gt; Rule &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; Events &gt; Target &gt; Allowed
- AWS &gt; Events &gt; Target &gt; Allowed &gt; Custom
- AWS &gt; Events &gt; Target &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; Events &gt; Target &gt; Allowed &gt; Region
- AWS &gt; Events &gt; Target &gt; Allowed &gt; Region &gt; Regions</description>
            <pubDate>Fri, 19 Dec 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-apigateway-v5-14-0</guid>
            <title>aws-apigateway v5.14.0 - Identify and remove unallowed resources from CMDB</title>
            <link>https://turbot.com/guardrails/changelog/aws-apigateway-v5-14-0</link>
            <description>_What&apos;s new?_

_Control Types_

- AWS &gt; API Gateway &gt; API &gt; Allowed
- AWS &gt; API Gateway &gt; API &gt; Allowed &gt; Custom
- AWS &gt; API Gateway &gt; API &gt; Allowed &gt; Region
- AWS &gt; API Gateway &gt; API Key &gt; Allowed
- AWS &gt; API Gateway &gt; API Key &gt; Allowed &gt; Custom
- AWS &gt; API Gateway &gt; API Key &gt; Allowed &gt; Region
- AWS &gt; API Gateway &gt; API V2 &gt; Allowed
- AWS &gt; API Gateway &gt; API V2 &gt; Allowed &gt; Custom
- AWS &gt; API Gateway &gt; API V2 &gt; Allowed &gt; Region
- AWS &gt; API Gateway &gt; Authorizer &gt; Allowed
- AWS &gt; API Gateway &gt; Authorizer &gt; Allowed &gt; Custom
- AWS &gt; API Gateway &gt; Authorizer &gt; Allowed &gt; Region
- AWS &gt; API Gateway &gt; Authorizer V2 &gt; Allowed
- AWS &gt; API Gateway &gt; Authorizer V2 &gt; Allowed &gt; Custom
- AWS &gt; API Gateway &gt; Authorizer V2 &gt; Allowed &gt; Region
- AWS &gt; API Gateway &gt; Domain Name V2 &gt; Allowed
- AWS &gt; API Gateway &gt; Domain Name V2 &gt; Allowed &gt; Custom
- AWS &gt; API Gateway &gt; Domain Name V2 &gt; Allowed &gt; Region
- AWS &gt; API Gateway &gt; Integration V2 &gt; Allowed
- AWS &gt; API Gateway &gt; Integration V2 &gt; Allowed &gt; Custom
- AWS &gt; API Gateway &gt; Integration V2 &gt; Allowed &gt; Region
- AWS &gt; API Gateway &gt; Resource &gt; Allowed
- AWS &gt; API Gateway &gt; Resource &gt; Allowed &gt; Custom
- AWS &gt; API Gateway &gt; Resource &gt; Allowed &gt; Region
- AWS &gt; API Gateway &gt; Stage &gt; Allowed
- AWS &gt; API Gateway &gt; Stage &gt; Allowed &gt; Custom
- AWS &gt; API Gateway &gt; Stage &gt; Allowed &gt; Region
- AWS &gt; API Gateway &gt; Stage v2 &gt; Allowed
- AWS &gt; API Gateway &gt; Stage v2 &gt; Allowed &gt; Custom
- AWS &gt; API Gateway &gt; Stage v2 &gt; Allowed &gt; Region
- AWS &gt; API Gateway &gt; Usage Plan &gt; Allowed
- AWS &gt; API Gateway &gt; Usage Plan &gt; Allowed &gt; Custom
- AWS &gt; API Gateway &gt; Usage Plan &gt; Allowed &gt; Region

_Policy Types_

- AWS &gt; API Gateway &gt; API &gt; Allowed
- AWS &gt; API Gateway &gt; API &gt; Allowed &gt; Custom
- AWS &gt; API Gateway &gt; API &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; API Gateway &gt; API &gt; Allowed &gt; Region
- AWS &gt; API Gateway &gt; API &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; API Gateway &gt; API Key &gt; Allowed
- AWS &gt; API Gateway &gt; API Key &gt; Allowed &gt; Custom
- AWS &gt; API Gateway &gt; API Key &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; API Gateway &gt; API Key &gt; Allowed &gt; Region
- AWS &gt; API Gateway &gt; API Key &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; API Gateway &gt; API V2 &gt; Allowed
- AWS &gt; API Gateway &gt; API V2 &gt; Allowed &gt; Custom
- AWS &gt; API Gateway &gt; API V2 &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; API Gateway &gt; API V2 &gt; Allowed &gt; Region
- AWS &gt; API Gateway &gt; API V2 &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; API Gateway &gt; Allowed Regions [Default]
- AWS &gt; API Gateway &gt; Authorizer &gt; Allowed
- AWS &gt; API Gateway &gt; Authorizer &gt; Allowed &gt; Custom
- AWS &gt; API Gateway &gt; Authorizer &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; API Gateway &gt; Authorizer &gt; Allowed &gt; Region
- AWS &gt; API Gateway &gt; Authorizer &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; API Gateway &gt; Authorizer V2 &gt; Allowed
- AWS &gt; API Gateway &gt; Authorizer V2 &gt; Allowed &gt; Custom
- AWS &gt; API Gateway &gt; Authorizer V2 &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; API Gateway &gt; Authorizer V2 &gt; Allowed &gt; Region
- AWS &gt; API Gateway &gt; Authorizer V2 &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; API Gateway &gt; Domain Name V2 &gt; Allowed
- AWS &gt; API Gateway &gt; Domain Name V2 &gt; Allowed &gt; Custom
- AWS &gt; API Gateway &gt; Domain Name V2 &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; API Gateway &gt; Domain Name V2 &gt; Allowed &gt; Region
- AWS &gt; API Gateway &gt; Domain Name V2 &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; API Gateway &gt; Integration V2 &gt; Allowed
- AWS &gt; API Gateway &gt; Integration V2 &gt; Allowed &gt; Custom
- AWS &gt; API Gateway &gt; Integration V2 &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; API Gateway &gt; Integration V2 &gt; Allowed &gt; Region
- AWS &gt; API Gateway &gt; Integration V2 &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; API Gateway &gt; Resource &gt; Allowed
- AWS &gt; API Gateway &gt; Resource &gt; Allowed &gt; Custom
- AWS &gt; API Gateway &gt; Resource &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; API Gateway &gt; Resource &gt; Allowed &gt; Region
- AWS &gt; API Gateway &gt; Resource &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; API Gateway &gt; Stage &gt; Allowed
- AWS &gt; API Gateway &gt; Stage &gt; Allowed &gt; Custom
- AWS &gt; API Gateway &gt; Stage &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; API Gateway &gt; Stage &gt; Allowed &gt; Region
- AWS &gt; API Gateway &gt; Stage &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; API Gateway &gt; Stage v2 &gt; Allowed
- AWS &gt; API Gateway &gt; Stage v2 &gt; Allowed &gt; Custom
- AWS &gt; API Gateway &gt; Stage v2 &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; API Gateway &gt; Stage v2 &gt; Allowed &gt; Region
- AWS &gt; API Gateway &gt; Stage v2 &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; API Gateway &gt; Usage Plan &gt; Allowed
- AWS &gt; API Gateway &gt; Usage Plan &gt; Allowed &gt; Custom
- AWS &gt; API Gateway &gt; Usage Plan &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; API Gateway &gt; Usage Plan &gt; Allowed &gt; Region
- AWS &gt; API Gateway &gt; Usage Plan &gt; Allowed &gt; Region &gt; Regions</description>
            <pubDate>Fri, 19 Dec 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-s3-v5-33-2</guid>
            <title>aws-s3 v5.33.2 - Real-time tagging events for buckets will now be processed correctly</title>
            <link>https://turbot.com/guardrails/changelog/aws-s3-v5-33-2</link>
            <description>_Bug fixes_

- Real-time tagging events for `AWS &gt; S3 &gt; Bucket` were not being processed correctly. This is now fixed.</description>
            <pubDate>Thu, 18 Dec 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-route53resolver-v5-7-0</guid>
            <title>aws-route53resolver v5.7.0 - Identify and remove unallowed resources from CMDB</title>
            <link>https://turbot.com/guardrails/changelog/aws-route53resolver-v5-7-0</link>
            <description>_What&apos;s new?_

_Control Types_

- AWS &gt; Route 53 Resolver &gt; Resolver Endpoint &gt; Allowed
- AWS &gt; Route 53 Resolver &gt; Resolver Endpoint &gt; Allowed &gt; Custom
- AWS &gt; Route 53 Resolver &gt; Resolver Endpoint &gt; Allowed &gt; Region
- AWS &gt; Route 53 Resolver &gt; Resolver Rule &gt; Allowed
- AWS &gt; Route 53 Resolver &gt; Resolver Rule &gt; Allowed &gt; Custom
- AWS &gt; Route 53 Resolver &gt; Resolver Rule &gt; Allowed &gt; Region

_Policy Types_

- AWS &gt; Route 53 Resolver &gt; Allowed Regions [Default]
- AWS &gt; Route 53 Resolver &gt; Resolver Endpoint &gt; Allowed
- AWS &gt; Route 53 Resolver &gt; Resolver Endpoint &gt; Allowed &gt; Custom
- AWS &gt; Route 53 Resolver &gt; Resolver Endpoint &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; Route 53 Resolver &gt; Resolver Endpoint &gt; Allowed &gt; Region
- AWS &gt; Route 53 Resolver &gt; Resolver Endpoint &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; Route 53 Resolver &gt; Resolver Rule &gt; Allowed
- AWS &gt; Route 53 Resolver &gt; Resolver Rule &gt; Allowed &gt; Custom
- AWS &gt; Route 53 Resolver &gt; Resolver Rule &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; Route 53 Resolver &gt; Resolver Rule &gt; Allowed &gt; Region
- AWS &gt; Route 53 Resolver &gt; Resolver Rule &gt; Allowed &gt; Region &gt; Regions</description>
            <pubDate>Thu, 18 Dec 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-elasticsearch-v5-9-0</guid>
            <title>aws-elasticsearch v5.9.0 - Identify and remove unallowed resources from CMDB</title>
            <link>https://turbot.com/guardrails/changelog/aws-elasticsearch-v5-9-0</link>
            <description>_What&apos;s new?_

_Control Types_

- AWS &gt; Elasticsearch &gt; Domain &gt; Allowed
- AWS &gt; Elasticsearch &gt; Domain &gt; Allowed &gt; Custom
- AWS &gt; Elasticsearch &gt; Domain &gt; Allowed &gt; Encryption at Rest
- AWS &gt; Elasticsearch &gt; Domain &gt; Allowed &gt; Region

_Policy Types_

- AWS &gt; Elasticsearch &gt; Allowed Regions [Default]
- AWS &gt; Elasticsearch &gt; Domain &gt; Allowed
- AWS &gt; Elasticsearch &gt; Domain &gt; Allowed &gt; Custom
- AWS &gt; Elasticsearch &gt; Domain &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; Elasticsearch &gt; Domain &gt; Allowed &gt; Encryption at Rest
- AWS &gt; Elasticsearch &gt; Domain &gt; Allowed &gt; Encryption at Rest &gt; Level
- AWS &gt; Elasticsearch &gt; Domain &gt; Allowed &gt; Encryption at Rest &gt; Level &gt; Customer Managed Key
- AWS &gt; Elasticsearch &gt; Domain &gt; Allowed &gt; Region
- AWS &gt; Elasticsearch &gt; Domain &gt; Allowed &gt; Region &gt; Regions</description>
            <pubDate>Thu, 18 Dec 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-dynamodb-v5-18-0</guid>
            <title>aws-dynamodb v5.18.0 - Identify and remove unallowed resources from CMDB</title>
            <link>https://turbot.com/guardrails/changelog/aws-dynamodb-v5-18-0</link>
            <description>_What&apos;s new?_

_Control Types_

- AWS &gt; DynamoDB &gt; Backup &gt; Allowed
- AWS &gt; DynamoDB &gt; Backup &gt; Allowed &gt; Custom
- AWS &gt; DynamoDB &gt; Backup &gt; Allowed &gt; Region
- AWS &gt; DynamoDB &gt; Global Table &gt; Allowed
- AWS &gt; DynamoDB &gt; Global Table &gt; Allowed &gt; Custom
- AWS &gt; DynamoDB &gt; Table &gt; Allowed
- AWS &gt; DynamoDB &gt; Table &gt; Allowed &gt; Custom
- AWS &gt; DynamoDB &gt; Table &gt; Allowed &gt; Region

_Policy Types_

- AWS &gt; DynamoDB &gt; Allowed Regions [Default]
- AWS &gt; DynamoDB &gt; Backup &gt; Allowed
- AWS &gt; DynamoDB &gt; Backup &gt; Allowed &gt; Custom
- AWS &gt; DynamoDB &gt; Backup &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; DynamoDB &gt; Backup &gt; Allowed &gt; Region
- AWS &gt; DynamoDB &gt; Backup &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; DynamoDB &gt; Global Table &gt; Allowed
- AWS &gt; DynamoDB &gt; Global Table &gt; Allowed &gt; Custom
- AWS &gt; DynamoDB &gt; Global Table &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; DynamoDB &gt; Table &gt; Allowed
- AWS &gt; DynamoDB &gt; Table &gt; Allowed &gt; Custom
- AWS &gt; DynamoDB &gt; Table &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; DynamoDB &gt; Table &gt; Allowed &gt; Region
- AWS &gt; DynamoDB &gt; Table &gt; Allowed &gt; Region &gt; Regions</description>
            <pubDate>Thu, 18 Dec 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-controltower-v5-0-0</guid>
            <title>aws-controltower v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/aws-controltower-v5-0-0</link>
            <description>_What&apos;s new?_

_Resource Types_

- AWS &gt; Control Tower
- AWS &gt; Control Tower &gt; Enabled Control
- AWS &gt; Control Tower &gt; Landing Zone

_Control Types_

- AWS &gt; Control Tower &gt; Enabled Control &gt; CMDB
- AWS &gt; Control Tower &gt; Enabled Control &gt; Discovery
- AWS &gt; Control Tower &gt; Enabled Control &gt; Tags
- AWS &gt; Control Tower &gt; Landing Zone &gt; CMDB
- AWS &gt; Control Tower &gt; Landing Zone &gt; Discovery

_Policy Types_

- AWS &gt; Control Tower &gt; API Enabled
- AWS &gt; Control Tower &gt; Allowed Regions [Default]
- AWS &gt; Control Tower &gt; Approved Regions [Default]
- AWS &gt; Control Tower &gt; Enabled
- AWS &gt; Control Tower &gt; Enabled Control &gt; CMDB
- AWS &gt; Control Tower &gt; Enabled Control &gt; Regions
- AWS &gt; Control Tower &gt; Enabled Control &gt; Tags
- AWS &gt; Control Tower &gt; Enabled Control &gt; Tags &gt; Template
- AWS &gt; Control Tower &gt; Landing Zone &gt; CMDB
- AWS &gt; Control Tower &gt; Landing Zone &gt; Regions
- AWS &gt; Control Tower &gt; Permissions
- AWS &gt; Control Tower &gt; Permissions &gt; Levels
- AWS &gt; Control Tower &gt; Permissions &gt; Levels &gt; Modifiers
- AWS &gt; Control Tower &gt; Permissions &gt; Lockdown
- AWS &gt; Control Tower &gt; Permissions &gt; Lockdown &gt; API Boundary
- AWS &gt; Control Tower &gt; Regions
- AWS &gt; Control Tower &gt; Tags Template [Default]
- AWS &gt; Turbot &gt; Event Handlers &gt; Events &gt; Rules &gt; Custom Event Patterns &gt; @turbot/aws-controltower
- AWS &gt; Turbot &gt; Permissions &gt; Compiled &gt; API Boundary &gt; @turbot/aws-controltower
- AWS &gt; Turbot &gt; Permissions &gt; Compiled &gt; Levels &gt; @turbot/aws-controltower
- AWS &gt; Turbot &gt; Permissions &gt; Compiled &gt; Service Permissions &gt; @turbot/aws-controltower

_Action Types_

- AWS &gt; Control Tower &gt; Enabled Control &gt; Router
- AWS &gt; Control Tower &gt; Enabled Control &gt; Set Tags
- AWS &gt; Control Tower &gt; Enabled Control &gt; Skip alarm for Tags control
- AWS &gt; Control Tower &gt; Enabled Control &gt; Skip alarm for Tags control [90 days]
- AWS &gt; Control Tower &gt; Enabled Control &gt; Update Tags
- AWS &gt; Control Tower &gt; Landing Zone &gt; Delete
- AWS &gt; Control Tower &gt; Landing Zone &gt; Delete Landing Zone
- AWS &gt; Control Tower &gt; Landing Zone &gt; Router</description>
            <pubDate>Thu, 18 Dec 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-cloudtrail-v5-16-0</guid>
            <title>aws-cloudtrail v5.16.0 - Identify and remove unallowed resources from CMDB</title>
            <link>https://turbot.com/guardrails/changelog/aws-cloudtrail-v5-16-0</link>
            <description>_What&apos;s new?_

_Control Types_

- AWS &gt; CloudTrail &gt; Trail &gt; Allowed
- AWS &gt; CloudTrail &gt; Trail &gt; Allowed &gt; Custom
- AWS &gt; CloudTrail &gt; Trail &gt; Allowed &gt; Region

_Policy Types_

- AWS &gt; CloudTrail &gt; Allowed Regions [Default]
- AWS &gt; CloudTrail &gt; Trail &gt; Allowed
- AWS &gt; CloudTrail &gt; Trail &gt; Allowed &gt; Custom
- AWS &gt; CloudTrail &gt; Trail &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; CloudTrail &gt; Trail &gt; Allowed &gt; Region
- AWS &gt; CloudTrail &gt; Trail &gt; Allowed &gt; Region &gt; Regions</description>
            <pubDate>Thu, 18 Dec 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-cloudformation-v5-14-0</guid>
            <title>aws-cloudformation v5.14.0 - Track and manage hook resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/aws-cloudformation-v5-14-0</link>
            <description>_What&apos;s new?_

_Resource Types_

- AWS &gt; CloudFormation &gt; Hook

_Control Types_

- AWS &gt; CloudFormation &gt; Hook &gt; Active
- AWS &gt; CloudFormation &gt; Hook &gt; Allowed
- AWS &gt; CloudFormation &gt; Hook &gt; Allowed &gt; Custom
- AWS &gt; CloudFormation &gt; Hook &gt; Allowed &gt; Region
- AWS &gt; CloudFormation &gt; Hook &gt; CMDB
- AWS &gt; CloudFormation &gt; Hook &gt; Discovery
- AWS &gt; CloudFormation &gt; Hook &gt; Usage
- AWS &gt; CloudFormation &gt; Stack &gt; Allowed
- AWS &gt; CloudFormation &gt; Stack &gt; Allowed &gt; Custom
- AWS &gt; CloudFormation &gt; Stack &gt; Allowed &gt; Region
- AWS &gt; CloudFormation &gt; StackSet &gt; Allowed
- AWS &gt; CloudFormation &gt; StackSet &gt; Allowed &gt; Custom
- AWS &gt; CloudFormation &gt; StackSet &gt; Allowed &gt; Region

_Policy Types_

- AWS &gt; CloudFormation &gt; Allowed Regions [Default]
- AWS &gt; CloudFormation &gt; Hook &gt; Active
- AWS &gt; CloudFormation &gt; Hook &gt; Active &gt; Age
- AWS &gt; CloudFormation &gt; Hook &gt; Active &gt; Last Modified
- AWS &gt; CloudFormation &gt; Hook &gt; Allowed
- AWS &gt; CloudFormation &gt; Hook &gt; Allowed &gt; Custom
- AWS &gt; CloudFormation &gt; Hook &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; CloudFormation &gt; Hook &gt; Allowed &gt; Region
- AWS &gt; CloudFormation &gt; Hook &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; CloudFormation &gt; Hook &gt; CMDB
- AWS &gt; CloudFormation &gt; Hook &gt; Regions
- AWS &gt; CloudFormation &gt; Hook &gt; Usage
- AWS &gt; CloudFormation &gt; Hook &gt; Usage &gt; Limit
- AWS &gt; CloudFormation &gt; Stack &gt; Allowed
- AWS &gt; CloudFormation &gt; Stack &gt; Allowed &gt; Custom
- AWS &gt; CloudFormation &gt; Stack &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; CloudFormation &gt; Stack &gt; Allowed &gt; Region
- AWS &gt; CloudFormation &gt; Stack &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; CloudFormation &gt; StackSet &gt; Allowed
- AWS &gt; CloudFormation &gt; StackSet &gt; Allowed &gt; Custom
- AWS &gt; CloudFormation &gt; StackSet &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; CloudFormation &gt; StackSet &gt; Allowed &gt; Region
- AWS &gt; CloudFormation &gt; StackSet &gt; Allowed &gt; Region &gt; Regions

_Action Types_

- AWS &gt; CloudFormation &gt; Hook &gt; Delete
- AWS &gt; CloudFormation &gt; Hook &gt; Delete from AWS
- AWS &gt; CloudFormation &gt; Hook &gt; Router
- AWS &gt; CloudFormation &gt; Hook &gt; Skip alarm for Active control
- AWS &gt; CloudFormation &gt; Hook &gt; Skip alarm for Active control [90 days]</description>
            <pubDate>Thu, 18 Dec 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-backup-v5-15-0</guid>
            <title>aws-backup v5.15.0 - Identify and remove unallowed resources from CMDB</title>
            <link>https://turbot.com/guardrails/changelog/aws-backup-v5-15-0</link>
            <description>_What&apos;s new?_

_Control Types_

- AWS &gt; Backup &gt; Backup Plan &gt; Allowed
- AWS &gt; Backup &gt; Backup Plan &gt; Allowed &gt; Custom
- AWS &gt; Backup &gt; Backup Plan &gt; Allowed &gt; Region
- AWS &gt; Backup &gt; Backup Selection &gt; Allowed
- AWS &gt; Backup &gt; Backup Selection &gt; Allowed &gt; Custom
- AWS &gt; Backup &gt; Backup Selection &gt; Allowed &gt; Region
- AWS &gt; Backup &gt; Backup Vault &gt; Allowed
- AWS &gt; Backup &gt; Backup Vault &gt; Allowed &gt; Custom
- AWS &gt; Backup &gt; Backup Vault &gt; Allowed &gt; Encryption at Rest
- AWS &gt; Backup &gt; Backup Vault &gt; Allowed &gt; Region
- AWS &gt; Backup &gt; Recovery Point &gt; Allowed
- AWS &gt; Backup &gt; Recovery Point &gt; Allowed &gt; Custom
- AWS &gt; Backup &gt; Recovery Point &gt; Allowed &gt; Region

_Policy Types_

- AWS &gt; Backup &gt; Allowed Regions [Default]
- AWS &gt; Backup &gt; Backup Plan &gt; Allowed
- AWS &gt; Backup &gt; Backup Plan &gt; Allowed &gt; Custom
- AWS &gt; Backup &gt; Backup Plan &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; Backup &gt; Backup Plan &gt; Allowed &gt; Region
- AWS &gt; Backup &gt; Backup Plan &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; Backup &gt; Backup Selection &gt; Allowed
- AWS &gt; Backup &gt; Backup Selection &gt; Allowed &gt; Custom
- AWS &gt; Backup &gt; Backup Selection &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; Backup &gt; Backup Selection &gt; Allowed &gt; Region
- AWS &gt; Backup &gt; Backup Selection &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; Backup &gt; Backup Vault &gt; Allowed
- AWS &gt; Backup &gt; Backup Vault &gt; Allowed &gt; Custom
- AWS &gt; Backup &gt; Backup Vault &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; Backup &gt; Backup Vault &gt; Allowed &gt; Encryption at Rest
- AWS &gt; Backup &gt; Backup Vault &gt; Allowed &gt; Encryption at Rest &gt; Level
- AWS &gt; Backup &gt; Backup Vault &gt; Allowed &gt; Encryption at Rest &gt; Level &gt; Customer Managed Key
- AWS &gt; Backup &gt; Backup Vault &gt; Allowed &gt; Region
- AWS &gt; Backup &gt; Backup Vault &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; Backup &gt; Recovery Point &gt; Allowed
- AWS &gt; Backup &gt; Recovery Point &gt; Allowed &gt; Custom
- AWS &gt; Backup &gt; Recovery Point &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; Backup &gt; Recovery Point &gt; Allowed &gt; Region
- AWS &gt; Backup &gt; Recovery Point &gt; Allowed &gt; Region &gt; Regions</description>
            <pubDate>Thu, 18 Dec 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/turbot-guardrails-cli-v1-30-0</guid>
            <title>Turbot Guardrails CLI v1.30.0 - Added prevention support and improved inspect output</title>
            <link>https://turbot.com/guardrails/changelog/turbot-guardrails-cli-v1-30-0</link>
            <description>_What&apos;s new?_

- `turbot inspect` now supports **prevention types**, including validation for prevention mods.
- Improved the `turbot inspect` command with better output formatting and more detailed information display for easier troubleshooting and analysis.</description>
            <pubDate>Thu, 18 Dec 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-batch-v5-9-0</guid>
            <title>aws-batch v5.9.0 - Identify and remove unallowed resources from CMDB</title>
            <link>https://turbot.com/guardrails/changelog/aws-batch-v5-9-0</link>
            <description>_What&apos;s new?_

_Control Types_

- AWS &gt; Batch &gt; Compute Environment &gt; Allowed
- AWS &gt; Batch &gt; Compute Environment &gt; Allowed &gt; Custom
- AWS &gt; Batch &gt; Compute Environment &gt; Allowed &gt; Region
- AWS &gt; Batch &gt; Job Definition &gt; Allowed
- AWS &gt; Batch &gt; Job Definition &gt; Allowed &gt; Custom
- AWS &gt; Batch &gt; Job Definition &gt; Allowed &gt; Region
- AWS &gt; Batch &gt; Job Queue &gt; Allowed
- AWS &gt; Batch &gt; Job Queue &gt; Allowed &gt; Custom
- AWS &gt; Batch &gt; Job Queue &gt; Allowed &gt; Region

_Policy Types_

- AWS &gt; Batch &gt; Allowed Regions [Default]
- AWS &gt; Batch &gt; Compute Environment &gt; Allowed
- AWS &gt; Batch &gt; Compute Environment &gt; Allowed &gt; Custom
- AWS &gt; Batch &gt; Compute Environment &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; Batch &gt; Compute Environment &gt; Allowed &gt; Region
- AWS &gt; Batch &gt; Compute Environment &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; Batch &gt; Job Definition &gt; Allowed
- AWS &gt; Batch &gt; Job Definition &gt; Allowed &gt; Custom
- AWS &gt; Batch &gt; Job Definition &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; Batch &gt; Job Definition &gt; Allowed &gt; Region
- AWS &gt; Batch &gt; Job Definition &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; Batch &gt; Job Queue &gt; Allowed
- AWS &gt; Batch &gt; Job Queue &gt; Allowed &gt; Custom
- AWS &gt; Batch &gt; Job Queue &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; Batch &gt; Job Queue &gt; Allowed &gt; Region
- AWS &gt; Batch &gt; Job Queue &gt; Allowed &gt; Region &gt; Regions</description>
            <pubDate>Tue, 16 Dec 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-acm-v5-12-0</guid>
            <title>aws-acm v5.12.0 - Identify and remove unallowed resources from CMDB</title>
            <link>https://turbot.com/guardrails/changelog/aws-acm-v5-12-0</link>
            <description>_What&apos;s new?_

_Control Types_

- AWS &gt; ACM &gt; Certificate &gt; Allowed
- AWS &gt; ACM &gt; Certificate &gt; Allowed &gt; Custom
- AWS &gt; ACM &gt; Certificate &gt; Allowed &gt; Region

_Policy Types_

- AWS &gt; ACM &gt; Allowed Region [Default]
- AWS &gt; ACM &gt; Certificate &gt; Allowed
- AWS &gt; ACM &gt; Certificate &gt; Allowed &gt; Custom
- AWS &gt; ACM &gt; Certificate &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; ACM &gt; Certificate &gt; Allowed &gt; Region
- AWS &gt; ACM &gt; Certificate &gt; Allowed &gt; Region &gt; Regions</description>
            <pubDate>Tue, 16 Dec 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-54-5</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.54.5 - Version bump to align with deployment requirements</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-54-5</link>
            <description>Version bump to align with deployment requirements.

_Requirements_

- Upgrade to `5.54.5` requires your workspace to be on `5.53.x`
- PostgreSQL (RDS engine): &gt;= 15
- TEF: 1.66.0
- TED: 1.37.0
- Mods:
  - @turbot/turbot: 5.56.0

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Mon, 15 Dec 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-55-0</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.55.0 - Materialization default has changed to Automatic</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-55-0</link>
            <description>_What&apos;s new?_

In this release, Guardrails changes the default for the `Turbot &gt; Materialization` policy from `Always` to `Automatic`.

-	**Automatic** (Default) — Create controls and policy values only if a setting is explicitly defined for the primary policy. This can significantly reduce noise and improve performance.
-	**Always** — Guardrails creates controls and policy values for all applicable resources, even if no setting exists (legacy behavior).

To retain the existing behavior (legacy materialization), set the Turbot &gt; Materialization policy to Always before upgrading to 5.55.0.

_Requirements_

- Upgrade to `5.55.0` requires your workspace to be on `5.54.x`
- PostgreSQL (RDS engine): &gt;= 15
- TEF: 1.66.0
- TED: 1.37.0
- Mods:
  - @turbot/turbot: 5.56.0

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Fri, 12 Dec 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-kms-v5-22-0</guid>
            <title>aws-kms v5.22.0 - Identify and remove unallowed resources from CMDB</title>
            <link>https://turbot.com/guardrails/changelog/aws-kms-v5-22-0</link>
            <description>_What&apos;s new?_

_Control Types_

- AWS &gt; KMS &gt; Key &gt; Allowed
- AWS &gt; KMS &gt; Key &gt; Allowed &gt; Custom
- AWS &gt; KMS &gt; Key &gt; Allowed &gt; Customer Master Key Spec
- AWS &gt; KMS &gt; Key &gt; Allowed &gt; Region

_Policy Types_

- AWS &gt; KMS &gt; Allowed Regions [Default]
- AWS &gt; KMS &gt; Key &gt; Allowed
- AWS &gt; KMS &gt; Key &gt; Allowed &gt; Custom
- AWS &gt; KMS &gt; Key &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; KMS &gt; Key &gt; Allowed &gt; Customer Master Key Spec
- AWS &gt; KMS &gt; Key &gt; Allowed &gt; Customer Master Key Spec &gt; Specs
- AWS &gt; KMS &gt; Key &gt; Allowed &gt; Region
- AWS &gt; KMS &gt; Key &gt; Allowed &gt; Region &gt; Regions</description>
            <pubDate>Fri, 12 Dec 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-directconnect-v5-8-0</guid>
            <title>aws-directconnect v5.8.0 - Identify and remove unallowed resources from CMDB</title>
            <link>https://turbot.com/guardrails/changelog/aws-directconnect-v5-8-0</link>
            <description>_What&apos;s new?_

_Control Types_

- AWS &gt; Direct Connect &gt; Connection &gt; Allowed
- AWS &gt; Direct Connect &gt; Connection &gt; Allowed &gt; Custom
- AWS &gt; Direct Connect &gt; Connection &gt; Allowed &gt; Region
- AWS &gt; Direct Connect &gt; Direct Connect Gateway &gt; Allowed
- AWS &gt; Direct Connect &gt; Direct Connect Gateway &gt; Allowed &gt; Custom
- AWS &gt; Direct Connect &gt; Lag &gt; Allowed
- AWS &gt; Direct Connect &gt; Lag &gt; Allowed &gt; Custom
- AWS &gt; Direct Connect &gt; Lag &gt; Allowed &gt; Region
- AWS &gt; Direct Connect &gt; Virtual Interface &gt; Allowed
- AWS &gt; Direct Connect &gt; Virtual Interface &gt; Allowed &gt; Custom
- AWS &gt; Direct Connect &gt; Virtual Interface &gt; Allowed &gt; Region

_Policy Types_

- AWS &gt; Direct Connect &gt; Allowed Regions [Default]
- AWS &gt; Direct Connect &gt; Connection &gt; Allowed
- AWS &gt; Direct Connect &gt; Connection &gt; Allowed &gt; Custom
- AWS &gt; Direct Connect &gt; Connection &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; Direct Connect &gt; Connection &gt; Allowed &gt; Region
- AWS &gt; Direct Connect &gt; Connection &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; Direct Connect &gt; Direct Connect Gateway &gt; Allowed
- AWS &gt; Direct Connect &gt; Direct Connect Gateway &gt; Allowed &gt; Custom
- AWS &gt; Direct Connect &gt; Direct Connect Gateway &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; Direct Connect &gt; Lag &gt; Allowed
- AWS &gt; Direct Connect &gt; Lag &gt; Allowed &gt; Custom
- AWS &gt; Direct Connect &gt; Lag &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; Direct Connect &gt; Lag &gt; Allowed &gt; Region
- AWS &gt; Direct Connect &gt; Lag &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; Direct Connect &gt; Virtual Interface &gt; Allowed
- AWS &gt; Direct Connect &gt; Virtual Interface &gt; Allowed &gt; Custom
- AWS &gt; Direct Connect &gt; Virtual Interface &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; Direct Connect &gt; Virtual Interface &gt; Allowed &gt; Region
- AWS &gt; Direct Connect &gt; Virtual Interface &gt; Allowed &gt; Region &gt; Regions</description>
            <pubDate>Fri, 12 Dec 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-appmesh-v5-7-0</guid>
            <title>aws-appmesh v5.7.0 - Identify and remove unallowed resources from CMDB</title>
            <link>https://turbot.com/guardrails/changelog/aws-appmesh-v5-7-0</link>
            <description>_What&apos;s new?_

_Control Types_

- AWS &gt; App Mesh &gt; Mesh &gt; Allowed
- AWS &gt; App Mesh &gt; Mesh &gt; Allowed &gt; Custom
- AWS &gt; App Mesh &gt; Mesh &gt; Allowed &gt; Region

_Policy Types_

- AWS &gt; App Mesh &gt; Allowed Regions [Default]
- AWS &gt; App Mesh &gt; Mesh &gt; Allowed
- AWS &gt; App Mesh &gt; Mesh &gt; Allowed &gt; Custom
- AWS &gt; App Mesh &gt; Mesh &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; App Mesh &gt; Mesh &gt; Allowed &gt; Region
- AWS &gt; App Mesh &gt; Mesh &gt; Allowed &gt; Region &gt; Regions</description>
            <pubDate>Fri, 12 Dec 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-amplify-v5-7-0</guid>
            <title>aws-amplify v5.7.0 - Identify and remove unallowed resources from CMDB</title>
            <link>https://turbot.com/guardrails/changelog/aws-amplify-v5-7-0</link>
            <description>_What&apos;s new?_

_Control Types_

- AWS &gt; Amplify &gt; App &gt; Allowed
- AWS &gt; Amplify &gt; App &gt; Allowed &gt; Custom
- AWS &gt; Amplify &gt; App &gt; Allowed &gt; Region

_Policy Types_

- AWS &gt; Amplify &gt; Allowed Regions [Default]
- AWS &gt; Amplify &gt; App &gt; Allowed
- AWS &gt; Amplify &gt; App &gt; Allowed &gt; Custom
- AWS &gt; Amplify &gt; App &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; Amplify &gt; App &gt; Allowed &gt; Region
- AWS &gt; Amplify &gt; App &gt; Allowed &gt; Region &gt; Regions</description>
            <pubDate>Fri, 12 Dec 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-53-11</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.53.11 - Simplified notification handling by removing checks that weren’t needed</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-53-11</link>
            <description>_Bug fixes_

- Server
  - Simplified notification handling by removing checks that weren’t needed.

_Requirements_

- Upgrade to `5.53.11` requires your workspace to be on `5.51.x`
- TEF: 1.66.0
- TED: 1.9.1
- Mods:
	-	@turbot/turbot: 5.55.0


_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Thu, 11 Dec 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-quicksight-v5-3-0</guid>
            <title>aws-quicksight v5.3.0 - Track and manage account settings resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/aws-quicksight-v5-3-0</link>
            <description>_What&apos;s new?_

_Resource Types_

- AWS &gt; QuickSight &gt; Account Settings

_Control Types_

- AWS &gt; QuickSight &gt; Account Settings &gt; CMDB
- AWS &gt; QuickSight &gt; Account Settings &gt; Discovery

_Policy Types_

- AWS &gt; QuickSight &gt; Account Settings &gt; CMDB
- AWS &gt; QuickSight &gt; Connection Region
- AWS &gt; Turbot &gt; Event Handlers &gt; Events &gt; Rules &gt; Custom Event Patterns &gt; @turbot/aws-quicksight

_Action Types_

- AWS &gt; QuickSight &gt; Account Settings &gt; Router

Note: We recommend updating the `@turbot/aws` mod to `v5.41.0` for proper functionality.</description>
            <pubDate>Thu, 11 Dec 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/github-v5-5-0</guid>
            <title>github v5.5.0 - Fixed SSL certificate validation for GitHub Enterprise Server with self-signed certificates</title>
            <link>https://turbot.com/guardrails/changelog/github-v5-5-0</link>
            <description>_What&apos;s new?_

- GitHub controls previously failed to connect to the GitHub API when using GitHub Enterprise Server instances with self-signed certificates or internal CAs. The `NODE_TLS_REJECT_UNAUTHORIZED=0` environment variable is now correctly respected.</description>
            <pubDate>Wed, 10 Dec 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-54-4</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.54.4 - Improved materialization &amp; TLS handling</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-54-4</link>
            <description>_What&apos;s new?_

- Server
  - Propagate NODE_TLS_REJECT_UNAUTHORIZED to the GitHub mod Lambdas for VPC deployments that use self-signed certificates.

_Bug fixes_

- Server
  - In Automatic materialization mode, the calculated policy values were coming through as null, but they are now being computed correctly.

_Requirements_

- Upgrade to `5.54.4` requires your workspace to be on `5.53.x`
- PostgreSQL (RDS engine): &gt;= 15
- TEF: 1.66.0
- TED: 1.37.0
- Mods:
  - @turbot/turbot: 5.56.0

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Tue, 09 Dec 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-v5-41-0</guid>
            <title>aws v5.41.0 - Added support to process real-time events for AWS QuickSight</title>
            <link>https://turbot.com/guardrails/changelog/aws-v5-41-0</link>
            <description>_What&apos;s new?_

- The `AWS &gt; Turbot &gt; Event Handlers` now support real-time events for AWS QuickSight.

_Bug fixes_

- Fixed an issue where controls related to `AWS &gt; Account &gt; Budget &gt; Target` and `AWS &gt; Account &gt; Budget &gt; State` policy types were entering a TBD state because these policy types remained in an Inactive state even after policy settings were configured.</description>
            <pubDate>Fri, 05 Dec 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-iam-v5-47-1</guid>
            <title>aws-iam v5.47.1 - Fixed policy mapping in IAM group managed control type</title>
            <link>https://turbot.com/guardrails/changelog/aws-iam-v5-47-1</link>
            <description>_Bug fixes_

- Fixed policy mapping in `AWS &gt; Turbot &gt; IAM &gt; Group &gt; Managed` control type.</description>
            <pubDate>Fri, 28 Nov 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-cloudtrail-v5-15-0</guid>
            <title>aws-cloudtrail v5.15.0 - CMDB control for shadow trail will no longer transition to an error state when trails are deleted from the management account</title>
            <link>https://turbot.com/guardrails/changelog/aws-cloudtrail-v5-15-0</link>
            <description>_What&apos;s new?_

_Action Types_

- AWS &gt; CloudTrail &gt; Shadow Trail &gt; Router

_Bug fixes_

- The `AWS &gt; CloudTrail &gt; Shadow Trail &gt; CMDB` control would enter an error state when trails were deleted from the management account. This issue has now been fixed.</description>
            <pubDate>Fri, 28 Nov 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-53-10</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.53.10 - Version bump to align with deployment requirements</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-53-10</link>
            <description>Version bump to align with deployment requirements.

_Requirements_

- Upgrade to `5.53.10` requires your workspace to be on `5.51.x`
- TEF: 1.66.0
- TED: 1.9.1
- Mods:
	-	@turbot/turbot: 5.55.0


_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Thu, 27 Nov 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ec2-v5-49-0</guid>
            <title>aws-ec2 v5.49.0 - AMI CMDB control now automatically tracks parent AMI hierarchy</title>
            <link>https://turbot.com/guardrails/changelog/aws-ec2-v5-49-0</link>
            <description>_What&apos;s new?_

- The `AWS &gt; EC2 &gt; AMI &gt; CMDB` control now automatically tracks the parent AMI hierarchy for each AMI. Parent lineage details—including AMI ID, creation date, source account ID, and source region—are stored in the parentImageIds metadata array. The system captures up to three levels of ancestry (parent, grandparent, and great-grandparent), providing improved visibility into AMI lineage across accounts and regions.</description>
            <pubDate>Wed, 26 Nov 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-53-9</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.53.9 - Version bump to align with deployment requirements</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-53-9</link>
            <description>Version bump to align with deployment requirements.

_Requirements_

- Upgrade to `5.53.9` requires your workspace to be on `5.51.x`
- TEF: 1.66.0
- TED: 1.9.1
- Mods:
	-	@turbot/turbot: 5.55.0


_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Tue, 25 Nov 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-eks-v5-9-2</guid>
            <title>aws-eks v5.9.2 - Fixed control mapping in cluster endpoint access policy and action types</title>
            <link>https://turbot.com/guardrails/changelog/aws-eks-v5-9-2</link>
            <description>_Bug fixes_

- Fixed control mapping in `AWS &gt; EKS &gt; Cluster &gt; Endpoint Access` policy and action types.</description>
            <pubDate>Mon, 24 Nov 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-53-8</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.53.8 - Version bump to align with deployment requirements</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-53-8</link>
            <description>Version bump to align with deployment requirements.

_Requirements_

- Upgrade to `5.53.8` requires your workspace to be on `5.51.x`
- TEF: 1.66.0
- TED: 1.9.1
- Mods:
	-	@turbot/turbot: 5.55.0


_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Thu, 20 Nov 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-54-3</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.54.3 - Improved cleanup of failed DB transactions</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-54-3</link>
            <description>_Bug fixes_

- Server
  - Resolved a problem where notifications weren’t being delivered due to incorrectly handled rule settings.
  - Improved cleanup of failed DB transactions.

_Requirements_

- Upgrade to `5.54.3` requires your workspace to be on `5.53.x`
- PostgreSQL (RDS engine): &gt;= 15
- TEF: 1.66.0
- TED: 1.37.0
- Mods:
  - @turbot/turbot: 5.56.0

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Tue, 18 Nov 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-53-7</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.53.7 - Fix notification failures caused by rule settings</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-53-7</link>
            <description>_Bug fixes_

- Server
  - Resolved a problem where notifications weren’t being delivered due to incorrectly handled rule settings.

_Requirements_

- Upgrade to `5.53.7` requires your workspace to be on `5.51.x`
- TEF: 1.66.0
- TED: 1.9.1
- Mods:
	-	@turbot/turbot: 5.55.0


_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Tue, 18 Nov 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/turbot-guardrails-cli-v1-29-1</guid>
            <title>Turbot Guardrails CLI v1.29.1 - Restored graphql notifications subcommand</title>
            <link>https://turbot.com/guardrails/changelog/turbot-guardrails-cli-v1-29-1</link>
            <description>_Bug Fixes_

- The `graphql notifications` subcommand, which was inadvertently removed in a previous version, has been restored.</description>
            <pubDate>Fri, 14 Nov 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/policy-control-action-type-mapping-76-mods</guid>
            <title>Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them for 76 mods</title>
            <link>https://turbot.com/guardrails/changelog/policy-control-action-type-mapping-76-mods</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.

- servicenow `v5.6.0`
- servicenow-aws `v5.6.0`
- servicenow-aws-cloudtrail `v5.3.0`
- servicenow-aws-cloudwatch `v5.3.0`
- servicenow-aws-ec2 `v5.4.0`
- servicenow-aws-iam `v5.3.0`
- servicenow-aws-kms `v5.3.0`
- servicenow-aws-rds `v5.3.0`
- servicenow-aws-s3 `v5.5.0`
- servicenow-aws-vpc-connect `v5.3.0`
- servicenow-aws-vpc-core `v5.4.0`
- servicenow-aws-vpc-internet `v5.4.0`
- servicenow-aws-vpc-security `v5.3.0`
- servicenow-azure `v5.9.0`
- servicenow-azure-activedirectory `v5.3.0`
- servicenow-azure-aks `v5.4.0`
- servicenow-azure-apimanagement `v5.3.0`
- servicenow-azure-applicationgateway `v5.3.0`
- servicenow-azure-applicationinsights `v5.3.0`
- servicenow-azure-appservice `v5.3.0`
- servicenow-azure-automation `v5.3.0`
- servicenow-azure-compute `v5.5.0`
- servicenow-azure-cosmosdb `v5.3.0`
- servicenow-azure-databricks `v5.3.0`
- servicenow-azure-datafactory `v5.3.0`
- servicenow-azure-dns `v5.3.0`
- servicenow-azure-firewall `v5.3.0`
- servicenow-azure-frontdoorservice `v5.3.0`
- servicenow-azure-iam `v5.3.0`
- servicenow-azure-keyvault `v5.3.0`
- servicenow-azure-loadbalancer `v5.3.0`
- servicenow-azure-loganalytics `v5.3.0`
- servicenow-azure-monitor `v5.3.0`
- servicenow-azure-mysql `v5.4.0`
- servicenow-azure-network `v5.7.0`
- servicenow-azure-networkwatcher `v5.3.0`
- servicenow-azure-postgresql `v5.4.0`
- servicenow-azure-recoveryservice `v5.3.0`
- servicenow-azure-relay `v5.3.0`
- servicenow-azure-searchmanagement `v5.2.0`
- servicenow-azure-securitycenter `v5.3.0`
- servicenow-azure-servicebus `v5.3.0`
- servicenow-azure-signalr `v5.3.0`
- servicenow-azure-sql `v5.4.0`
- servicenow-azure-sqlvirtualmachine `v5.3.0`
- servicenow-azure-storage `v5.7.0`
- servicenow-azure-synapseanalytics `v5.3.0`
- servicenow-gcp `v5.10.0`
- servicenow-gcp-appengine `v5.3.0`
- servicenow-gcp-bigquery `v5.3.0`
- servicenow-gcp-bigtable `v5.3.0`
- servicenow-gcp-composer `v5.3.0`
- servicenow-gcp-computeengine `v5.5.0`
- servicenow-gcp-dataflow `v5.3.0`
- servicenow-gcp-datapipeline `v5.3.0`
- servicenow-gcp-dataplex `v5.3.0`
- servicenow-gcp-dataproc `v5.3.0`
- servicenow-gcp-dns `v5.3.0`
- servicenow-gcp-functions `v5.3.0`
- servicenow-gcp-iam `v5.3.0`
- servicenow-gcp-kms `v5.3.0`
- servicenow-gcp-kubernetesengine `v5.4.0`
- servicenow-gcp-logging `v5.3.0`
- servicenow-gcp-memorystore `v5.3.0`
- servicenow-gcp-monitoring `v5.3.0`
- servicenow-gcp-network `v5.3.0`
- servicenow-gcp-pubsub `v5.3.0`
- servicenow-gcp-run `v5.3.0`
- servicenow-gcp-scheduler `v5.3.0`
- servicenow-gcp-secretmanager `v5.3.0`
- servicenow-gcp-spanner `v5.3.0`
- servicenow-gcp-sql `v5.4.0`
- servicenow-gcp-storage `v5.8.0`
- servicenow-gcp-vertexai `v5.3.0`
- servicenow-custom `v5.2.0`
- servicenow-kubernetes `v5.8.0`</description>
            <pubDate>Mon, 03 Nov 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/osquery-v5-3-0</guid>
            <title>osquery v5.3.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/osquery-v5-3-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.</description>
            <pubDate>Mon, 03 Nov 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/kubernetes-v5-4-0</guid>
            <title>kubernetes v5.4.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/kubernetes-v5-4-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.</description>
            <pubDate>Mon, 03 Nov 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-virtualdesktop-v5-0-0</guid>
            <title>azure-virtualdesktop v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/azure-virtualdesktop-v5-0-0</link>
            <description>_What&apos;s new?_

_Resource Types_

- Azure &gt; Virtual Desktop
- Azure &gt; Virtual Desktop &gt; Host Pool
- Azure &gt; Virtual Desktop &gt; Workspace

_Control Types_

- Azure &gt; Virtual Desktop &gt; Host Pool &gt; Active
- Azure &gt; Virtual Desktop &gt; Host Pool &gt; Allowed
- Azure &gt; Virtual Desktop &gt; Host Pool &gt; Allowed &gt; Custom
- Azure &gt; Virtual Desktop &gt; Host Pool &gt; Allowed &gt; Region
- Azure &gt; Virtual Desktop &gt; Host Pool &gt; CMDB
- Azure &gt; Virtual Desktop &gt; Host Pool &gt; Discovery
- Azure &gt; Virtual Desktop &gt; Host Pool &gt; Tags
- Azure &gt; Virtual Desktop &gt; Workspace &gt; Active
- Azure &gt; Virtual Desktop &gt; Workspace &gt; Allowed
- Azure &gt; Virtual Desktop &gt; Workspace &gt; Allowed &gt; Custom
- Azure &gt; Virtual Desktop &gt; Workspace &gt; Allowed &gt; Region
- Azure &gt; Virtual Desktop &gt; Workspace &gt; CMDB
- Azure &gt; Virtual Desktop &gt; Workspace &gt; Discovery
- Azure &gt; Virtual Desktop &gt; Workspace &gt; Tags

_Policy Types_

- Azure &gt; Turbot &gt; Permissions &gt; Compiled &gt; Levels &gt; @turbot/azure-virtualdesktop
- Azure &gt; Turbot &gt; Permissions &gt; Compiled &gt; Service Permissions &gt; @turbot/azure-virtualdesktop
- Azure &gt; Virtual Desktop &gt; Allowed Regions [Default]
- Azure &gt; Virtual Desktop &gt; Approved Regions [Default]
- Azure &gt; Virtual Desktop &gt; Enabled
- Azure &gt; Virtual Desktop &gt; Host Pool &gt; Active
- Azure &gt; Virtual Desktop &gt; Host Pool &gt; Active &gt; Age
- Azure &gt; Virtual Desktop &gt; Host Pool &gt; Active &gt; Last Modified
- Azure &gt; Virtual Desktop &gt; Host Pool &gt; Allowed
- Azure &gt; Virtual Desktop &gt; Host Pool &gt; Allowed &gt; Custom
- Azure &gt; Virtual Desktop &gt; Host Pool &gt; Allowed &gt; Custom &gt; Rules
- Azure &gt; Virtual Desktop &gt; Host Pool &gt; Allowed &gt; Region
- Azure &gt; Virtual Desktop &gt; Host Pool &gt; Allowed &gt; Region &gt; Regions
- Azure &gt; Virtual Desktop &gt; Host Pool &gt; CMDB
- Azure &gt; Virtual Desktop &gt; Host Pool &gt; Regions
- Azure &gt; Virtual Desktop &gt; Host Pool &gt; Tags
- Azure &gt; Virtual Desktop &gt; Host Pool &gt; Tags &gt; Template
- Azure &gt; Virtual Desktop &gt; Permissions
- Azure &gt; Virtual Desktop &gt; Permissions &gt; Levels
- Azure &gt; Virtual Desktop &gt; Permissions &gt; Levels &gt; Modifiers
- Azure &gt; Virtual Desktop &gt; Regions
- Azure &gt; Virtual Desktop &gt; Tags Template [Default]
- Azure &gt; Virtual Desktop &gt; Workspace &gt; Active
- Azure &gt; Virtual Desktop &gt; Workspace &gt; Active &gt; Age
- Azure &gt; Virtual Desktop &gt; Workspace &gt; Active &gt; Last Modified
- Azure &gt; Virtual Desktop &gt; Workspace &gt; Allowed
- Azure &gt; Virtual Desktop &gt; Workspace &gt; Allowed &gt; Custom
- Azure &gt; Virtual Desktop &gt; Workspace &gt; Allowed &gt; Custom &gt; Rules
- Azure &gt; Virtual Desktop &gt; Workspace &gt; Allowed &gt; Region
- Azure &gt; Virtual Desktop &gt; Workspace &gt; Allowed &gt; Region &gt; Regions
- Azure &gt; Virtual Desktop &gt; Workspace &gt; CMDB
- Azure &gt; Virtual Desktop &gt; Workspace &gt; Regions
- Azure &gt; Virtual Desktop &gt; Workspace &gt; Tags
- Azure &gt; Virtual Desktop &gt; Workspace &gt; Tags &gt; Template

_Action Types_

- Azure &gt; Virtual Desktop &gt; Host Pool &gt; Delete
- Azure &gt; Virtual Desktop &gt; Host Pool &gt; Router
- Azure &gt; Virtual Desktop &gt; Host Pool &gt; Set Tags
- Azure &gt; Virtual Desktop &gt; Workspace &gt; Delete
- Azure &gt; Virtual Desktop &gt; Workspace &gt; Router
- Azure &gt; Virtual Desktop &gt; Workspace &gt; Set Tags

Note: We recommend updating the `@turbot/azure-provider` mod to `v5.19.1` for proper functionality.</description>
            <pubDate>Fri, 31 Oct 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-provider-v5-20-0</guid>
            <title>azure-provider v5.20.0 - Track and manage Cognitive Services resource provider in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-provider-v5-20-0</link>
            <description>_What&apos;s new?_

_Resource Types_

- Azure &gt; Provider &gt; Cognitive Services

_Control Types_

- Azure &gt; Provider &gt; Cognitive Services &gt; CMDB
- Azure &gt; Provider &gt; Cognitive Services &gt; Discovery
- Azure &gt; Provider &gt; Cognitive Services &gt; Registered

_Policy Types_

- Azure &gt; Provider &gt; Cognitive Services &gt; CMDB
- Azure &gt; Provider &gt; Cognitive Services &gt; Registered

_Action Types_

- Azure &gt; Provider &gt; Cognitive Services &gt; Set Registered</description>
            <pubDate>Fri, 31 Oct 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-provider-v5-19-1</guid>
            <title>azure-provider v5.19.1 - Real-time register and unregister events for Virtual Desktop provider will now be processed correctly</title>
            <link>https://turbot.com/guardrails/changelog/azure-provider-v5-19-1</link>
            <description>_Bug fixes_

- Guardrails would fail to process real-time register and unregister events for Virtual Desktop provider. This is now fixed.</description>
            <pubDate>Fri, 31 Oct 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-cosmosdb-v5-13-0</guid>
            <title>azure-cosmosdb v5.13.0 - Configure public network access for database accounts</title>
            <link>https://turbot.com/guardrails/changelog/azure-cosmosdb-v5-13-0</link>
            <description>_What&apos;s new?_

- You can now configure public network access for database accounts. To get started, set the `Azure &gt; Cosmos DB &gt; Database Account &gt; Public Network Access` policy.

_Control Types_

- Azure &gt; Cosmos DB &gt; Database Account &gt; Public Network Access

_Policy Types_

- Azure &gt; Cosmos DB &gt; Database Account &gt; Public Network Access

_Action Types_

- Azure &gt; Cosmos DB &gt; Database Account &gt; Set Public Network Access</description>
            <pubDate>Fri, 31 Oct 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ec2-v5-48-1</guid>
            <title>aws-ec2 v5.48.1 - Fixed policy mappings in various control types</title>
            <link>https://turbot.com/guardrails/changelog/aws-ec2-v5-48-1</link>
            <description>_Bug fixes_

- Fixed policy mappings in various control types.</description>
            <pubDate>Fri, 31 Oct 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-synapseanalytics-v5-14-0</guid>
            <title>azure-synapseanalytics v5.14.0 - Configure advanced data security for workspaces</title>
            <link>https://turbot.com/guardrails/changelog/azure-synapseanalytics-v5-14-0</link>
            <description>_What&apos;s new?_

- You can now configure advanced data security for workspaces. To get started, set the `Azure &gt; Synapse Analytics &gt; Workspace &gt; Advanced Data Security &gt; *` policies.

_Control Types_

- Azure &gt; Synapse Analytics &gt; Workspace &gt; Advanced Data Security

_Policy Types_

- Azure &gt; Synapse Analytics &gt; Workspace &gt; Advanced Data Security
- Azure &gt; Synapse Analytics &gt; Workspace &gt; Advanced Data Security &gt; Threat Protection
- Azure &gt; Synapse Analytics &gt; Workspace &gt; Advanced Data Security &gt; Threat Protection &gt; Notify Admins
- Azure &gt; Synapse Analytics &gt; Workspace &gt; Advanced Data Security &gt; Threat Protection &gt; Types
- Azure &gt; Synapse Analytics &gt; Workspace &gt; Advanced Data Security &gt; Threat Protection &gt; Types &gt; Email Addresses
- Azure &gt; Synapse Analytics &gt; Workspace &gt; Advanced Data Security &gt; Vulnerability Assessment
- Azure &gt; Synapse Analytics &gt; Workspace &gt; Advanced Data Security &gt; Vulnerability Assessment &gt; Periodic Scans
- Azure &gt; Synapse Analytics &gt; Workspace &gt; Advanced Data Security &gt; Vulnerability Assessment &gt; Periodic Scans &gt; Email Addresses
- Azure &gt; Synapse Analytics &gt; Workspace &gt; Advanced Data Security &gt; Vulnerability Assessment &gt; Periodic Scans &gt; Notify Admins
- Azure &gt; Synapse Analytics &gt; Workspace &gt; Advanced Data Security &gt; Vulnerability Assessment &gt; Storage Account

_Action Types_

- Azure &gt; Synapse Analytics &gt; Workspace &gt; Update Advanced Data Security</description>
            <pubDate>Thu, 30 Oct 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-automation-v5-5-0</guid>
            <title>azure-automation v5.5.0 - Configure public network access for automation accounts</title>
            <link>https://turbot.com/guardrails/changelog/azure-automation-v5-5-0</link>
            <description>_What&apos;s new?_

- You can now configure public network access for automation accounts. To get started, set the `Azure &gt; Automation &gt; Automation Account &gt; Public Network Access` policy.

_Control Types_

- Azure &gt; Automation &gt; Automation Account &gt; Public Network Access

_Policy Types_

- Azure &gt; Automation &gt; Automation Account &gt; Public Network Access

_Action Types_

- Azure &gt; Automation &gt; Automation Account &gt; Set Public Network Access</description>
            <pubDate>Thu, 30 Oct 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-v5-33-1</guid>
            <title>gcp v5.33.1 - Added support to process real-time enable and disable events for Vertex AI API</title>
            <link>https://turbot.com/guardrails/changelog/gcp-v5-33-1</link>
            <description>_Bug fixes_

- Added support to process enable and disable real-time events for Vertex AI API via Service Usage APIs.</description>
            <pubDate>Wed, 29 Oct 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-bedrock-v5-3-1</guid>
            <title>aws-bedrock v5.3.1 - Unsupported regions for Bedrock custom model are now removed from the regions policy</title>
            <link>https://turbot.com/guardrails/changelog/aws-bedrock-v5-3-1</link>
            <description>_Bug fixes_

- Unsupported regions were inadvertently included in the `AWS &gt; Bedrock &gt; Custom Model &gt; Regions` policy, which led to the `AWS &gt; Bedrock &gt; Custom Model &gt; Discovery` control being in an error state for those regions. We&apos;ve now removed the unsupported regions from the Regions policy.</description>
            <pubDate>Wed, 29 Oct 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/github-v5-4-0</guid>
            <title>github v5.4.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/github-v5-4-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.</description>
            <pubDate>Tue, 28 Oct 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-provider-v5-19-0</guid>
            <title>azure-provider v5.19.0 - Track and manage Virtual Desktop resource provider in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-provider-v5-19-0</link>
            <description>_What&apos;s new?_

_Resource Types_

- Azure &gt; Provider &gt; Virtual Desktop

_Control Types_

- Azure &gt; Provider &gt; Virtual Desktop &gt; CMDB
- Azure &gt; Provider &gt; Virtual Desktop &gt; Discovery
- Azure &gt; Provider &gt; Virtual Desktop &gt; Registered

_Policy Types_

- Azure &gt; Provider &gt; Virtual Desktop &gt; CMDB
- Azure &gt; Provider &gt; Virtual Desktop &gt; Registered

_Action Types_

- Azure &gt; Provider &gt; Virtual Desktop &gt; Set Registered</description>
            <pubDate>Mon, 27 Oct 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-cognito-v5-3-0</guid>
            <title>aws-cognito v5.3.0 - Track and manage identity pool resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/aws-cognito-v5-3-0</link>
            <description>_What&apos;s new?_

_Resource Types_

- AWS &gt; Cognito &gt; Identity Pool

_Control Types_

- AWS &gt; Cognito &gt; Identity Pool &gt; Active
- AWS &gt; Cognito &gt; Identity Pool &gt; Allowed
- AWS &gt; Cognito &gt; Identity Pool &gt; Allowed &gt; Custom
- AWS &gt; Cognito &gt; Identity Pool &gt; Allowed &gt; Region
- AWS &gt; Cognito &gt; Identity Pool &gt; CMDB
- AWS &gt; Cognito &gt; Identity Pool &gt; Classic Authentication Flow
- AWS &gt; Cognito &gt; Identity Pool &gt; Discovery
- AWS &gt; Cognito &gt; Identity Pool &gt; Guest Access
- AWS &gt; Cognito &gt; Identity Pool &gt; Tags

_Policy Types_

- AWS &gt; Cognito &gt; Allowed Regions [Default]
- AWS &gt; Cognito &gt; Identity Pool &gt; Active
- AWS &gt; Cognito &gt; Identity Pool &gt; Active &gt; Age
- AWS &gt; Cognito &gt; Identity Pool &gt; Active &gt; Last Modified
- AWS &gt; Cognito &gt; Identity Pool &gt; Allowed
- AWS &gt; Cognito &gt; Identity Pool &gt; Allowed &gt; Custom
- AWS &gt; Cognito &gt; Identity Pool &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; Cognito &gt; Identity Pool &gt; Allowed &gt; Region
- AWS &gt; Cognito &gt; Identity Pool &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; Cognito &gt; Identity Pool &gt; CMDB
- AWS &gt; Cognito &gt; Identity Pool &gt; Classic Authentication Flow
- AWS &gt; Cognito &gt; Identity Pool &gt; Guest Access
- AWS &gt; Cognito &gt; Identity Pool &gt; Regions
- AWS &gt; Cognito &gt; Identity Pool &gt; Tags
- AWS &gt; Cognito &gt; Identity Pool &gt; Tags &gt; Template
- AWS &gt; Turbot &gt; Event Handlers &gt; Events &gt; Rules &gt; Custom Event Patterns &gt; @turbot/aws-cognito

_Action Types_

- AWS &gt; Cognito &gt; Identity Pool &gt; Delete
- AWS &gt; Cognito &gt; Identity Pool &gt; Router
- AWS &gt; Cognito &gt; Identity Pool &gt; Update Classic Authentication Flow
- AWS &gt; Cognito &gt; Identity Pool &gt; Update Guest Access
- AWS &gt; Cognito &gt; Identity Pool &gt; Update Tags

Note: We recommend updating the `@turbot/aws` mod to `v5.40.0` for proper functionality.</description>
            <pubDate>Mon, 27 Oct 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ec2-v5-48-0</guid>
            <title>aws-ec2 v5.48.0 - Migrated lambda functions for AMI to use AWS SDK v3</title>
            <link>https://turbot.com/guardrails/changelog/aws-ec2-v5-48-0</link>
            <description>_What&apos;s new?_

- `AWS &gt;  EC2 &gt; AMI &gt; *` Lambda functions have been migrated to use AWS SDK v3, reducing the mod package size and improving deployment efficiency. You will not notice any differences, and things will continue to work smoothly as before.</description>
            <pubDate>Sat, 25 Oct 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-v5-34-0</guid>
            <title>azure v5.34.0 - Regions default value is now available for allowed controls</title>
            <link>https://turbot.com/guardrails/changelog/azure-v5-34-0</link>
            <description>_What&apos;s new?_

_Policy Types_

- Azure &gt; Subscription &gt; Allowed Regions [Default]</description>
            <pubDate>Fri, 24 Oct 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-secretsmanager-v5-11-1</guid>
            <title>aws-secretsmanager v5.11.1 - Real-time event handlers now process tagging events for secrets correctly</title>
            <link>https://turbot.com/guardrails/changelog/aws-secretsmanager-v5-11-1</link>
            <description>_Bug fixes_

- The real-time Event Handlers would fail to process tagging events for `AWS &gt; Secrets Manager &gt; Secret` resources. This is now fixed.</description>
            <pubDate>Fri, 24 Oct 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-sql-v5-21-0</guid>
            <title>azure-sql v5.21.0 - Virtual network rules details will now be available in CMDB for servers</title>
            <link>https://turbot.com/guardrails/changelog/azure-sql-v5-21-0</link>
            <description>_What&apos;s new?_

- Virtual network rules details will now be available in CMDB for servers.</description>
            <pubDate>Wed, 22 Oct 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-lambda-v5-19-1</guid>
            <title>aws-lambda v5.19.1 - Function URL auth type control will now transition to a skipped state when no function URL is configured</title>
            <link>https://turbot.com/guardrails/changelog/aws-lambda-v5-19-1</link>
            <description>_Bug fixes_

- The `AWS &gt; Lambda &gt; Function &gt; URL Auth Type` control previously entered an invalid state when a Function URL was not configured. This issue has now been resolved and the control will correctly transition to a skipped state in such cases.</description>
            <pubDate>Wed, 22 Oct 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-dynamodb-v5-17-1</guid>
            <title>aws-dynamodb v5.17.1 - Encryption at rest control for tables will now transition to an invalid state when encryption was enforced on global table replicas</title>
            <link>https://turbot.com/guardrails/changelog/aws-dynamodb-v5-17-1</link>
            <description>_Bug fixes_

- The `AWS &gt; DynamoDB &gt; Table &gt; Encryption at Rest` control previously remained incorrectly in an alarm state when encryption was enforced on Global Table replicas. This issue has been resolved; the control now transitions to an invalid state for replicas, as AWS Global Tables require a single, coordinated cross-region encryption update rather than per-replica changes.</description>
            <pubDate>Wed, 22 Oct 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-neptune-v5-7-0</guid>
            <title>aws-neptune v5.7.0 - Track and manage cluster snapshot resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/aws-neptune-v5-7-0</link>
            <description>_What&apos;s new?_

_Resource Types_

- AWS &gt; Neptune &gt; DB Cluster Snapshot

_Control Types_

- AWS &gt; Neptune &gt; DB Cluster Snapshot &gt; Active
- AWS &gt; Neptune &gt; DB Cluster Snapshot &gt; Allowed
- AWS &gt; Neptune &gt; DB Cluster Snapshot &gt; Allowed &gt; Custom
- AWS &gt; Neptune &gt; DB Cluster Snapshot &gt; Allowed &gt; Region
- AWS &gt; Neptune &gt; DB Cluster Snapshot &gt; CMDB
- AWS &gt; Neptune &gt; DB Cluster Snapshot &gt; Discovery
- AWS &gt; Neptune &gt; DB Cluster Snapshot &gt; Tags
- AWS &gt; Neptune &gt; DB Cluster Snapshot &gt; Usage

_Policy Types_

- AWS &gt; Neptune &gt; Allowed Regions [Default]
- AWS &gt; Neptune &gt; DB Cluster Snapshot &gt; Active
- AWS &gt; Neptune &gt; DB Cluster Snapshot &gt; Active &gt; Age
- AWS &gt; Neptune &gt; DB Cluster Snapshot &gt; Active &gt; Last Modified
- AWS &gt; Neptune &gt; DB Cluster Snapshot &gt; Allowed
- AWS &gt; Neptune &gt; DB Cluster Snapshot &gt; Allowed &gt; Custom
- AWS &gt; Neptune &gt; DB Cluster Snapshot &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; Neptune &gt; DB Cluster Snapshot &gt; Allowed &gt; Region
- AWS &gt; Neptune &gt; DB Cluster Snapshot &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; Neptune &gt; DB Cluster Snapshot &gt; CMDB
- AWS &gt; Neptune &gt; DB Cluster Snapshot &gt; Regions
- AWS &gt; Neptune &gt; DB Cluster Snapshot &gt; Tags
- AWS &gt; Neptune &gt; DB Cluster Snapshot &gt; Tags &gt; Template
- AWS &gt; Neptune &gt; DB Cluster Snapshot &gt; Usage
- AWS &gt; Neptune &gt; DB Cluster Snapshot &gt; Usage &gt; Limit

_Action Types_

- AWS &gt; Neptune &gt; DB Cluster Snapshot &gt; Delete
- AWS &gt; Neptune &gt; DB Cluster Snapshot &gt; Delete from AWS
- AWS &gt; Neptune &gt; DB Cluster Snapshot &gt; Router
- AWS &gt; Neptune &gt; DB Cluster Snapshot &gt; Set Tags
- AWS &gt; Neptune &gt; DB Cluster Snapshot &gt; Skip alarm for Active control
- AWS &gt; Neptune &gt; DB Cluster Snapshot &gt; Skip alarm for Active control [90 days]
- AWS &gt; Neptune &gt; DB Cluster Snapshot &gt; Skip alarm for Tags control
- AWS &gt; Neptune &gt; DB Cluster Snapshot &gt; Skip alarm for Tags control [90 days]
- AWS &gt; Neptune &gt; DB Cluster Snapshot &gt; Update Tags

Note: We recommend updating the `@turbot/aws-rds` mod to `v5.32.2` and the `@turbot/aws` mod to `v5.40.0` for proper functionality.</description>
            <pubDate>Fri, 17 Oct 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-54-2</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.54.2 - Prevent materialization failures from bad policy type mappings</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-54-2</link>
            <description>_Bug fixes_

- Server:
  - Materialization now handles invalid policy type mappings gracefully by skipping them instead of failing.

_Requirements_

- Upgrade to `5.54.2` requires your workspace to be on `5.53.x`
- PostgreSQL (RDS engine): &gt;= 15
- TEF: 1.66.0
- TED: 1.37.0
- Mods:
  - @turbot/turbot: 5.56.0

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Thu, 16 Oct 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-53-6</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.53.6 - Policy pack enhancements and UI fixes</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-53-6</link>
            <description>_What&apos;s new?_

- UI
  - Added Terraform import block generation to policy pack developer tab alongside existing import commands.

_Bug fixes_

- UI
  - Control page policy lists now show complete trunk names without cutting them off.
  - Resource page alert counts now accurately reflect the actual number of alerts

_Requirements_

- Upgrade to `5.53.6` requires your workspace to be on `5.51.x`
- TEF: 1.66.0
- TED: 1.9.1
- Mods:
	-	@turbot/turbot: 5.55.0


_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Thu, 16 Oct 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-rds-v5-32-2</guid>
            <title>aws-rds v5.32.2 - Updated permissions to support real-time event processing for DB cluster snapshot resources used by Neptune and DocDB services</title>
            <link>https://turbot.com/guardrails/changelog/aws-rds-v5-32-2</link>
            <description>_Bug fixes_

- Updated permissions to support real-time event processing for DB cluster snapshot resources used by Neptune and DocDB services.</description>
            <pubDate>Thu, 16 Oct 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-docdb-v5-5-0</guid>
            <title>aws-docdb v5.5.0 - Track and manage cluster snapshot resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/aws-docdb-v5-5-0</link>
            <description>_What&apos;s new?_

_Resource Types_

- AWS &gt; Doc DB &gt; DB Cluster Snapshot

_Control Types_

- AWS &gt; Doc DB &gt; DB Cluster Snapshot &gt; Active
- AWS &gt; Doc DB &gt; DB Cluster Snapshot &gt; Allowed
- AWS &gt; Doc DB &gt; DB Cluster Snapshot &gt; Allowed &gt; Custom
- AWS &gt; Doc DB &gt; DB Cluster Snapshot &gt; Allowed &gt; Region
- AWS &gt; Doc DB &gt; DB Cluster Snapshot &gt; CMDB
- AWS &gt; Doc DB &gt; DB Cluster Snapshot &gt; Discovery
- AWS &gt; Doc DB &gt; DB Cluster Snapshot &gt; Tags
- AWS &gt; Doc DB &gt; DB Cluster Snapshot &gt; Usage

_Policy Types_

- AWS &gt; Doc DB &gt; Allowed Regions [Default]
- AWS &gt; Doc DB &gt; DB Cluster Snapshot &gt; Active
- AWS &gt; Doc DB &gt; DB Cluster Snapshot &gt; Active &gt; Age
- AWS &gt; Doc DB &gt; DB Cluster Snapshot &gt; Active &gt; Budget
- AWS &gt; Doc DB &gt; DB Cluster Snapshot &gt; Active &gt; Last Modified
- AWS &gt; Doc DB &gt; DB Cluster Snapshot &gt; Allowed
- AWS &gt; Doc DB &gt; DB Cluster Snapshot &gt; Allowed &gt; Custom
- AWS &gt; Doc DB &gt; DB Cluster Snapshot &gt; Allowed &gt; Custom &gt; Rules
- AWS &gt; Doc DB &gt; DB Cluster Snapshot &gt; Allowed &gt; Region
- AWS &gt; Doc DB &gt; DB Cluster Snapshot &gt; Allowed &gt; Region &gt; Regions
- AWS &gt; Doc DB &gt; DB Cluster Snapshot &gt; CMDB
- AWS &gt; Doc DB &gt; DB Cluster Snapshot &gt; Regions
- AWS &gt; Doc DB &gt; DB Cluster Snapshot &gt; Tags
- AWS &gt; Doc DB &gt; DB Cluster Snapshot &gt; Tags &gt; Template
- AWS &gt; Doc DB &gt; DB Cluster Snapshot &gt; Usage
- AWS &gt; Doc DB &gt; DB Cluster Snapshot &gt; Usage &gt; Limit

_Action Types_

- AWS &gt; Doc DB &gt; DB Cluster Snapshot &gt; Delete
- AWS &gt; Doc DB &gt; DB Cluster Snapshot &gt; Delete from AWS
- AWS &gt; Doc DB &gt; DB Cluster Snapshot &gt; Router
- AWS &gt; Doc DB &gt; DB Cluster Snapshot &gt; Set Tags
- AWS &gt; Doc DB &gt; DB Cluster Snapshot &gt; Skip alarm for Active control
- AWS &gt; Doc DB &gt; DB Cluster Snapshot &gt; Skip alarm for Active control [90 days]
- AWS &gt; Doc DB &gt; DB Cluster Snapshot &gt; Skip alarm for Tags control
- AWS &gt; Doc DB &gt; DB Cluster Snapshot &gt; Skip alarm for Tags control [90 days]
- AWS &gt; Doc DB &gt; DB Cluster Snapshot &gt; Update Tags

Note: We recommend updating the `@turbot/aws-rds` mod to `v5.32.2` and the `@turbot/aws` mod to `v5.40.0` for proper functionality.</description>
            <pubDate>Thu, 16 Oct 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-synapseanalytics-v5-13-0</guid>
            <title>azure-synapseanalytics v5.13.0 - Firewall rules details will now be available in CMDB for workspaces</title>
            <link>https://turbot.com/guardrails/changelog/azure-synapseanalytics-v5-13-0</link>
            <description>_What&apos;s new?_

- Firewall rules details will now be available in CMDB for workspaces.
- Security alert policy and vulnerability assessments details will now be available in CMDB for workspaces.</description>
            <pubDate>Wed, 15 Oct 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-redis-v5-1-0</guid>
            <title>azure-redis v5.1.0 - Firewall rules details will now be available in CMDB for redis cache</title>
            <link>https://turbot.com/guardrails/changelog/azure-redis-v5-1-0</link>
            <description>_What&apos;s new?_

- Firewall rules details will now be available in CMDB for redis cache.</description>
            <pubDate>Wed, 15 Oct 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-mysql-v5-19-0</guid>
            <title>azure-mysql v5.19.0 - Firewall rules details will now be available in CMDB for flexible servers</title>
            <link>https://turbot.com/guardrails/changelog/azure-mysql-v5-19-0</link>
            <description>_What&apos;s new?_

- Firewall rules details will now be available in CMDB for flexible servers.</description>
            <pubDate>Wed, 15 Oct 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-53-5</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.53.5 - Turbot &gt; Notifications &gt; Rule-Based Routing now supports using Turbot &gt; File resources as notification templates</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-53-5</link>
            <description>_What&apos;s new?_

- Server
  - `Turbot &gt; Notifications &gt; Rule-Based Routing` now supports using `Turbot &gt; File` resources as notification templates — update the `@turbot/turbot` mod to `v5.56.1` or later to enable this feature.

_Requirements_

- Upgrade to `5.53.5` requires your workspace to be on `5.51.x`
- TEF: 1.66.0
- TED: 1.9.1
- Mods:
	-	@turbot/turbot: 5.55.0


_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Mon, 13 Oct 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-53-4</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.53.4 - Infrastructure and maintenance updates</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-53-4</link>
            <description>_Bug fixes_

- Server
  - Redis/Valkey connection management now tracks connection creation times for improved visibility and connection lifecycle tracking.
  - Maintenance container logic refined to avoid errors when attempting to drop unique index constraints.

_Requirements_

- Upgrade to `5.53.4` requires your workspace to be on `5.51.x`
- TEF: 1.66.0
- TED: 1.9.1
- Mods:
	-	@turbot/turbot: 5.55.0


_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Thu, 09 Oct 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-lambda-v5-19-0</guid>
            <title>aws-lambda v5.19.0 - Manage trusted access for layers</title>
            <link>https://turbot.com/guardrails/changelog/aws-lambda-v5-19-0</link>
            <description>_What&apos;s new?_

- Users can now manage trusted access for layers. To get started, set the `AWS &gt; Lambda &gt; Function &gt; Layer Trusted Access &gt; *` policies.

_Control Types_

- AWS &gt; Lambda &gt; Function &gt; Layer Trusted Access

_Policy Types_

- AWS &gt; Lambda &gt; Function &gt; Layer Trusted Access
- AWS &gt; Lambda &gt; Function &gt; Layer Trusted Access &gt; Accounts

_Action Types_

- AWS &gt; Lambda &gt; Function &gt; Set Layer Trusted Access</description>
            <pubDate>Thu, 09 Oct 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-v5-40-0</guid>
            <title>aws v5.40.0 - Regions default value is now available for allowed controls</title>
            <link>https://turbot.com/guardrails/changelog/aws-v5-40-0</link>
            <description>_What&apos;s new?_

_Policy Types_

- AWS &gt; Account &gt; Allowed Regions [Default]</description>
            <pubDate>Wed, 08 Oct 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-iam-v5-47-0</guid>
            <title>aws-iam v5.47.0 - Remove unallowed access keys from the CMDB</title>
            <link>https://turbot.com/guardrails/changelog/aws-iam-v5-47-0</link>
            <description>_What&apos;s new?_

- You can now remove unallowed access keys from the CMDB. To get started, set the `AWS &gt; IAM &gt; Access Key &gt; Allowed &gt; *` policies.

_Control Types_

- AWS &gt; IAM &gt; Access Key &gt; Allowed
- AWS &gt; IAM &gt; Access Key &gt; Allowed &gt; Custom

_Policy Types_

- AWS &gt; IAM &gt; Access Key &gt; Allowed
- AWS &gt; IAM &gt; Access Key &gt; Allowed &gt; Custom
- AWS &gt; IAM &gt; Access Key &gt; Allowed &gt; Custom &gt; Rules</description>
            <pubDate>Wed, 08 Oct 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-redis-v5-0-0</guid>
            <title>azure-redis v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/azure-redis-v5-0-0</link>
            <description>_What&apos;s new?_

_Resource Types_

- Azure &gt; Redis
- Azure &gt; Redis &gt; Redis Cache

_Control Types_

- Azure &gt; Redis &gt; Redis Cache &gt; Active
- Azure &gt; Redis &gt; Redis Cache &gt; CMDB
- Azure &gt; Redis &gt; Redis Cache &gt; Discovery
- Azure &gt; Redis &gt; Redis Cache &gt; Tags

_Policy Types_

- Azure &gt; Redis &gt; Approved Regions [Default]
- Azure &gt; Redis &gt; Enabled
- Azure &gt; Redis &gt; Permissions
- Azure &gt; Redis &gt; Permissions &gt; Levels
- Azure &gt; Redis &gt; Permissions &gt; Levels &gt; Modifiers
- Azure &gt; Redis &gt; Redis Cache &gt; Active
- Azure &gt; Redis &gt; Redis Cache &gt; Active &gt; Age
- Azure &gt; Redis &gt; Redis Cache &gt; Active &gt; Last Modified
- Azure &gt; Redis &gt; Redis Cache &gt; CMDB
- Azure &gt; Redis &gt; Redis Cache &gt; Regions
- Azure &gt; Redis &gt; Redis Cache &gt; Tags
- Azure &gt; Redis &gt; Redis Cache &gt; Tags &gt; Template
- Azure &gt; Redis &gt; Regions
- Azure &gt; Redis &gt; Tags Template [Default]
- Azure &gt; Turbot &gt; Permissions &gt; Compiled &gt; Levels &gt; @turbot/azure-redis
- Azure &gt; Turbot &gt; Permissions &gt; Compiled &gt; Service Permissions &gt; @turbot/azure-redis

_Action Types_

- Azure &gt; Redis &gt; Redis Cache &gt; Delete
- Azure &gt; Redis &gt; Redis Cache &gt; Router
- Azure &gt; Redis &gt; Redis Cache &gt; Set Tags</description>
            <pubDate>Mon, 06 Oct 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-provider-v5-18-0</guid>
            <title>azure-provider v5.18.0 - Track and manage Redis resource provider in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-provider-v5-18-0</link>
            <description>_What&apos;s new?_

_Resource Types_

- Azure &gt; Provider &gt; Redis

_Control Types_

- Azure &gt; Provider &gt; Redis &gt; CMDB
- Azure &gt; Provider &gt; Redis &gt; Discovery
- Azure &gt; Provider &gt; Redis &gt; Registered

_Policy Types_

- Azure &gt; Provider &gt; Redis &gt; CMDB
- Azure &gt; Provider &gt; Redis &gt; Registered

_Action Types_

- Azure &gt; Provider &gt; Redis &gt; Set Registered</description>
            <pubDate>Mon, 06 Oct 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-containerregistry-v5-7-0</guid>
            <title>azure-containerregistry v5.7.0 - Configure anonymous pull access for registries</title>
            <link>https://turbot.com/guardrails/changelog/azure-containerregistry-v5-7-0</link>
            <description>_What&apos;s new?_

- You can now configure anonymous pull access for registries. To get started, set the `Azure &gt; Container Registry &gt; Registry &gt; Anonymous Pull Access` policy.

_Control Types_

- Azure &gt; Container Registry &gt; Registry &gt; Anonymous Pull Access

_Policy Types_

- Azure &gt; Container Registry &gt; Registry &gt; Anonymous Pull Access

_Action Types_

- Azure &gt; Container Registry &gt; Registry &gt; Set Anonymous Pull Access</description>
            <pubDate>Mon, 06 Oct 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-pciv3-2-1-v5-1-1</guid>
            <title>aws-pciv3-2-1 v5.1.1 - Controls for Lambda functions now use updated CMDB references in internal GraphQL queries</title>
            <link>https://turbot.com/guardrails/changelog/aws-pciv3-2-1-v5-1-1</link>
            <description>_Bug fixes_

- Controls for Lambda functions now use updated CMDB references in internal GraphQL queries. You will not notice any differences, and things will continue to work smoothly as before.</description>
            <pubDate>Fri, 26 Sep 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-opensearch-v5-3-0</guid>
            <title>aws-opensearch v5.3.0 - Configure anonymous auth for domains</title>
            <link>https://turbot.com/guardrails/changelog/aws-opensearch-v5-3-0</link>
            <description>_What&apos;s new?_

- You can now configure anonymous auth for domains. To get started, set the `AWS &gt; OpenSearch &gt; Domain &gt; Anonymous Auth` policy.

_Control Types_

- AWS &gt; OpenSearch &gt; Domain &gt; Anonymous Auth

_Policy Types_

- AWS &gt; OpenSearch &gt; Domain &gt; Anonymous Auth

_Action Types_

- AWS &gt; OpenSearch &gt; Domain &gt; Disable Anonymous Auth</description>
            <pubDate>Fri, 26 Sep 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-lambda-v5-18-0</guid>
            <title>aws-lambda v5.18.0 - Configure URL auth type for functions</title>
            <link>https://turbot.com/guardrails/changelog/aws-lambda-v5-18-0</link>
            <description>_What&apos;s new?_

- You can now configure URL auth type for functions. To get started, set the `AWS &gt; Lambda &gt; Function &gt; URL Auth Type` policy.

_Bug fixes_

- Fixed action and control mappings in various control types and policy types.
- We&apos;ve removed the redundant `Configuration` details for functions from the CMDB. We recommend updating your existing policy settings to reference the top-level attributes from the CMDB data instead.

  **Removed:**
  In AWS &gt; Lambda &gt; Function:

  - `Configuration`

_Control Types_

- AWS &gt; Lambda &gt; Function &gt; URL Auth Type

_Policy Types_

- AWS &gt; Lambda &gt; Function &gt; URL Auth Type

_Action Types_

- AWS &gt; Lambda &gt; Function &gt; Update URL Auth Type</description>
            <pubDate>Fri, 26 Sep 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-hipaa-v5-2-1</guid>
            <title>aws-hipaa v5.2.1 - Controls for Lambda functions now use updated CMDB references in internal GraphQL queries</title>
            <link>https://turbot.com/guardrails/changelog/aws-hipaa-v5-2-1</link>
            <description>_Bug fixes_

- Controls for Lambda functions now use updated CMDB references in internal GraphQL queries. You will not notice any differences, and things will continue to work smoothly as before.</description>
            <pubDate>Fri, 26 Sep 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ec2-v5-47-1</guid>
            <title>aws-ec2 v5.47.1 - Real-time events for account attributes will now be processed more reliably</title>
            <link>https://turbot.com/guardrails/changelog/aws-ec2-v5-47-1</link>
            <description>_Bug fixes_

- Guardrails would sometimes fail to process the real-time `ec2:DisableSnapshotBlockPublicAccess` event for EC2 Account Attributes correctly. This is now fixed.</description>
            <pubDate>Fri, 26 Sep 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-54-1</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.54.1 -  Resolved an issue where creating policy values could hang when related policies had no targets</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-54-1</link>
            <description>_Bug fixes_

- Server
  - Resolved an issue where creating policy values could hang when related policies had no targets.

- UI
  - Policy value cards are now better aligned, improving readability and visual consistency.
  - Smoothed out the header experience on the resources page by removing flicker.

_Requirements_

- Upgrade to `5.54.1` requires your workspace to be on `5.53.x`
- PostgreSQL (RDS engine): &gt;= 15
- TEF: 1.66.0
- TED: 1.37.0
- Mods:
  - @turbot/turbot: 5.56.0

_Base images_

- Alpine: 3.17.5
- Ubuntu: 22.04.3</description>
            <pubDate>Thu, 25 Sep 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-53-3</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.53.3 - Increased type installation limit from 600 to 1500</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-53-3</link>
            <description>_What&apos;s new?_

- Server
  - Increased type installation limit from 600 to 1500.

_Bug fixes_

- UI
  - Policy value cards are now better aligned, improving readability and visual consistency.
  - Smoothed out the header experience on the resources page by removing flicker.

_Requirements_

- Upgrade to `5.53.3` requires your workspace to be on `5.51.x`
- TEF: 1.66.0
- TED: 1.9.1
- Mods:
	-	@turbot/turbot: 5.55.0


_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Thu, 25 Sep 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-54-0</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.54.0 - Smarter control and policy value creation</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-54-0</link>
            <description>_What&apos;s new?_

You now have more control over when Guardrails creates controls and policy values based on policy settings. Previously, Guardrails would evaluate all possible controls for every resource by default. With this release, Guardrails can be configured to only create controls impacted by policy settings, improving both user experience and backend performance.

The `Turbot &gt; Materialization` policy supports two modes:

- **Always** (Default) — Create controls and policy values for all applicable resources, even if no setting exists. This matches legacy behavior.
- **Automatic** — Create controls and policy values only if a setting is explicitly defined for the primary policy. This can significantly reduce noise and improve performance.

Note that some types, such as those used to discover resources and configure accounts, are always created regardless of the materialization mode.

To get started, we recommend setting the `Turbot &gt; Materialization` policy to `Automatic` and updating any cloud mods currently installed, like `aws`, `aws-s3`, `azure`, to their latest versions.

In the upcoming TE version, the default for the `Turbot &gt; Materialization` policy will change from `Always` to `Automatic`. To retain the existing behavior, set the `Turbot &gt; Materialization` policy to `Always` before upgrading to the next TE version.

_Requirements_

- Upgrade to `5.54.0` requires your workspace to be on `5.53.x`
- PostgreSQL (RDS engine): &gt;= 15
- TEF: 1.66.0
- TED: 1.37.0
- Mods:
  - @turbot/turbot: 5.56.0

_Base images_

- Alpine: 3.17.5
- Ubuntu: 22.04.3</description>
            <pubDate>Tue, 23 Sep 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/turbot-v5-56-0</guid>
            <title>turbot v5.56.0 - Added the `Turbot &gt; Materialization` policy to control when Guardrails creates controls and policy values</title>
            <link>https://turbot.com/guardrails/changelog/turbot-v5-56-0</link>
            <description>_What&apos;s new?_

- Added the `Turbot &gt; Materialization` policy to control when Guardrails creates controls and policy values, with modes for `Always` (legacy behavior) and `Automatic` (create only when explicitly set), reducing noise and improving performance.

_Control Types_

- Turbot &gt; Policy Pack &gt; Materialize
- Turbot &gt; Guardrail &gt; Materialize
- Turbot &gt; Materialize

_Policy Types_

- Turbot &gt; Materialization

- Renamed
  - Turbot &gt; Notifications &gt; Email &gt; CC &gt; Tag &gt; Name to Turbot &gt; Notifications &gt; Email &gt; CC &gt; Tag Name.

- Deprecated
  - Turbot &gt; Notifications &gt; Email &gt; CC &gt; Tag

_Requirements_

- TE: 5.35.4</description>
            <pubDate>Tue, 23 Sep 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-cosmosdb-v5-12-0</guid>
            <title>azure-cosmosdb v5.12.0 - Configure key based metadata write access for database accounts</title>
            <link>https://turbot.com/guardrails/changelog/azure-cosmosdb-v5-12-0</link>
            <description>_What&apos;s new?_

- You can now configure key based metadata write access for database accounts. To get started, set the `Azure &gt; Cosmos DB &gt; Database Account &gt; Key Based Metadata Write Access` policy.

_Control Types_

- Azure &gt; Cosmos DB &gt; Database Account &gt; Key Based Metadata Write Access

_Policy Types_

- Azure &gt; Cosmos DB &gt; Database Account &gt; Key Based Metadata Write Access

_Action Types_

- Azure &gt; Cosmos DB &gt; Database Account &gt; Set Key Based Metadata Write Access</description>
            <pubDate>Tue, 23 Sep 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-kms-v5-21-1</guid>
            <title>aws-kms v5.21.1 - Migrated all Lambda functions to use AWS SDK v3</title>
            <link>https://turbot.com/guardrails/changelog/aws-kms-v5-21-1</link>
            <description>_Bug fixes_

- All Lambda functions have been migrated to use AWS SDK v3, reducing the mod package size and improving deployment efficiency. You will not notice any differences, and things will continue to work smoothly as before.</description>
            <pubDate>Tue, 23 Sep 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-53-2</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.53.2 - Added support for importing GitHub Enterprise organizations</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-53-2</link>
            <description>_What&apos;s new?_

- Server
  - GitHub integration now supports importing GitHub Enterprise organizations, expanding coverage for enterprise users.

- UI
  - The main dashboard’s resource list is now split into favorites and accounts for easier navigation and prioritization.
  - The GitHub import page now includes support for GitHub Enterprise.

_Bug fixes_

- Server
  - Resolved an issue that could prevent confirmation of SNS subscriptions during event handler setup for accounts.
  - Resolved issues with incorrect index mapping definitions in the maintenance container.

- UI
  - Improved UI consistency and usability across policy value cards, control actions, and resource control lists.

_Requirements_

- Upgrade to `5.53.2` requires your workspace to be on `5.51.x`
- TEF: 1.66.0
- TED: 1.9.1
- Mods:
	-	@turbot/turbot: 5.55.0


_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Mon, 22 Sep 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-opensearch-v5-2-0</guid>
            <title>aws-opensearch v5.2.0 - Track and manage domain resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/aws-opensearch-v5-2-0</link>
            <description>_What&apos;s new?_

- Track and manage domain resources in Guardrails.

_Resource Types_

- AWS &gt; OpenSearch &gt; Domain

_Control Types_

- AWS &gt; OpenSearch &gt; Domain &gt; Active
- AWS &gt; OpenSearch &gt; Domain &gt; Approved
- AWS &gt; OpenSearch &gt; Domain &gt; CMDB
- AWS &gt; OpenSearch &gt; Domain &gt; Discovery
- AWS &gt; OpenSearch &gt; Domain &gt; Tags

_Policy Types_

- AWS &gt; OpenSearch &gt; Domain &gt; Active
- AWS &gt; OpenSearch &gt; Domain &gt; Active &gt; Age
- AWS &gt; OpenSearch &gt; Domain &gt; Active &gt; Last Modified
- AWS &gt; OpenSearch &gt; Domain &gt; Approved
- AWS &gt; OpenSearch &gt; Domain &gt; Approved &gt; Custom
- AWS &gt; OpenSearch &gt; Domain &gt; Approved &gt; Regions
- AWS &gt; OpenSearch &gt; Domain &gt; Approved &gt; Usage
- AWS &gt; OpenSearch &gt; Domain &gt; CMDB
- AWS &gt; OpenSearch &gt; Domain &gt; Regions
- AWS &gt; OpenSearch &gt; Domain &gt; Tags
- AWS &gt; OpenSearch &gt; Domain &gt; Tags &gt; Template
- AWS &gt; Turbot &gt; Event Handlers &gt; Events &gt; Rules &gt; Custom Event Patterns &gt; @turbot/aws-opensearch

_Action Types_

- AWS &gt; OpenSearch &gt; Domain &gt; Delete
- AWS &gt; OpenSearch &gt; Domain &gt; Delete from AWS
- AWS &gt; OpenSearch &gt; Domain &gt; Router
- AWS &gt; OpenSearch &gt; Domain &gt; Set Tags
- AWS &gt; OpenSearch &gt; Domain &gt; Skip alarm for Active control
- AWS &gt; OpenSearch &gt; Domain &gt; Skip alarm for Active control [90 days]
- AWS &gt; OpenSearch &gt; Domain &gt; Skip alarm for Approved control
- AWS &gt; OpenSearch &gt; Domain &gt; Skip alarm for Approved control [90 days]
- AWS &gt; OpenSearch &gt; Domain &gt; Skip alarm for Tags control
- AWS &gt; OpenSearch &gt; Domain &gt; Skip alarm for Tags control [90 days]
- AWS &gt; OpenSearch &gt; Domain &gt; Update Tags</description>
            <pubDate>Mon, 22 Sep 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/ia-class-contactable-all-mods</guid>
            <title>Intelligent Assessment controls now also support OpenAI GPT-5 and Anthropic Claude Opus 4.1 models</title>
            <link>https://turbot.com/guardrails/changelog/ia-class-contactable-all-mods</link>
            <description>_What&apos;s new?_

- Intelligent Assessment controls now also support OpenAI GPT-5 and Anthropic Claude Opus 4.1 models.
- All policy types across AWS, Azure, GCP, GitHub, Kubernetes, and ServiceNow mods now have an associated class. You will not notice any differences, and everything will continue to function smoothly as before.

_Bug fixes_

- Support for the contactable interface has been removed from all resource types except AWS Account, Azure Subscription, and GCP Project. As a result, the `Turbot &gt; Notifications &gt; Email &gt; CC &gt; Tag Name` policy can no longer be explicitly set for the affected resource types.</description>
            <pubDate>Fri, 19 Sep 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-containerregistry-v5-6-0</guid>
            <title>azure-containerregistry v5.6.0 - Configure public network access for registries</title>
            <link>https://turbot.com/guardrails/changelog/azure-containerregistry-v5-6-0</link>
            <description>_What&apos;s new?_

- You can now configure public network access for registries. To get started, set the `Azure &gt; Container Registry &gt; Registry &gt; Public Network Access` policy.

_Control Types_

- Azure &gt; Container Registry &gt; Registry &gt; Public Network Access

_Policy Types_

- Azure &gt; Container Registry &gt; Registry &gt; Public Network Access

_Action Types_

- Azure &gt; Container Registry &gt; Registry &gt; Set Public Network Access</description>
            <pubDate>Fri, 19 Sep 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-cisv3-0-v5-0-1</guid>
            <title>azure-cisv3-0 v5.0.1 - Various controls will now evaluate their dependent policies correctly</title>
            <link>https://turbot.com/guardrails/changelog/azure-cisv3-0-v5-0-1</link>
            <description>_Bug fixes_

- Various controls sometimes failed to evaluate their dependent policies correctly, which led to the controls failing without explicitly throwing errors. This issue has been fixed, and such controls will now work as expected.</description>
            <pubDate>Fri, 19 Sep 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-apimanagement-v5-8-0</guid>
            <title>azure-apimanagement v5.8.0 - Configure public network access for API management services</title>
            <link>https://turbot.com/guardrails/changelog/azure-apimanagement-v5-8-0</link>
            <description>_What&apos;s new?_

- You can now configure public network access for API management services. To get started, set the `Azure &gt; API Management &gt; API Management Service &gt; Public Network Access` policy.

_Control Types_

- Azure &gt; API Management &gt; API Management Service &gt; Public Network Access

_Policy Types_

- Azure &gt; API Management &gt; API Management Service &gt; Public Network Access

_Action Types_

- Azure &gt; API Management &gt; API Management Service &gt; Set Public Network Access</description>
            <pubDate>Fri, 19 Sep 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/github-v5-3-0</guid>
            <title>github v5.3.0 - Import GitHub Enterprise organizations in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/github-v5-3-0</link>
            <description>_What&apos;s new?_

- You can now import GitHub Enterprise organizations in Guardrails. To get started, select GitHub Enterprise Organization from the Connect screen and configure details. We recommend upgrading TE to v5.53.2 for this change to take effect.
- Added support for `class` attribute for various policy types.

_Policy Types_

- GitHub &gt; Config &gt; Base URL</description>
            <pubDate>Thu, 18 Sep 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-iam-v5-46-0</guid>
            <title>aws-iam v5.46.0 - Track and manage service specific credential resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/aws-iam-v5-46-0</link>
            <description>_Resource Types_

- AWS &gt; IAM &gt; Service Specific Credential

_Control Types_

- AWS &gt; IAM &gt; Service Specific Credential &gt; Active
- AWS &gt; IAM &gt; Service Specific Credential &gt; Approved
- AWS &gt; IAM &gt; Service Specific Credential &gt; CMDB
- AWS &gt; IAM &gt; Service Specific Credential &gt; Discovery

_Policy Types_

- AWS &gt; IAM &gt; Service Specific Credential &gt; Active
- AWS &gt; IAM &gt; Service Specific Credential &gt; Active &gt; Age
- AWS &gt; IAM &gt; Service Specific Credential &gt; Active &gt; Last Modified
- AWS &gt; IAM &gt; Service Specific Credential &gt; Approved
- AWS &gt; IAM &gt; Service Specific Credential &gt; Approved &gt; Custom
- AWS &gt; IAM &gt; Service Specific Credential &gt; Approved &gt; Usage
- AWS &gt; IAM &gt; Service Specific Credential &gt; CMDB

_Action Types_

- AWS &gt; IAM &gt; Service Specific Credential &gt; Delete
- AWS &gt; IAM &gt; Service Specific Credential &gt; Delete from AWS
- AWS &gt; IAM &gt; Service Specific Credential &gt; Router
- AWS &gt; IAM &gt; Service Specific Credential &gt; Skip alarm for Active control
- AWS &gt; IAM &gt; Service Specific Credential &gt; Skip alarm for Active control [90 days]
- AWS &gt; IAM &gt; Service Specific Credential &gt; Skip alarm for Approved control
- AWS &gt; IAM &gt; Service Specific Credential &gt; Skip alarm for Approved control [90 days]</description>
            <pubDate>Thu, 18 Sep 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-bedrock-v5-3-0</guid>
            <title>aws-bedrock v5.3.0 - Configure encryption at rest for agents</title>
            <link>https://turbot.com/guardrails/changelog/aws-bedrock-v5-3-0</link>
            <description>_What&apos;s new?_

- You can now configure Encryption at Rest for agents. To get started, set the `AWS &gt; Bedrock &gt; Agent &gt; Encryption at Rest &gt; *` policies.

_Bug fixes_

- The `promptOverrideConfiguration.promptConfigurations` attribute for agents has now been made dynamic to avoid unnecessary notifications in the activity tab.

_Control Types_

- AWS &gt; Bedrock &gt; Agent &gt; Encryption at Rest

_Policy Types_

- AWS &gt; Bedrock &gt; Agent &gt; Encryption at Rest
- AWS &gt; Bedrock &gt; Agent &gt; Encryption at Rest &gt; Customer Managed Key

_Action Types_

- AWS &gt; Bedrock &gt; Agent &gt; Update Encryption at Rest</description>
            <pubDate>Tue, 16 Sep 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-53-1</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.53.1 -  Added support for the class property in policy types</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-53-1</link>
            <description>_What&apos;s new?_

- Server
  - Added support for the class property in policy types.

_Requirements_

- Upgrade to `5.53.1` requires your workspace to be on `5.51.x`
- TEF: 1.66.0
- TED: 1.9.1
- Mods:
	-	@turbot/turbot: 5.55.0

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Thu, 11 Sep 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-codeartifact-v5-0-2</guid>
            <title>aws-codeartifact v5.0.2 - Fixed service title to `CodeArtifact`</title>
            <link>https://turbot.com/guardrails/changelog/aws-codeartifact-v5-0-2</link>
            <description>_Bug fixes_

- Fixed service title to `CodeArtifact`.

_Resource Types_

_Renamed_

- AWS &gt; Code Artifact to AWS &gt; CodeArtifact

_Policy Types_

_Renamed_

- AWS &gt; Code Artifact &gt; API Enabled to AWS &gt; CodeArtifact &gt; API Enabled
- AWS &gt; Code Artifact &gt; Enabled to AWS &gt; CodeArtifact &gt; Enabled
- AWS &gt; Code Artifact &gt; Permissions to AWS &gt; CodeArtifact &gt; Permissions
- AWS &gt; Code Artifact &gt; Permissions &gt; Levels to AWS &gt; CodeArtifact &gt; Permissions &gt; Levels
- AWS &gt; Code Artifact &gt; Permissions &gt; Levels &gt; Modifiers to AWS &gt; CodeArtifact &gt; Permissions &gt; Levels &gt; Modifiers
- AWS &gt; Code Artifact &gt; Permissions &gt; Lockdown to AWS &gt; CodeArtifact &gt; Permissions &gt; Lockdown
- AWS &gt; Code Artifact &gt; Permissions &gt; Lockdown &gt; API Boundary to AWS &gt; CodeArtifact &gt; Permissions &gt; Lockdown &gt; API Boundary</description>
            <pubDate>Thu, 11 Sep 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-codeartifact-v5-0-1</guid>
            <title>aws-codeartifact v5.0.1 - Removed the unnecessary event sources policy</title>
            <link>https://turbot.com/guardrails/changelog/aws-codeartifact-v5-0-1</link>
            <description>_Bug fixes_

- Removed the unnecessary `AWS &gt; Turbot &gt; Event Handlers &gt; Events &gt; Rules &gt; Event Sources &gt; @turbot/aws-codeartifact` policy.

_Policy Types_

_Removed_

- AWS &gt; Turbot &gt; Event Handlers &gt; Events &gt; Rules &gt; Event Sources &gt; @turbot/aws-codeartifact</description>
            <pubDate>Wed, 10 Sep 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-codeartifact-v5-0-0</guid>
            <title>aws-codeartifact v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/aws-codeartifact-v5-0-0</link>
            <description>_What&apos;s new?_

_Resource Types_

- AWS &gt; Code Artifact

_Policy Types_

- AWS &gt; Code Artifact &gt; API Enabled
- AWS &gt; Code Artifact &gt; Enabled
- AWS &gt; Code Artifact &gt; Permissions
- AWS &gt; Code Artifact &gt; Permissions &gt; Levels
- AWS &gt; Code Artifact &gt; Permissions &gt; Levels &gt; Modifiers
- AWS &gt; Code Artifact &gt; Permissions &gt; Lockdown
- AWS &gt; Code Artifact &gt; Permissions &gt; Lockdown &gt; API Boundary
- AWS &gt; Turbot &gt; Event Handlers &gt; Events &gt; Rules &gt; Event Sources &gt; @turbot/aws-codeartifact
- AWS &gt; Turbot &gt; Permissions &gt; Compiled &gt; API Boundary &gt; @turbot/aws-codeartifact
- AWS &gt; Turbot &gt; Permissions &gt; Compiled &gt; Levels &gt; @turbot/aws-codeartifact
- AWS &gt; Turbot &gt; Permissions &gt; Compiled &gt; Service Permissions &gt; @turbot/aws-codeartifact</description>
            <pubDate>Wed, 10 Sep 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-52-5</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.52.5 -  Azure credential resolver now supports storage authentication</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-52-5</link>
            <description>_What&apos;s new?_

- Server
  - Added support for the Storage token audience in the Azure credential resolver.

_Bug fixes_

- Server
  - Creating a new workspace now correctly adds the missing policy pack (aka) for Smart Folder resource types.
  - Numeric values in wildcard tag filters are now processed correctly.

_Requirements_

- Upgrade to `5.52.5` requires your workspace to be on `5.51.x`
- TEF: 1.66.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Mon, 08 Sep 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-storage-v5-29-0</guid>
            <title>azure-storage v5.29.0 - CMDB control for storage accounts no longer requires the `listkeys` permission on storage accounts to fetch details for blob, queue, and file share services</title>
            <link>https://turbot.com/guardrails/changelog/azure-storage-v5-29-0</link>
            <description>_What&apos;s new?_

- The `Azure &gt; Storage &gt; Storage Account &gt; CMDB` no longer requires the `listkeys` permission on storage accounts to fetch details for Blob, Queue, and File Share services. We recommend upgrading TE to `v5.52.5` for this change to take effect.</description>
            <pubDate>Mon, 08 Sep 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-s3-v5-32-3</guid>
            <title>aws-s3 v5.32.3 - Encryption in transit control will check only for the relevant encryption in transit condition without explicitly matching on the Sid</title>
            <link>https://turbot.com/guardrails/changelog/aws-s3-v5-32-3</link>
            <description>_Bug fixes_

- The `AWS &gt; S3 &gt; Bucket &gt; Encryption In Transit` control previously required an Encryption in Transit policy statement with the Sid `MustBeEncryptedInTransit` and the condition `&quot;aws:SecureTransport&quot;: &quot;false&quot;`. This sometimes caused the control to incorrectly enter an alarm state when the bucket had the correct condition but a different Sid. The control has been updated to check only for the relevant Encryption in Transit condition, without explicitly requiring the Sid `MustBeEncryptedInTransit`.</description>
            <pubDate>Mon, 08 Sep 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-storage-v5-28-1</guid>
            <title>azure-storage v5.28.1 - Soft Delete control will no longer attempt to apply soft delete settings if Guardrails does not have the required permissions to read or write soft delete data</title>
            <link>https://turbot.com/guardrails/changelog/azure-storage-v5-28-1</link>
            <description>_Bug fixes_

- The `Azure &gt; Storage &gt; Storage Account &gt; Data Protection &gt; Soft Delete` control will no longer attempt to apply soft delete settings if Guardrails does not have the required permissions to read or write soft delete data. Instead, it will transition to an invalid state.</description>
            <pubDate>Wed, 03 Sep 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-bigquery-v5-10-0</guid>
            <title>gcp-bigquery v5.10.0 - Manage trusted access for datasets</title>
            <link>https://turbot.com/guardrails/changelog/gcp-bigquery-v5-10-0</link>
            <description>_What&apos;s new?_

- Users can now manage trusted access for datasets. To get started, set the `GCP &gt; BigQuery &gt; Dataset &gt; Policy &gt; Trusted Access &gt; *` policies.

_Control Types_

- GCP &gt; BigQuery &gt; Dataset &gt; Policy
- GCP &gt; BigQuery &gt; Dataset &gt; Policy &gt; Trusted Access

_Policy Types_

- GCP &gt; BigQuery &gt; Dataset &gt; Policy
- GCP &gt; BigQuery &gt; Dataset &gt; Policy &gt; Trusted Access
- GCP &gt; BigQuery &gt; Dataset &gt; Policy &gt; Trusted Access &gt; Domains
- GCP &gt; BigQuery &gt; Dataset &gt; Policy &gt; Trusted Access &gt; Groups
- GCP &gt; BigQuery &gt; Dataset &gt; Policy &gt; Trusted Access &gt; Service Accounts
- GCP &gt; BigQuery &gt; Dataset &gt; Policy &gt; Trusted Access &gt; Users

_Action Types_

- GCP &gt; BigQuery &gt; Dataset &gt; Set Trusted Access</description>
            <pubDate>Fri, 29 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-postgresql-v5-20-1</guid>
            <title>azure-postgresql v5.20.1 - Tags control for various resources no longer includes unnecessary parameters in API calls when updating tags</title>
            <link>https://turbot.com/guardrails/changelog/azure-postgresql-v5-20-1</link>
            <description>_Bug fixes_

- The `Azure &gt; PostgreSQL &gt; *` tags controls will no longer pass unnecessary arguments as parameter to the API call while updating tags for the resource.</description>
            <pubDate>Fri, 29 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-52-4</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.52.4 - Simplification of notification tag policy for better consistency</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-52-4</link>
            <description>_What&apos;s new?_

- Server
  - The `Turbot &gt; Notifications &gt; CC &gt; Tag` policy is no longer checked; resource tags previously specified in `Turbot &gt; Notifications &gt; CC &gt; Tag &gt; Name` are now associated with the `Account/CC` policy instead of being evaluated independently.

_Bug fixes_

- Server
  - Policy settings now return results correctly for policies inside Policy Packs when you have valid access.

_Requirements_

- Upgrade to `5.52.4` requires your workspace to be on `5.51.x`
- TEF: 1.66.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Thu, 28 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-iam-v5-21-0</guid>
            <title>gcp-iam v5.21.0 - Configure and manage project role bindings for service accounts</title>
            <link>https://turbot.com/guardrails/changelog/gcp-iam-v5-21-0</link>
            <description>_What&apos;s new?_

- You can now configure and manage project role bindings for service accounts. To get started, set the `GCP &gt; IAM &gt; Service Account &gt; Project Role Bindings &gt; *` policies.

_Control Types_

- GCP &gt; IAM &gt; Service Account &gt; Project Role Bindings
- GCP &gt; IAM &gt; Service Account &gt; Project Role Bindings &gt; Approved

_Policy Types_

- GCP &gt; IAM &gt; Service Account &gt; Project Role Bindings
- GCP &gt; IAM &gt; Service Account &gt; Project Role Bindings &gt; Approved
- GCP &gt; IAM &gt; Service Account &gt; Project Role Bindings &gt; Approved &gt; Rules

_Action Types_

- GCP &gt; IAM &gt; Service Account &gt; Update Project Role Bindings</description>
            <pubDate>Thu, 28 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-v5-32-1</guid>
            <title>azure v5.32.1 - Tags control for various resources no longer includes unnecessary parameters in API calls when updating tags</title>
            <link>https://turbot.com/guardrails/changelog/azure-v5-32-1</link>
            <description>_Bug fixes_

- The `Azure &gt; Azure &gt; *` tags controls will no longer pass unnecessary arguments as parameter to the API call while updating tags for the resource.</description>
            <pubDate>Thu, 28 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-mysql-v5-17-1</guid>
            <title>azure-mysql v5.17.1 - Tags control for various resources no longer includes unnecessary parameters in API calls when updating tags</title>
            <link>https://turbot.com/guardrails/changelog/azure-mysql-v5-17-1</link>
            <description>_Bug fixes_

- The `Azure &gt; MySQL &gt; *` tags controls will no longer pass unnecessary arguments as parameter to the API call while updating tags for the resource.</description>
            <pubDate>Thu, 28 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-monitor-v5-11-1</guid>
            <title>azure-monitor v5.11.1 - Tags control for various resources no longer includes unnecessary parameters in API calls when updating tags</title>
            <link>https://turbot.com/guardrails/changelog/azure-monitor-v5-11-1</link>
            <description>_Bug fixes_

- The `Azure &gt; Monitor &gt; *` tags controls will no longer pass unnecessary arguments as parameter to the API call while updating tags for the resource.</description>
            <pubDate>Thu, 28 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-datafactory-v5-10-1</guid>
            <title>azure-datafactory v5.10.1 - Tags control for various resources no longer includes unnecessary parameters in API calls when updating tags</title>
            <link>https://turbot.com/guardrails/changelog/azure-datafactory-v5-10-1</link>
            <description>_Bug fixes_

- The `Azure &gt; Data Factory &gt; *` tags controls will no longer pass unnecessary arguments as parameter to the API call while updating tags for the resource.</description>
            <pubDate>Thu, 28 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-cosmosdb-v5-10-1</guid>
            <title>azure-cosmosdb v5.10.1 - Tags control for various resources no longer includes unnecessary parameters in API calls when updating tags</title>
            <link>https://turbot.com/guardrails/changelog/azure-cosmosdb-v5-10-1</link>
            <description>_Bug fixes_

- The `Azure &gt; Cosmos DB &gt; *` tags controls will no longer pass unnecessary arguments as parameter to the API call while updating tags for the resource.</description>
            <pubDate>Thu, 28 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-automation-v5-3-1</guid>
            <title>azure-automation v5.3.1 - Tags control for various resources no longer includes unnecessary parameters in API calls when updating tags</title>
            <link>https://turbot.com/guardrails/changelog/azure-automation-v5-3-1</link>
            <description>_Bug fixes_

- The `Azure &gt; Automation &gt; *` tags controls will no longer pass unnecessary arguments as parameter to the API call while updating tags for the resource.</description>
            <pubDate>Thu, 28 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-cisv3-0-v5-0-6</guid>
            <title>aws-cisv3-0 v5.0.6 - Controls will no longer enter invalid or TBD state when corresponding CIS policies are set to `Skip`</title>
            <link>https://turbot.com/guardrails/changelog/aws-cisv3-0-v5-0-6</link>
            <description>_Bug fixes_

- CIS controls previously entered an invalid or TBD state when the CMDB controls for associated resources were in a skipped or TBD state, even if the corresponding CIS policies were set to `Skip`. This issue has been resolved; such controls will now correctly transition to a skipped state.</description>
            <pubDate>Mon, 25 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-cisv2-0-v5-0-5</guid>
            <title>aws-cisv2-0 v5.0.5 - Controls will no longer enter invalid or TBD state when corresponding CIS policies are set to `Skip`</title>
            <link>https://turbot.com/guardrails/changelog/aws-cisv2-0-v5-0-5</link>
            <description>_Bug fixes_

- CIS controls previously entered an invalid or TBD state when the CMDB controls for associated resources were in a skipped or TBD state, even if the corresponding CIS policies were set to `Skip`. This issue has been resolved; such controls will now correctly transition to a skipped state.</description>
            <pubDate>Mon, 25 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-53-0</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.53.0 - Smarter control runs based on policy dependencies</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-53-0</link>
            <description>_What&apos;s new?_

- Server
	- Controls now wait for dependent policy values to finish processing, preventing redundant runs and duplicate execution attempts.

_Bug fixes_

- Server
  - Restrict smart folder and policy pack to create exception if there is a top level setting available.


_Requirements_

- Upgrade to `5.53.0` requires your workspace to be on `5.51.x`
- TEF: 1.66.0
- TED: 1.9.1
- Mods:
	-	@turbot/turbot: 5.55.0

_Base images_

- Alpine: 3.17.5
- Ubuntu: 22.04.3</description>
            <pubDate>Fri, 22 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-compute-v5-26-0</guid>
            <title>azure-compute v5.26.0 - Configure boot diagnostics for virtual machines</title>
            <link>https://turbot.com/guardrails/changelog/azure-compute-v5-26-0</link>
            <description>_What&apos;s new?_

- You can now configure boot diagnostics for virtual machines. To get started, set the `Azure &gt; Compute &gt; Virtual Machine &gt; Update Boot Diagnostics` policy.

_Control Types_

- Azure &gt; Compute &gt; Virtual Machine &gt; Boot Diagnostics

_Policy Types_

- Azure &gt; Compute &gt; Virtual Machine &gt; Boot Diagnostics
- Azure &gt; Compute &gt; Virtual Machine &gt; Boot Diagnostics &gt; Custom Storage Account

_Action Types_

- Azure &gt; Compute &gt; Virtual Machine &gt; Update Boot Diagnostics</description>
            <pubDate>Fri, 22 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-appservice-v5-15-2</guid>
            <title>azure-appservice v5.15.2 - Web app and function app metadata will now also include `createdBy` details in Guardrails CMDB</title>
            <link>https://turbot.com/guardrails/changelog/azure-appservice-v5-15-2</link>
            <description>_Bug fixes_

- Web App and Function App metadata will now also include `createdBy` details in Guardrails CMDB.</description>
            <pubDate>Fri, 22 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-activedirectory-v5-9-1</guid>
            <title>azure-activedirectory v5.9.1 - Discovery control for directories will run more efficiently and prevent unnecessary resource updates</title>
            <link>https://turbot.com/guardrails/changelog/azure-activedirectory-v5-9-1</link>
            <description>_Bug fixes_

- Optimized the `Azure &gt; Active Directory &gt; Directory &gt; Discovery` control to run more efficiently and prevent unnecessary resource updates, thereby reducing CMDB churn.</description>
            <pubDate>Fri, 22 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-lambda-v5-16-0</guid>
            <title>aws-lambda v5.16.0 - Configure organization restrictions for lambda functions</title>
            <link>https://turbot.com/guardrails/changelog/aws-lambda-v5-16-0</link>
            <description>_What&apos;s new?_

- You can now configure organization restrictions for AWS Lambda function policies. To get started, configure the AWS &gt; Lambda &gt; Function &gt; Policy &gt; Trusted Access &gt; Organization Restrictions policy accordingly.

_Policy Types_

- AWS &gt; Lambda &gt; Function &gt; Policy &gt; Trusted Access &gt; Organization Restrictions
- AWS &gt; Lambda &gt; Trusted Organizations [Default]</description>
            <pubDate>Fri, 22 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/turbot-v5-55-0</guid>
            <title>turbot v5.55.0 - New guardrail and rollout resources, policies &amp; controls (preview)</title>
            <link>https://turbot.com/guardrails/changelog/turbot-v5-55-0</link>
            <description>_Preview_

All of the following resource types, policy types, and control types are currently in preview and may change in future releases.

- Resource Types:
  - Turbot &gt; Rollout
  - Turbot &gt; Guardrail

- Policy Types:
  - Turbot &gt; Notifications &gt; Email &gt; Rollout &gt; Check Template
  - Turbot &gt; Notifications &gt; Email &gt; Rollout &gt; Check Template &gt; Warning Body
  - Turbot &gt; Notifications &gt; Email &gt; Rollout &gt; Check Template &gt; Warning Subject
  - Turbot &gt; Notifications &gt; Email &gt; Rollout &gt; Check Template &gt; Welcome Body
  - Turbot &gt; Notifications &gt; Email &gt; Rollout &gt; Check Template &gt; Welcome Subject
  - Turbot &gt; Notifications &gt; Email &gt; Rollout &gt; Detach Template
  - Turbot &gt; Notifications &gt; Email &gt; Rollout &gt; Detach Template &gt; Warning Body
  - Turbot &gt; Notifications &gt; Email &gt; Rollout &gt; Detach Template &gt; Warning Subject
  - Turbot &gt; Notifications &gt; Email &gt; Rollout &gt; Enforce Template
  - Turbot &gt; Notifications &gt; Email &gt; Rollout &gt; Enforce Template &gt; Warning Body
  - Turbot &gt; Notifications &gt; Email &gt; Rollout &gt; Enforce Template &gt; Warning Subject
  - Turbot &gt; Notifications &gt; Email &gt; Rollout &gt; Enforce Template &gt; Welcome Body
  - Turbot &gt; Notifications &gt; Email &gt; Rollout &gt; Enforce Template &gt; Welcome Subject
  - Turbot &gt; Notifications &gt; Email &gt; Rollout &gt; Preview Template
  - Turbot &gt; Notifications &gt; Email &gt; Rollout &gt; Preview Template &gt; Warning Body
  - Turbot &gt; Notifications &gt; Email &gt; Rollout &gt; Preview Template &gt; Warning Subject
  - Turbot &gt; Notifications &gt; Email &gt; Rollout &gt; Preview Template &gt; Welcome Subject
  - Turbot &gt; Notifications &gt; Email &gt; Rollout &gt; Preview Template &gt; Welcome Body

- Control types
  - Turbot &gt; Rollout &gt; Events</description>
            <pubDate>Thu, 21 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ec2-v5-46-3</guid>
            <title>aws-ec2 v5.46.3 - Discovery controls for target groups will no longer enter an error state when upserting a resource if the parent load balancer isn’t available in the CMDB</title>
            <link>https://turbot.com/guardrails/changelog/aws-ec2-v5-46-3</link>
            <description>_Bug fixes_

- The `AWS &gt; EC2 &gt; Target Group &gt; Discovery` control could previously enter an error state when upserting a target group whose parent load balancer was not available in CMDB. We have improved this process so that all target groups are now upserted under a region, ensuring better consistency and reliability. Existing target groups under load balancers will also be moved under their respective regions automatically.</description>
            <pubDate>Thu, 21 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-storage-v5-28-0</guid>
            <title>azure-storage v5.28.0 - Configure soft delete for file shares in storage accounts</title>
            <link>https://turbot.com/guardrails/changelog/azure-storage-v5-28-0</link>
            <description>_What&apos;s new?_

- You can now configure soft delete for file shares in storage accounts. To get started, configure the `Azure &gt; Storage &gt; Storage Account &gt; Data Protection &gt; Soft Delete &gt; File Shares &gt; *` policies accordingly.
- Delete retention policy details for file share will now be available in CMDB for Storage Accounts.

_Policy Types_

- Azure &gt; Storage &gt; Storage Account &gt; Data Protection &gt; Soft Delete &gt; File Shares
- Azure &gt; Storage &gt; Storage Account &gt; Data Protection &gt; Soft Delete &gt; File Shares &gt; Retention Days</description>
            <pubDate>Wed, 20 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-relay-v5-5-1</guid>
            <title>azure-relay v5.5.1 - Tags control for various resources no longer includes unnecessary parameters in API calls when updating tags</title>
            <link>https://turbot.com/guardrails/changelog/azure-relay-v5-5-1</link>
            <description>_Bug fixes_

- The `Azure &gt; Relay &gt; *` tags controls will no longer pass unnecessary arguments as parameter to the API call while updating tags for the resource.</description>
            <pubDate>Wed, 20 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-recoveryservice-v5-9-1</guid>
            <title>azure-recoveryservice v5.9.1 - Tags control for various resources no longer includes unnecessary parameters in API calls when updating tags</title>
            <link>https://turbot.com/guardrails/changelog/azure-recoveryservice-v5-9-1</link>
            <description>_Bug fixes_

- The `Azure &gt; Recovery Service &gt; *` tags controls will no longer pass unnecessary arguments as parameter to the API call while updating tags for the resource.</description>
            <pubDate>Wed, 20 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-keyvault-v5-18-1</guid>
            <title>azure-keyvault v5.18.1 - Tags control for various resources no longer includes unnecessary parameters in API calls when updating tags</title>
            <link>https://turbot.com/guardrails/changelog/azure-keyvault-v5-18-1</link>
            <description>_Bug fixes_

- The `Azure &gt; Key Vault &gt; *` tags controls will no longer pass unnecessary arguments as parameter to the API call while updating tags for the resource.</description>
            <pubDate>Wed, 20 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-dns-v5-11-1</guid>
            <title>azure-dns v5.11.1 - Tags control for various resources no longer includes unnecessary parameters in API calls when updating tags</title>
            <link>https://turbot.com/guardrails/changelog/azure-dns-v5-11-1</link>
            <description>_Bug fixes_

- The `Azure &gt; DNS &gt; *` tags controls will no longer pass unnecessary arguments as parameter to the API call while updating tags for the resource.</description>
            <pubDate>Wed, 20 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-databricks-v5-7-1</guid>
            <title>azure-databricks v5.7.1 - Tags control for various resources no longer includes unnecessary parameters in API calls when updating tags</title>
            <link>https://turbot.com/guardrails/changelog/azure-databricks-v5-7-1</link>
            <description>_Bug fixes_

- The `Azure &gt; Databricks &gt; *` tags controls will no longer pass unnecessary arguments as parameter to the API call while updating tags for the resource.</description>
            <pubDate>Wed, 20 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-synapseanalytics-v5-11-1</guid>
            <title>azure-synapseanalytics v5.11.1 - Tags control for various resources no longer includes unnecessary parameters in API calls when updating tags</title>
            <link>https://turbot.com/guardrails/changelog/azure-synapseanalytics-v5-11-1</link>
            <description>_Bug fixes_

- The `Azure &gt; Synapse Analytics &gt; *` tags controls will no longer pass unnecessary arguments as parameter to the API call while updating tags for the resource.</description>
            <pubDate>Mon, 18 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-sqlvirtualmachine-v5-3-1</guid>
            <title>azure-sqlvirtualmachine v5.3.1 - Tags control for various resources no longer includes unnecessary parameters in API calls when updating tags</title>
            <link>https://turbot.com/guardrails/changelog/azure-sqlvirtualmachine-v5-3-1</link>
            <description>_Bug fixes_

- The `Azure &gt; SQL Virtual Machine Service &gt; *` tags controls will no longer pass unnecessary arguments as parameter to the API call while updating tags for the resource.</description>
            <pubDate>Mon, 18 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-signalr-v5-5-1</guid>
            <title>azure-signalr v5.5.1 - Tags control for various resources no longer includes unnecessary parameters in API calls when updating tags</title>
            <link>https://turbot.com/guardrails/changelog/azure-signalr-v5-5-1</link>
            <description>_Bug fixes_

- The `Azure &gt; SignalR Service &gt; *` tags controls will no longer pass unnecessary arguments as parameter to the API call while updating tags for the resource.</description>
            <pubDate>Mon, 18 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-servicebus-v5-5-1</guid>
            <title>azure-servicebus v5.5.1 - Tags control for various resources no longer includes unnecessary parameters in API calls when updating tags</title>
            <link>https://turbot.com/guardrails/changelog/azure-servicebus-v5-5-1</link>
            <description>_Bug fixes_

- The `Azure &gt; Service Bus &gt; *` tags controls will no longer pass unnecessary arguments as parameter to the API call while updating tags for the resource.</description>
            <pubDate>Mon, 18 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-network-v5-26-1</guid>
            <title>azure-network v5.26.1 - Bastion host discovery control now upserts resources reliably and consistently under correct resource groups</title>
            <link>https://turbot.com/guardrails/changelog/azure-network-v5-26-1</link>
            <description>_Bug fixes_

- The `Azure &gt; Network &gt; *` tags controls will no longer pass unnecessary arguments as parameter to the API call while updating tags for the resource.
- The `Azure &gt; Network &gt; Bastion Host &gt; Discovery` control previously could inadvertently upsert bastion hosts under incorrect resource groups. This issue has been resolved, and the control now upserts bastion hosts more reliably and consistently.</description>
            <pubDate>Mon, 18 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-loganalytics-v5-12-1</guid>
            <title>azure-loganalytics v5.12.1 - Tags control for various resources no longer includes unnecessary parameters in API calls when updating tags</title>
            <link>https://turbot.com/guardrails/changelog/azure-loganalytics-v5-12-1</link>
            <description>_Bug fixes_

- The `Azure &gt; Log Analytics &gt; *` tags controls will no longer pass unnecessary arguments as parameter to the API call while updating tags for the resource.</description>
            <pubDate>Mon, 18 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-backup-v5-13-2</guid>
            <title>aws-backup v5.13.2 - Recovery point CMDB control no longer re-runs automatically for expired recovery points</title>
            <link>https://turbot.com/guardrails/changelog/aws-backup-v5-13-2</link>
            <description>_Bug fixes_

- The `AWS &gt; Backup &gt; Recovery Point &gt; CMDB` control previously ran every minute if a recovery point’s `CalculatedLifecycle.DeleteAt` timestamp was already in the past. It now deletes expired recovery points and no longer re-runs automatically when the next tick is also in the past.</description>
            <pubDate>Mon, 18 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/terraform-provider-v1-13-0</guid>
            <title>Terraform Provider v1.13.0 - Added support for tags in `turbot_policy_pack` resource</title>
            <link>https://turbot.com/guardrails/changelog/terraform-provider-v1-13-0</link>
            <description>_What&apos;s new?_

- Added support for `tags` attribute in the `turbot_policy_pack` resource. This will allow users to manage tags on policy packs.

Minimum version requirements:

TE v5.52.3</description>
            <pubDate>Thu, 14 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-52-3</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.52.3 - Add tags support for policy pack</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-52-3</link>
            <description>_What&apos;s new?_

- Server
  - Added support for tags in policy packs, making it easier to organize and filter them.

_Note_

Upgrade to `5.52.3` requires your workspace to be on `5.51.x`; direct upgrades from older versions (e.g., 5.49.x) will fail.

_Requirements_

- TEF: 1.66.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Thu, 14 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-v5-32-1</guid>
            <title>gcp v5.32.1 - The Event Handlers Pub/Sub Source policy now evaluates reliably on project imports in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/gcp-v5-32-1</link>
            <description>_Bug fixes_

- The `GCP &gt; Turbot &gt; Event Handlers &gt; Pub/Sub &gt; Source` policy could previously evaluate incorrectly immediately after a GCP Project import if the Project CMDB data was not up to date. The policy now checks the `GCP &gt; Project &gt; CMDB` control and evaluates only when that control has run successfully and is in an OK state, preventing incorrect results and improving clarity.
- Event Poller controls now display improved help messages when the API used to fetch events returns an error, instead of only logging the errors under Activities.

_Action Types_
_Removed_

- GCP &gt; Folder &gt; Event Poller
- GCP &gt; Organization &gt; Event Poller
- GCP &gt; Project &gt; Event Poller</description>
            <pubDate>Thu, 14 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-compute-v5-25-1</guid>
            <title>azure-compute v5.25.1 - Tags control for various resources no longer includes unnecessary parameters in API calls when updating tags</title>
            <link>https://turbot.com/guardrails/changelog/azure-compute-v5-25-1</link>
            <description>_Bug fixes_

- The `Azure &gt; Compute &gt; *` tags controls will no longer pass unnecessary arguments as parameter to the API call while updating tags for the resource.</description>
            <pubDate>Thu, 14 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-pciv3-2-1-v5-1-0</guid>
            <title>aws-pciv3-2-1 v5.1.0 - Improved GraphQL queries for `EC2 &gt; 3 Unused EC2 security groups should be removed` control</title>
            <link>https://turbot.com/guardrails/changelog/aws-pciv3-2-1-v5-1-0</link>
            <description>_Bug fixes_

- We have updated the internal GraphQL queries for the `AWS &gt; PCI v3.2.1 &gt; EC2 &gt; 3 Unused EC2 security groups should be removed` control to improve performance when evaluating the control’s outcome. There are no visible changes, but things will run smoother and faster than before.

Note: We recommend updating the `@turbot/aws-ec2` mod to `v5.46.2` for proper functionality.

_Policy Types_

- AWS &gt; PCI v3.2.1 &gt; EC2
- AWS &gt; PCI v3.2.1 &gt; EC2 &gt; 3 Unused EC2 security groups should be removed</description>
            <pubDate>Thu, 14 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ec2-v5-46-2</guid>
            <title>aws-ec2 v5.46.2 - Network interfaces CMDB data now includes additional metadata for associated security groups for internal performance improvements</title>
            <link>https://turbot.com/guardrails/changelog/aws-ec2-v5-46-2</link>
            <description>_Bug fixes_

- Added additional metadata for associated security groups to the CMDB data for network interfaces for internal performance improvements.</description>
            <pubDate>Thu, 14 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-logs-v5-16-0</guid>
            <title>aws-logs v5.16.0 - Track and manage delivery, delivery destination, delivery source, and destination resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/aws-logs-v5-16-0</link>
            <description>_What&apos;s new?_

- Track and manage delivery, delivery destination, delivery source, and destination resources in Guardrails.

_Resource Types_

- AWS &gt; Logs &gt; Delivery
- AWS &gt; Logs &gt; Delivery Destination
- AWS &gt; Logs &gt; Delivery Source
- AWS &gt; Logs &gt; Destination

_Control Types_

- AWS &gt; Logs &gt; Delivery &gt; Active
- AWS &gt; Logs &gt; Delivery &gt; CMDB
- AWS &gt; Logs &gt; Delivery &gt; Discovery
- AWS &gt; Logs &gt; Delivery &gt; Tags
- AWS &gt; Logs &gt; Delivery Destination &gt; Active
- AWS &gt; Logs &gt; Delivery Destination &gt; CMDB
- AWS &gt; Logs &gt; Delivery Destination &gt; Discovery
- AWS &gt; Logs &gt; Delivery Destination &gt; Tags
- AWS &gt; Logs &gt; Delivery Source &gt; Active
- AWS &gt; Logs &gt; Delivery Source &gt; CMDB
- AWS &gt; Logs &gt; Delivery Source &gt; Discovery
- AWS &gt; Logs &gt; Delivery Source &gt; Tags
- AWS &gt; Logs &gt; Destination &gt; Active
- AWS &gt; Logs &gt; Destination &gt; CMDB
- AWS &gt; Logs &gt; Destination &gt; Discovery

_Policy Types_

- AWS &gt; Logs &gt; Delivery &gt; Active
- AWS &gt; Logs &gt; Delivery &gt; Active &gt; Age
- AWS &gt; Logs &gt; Delivery &gt; Active &gt; Budget
- AWS &gt; Logs &gt; Delivery &gt; Active &gt; Last Modified
- AWS &gt; Logs &gt; Delivery &gt; CMDB
- AWS &gt; Logs &gt; Delivery &gt; Regions
- AWS &gt; Logs &gt; Delivery &gt; Tags
- AWS &gt; Logs &gt; Delivery &gt; Tags &gt; Template
- AWS &gt; Logs &gt; Delivery Destination &gt; Active
- AWS &gt; Logs &gt; Delivery Destination &gt; Active &gt; Age
- AWS &gt; Logs &gt; Delivery Destination &gt; Active &gt; Budget
- AWS &gt; Logs &gt; Delivery Destination &gt; Active &gt; Last Modified
- AWS &gt; Logs &gt; Delivery Destination &gt; CMDB
- AWS &gt; Logs &gt; Delivery Destination &gt; Regions
- AWS &gt; Logs &gt; Delivery Destination &gt; Tags
- AWS &gt; Logs &gt; Delivery Destination &gt; Tags &gt; Template
- AWS &gt; Logs &gt; Delivery Source &gt; Active
- AWS &gt; Logs &gt; Delivery Source &gt; Active &gt; Age
- AWS &gt; Logs &gt; Delivery Source &gt; Active &gt; Budget
- AWS &gt; Logs &gt; Delivery Source &gt; Active &gt; Last Modified
- AWS &gt; Logs &gt; Delivery Source &gt; CMDB
- AWS &gt; Logs &gt; Delivery Source &gt; Regions
- AWS &gt; Logs &gt; Delivery Source &gt; Tags
- AWS &gt; Logs &gt; Delivery Source &gt; Tags &gt; Template
- AWS &gt; Logs &gt; Destination &gt; Active
- AWS &gt; Logs &gt; Destination &gt; Active &gt; Age
- AWS &gt; Logs &gt; Destination &gt; Active &gt; Budget
- AWS &gt; Logs &gt; Destination &gt; Active &gt; Last Modified
- AWS &gt; Logs &gt; Destination &gt; CMDB
- AWS &gt; Logs &gt; Destination &gt; Regions

_Action Types_

- AWS &gt; Logs &gt; Delivery &gt; Delete
- AWS &gt; Logs &gt; Delivery &gt; Router
- AWS &gt; Logs &gt; Delivery &gt; Update Tags
- AWS &gt; Logs &gt; Delivery Destination &gt; Delete
- AWS &gt; Logs &gt; Delivery Destination &gt; Router
- AWS &gt; Logs &gt; Delivery Destination &gt; Update Tags
- AWS &gt; Logs &gt; Delivery Source &gt; Delete
- AWS &gt; Logs &gt; Delivery Source &gt; Router
- AWS &gt; Logs &gt; Delivery Source &gt; Update Tags
- AWS &gt; Logs &gt; Destination &gt; Delete
- AWS &gt; Logs &gt; Destination &gt; Router</description>
            <pubDate>Wed, 13 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-iam-v5-44-1</guid>
            <title>aws-iam v5.44.1 - Stack control will now be able to claim existing OpenID connect providers correctly</title>
            <link>https://turbot.com/guardrails/changelog/aws-iam-v5-44-1</link>
            <description>_Bug fixes_

- Guardrails stack controls would fail to claim any existing OpenID Connect provider if the OpenID Connect provider was available in Guardrails CMDB and the stack&apos;s Source policy included the Terraform plan for the OpenID Connect provider. This is fixed and stack control will now be able to claim existing OpenID Connect providers correctly.</description>
            <pubDate>Wed, 13 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-52-2</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.52.2 - Fixed server stability issues and improved UI consistency</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-52-2</link>
            <description>_What&apos;s new?_

- Server
  - Added retry mechanism for Mod expired URL errors.

_Bug Fixes_

- Server
  - Turbot &gt; Workspace &gt; Background Tasks now ignore deleted resources.
  - Resolved an issue where the worker could crash while processing errors.
  - Addressed a cleanup script bug that was incorrectly removing active Lambda version aliases and associated topics. The script now deletes only unused resources.

- UI
  - Saving in the calculated policy editor is now prevented if there is an error.
  - Alignment of `Note` in the policy tab is now consistent across all entries.
  - Multi-step queries in the calculated policy editor are now displayed correctly as separate steps.
  - Policy packs no longer show a blank page when the description is missing.
  - Policy Pack details screen should not show summary when AI summary is disabled.

_Note_

Upgrade to `5.52.2` requires your workspace to be on `5.51.x`; direct upgrades from older versions (e.g., 5.49.x) will fail.

_Requirements_

- TEF: 1.66.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Tue, 12 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-storage-v5-27-1</guid>
            <title>azure-storage v5.27.1 - Storage account CMDB control will no longer attempt to access table services for premium storage accounts</title>
            <link>https://turbot.com/guardrails/changelog/azure-storage-v5-27-1</link>
            <description>_Bug fixes_

- The `Azure &gt; Storage &gt; Storage Account &gt; CMDB` control previously encountered errors with Premium storage accounts when attempting to access unsupported Table services. This has now been resolved.</description>
            <pubDate>Tue, 12 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/turbot-v5-54-3</guid>
            <title>turbot v5.54.3 - Prevent background task errors for non existent resources</title>
            <link>https://turbot.com/guardrails/changelog/turbot-v5-54-3</link>
            <description>_What&apos;s new?_

- Turbot &gt; Workspace &gt; Background Tasks will no longer go into an error state if the resource does not exist.

_Requirements_

- TE: 5.35.4</description>
            <pubDate>Fri, 08 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-storage-v5-27-0</guid>
            <title>azure-storage v5.27.0 - Create and manage cloud resources via Stack [Native] controls</title>
            <link>https://turbot.com/guardrails/changelog/azure-storage-v5-27-0</link>
            <description>_What&apos;s new?_

- Users can now create and manage cloud resources using Terraform 1.x via Guardrails, fully leveraging all features available in this version. To get started, set the `Stack [Native] &gt; *` policies.

_Bug fixes_

- The `Azure &gt; Storage &gt; Storage Account &gt; CMDB` control now stores details of API calls that fail due to insufficient permissions granted to Guardrails&apos; service principal. This enables Guardrails to mark controls that depend on the respective data as invalid, rather than enforcing settings unnecessarily.

_Control Types_

- Azure &gt; Storage &gt; Storage Account &gt; Stack [Native]

_Policy Types_

- Azure &gt; Storage &gt; Storage Account &gt; Stack [Native]
- Azure &gt; Storage &gt; Storage Account &gt; Stack [Native] &gt; Drift Detection
- Azure &gt; Storage &gt; Storage Account &gt; Stack [Native] &gt; Drift Detection &gt; Interval
- Azure &gt; Storage &gt; Storage Account &gt; Stack [Native] &gt; Modifier
- Azure &gt; Storage &gt; Storage Account &gt; Stack [Native] &gt; Secret Variables
- Azure &gt; Storage &gt; Storage Account &gt; Stack [Native] &gt; Source
- Azure &gt; Storage &gt; Storage Account &gt; Stack [Native] &gt; Timeout
- Azure &gt; Storage &gt; Storage Account &gt; Stack [Native] &gt; Variables
- Azure &gt; Storage &gt; Storage Account &gt; Stack [Native] &gt; Version</description>
            <pubDate>Fri, 08 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-keyvault-v5-18-0</guid>
            <title>azure-keyvault v5.18.0 - Create and manage cloud resources via Stack [Native] controls</title>
            <link>https://turbot.com/guardrails/changelog/azure-keyvault-v5-18-0</link>
            <description>_What&apos;s new?_

- Users can now create and manage cloud resources using Terraform 1.x via Guardrails, fully leveraging all features available in this version. To get started, set the `Stack [Native] &gt; *` policies.

_Control Types_

- Azure &gt; Key Vault &gt; Vault &gt; Stack [Native]

_Policy Types_

- Azure &gt; Key Vault &gt; Vault &gt; Stack [Native]
- Azure &gt; Key Vault &gt; Vault &gt; Stack [Native] &gt; Drift Detection
- Azure &gt; Key Vault &gt; Vault &gt; Stack [Native] &gt; Drift Detection &gt; Interval
- Azure &gt; Key Vault &gt; Vault &gt; Stack [Native] &gt; Modifier
- Azure &gt; Key Vault &gt; Vault &gt; Stack [Native] &gt; Secret Variables
- Azure &gt; Key Vault &gt; Vault &gt; Stack [Native] &gt; Source
- Azure &gt; Key Vault &gt; Vault &gt; Stack [Native] &gt; Timeout
- Azure &gt; Key Vault &gt; Vault &gt; Stack [Native] &gt; Variables
- Azure &gt; Key Vault &gt; Vault &gt; Stack [Native] &gt; Version</description>
            <pubDate>Fri, 08 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-v5-8-1</guid>
            <title>servicenow-gcp v5.8.1 - Fixed invalid CMDB references for region resource types causing control errors</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-v5-8-1</link>
            <description>_Bug fixes_

- Fixed invalid CMDB references for the `Zone`, `Region`, `Multi-Region`, and `Global Region` resource types that caused the `Relationships` and `Import Set` controls to enter an error state. The controls now run reliably without errors.</description>
            <pubDate>Thu, 07 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-v5-38-1</guid>
            <title>aws v5.38.1 - Budget control will no longer run unnecessarily when notifications are enabled in the workspaces</title>
            <link>https://turbot.com/guardrails/changelog/aws-v5-38-1</link>
            <description>_Bug fixes_

- The `AWS &gt; Account &gt; Budget &gt; Budget` control previously reran unnecessarily in workspaces with `Turbot &gt; Notifications` enabled. This issue has been resolved, and the control now runs as expected.</description>
            <pubDate>Thu, 07 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/terraform-provider-v1-12-5</guid>
            <title>Terraform Provider v1.12.5 - Improved handling of `turbot_file` updates</title>
            <link>https://turbot.com/guardrails/changelog/terraform-provider-v1-12-5</link>
            <description>_Bug fixes_

- Fixed an issue in the `turbot_file` resource where removed keys in the content field were incorrectly sent as `&quot;key&quot;: null` in the update payload. The provider now sends the content exactly as specified in the Terraform configuration, ensuring that only the intended keys appear in the Turbot console.</description>
            <pubDate>Wed, 06 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/ted-v1-51-1</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.51.1 -Added CPU and memory settings for PgBouncer task</title>
            <link>https://turbot.com/guardrails/changelog/ted-v1-51-1</link>
            <description>_What&apos;s new?_

- Added CPU and memory settings for the PgBouncer task, giving you more control over resource allocation.</description>
            <pubDate>Wed, 06 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-storage-v5-26-0</guid>
            <title>azure-storage v5.26.0 - Configure cross-tenant replication for storage accounts</title>
            <link>https://turbot.com/guardrails/changelog/azure-storage-v5-26-0</link>
            <description>_What&apos;s new?_

- You can now configure cross-tenant replication for storage accounts. To get started, set the `Azure &gt; Storage &gt; Storage Account &gt; Cross-Tenant Replication` policy.

_Control Types_

- Azure &gt; Storage &gt; Storage Account &gt; Cross-Tenant Replication

_Policy Types_

- Azure &gt; Storage &gt; Storage Account &gt; Cross-Tenant Replication

_Action Types_

- Azure &gt; Storage &gt; Storage Account &gt; Set Cross-Tenant Replication</description>
            <pubDate>Wed, 06 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-sql-v5-19-1</guid>
            <title>azure-sql v5.19.1 - Updated internal Node SDK package to delete SQL resources correctly</title>
            <link>https://turbot.com/guardrails/changelog/azure-sql-v5-19-1</link>
            <description>_Bug fixes_

- Guardrails previously failed to delete `Azure &gt; SQL &gt; *` resources due to limitations in the internal Node SDK package version. This issue has now been resolved, and the resources will be deleted as expected.
- The `Azure &gt; SQL &gt; *` tags controls will no longer pass unnecessary arguments as parameter to the API call while updating tags for the resource.</description>
            <pubDate>Wed, 06 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-iam-v5-20-0</guid>
            <title>gcp-iam v5.20.0 - Manage role bindings for service accounts</title>
            <link>https://turbot.com/guardrails/changelog/gcp-iam-v5-20-0</link>
            <description>_What&apos;s new?_

- You can now manage role bindings for service accounts. To get started, set the `GCP &gt; IAM &gt; Service Account &gt; Role Bindings &gt; *` policies.

_Control Types_

- GCP &gt; IAM &gt; Service Account &gt; Role Bindings
- GCP &gt; IAM &gt; Service Account &gt; Role Bindings &gt; Approved

_Policy Types_

- GCP &gt; IAM &gt; Service Account &gt; Role Bindings
- GCP &gt; IAM &gt; Service Account &gt; Role Bindings &gt; Approved
- GCP &gt; IAM &gt; Service Account &gt; Role Bindings &gt; Approved &gt; Rules

_Action Types_

- GCP &gt; IAM &gt; Service Account &gt; Update Role Bindings</description>
            <pubDate>Tue, 05 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-storage-v5-25-2</guid>
            <title>azure-storage v5.25.2 - Diagnostic settings data will now be retrieved accurately for all storage services</title>
            <link>https://turbot.com/guardrails/changelog/azure-storage-v5-25-2</link>
            <description>_Bug fixes_

- In the previous version, an issue was introduced in the CMDB control for `Azure &gt; Storage &gt; Storage Account` that prevented the retrieval of diagnostic settings. This has now been resolved, and the control successfully processes diagnostic settings for all storage services, including Blob, Table, Queue, and the primary account.</description>
            <pubDate>Mon, 04 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-iam-v5-19-0</guid>
            <title>gcp-iam v5.19.0 - Manage role bindings for project users</title>
            <link>https://turbot.com/guardrails/changelog/gcp-iam-v5-19-0</link>
            <description>_What&apos;s new?_

- You can now manage role bindings for project users. To get started, set the `GCP &gt; IAM &gt; Project User &gt; Role Bindings &gt; *` policies.

_Control Types_

- GCP &gt; IAM &gt; Project User &gt; Role Bindings
- GCP &gt; IAM &gt; Project User &gt; Role Bindings &gt; Approved

_Policy Types_

- GCP &gt; IAM &gt; Project User &gt; Role Bindings
- GCP &gt; IAM &gt; Project User &gt; Role Bindings &gt; Approved
- GCP &gt; IAM &gt; Project User &gt; Role Bindings &gt; Approved &gt; Rules

_Action Types_

- GCP &gt; IAM &gt; Project User &gt; Update Role Bindings</description>
            <pubDate>Fri, 01 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-servicebus-v5-5-0</guid>
            <title>azure-servicebus v5.5.0 - Network rule set details will now be available in CMDB for namespaces</title>
            <link>https://turbot.com/guardrails/changelog/azure-servicebus-v5-5-0</link>
            <description>_What&apos;s new?_

- Network rule set details will now be available in CMDB for namespaces.</description>
            <pubDate>Fri, 01 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-cisv3-0-v5-0-0</guid>
            <title>azure-cisv3-0 v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/azure-cisv3-0-v5-0-0</link>
            <description>_What&apos;s new?_

_Control Types_

- Azure &gt; CIS v3.0
- Azure &gt; CIS v3.0 &gt; 02 - Identity
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.01 - Security Defaults (Per-User MFA)
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.01 - Security Defaults (Per-User MFA) &gt; 02.01.01 - Ensure Security Defaults is enabled on Microsoft Entra ID
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.01 - Security Defaults (Per-User MFA) &gt; 02.01.02 - Ensure that &apos;Multi-Factor Auth Status&apos; is &apos;Enabled&apos; for all Privileged Users
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.01 - Security Defaults (Per-User MFA) &gt; 02.01.03 - Ensure that &apos;Multi-Factor Auth Status&apos; is &apos;Enabled&apos; for all Non-Privileged Users
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.01 - Security Defaults (Per-User MFA) &gt; 02.01.04 - Ensure that &apos;Allow users to remember multi-factor authentication on devices they trust&apos; is Disabled
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.02 - Conditional Access
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.02 - Conditional Access &gt; 02.02.01 - Ensure Trusted Locations Are Defined
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.02 - Conditional Access &gt; 02.02.02 - Ensure that an exclusionary Geographic Access Policy is considered
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.02 - Conditional Access &gt; 02.02.03 - Ensure that an exclusionary Device code flow policy is considered
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.02 - Conditional Access &gt; 02.02.04 - Ensure that A Multi-factor Authentication Policy Exists for Administrative Groups
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.02 - Conditional Access &gt; 02.02.05 - Ensure that A Multi-factor Authentication Policy Exists for All Users
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.02 - Conditional Access &gt; 02.02.06 - Ensure Multi-factor Authentication is Required for Risky Sign-ins
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.02 - Conditional Access &gt; 02.02.07 - Ensure Multi-factor Authentication is Required for Windows Azure Service Management API
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.02 - Conditional Access &gt; 02.02.08 - Ensure Multi-factor Authentication is Required to access Microsoft Admin Portals
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.03 - Ensure that &apos;Restrict non-admin users from creating tenants&apos; is set to &apos;Yes&apos;
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.04 - Ensure Guest Users Are Reviewed on a Regular Basis
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.05 - Ensure That &apos;Number of methods required to reset&apos; is set to &apos;2&apos;
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.06 - Ensure that account &apos;Lockout Threshold&apos; is less than or equal to &apos;10&apos;
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.07 - Ensure that account &apos;Lockout duration in seconds&apos; is greater than or equal to &apos;60&apos;
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.08 - Ensure that a Custom Bad Password List is set to &apos;Enforce&apos; for your Organization
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.09 - Ensure that &apos;Number of days before users are asked to re-confirm their authentication information&apos; is not set to &apos;0&apos;
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.10 - Ensure that &apos;Notify users on password resets?&apos; is set to &apos;Yes&apos;
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.11 - Ensure That &apos;Notify all admins when other admins reset their password?&apos; is set to &apos;Yes&apos;
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.12 - Ensure `User consent for applications` is set to `Do not allow user consent`
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.13 - Ensure &apos;User consent for applications&apos; Is Set To &apos;Allow for Verified Publishers&apos;
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.14 - Ensure That &apos;Users Can Register Applications&apos; Is Set to &apos;No&apos;
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.15 - Ensure That &apos;Guest users access restrictions&apos; is set to &apos;Guest user access is restricted to properties and memberships of their own directory objects&apos;
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.16 - Ensure that &apos;Guest invite restrictions&apos; is set to &apos;Only users assigned to specific admin roles can invite guest users&apos;
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.17 - Ensure That &apos;Restrict access to Microsoft Entra admin center&apos; is Set to &apos;Yes&apos;
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.18 - Ensure that &apos;Restrict user ability to access groups features in the Access Pane&apos; is Set to &apos;Yes&apos;
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.19 - Ensure that &apos;Users can create security groups in Azure portals, API or PowerShell&apos; is set to &apos;No&apos;
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.20 - Ensure that &apos;Owners can manage group membership requests in My Groups&apos; is set to &apos;No&apos;
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.21 - Ensure that &apos;Users can create Microsoft 365 groups in Azure portals, API or PowerShell&apos; is set to &apos;No&apos;
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.22 - Ensure that &apos;Require Multifactor Authentication to register or join devices with Microsoft Entra&apos; is set to &apos;Yes&apos;
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.23 - Ensure That No Custom Subscription Administrator Roles Exist
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.24 - Ensure a Custom Role is Assigned Permissions for Administering Resource Locks
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.25 - Ensure That &apos;Subscription leaving Microsoft Entra tenant&apos; and &apos;Subscription entering Microsoft Entra tenant&apos; Is Set To &apos;Permit no one&apos;
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.26 - Ensure fewer than 5 users have global administrator assignment
- Azure &gt; CIS v3.0 &gt; 03 - Security
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.01 - Microsoft Cloud Security Posture Management (CSPM)
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.01 - Microsoft Cloud Security Posture Management (CSPM) &gt; 03.01.01.01 - Ensure that Auto provisioning of &apos;Log Analytics agent for Azure VMs&apos; is Set to &apos;On&apos;
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.01 - Microsoft Cloud Security Posture Management (CSPM) &gt; 03.01.01.02 - Ensure that Microsoft Defender for Cloud Apps integration with Microsoft Defender for Cloud is Selected
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.02 - Defender Plan APIs
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.03 - Defender Plan Servers
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.03 - Defender Plan Servers &gt; 03.01.03.01 - Ensure That Microsoft Defender for Servers Is Set to &apos;On&apos;
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.03 - Defender Plan Servers &gt; 03.01.03.02 - Ensure that &apos;Vulnerability assessment for machines&apos; component status is set to &apos;On&apos;
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.03 - Defender Plan Servers &gt; 03.01.03.03 - Ensure that &apos;Endpoint protection&apos; component status is set to &apos;On&apos;
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.03 - Defender Plan Servers &gt; 03.01.03.04 - Ensure that &apos;Agentless scanning for machines&apos; component status is set to &apos;On&apos;
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.03 - Defender Plan Servers &gt; 03.01.03.05 - Ensure that &apos;File Integrity Monitoring&apos; component status is set to &apos;On&apos;
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.04 - Defender Plan Containers
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.04 - Defender Plan Containers &gt; 03.01.04.01 - Ensure That Microsoft Defender for Containers Is Set To &apos;On&apos;
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.04 - Defender Plan Containers &gt; 03.01.04.02 - Ensure that &apos;Agentless discovery for Kubernetes&apos; component status &apos;On&apos;
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.04 - Defender Plan Containers &gt; 03.01.04.03 - Ensure that &apos;Agentless container vulnerability assessment&apos; component status is &apos;On&apos;
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.05 - Defender Plan - Storage
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.05 - Defender Plan - Storage &gt; 03.01.05.01 - Ensure That Microsoft Defender for Storage Is Set To &apos;On&apos;
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.06 - Defender Plan - App Service
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.06 - Defender Plan - App Service &gt; 03.01.06.01 - Ensure That Microsoft Defender for App Services Is Set To &apos;On&apos;
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.07 - Defender Plan - Databases
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.07 - Defender Plan - Databases &gt; 03.01.07.01 - Ensure That Microsoft Defender for Azure Cosmos DB Is Set To &apos;On&apos;
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.07 - Defender Plan - Databases &gt; 03.01.07.02 - Ensure That Microsoft Defender for Open-Source Relational Databases Is Set To &apos;On&apos;
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.07 - Defender Plan - Databases &gt; 03.01.07.03 - Ensure That Microsoft Defender for (Managed Instance) Azure SQL Databases Is Set To &apos;On&apos;
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.07 - Defender Plan - Databases &gt; 03.01.07.04 - Ensure That Microsoft Defender for SQL Servers on Machines Is Set To &apos;On&apos;
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.08 - Defender Plan - Key Vault
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.08 - Defender Plan - Key Vault &gt; 03.01.08.01 - Ensure That Microsoft Defender for Key Vault Is Set To &apos;On&apos;
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.09 - Defender Plan - Resource Manager
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.09 - Defender Plan - Resource Manager &gt; 03.01.09.01 - Ensure That Microsoft Defender for Resource Manager Is Set To &apos;On&apos;
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.10 - Ensure that Microsoft Defender Recommendation for &apos;Apply system updates&apos; status is &apos;Completed&apos;
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.11 - Ensure that Microsoft Cloud Security Benchmark policies are not set to &apos;Disabled&apos;
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.12 - Ensure That &apos;All users with the following roles&apos; is set to &apos;Owner&apos;
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.13 - Ensure &apos;Additional email addresses&apos; is Configured with a Security Contact Email
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.14 - Ensure That &apos;Notify about alerts with the following severity&apos; is Set to &apos;High&apos;
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.15 - Ensure that Microsoft Defender External Attack Surface Monitoring (EASM) is enabled
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.16 - [LEGACY] Ensure That Microsoft Defender for DNS Is Set To &apos;On&apos;
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.02 - Microsoft Defender for IoT
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.02 - Microsoft Defender for IoT &gt; 03.02.01 - Ensure That Microsoft Defender for IoT Hub Is Set To &apos;On&apos;
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.03 - Key Vault
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.03 - Key Vault &gt; 03.03.01 - Ensure that the Expiration Date is set for all Keys in RBAC Key Vaults
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.03 - Key Vault &gt; 03.03.02 - Ensure that the Expiration Date is set for all Keys in Non-RBAC Key Vaults
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.03 - Key Vault &gt; 03.03.03 - Ensure that the Expiration Date is set for all Secrets in RBAC Key Vaults
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.03 - Key Vault &gt; 03.03.04 - Ensure that the Expiration Date is set for all Secrets in Non-RBAC Key Vaults
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.03 - Key Vault &gt; 03.03.05 - Ensure the Key Vault is Recoverable
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.03 - Key Vault &gt; 03.03.06 - Enable Role Based Access Control for Azure Key Vault
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.03 - Key Vault &gt; 03.03.07 - Ensure that Private Endpoints are Used for Azure Key Vault
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.03 - Key Vault &gt; 03.03.08 - Ensure Automatic Key Rotation is Enabled Within Azure Key Vault for the Supported Services
- Azure &gt; CIS v3.0 &gt; 04 - Storage Accounts
- Azure &gt; CIS v3.0 &gt; 04 - Storage Accounts &gt; 04.01 - Ensure that &apos;Secure transfer required&apos; is set to &apos;Enabled&apos;
- Azure &gt; CIS v3.0 &gt; 04 - Storage Accounts &gt; 04.02 - Ensure that `Enable Infrastructure Encryption` for Each Storage Account in Azure Storage is Set to `enabled`
- Azure &gt; CIS v3.0 &gt; 04 - Storage Accounts &gt; 04.03 - Ensure that &apos;Enable key rotation reminders&apos; is enabled for each Storage Account
- Azure &gt; CIS v3.0 &gt; 04 - Storage Accounts &gt; 04.04 - Ensure that Storage Account Access Keys are Periodically Regenerated
- Azure &gt; CIS v3.0 &gt; 04 - Storage Accounts &gt; 04.05 - Ensure that Shared Access Signature Tokens Expire Within an Hour
- Azure &gt; CIS v3.0 &gt; 04 - Storage Accounts &gt; 04.06 - Ensure that &apos;Public Network Access&apos; is &apos;Disabled&apos; for storage accounts
- Azure &gt; CIS v3.0 &gt; 04 - Storage Accounts &gt; 04.07 - Ensure Default Network Access Rule for Storage Accounts is Set to Deny
- Azure &gt; CIS v3.0 &gt; 04 - Storage Accounts &gt; 04.08 - Ensure &apos;Allow Azure services on the trusted services list to access this storage account&apos; is Enabled for Storage Account Access
- Azure &gt; CIS v3.0 &gt; 04 - Storage Accounts &gt; 04.09 - Ensure Private Endpoints are used to access Storage Accounts
- Azure &gt; CIS v3.0 &gt; 04 - Storage Accounts &gt; 04.10 - Ensure Soft Delete is Enabled for Azure Containers and Blob Storage
- Azure &gt; CIS v3.0 &gt; 04 - Storage Accounts &gt; 04.11 - Ensure Storage for Critical Data are Encrypted with Customer Managed Keys (CMK)
- Azure &gt; CIS v3.0 &gt; 04 - Storage Accounts &gt; 04.12 - Ensure Storage Logging is Enabled for Queue Service for &apos;Read&apos;, &apos;Write&apos;, and &apos;Delete&apos; requests
- Azure &gt; CIS v3.0 &gt; 04 - Storage Accounts &gt; 04.13 - Ensure Storage logging is Enabled for Blob Service for &apos;Read&apos;, &apos;Write&apos;, and &apos;Delete&apos; requests
- Azure &gt; CIS v3.0 &gt; 04 - Storage Accounts &gt; 04.14 - Ensure Storage Logging is Enabled for Table Service for &apos;Read&apos;, &apos;Write&apos;, and &apos;Delete&apos; Requests
- Azure &gt; CIS v3.0 &gt; 04 - Storage Accounts &gt; 04.15 - Ensure the &apos;Minimum TLS version&apos; for storage accounts is set to &apos;Version 1.2&apos;
- Azure &gt; CIS v3.0 &gt; 04 - Storage Accounts &gt; 04.16 - Ensure &apos;Cross Tenant Replication&apos; is not enabled
- Azure &gt; CIS v3.0 &gt; 04 - Storage Accounts &gt; 04.17 - Ensure that &apos;Allow Blob Anonymous Access&apos; is set to &apos;Disabled&apos;
- Azure &gt; CIS v3.0 &gt; 05 - Database Services
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.01 - Azure SQL Database
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.01 - Azure SQL Database &gt; 05.01.01 - Ensure that &apos;Auditing&apos; is set to &apos;On&apos;
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.01 - Azure SQL Database &gt; 05.01.02 - Ensure no Azure SQL Databases allow ingress from 0.0.0.0/0 (ANY IP)
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.01 - Azure SQL Database &gt; 05.01.03 - Ensure SQL Server&apos;s Transparent Data Encryption (TDE) protector is encrypted with Customer-managed key
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.01 - Azure SQL Database &gt; 05.01.04 - Ensure that Microsoft Entra authentication is Configured for SQL Servers
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.01 - Azure SQL Database &gt; 05.01.05 - Ensure that &apos;Data encryption&apos; is set to &apos;On&apos; on a SQL Database
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.01 - Azure SQL Database &gt; 05.01.06 - Ensure that &apos;Auditing&apos; Retention is &apos;greater than 90 days&apos;
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.01 - Azure SQL Database &gt; 05.01.07 - Ensure Public Network Access is Disabled
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.02 - Azure Database for PostgreSQL
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.02 - Azure Database for PostgreSQL &gt; 05.02.01 - Ensure server parameter &apos;require_secure_transport&apos; is set to &apos;ON&apos; for PostgreSQL flexible server
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.02 - Azure Database for PostgreSQL &gt; 05.02.02 - Ensure server parameter &apos;log_checkpoints&apos; is set to &apos;ON&apos; for PostgreSQL flexible server
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.02 - Azure Database for PostgreSQL &gt; 05.02.03 - Ensure server parameter &apos;connection_throttle.enable&apos; is set to &apos;ON&apos; for PostgreSQL flexible server
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.02 - Azure Database for PostgreSQL &gt; 05.02.04 - Ensure server parameter &apos;logfiles.retention_days&apos; is greater than 3 days for PostgreSQL flexible server
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.02 - Azure Database for PostgreSQL &gt; 05.02.05 - Ensure &apos;Allow public access from any Azure service within Azure to this server&apos; for PostgreSQL flexible server is disabled
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.02 - Azure Database for PostgreSQL &gt; 05.02.06 - [LEGACY] Ensure server parameter &apos;log_connections&apos; is set to &apos;ON&apos; for PostgreSQL single server
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.02 - Azure Database for PostgreSQL &gt; 05.02.07 - [LEGACY] Ensure server parameter &apos;log_disconnections&apos; is set to &apos;ON&apos; for PostgreSQL single server
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.02 - Azure Database for PostgreSQL &gt; 05.02.08 - [LEGACY] Ensure &apos;Infrastructure double encryption&apos; for PostgreSQL single server is &apos;Enabled&apos;
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.03 - Azure Database for MySQL
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.03 - Azure Database for MySQL &gt; 05.03.01 - Ensure server parameter &apos;require_secure_transport&apos; is set to &apos;ON&apos; for MySQL flexible server
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.03 - Azure Database for MySQL &gt; 05.03.02 - Ensure server parameter &apos;tls_version&apos; is set to &apos;TLSv1.2&apos; (or higher) for MySQL flexible server
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.03 - Azure Database for MySQL &gt; 05.03.03 - Ensure server parameter &apos;audit_log_enabled&apos; is set to &apos;ON&apos; for MySQL flexible server
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.03 - Azure Database for MySQL &gt; 05.03.04 - Ensure server parameter &apos;audit_log_events&apos; has &apos;CONNECTION&apos; set for MySQL flexible server
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.04 - Azure Cosmos DB
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.04 - Azure Cosmos DB &gt; 05.04.01 - Ensure That &apos;Firewalls &amp; Networks&apos; Is Limited to Use Selected Networks Instead of All Networks
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.04 - Azure Cosmos DB &gt; 05.04.02 - Ensure That Private Endpoints Are Used Where Possible
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.04 - Azure Cosmos DB &gt; 05.04.03 - Use Entra ID Client Authentication and Azure RBAC where possible
- Azure &gt; CIS v3.0 &gt; 06 - Logging &amp; Monitoring
- Azure &gt; CIS v3.0 &gt; 06 - Logging &amp; Monitoring &gt; 06.01 - Configuring Diagnostic Settings
- Azure &gt; CIS v3.0 &gt; 06 - Logging &amp; Monitoring &gt; 06.01 - Configuring Diagnostic Settings &gt; 06.01.01 - Ensure that a &apos;Diagnostic Setting&apos; exists for Subscription Activity Logs
- Azure &gt; CIS v3.0 &gt; 06 - Logging &amp; Monitoring &gt; 06.01 - Configuring Diagnostic Settings &gt; 06.01.02 - Ensure Diagnostic Setting captures appropriate categories
- Azure &gt; CIS v3.0 &gt; 06 - Logging &amp; Monitoring &gt; 06.01 - Configuring Diagnostic Settings &gt; 06.01.03 - Ensure the storage account containing the container with activity logs is encrypted with Customer Managed Key (CMK)
- Azure &gt; CIS v3.0 &gt; 06 - Logging &amp; Monitoring &gt; 06.01 - Configuring Diagnostic Settings &gt; 06.01.04 - Ensure that logging for Azure Key Vault is &apos;Enabled&apos;
- Azure &gt; CIS v3.0 &gt; 06 - Logging &amp; Monitoring &gt; 06.01 - Configuring Diagnostic Settings &gt; 06.01.05 - Ensure that Network Security Group Flow logs are captured and sent to Log Analytics
- Azure &gt; CIS v3.0 &gt; 06 - Logging &amp; Monitoring &gt; 06.01 - Configuring Diagnostic Settings &gt; 06.01.06 - Ensure that logging for Azure AppService &apos;HTTP logs&apos; is enabled
- Azure &gt; CIS v3.0 &gt; 06 - Logging &amp; Monitoring &gt; 06.02 - Monitoring using Activity Log Alerts
- Azure &gt; CIS v3.0 &gt; 06 - Logging &amp; Monitoring &gt; 06.02 - Monitoring using Activity Log Alerts &gt; 06.02.01 - Ensure that Activity Log Alert exists for Create Policy Assignment
- Azure &gt; CIS v3.0 &gt; 06 - Logging &amp; Monitoring &gt; 06.02 - Monitoring using Activity Log Alerts &gt; 06.02.02 - Ensure that Activity Log Alert exists for Delete Policy Assignment
- Azure &gt; CIS v3.0 &gt; 06 - Logging &amp; Monitoring &gt; 06.02 - Monitoring using Activity Log Alerts &gt; 06.02.03 - Ensure that Activity Log Alert exists for Create or Update Network Security Group
- Azure &gt; CIS v3.0 &gt; 06 - Logging &amp; Monitoring &gt; 06.02 - Monitoring using Activity Log Alerts &gt; 06.02.04 - Ensure that Activity Log Alert exists for Delete Network Security Group
- Azure &gt; CIS v3.0 &gt; 06 - Logging &amp; Monitoring &gt; 06.02 - Monitoring using Activity Log Alerts &gt; 06.02.05 - Ensure that Activity Log Alert exists for Create or Update Security Solution
- Azure &gt; CIS v3.0 &gt; 06 - Logging &amp; Monitoring &gt; 06.02 - Monitoring using Activity Log Alerts &gt; 06.02.06 - Ensure that Activity Log Alert exists for Delete Security Solution
- Azure &gt; CIS v3.0 &gt; 06 - Logging &amp; Monitoring &gt; 06.02 - Monitoring using Activity Log Alerts &gt; 06.02.07 - Ensure that Activity Log Alert exists for Create or Update SQL Server Firewall Rule
- Azure &gt; CIS v3.0 &gt; 06 - Logging &amp; Monitoring &gt; 06.02 - Monitoring using Activity Log Alerts &gt; 06.02.08 - Ensure that Activity Log Alert exists for Delete SQL Server Firewall Rule
- Azure &gt; CIS v3.0 &gt; 06 - Logging &amp; Monitoring &gt; 06.02 - Monitoring using Activity Log Alerts &gt; 06.02.09 - Ensure that Activity Log Alert exists for Create or Update Public IP Address rule
- Azure &gt; CIS v3.0 &gt; 06 - Logging &amp; Monitoring &gt; 06.02 - Monitoring using Activity Log Alerts &gt; 06.02.10 - Ensure that Activity Log Alert exists for Delete Public IP Address rule
- Azure &gt; CIS v3.0 &gt; 06 - Logging &amp; Monitoring &gt; 06.03 - Configuring Application Insights
- Azure &gt; CIS v3.0 &gt; 06 - Logging &amp; Monitoring &gt; 06.03 - Configuring Application Insights &gt; 06.03.01 - Ensure Application Insights are Configured
- Azure &gt; CIS v3.0 &gt; 06 - Logging &amp; Monitoring &gt; 06.04 - Ensure that Azure Monitor Resource Logging is Enabled for All Services that Support it
- Azure &gt; CIS v3.0 &gt; 06 - Logging &amp; Monitoring &gt; 06.05 - Ensure that SKU Basic/Consumption is not used on artifacts that need to be monitored (Particularly for Production Workloads)
- Azure &gt; CIS v3.0 &gt; 07 - Networking
- Azure &gt; CIS v3.0 &gt; 07 - Networking &gt; 07.01 - Ensure that RDP access from the Internet is evaluated and restricted
- Azure &gt; CIS v3.0 &gt; 07 - Networking &gt; 07.02 - Ensure that SSH access from the Internet is evaluated and restricted
- Azure &gt; CIS v3.0 &gt; 07 - Networking &gt; 07.03 - Ensure that UDP access from the Internet is evaluated and restricted
- Azure &gt; CIS v3.0 &gt; 07 - Networking &gt; 07.04 - Ensure that HTTP(S) access from the Internet is evaluated and restricted
- Azure &gt; CIS v3.0 &gt; 07 - Networking &gt; 07.05 - Ensure that Network Security Group Flow Log retention period is &apos;greater than 90 days&apos;
- Azure &gt; CIS v3.0 &gt; 07 - Networking &gt; 07.06 - Ensure that Network Watcher is &apos;Enabled&apos; for Azure Regions that are in use
- Azure &gt; CIS v3.0 &gt; 07 - Networking &gt; 07.07 - Ensure that Public IP addresses are evaluated on a periodic basis
- Azure &gt; CIS v3.0 &gt; 08 - Virtual Machines
- Azure &gt; CIS v3.0 &gt; 08 - Virtual Machines &gt; 08.01 - Ensure an Azure Bastion Host Exists
- Azure &gt; CIS v3.0 &gt; 08 - Virtual Machines &gt; 08.02 - Ensure Virtual Machines are utilizing Managed Disks
- Azure &gt; CIS v3.0 &gt; 08 - Virtual Machines &gt; 08.03 - Ensure that &apos;OS and Data&apos; disks are encrypted with Customer Managed Key (CMK)
- Azure &gt; CIS v3.0 &gt; 08 - Virtual Machines &gt; 08.04 - Ensure that &apos;Unattached disks&apos; are encrypted with &apos;Customer Managed Key&apos; (CMK)
- Azure &gt; CIS v3.0 &gt; 08 - Virtual Machines &gt; 08.05 - Ensure that &apos;Disk Network Access&apos; is NOT set to &apos;Enable public access from all networks&apos;
- Azure &gt; CIS v3.0 &gt; 08 - Virtual Machines &gt; 08.06 - Ensure that &apos;Enable Data Access Authentication Mode&apos; is &apos;Checked&apos;
- Azure &gt; CIS v3.0 &gt; 08 - Virtual Machines &gt; 08.07 - Ensure that Only Approved Extensions Are Installed
- Azure &gt; CIS v3.0 &gt; 08 - Virtual Machines &gt; 08.08 - Ensure that Endpoint Protection for all Virtual Machines is installed
- Azure &gt; CIS v3.0 &gt; 08 - Virtual Machines &gt; 08.09 - [Legacy] Ensure that VHDs are Encrypted
- Azure &gt; CIS v3.0 &gt; 08 - Virtual Machines &gt; 08.10 - Ensure only MFA enabled identities can access privileged Virtual Machine
- Azure &gt; CIS v3.0 &gt; 08 - Virtual Machines &gt; 08.11 - Ensure Trusted Launch is enabled on Virtual Machines
- Azure &gt; CIS v3.0 &gt; 09 - Application Services
- Azure &gt; CIS v3.0 &gt; 09 - Application Services &gt; 09.01 - Ensure &apos;HTTPS Only&apos; is set to `On`
- Azure &gt; CIS v3.0 &gt; 09 - Application Services &gt; 09.02 - Ensure App Service Authentication is set up for apps in Azure App Service
- Azure &gt; CIS v3.0 &gt; 09 - Application Services &gt; 09.03 - Ensure &apos;FTP State&apos; is set to &apos;FTPS Only&apos; or &apos;Disabled&apos;
- Azure &gt; CIS v3.0 &gt; 09 - Application Services &gt; 09.04 - Ensure Web App is using the latest version of TLS encryption
- Azure &gt; CIS v3.0 &gt; 09 - Application Services &gt; 09.05 - Ensure that Register with Entra ID is enabled on App Service
- Azure &gt; CIS v3.0 &gt; 09 - Application Services &gt; 09.06 - Ensure that &apos;Basic Authentication&apos; is &apos;Disabled&apos;
- Azure &gt; CIS v3.0 &gt; 09 - Application Services &gt; 09.07 - Ensure that &apos;PHP version&apos; is currently supported (if in use)
- Azure &gt; CIS v3.0 &gt; 09 - Application Services &gt; 09.08 - Ensure that &apos;Python version&apos; is currently supported (if in use)
- Azure &gt; CIS v3.0 &gt; 09 - Application Services &gt; 09.09 - Ensure that &apos;Java version&apos; is currently supported (if in use)
- Azure &gt; CIS v3.0 &gt; 09 - Application Services &gt; 09.10 - Ensure that &apos;HTTP20enabled&apos; is set to &apos;true&apos; (if in use)
- Azure &gt; CIS v3.0 &gt; 09 - Application Services &gt; 09.11 - Ensure Azure Key Vaults are Used to Store Secrets
- Azure &gt; CIS v3.0 &gt; 09 - Application Services &gt; 09.12 - Ensure that &apos;Remote debugging&apos; is set to &apos;Off&apos;
- Azure &gt; CIS v3.0 &gt; 10 - Miscellaneous
- Azure &gt; CIS v3.0 &gt; 10 - Miscellaneous &gt; 10.01 - Ensure that Resource Locks are set for Mission-Critical Azure Resources

_Policy Types_

- Azure &gt; CIS v3.0
- Azure &gt; CIS v3.0 &gt; 02 - Identity
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.01 - Security Defaults (Per-User MFA)
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.01 - Security Defaults (Per-User MFA) &gt; 02.01.01 - Ensure Security Defaults is enabled on Microsoft Entra ID
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.01 - Security Defaults (Per-User MFA) &gt; 02.01.01 - Ensure Security Defaults is enabled on Microsoft Entra ID &gt; Attestation
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.01 - Security Defaults (Per-User MFA) &gt; 02.01.02 - Ensure that &apos;Multi-Factor Auth Status&apos; is &apos;Enabled&apos; for all Privileged Users
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.01 - Security Defaults (Per-User MFA) &gt; 02.01.02 - Ensure that &apos;Multi-Factor Auth Status&apos; is &apos;Enabled&apos; for all Privileged Users &gt; Attestation
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.01 - Security Defaults (Per-User MFA) &gt; 02.01.03 - Ensure that &apos;Multi-Factor Auth Status&apos; is &apos;Enabled&apos; for all Non-Privileged Users
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.01 - Security Defaults (Per-User MFA) &gt; 02.01.03 - Ensure that &apos;Multi-Factor Auth Status&apos; is &apos;Enabled&apos; for all Non-Privileged Users &gt; Attestation
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.01 - Security Defaults (Per-User MFA) &gt; 02.01.04 - Ensure that &apos;Allow users to remember multi-factor authentication on devices they trust&apos; is Disabled
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.01 - Security Defaults (Per-User MFA) &gt; 02.01.04 - Ensure that &apos;Allow users to remember multi-factor authentication on devices they trust&apos; is Disabled &gt; Attestation
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.02 - Conditional Access
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.02 - Conditional Access &gt; 02.02.01 - Ensure Trusted Locations Are Defined
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.02 - Conditional Access &gt; 02.02.02 - Ensure that an exclusionary Geographic Access Policy is considered
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.02 - Conditional Access &gt; 02.02.02 - Ensure that an exclusionary Geographic Access Policy is considered &gt; Attestation
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.02 - Conditional Access &gt; 02.02.03 - Ensure that an exclusionary Device code flow policy is considered
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.02 - Conditional Access &gt; 02.02.03 - Ensure that an exclusionary Device code flow policy is considered &gt; Attestation
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.02 - Conditional Access &gt; 02.02.04 - Ensure that A Multi-factor Authentication Policy Exists for Administrative Groups
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.02 - Conditional Access &gt; 02.02.04 - Ensure that A Multi-factor Authentication Policy Exists for Administrative Groups &gt; Attestation
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.02 - Conditional Access &gt; 02.02.05 - Ensure that A Multi-factor Authentication Policy Exists for All Users
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.02 - Conditional Access &gt; 02.02.05 - Ensure that A Multi-factor Authentication Policy Exists for All Users &gt; Attestation
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.02 - Conditional Access &gt; 02.02.06 - Ensure Multi-factor Authentication is Required for Risky Sign-ins
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.02 - Conditional Access &gt; 02.02.06 - Ensure Multi-factor Authentication is Required for Risky Sign-ins &gt; Attestation
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.02 - Conditional Access &gt; 02.02.07 - Ensure Multi-factor Authentication is Required for Windows Azure Service Management API
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.02 - Conditional Access &gt; 02.02.08 - Ensure Multi-factor Authentication is Required to access Microsoft Admin Portals
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.03 - Ensure that &apos;Restrict non-admin users from creating tenants&apos; is set to &apos;Yes&apos;
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.03 - Ensure that &apos;Restrict non-admin users from creating tenants&apos; is set to &apos;Yes&apos; &gt; Attestation
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.04 - Ensure Guest Users Are Reviewed on a Regular Basis
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.05 - Ensure That &apos;Number of methods required to reset&apos; is set to &apos;2&apos;
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.05 - Ensure That &apos;Number of methods required to reset&apos; is set to &apos;2&apos; &gt; Attestation
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.06 - Ensure that account &apos;Lockout Threshold&apos; is less than or equal to &apos;10&apos;
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.06 - Ensure that account &apos;Lockout Threshold&apos; is less than or equal to &apos;10&apos; &gt; Attestation
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.07 - Ensure that account &apos;Lockout duration in seconds&apos; is greater than or equal to &apos;60&apos;
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.07 - Ensure that account &apos;Lockout duration in seconds&apos; is greater than or equal to &apos;60&apos; &gt; Attestation
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.08 - Ensure that a Custom Bad Password List is set to &apos;Enforce&apos; for your Organization
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.08 - Ensure that a Custom Bad Password List is set to &apos;Enforce&apos; for your Organization &gt; Attestation
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.09 - Ensure that &apos;Number of days before users are asked to re-confirm their authentication information&apos; is not set to &apos;0&apos;
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.09 - Ensure that &apos;Number of days before users are asked to re-confirm their authentication information&apos; is not set to &apos;0&apos; &gt; Attestation
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.10 - Ensure that &apos;Notify users on password resets?&apos; is set to &apos;Yes&apos;
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.10 - Ensure that &apos;Notify users on password resets?&apos; is set to &apos;Yes&apos; &gt; Attestation
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.11 - Ensure That &apos;Notify all admins when other admins reset their password?&apos; is set to &apos;Yes&apos;
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.11 - Ensure That &apos;Notify all admins when other admins reset their password?&apos; is set to &apos;Yes&apos; &gt; Attestation
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.12 - Ensure `User consent for applications` is set to `Do not allow user consent`
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.12 - Ensure `User consent for applications` is set to `Do not allow user consent` &gt; Attestation
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.13 - Ensure &apos;User consent for applications&apos; Is Set To &apos;Allow for Verified Publishers&apos;
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.13 - Ensure &apos;User consent for applications&apos; Is Set To &apos;Allow for Verified Publishers&apos; &gt; Attestation
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.14 - Ensure That &apos;Users Can Register Applications&apos; Is Set to &apos;No&apos;
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.15 - Ensure That &apos;Guest users access restrictions&apos; is set to &apos;Guest user access is restricted to properties and memberships of their own directory objects&apos;
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.15 - Ensure That &apos;Guest users access restrictions&apos; is set to &apos;Guest user access is restricted to properties and memberships of their own directory objects&apos; &gt; Attestation
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.16 - Ensure that &apos;Guest invite restrictions&apos; is set to &apos;Only users assigned to specific admin roles can invite guest users&apos;
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.16 - Ensure that &apos;Guest invite restrictions&apos; is set to &apos;Only users assigned to specific admin roles can invite guest users&apos; &gt; Attestation
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.17 - Ensure That &apos;Restrict access to Microsoft Entra admin center&apos; is Set to &apos;Yes&apos;
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.17 - Ensure That &apos;Restrict access to Microsoft Entra admin center&apos; is Set to &apos;Yes&apos; &gt; Attestation
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.18 - Ensure that &apos;Restrict user ability to access groups features in the Access Pane&apos; is Set to &apos;Yes&apos;
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.18 - Ensure that &apos;Restrict user ability to access groups features in the Access Pane&apos; is Set to &apos;Yes&apos; &gt; Attestation
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.19 - Ensure that &apos;Users can create security groups in Azure portals, API or PowerShell&apos; is set to &apos;No&apos;
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.20 - Ensure that &apos;Owners can manage group membership requests in My Groups&apos; is set to &apos;No&apos;
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.20 - Ensure that &apos;Owners can manage group membership requests in My Groups&apos; is set to &apos;No&apos; &gt; Attestation
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.21 - Ensure that &apos;Users can create Microsoft 365 groups in Azure portals, API or PowerShell&apos; is set to &apos;No&apos;
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.21 - Ensure that &apos;Users can create Microsoft 365 groups in Azure portals, API or PowerShell&apos; is set to &apos;No&apos; &gt; Attestation
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.22 - Ensure that &apos;Require Multifactor Authentication to register or join devices with Microsoft Entra&apos; is set to &apos;Yes&apos;
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.22 - Ensure that &apos;Require Multifactor Authentication to register or join devices with Microsoft Entra&apos; is set to &apos;Yes&apos; &gt; Attestation
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.23 - Ensure That No Custom Subscription Administrator Roles Exist
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.24 - Ensure a Custom Role is Assigned Permissions for Administering Resource Locks
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.24 - Ensure a Custom Role is Assigned Permissions for Administering Resource Locks &gt; Attestation
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.25 - Ensure That &apos;Subscription leaving Microsoft Entra tenant&apos; and &apos;Subscription entering Microsoft Entra tenant&apos; Is Set To &apos;Permit no one&apos;
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.25 - Ensure That &apos;Subscription leaving Microsoft Entra tenant&apos; and &apos;Subscription entering Microsoft Entra tenant&apos; Is Set To &apos;Permit no one&apos; &gt; Attestation
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; 02.26 - Ensure fewer than 5 users have global administrator assignment
- Azure &gt; CIS v3.0 &gt; 02 - Identity &gt; Maximum Attestation Duration
- Azure &gt; CIS v3.0 &gt; 03 - Security
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.01 - Microsoft Cloud Security Posture Management (CSPM)
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.01 - Microsoft Cloud Security Posture Management (CSPM) &gt; 03.01.01.01 - Ensure that Auto provisioning of &apos;Log Analytics agent for Azure VMs&apos; is Set to &apos;On&apos;
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.01 - Microsoft Cloud Security Posture Management (CSPM) &gt; 03.01.01.02 - Ensure that Microsoft Defender for Cloud Apps integration with Microsoft Defender for Cloud is Selected
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.02 - Defender Plan APIs
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.03 - Defender Plan Servers
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.03 - Defender Plan Servers &gt; 03.01.03.01 - Ensure That Microsoft Defender for Servers Is Set to &apos;On&apos;
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.03 - Defender Plan Servers &gt; 03.01.03.02 - Ensure that &apos;Vulnerability assessment for machines&apos; component status is set to &apos;On&apos;
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.03 - Defender Plan Servers &gt; 03.01.03.02 - Ensure that &apos;Vulnerability assessment for machines&apos; component status is set to &apos;On&apos; &gt; Attestation
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.03 - Defender Plan Servers &gt; 03.01.03.03 - Ensure that &apos;Endpoint protection&apos; component status is set to &apos;On&apos;
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.03 - Defender Plan Servers &gt; 03.01.03.04 - Ensure that &apos;Agentless scanning for machines&apos; component status is set to &apos;On&apos;
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.03 - Defender Plan Servers &gt; 03.01.03.04 - Ensure that &apos;Agentless scanning for machines&apos; component status is set to &apos;On&apos; &gt; Attestation
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.03 - Defender Plan Servers &gt; 03.01.03.05 - Ensure that &apos;File Integrity Monitoring&apos; component status is set to &apos;On&apos;
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.03 - Defender Plan Servers &gt; 03.01.03.05 - Ensure that &apos;File Integrity Monitoring&apos; component status is set to &apos;On&apos; &gt; Attestation
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.04 - Defender Plan Containers
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.04 - Defender Plan Containers &gt; 03.01.04.01 - Ensure That Microsoft Defender for Containers Is Set To &apos;On&apos;
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.04 - Defender Plan Containers &gt; 03.01.04.02 - Ensure that &apos;Agentless discovery for Kubernetes&apos; component status &apos;On&apos;
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.04 - Defender Plan Containers &gt; 03.01.04.02 - Ensure that &apos;Agentless discovery for Kubernetes&apos; component status &apos;On&apos; &gt; Attestation
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.04 - Defender Plan Containers &gt; 03.01.04.03 - Ensure that &apos;Agentless container vulnerability assessment&apos; component status is &apos;On&apos;
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.04 - Defender Plan Containers &gt; 03.01.04.03 - Ensure that &apos;Agentless container vulnerability assessment&apos; component status is &apos;On&apos; &gt; Attestation
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.05 - Defender Plan - Storage
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.05 - Defender Plan - Storage &gt; 03.01.05.01 - Ensure That Microsoft Defender for Containers Is Set To &apos;On&apos;
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.06 - Defender Plan App - Service
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.06 - Defender Plan App - Service &gt; 03.01.06.01 - Ensure That Microsoft Defender for App Services Is Set To &apos;On&apos;
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.07 - Defender Plan - Databases
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.07 - Defender Plan - Databases &gt; 03.01.07.01 - Ensure That Microsoft Defender for Azure Cosmos DB Is Set To &apos;On&apos;
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.07 - Defender Plan - Databases &gt; 03.01.07.02 - Ensure That Microsoft Defender for Open-Source Relational Databases Is Set To &apos;On&apos;
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.07 - Defender Plan - Databases &gt; 03.01.07.03 - Ensure That Microsoft Defender for (Managed Instance) Azure SQL Databases Is Set To &apos;On&apos;
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.07 - Defender Plan - Databases &gt; 03.01.07.04 - Ensure That Microsoft Defender for SQL Servers on Machines Is Set To &apos;On&apos;
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.08 - Defender Plan - Key Vault
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.08 - Defender Plan - Key Vault &gt; 03.01.08.01 - Ensure That Microsoft Defender for Key Vault Is Set To &apos;On&apos;
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.09 - Defender Plan - Resource Manager
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.09 - Defender Plan - Resource Manager &gt; 03.01.09.01 - Ensure That Microsoft Defender for Resource Manager Is Set To &apos;On&apos;
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.10 - Ensure that Microsoft Defender Recommendation for &apos;Apply system updates&apos; status is &apos;Completed&apos;
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.10 - Ensure that Microsoft Defender Recommendation for &apos;Apply system updates&apos; status is &apos;Completed&apos; &gt; Attestation
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.11 - Ensure that Microsoft Cloud Security Benchmark policies are not set to &apos;Disabled&apos;
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.11 - Ensure that Microsoft Cloud Security Benchmark policies are not set to &apos;Disabled&apos; &gt; Attestation
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.12 - Ensure That &apos;All users with the following roles&apos; is set to &apos;Owner&apos;
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.13 - Ensure &apos;Additional email addresses&apos; is Configured with a Security Contact Email
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.14 - Ensure That &apos;Notify about alerts with the following severity&apos; is Set to &apos;High&apos;
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.15 - Ensure that Microsoft Defender External Attack Surface Monitoring (EASM) is enabled
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.15 - Ensure that Microsoft Defender External Attack Surface Monitoring (EASM) is enabled &gt; Attestation
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.01 - Microsoft Defender for Cloud &gt; 03.01.16 - [LEGACY] Ensure That Microsoft Defender for DNS Is Set To &apos;On&apos;
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.02 - Microsoft Defender for IoT
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.02 - Microsoft Defender for IoT &gt; 03.02.01 - Ensure That Microsoft Defender for IoT Hub Is Set To &apos;On&apos;
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.02 - Microsoft Defender for IoT &gt; Attestation
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.03 - Key Vault
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.03 - Key Vault &gt; 03.03.01 - Ensure that the Expiration Date is set for all Keys in RBAC Key Vaults
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.03 - Key Vault &gt; 03.03.02 - Ensure that the Expiration Date is set for all Keys in Non-RBAC Key Vaults
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.03 - Key Vault &gt; 03.03.03 - Ensure that the Expiration Date is set for all Secrets in RBAC Key Vaults
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.03 - Key Vault &gt; 03.03.04 - Ensure that the Expiration Date is set for all Secrets in Non-RBAC Key Vaults
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.03 - Key Vault &gt; 03.03.05 - Ensure the Key Vault is Recoverable
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.03 - Key Vault &gt; 03.03.06 - Enable Role Based Access Control for Azure Key Vault
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.03 - Key Vault &gt; 03.03.07 - Ensure that Private Endpoints are Used for Azure Key Vault
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.03 - Key Vault &gt; 03.03.08 - Ensure Automatic Key Rotation is Enabled Within Azure Key Vault for the Supported Services
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; 03.03 - Key Vault &gt; 03.03.08 - Ensure Automatic Key Rotation is Enabled Within Azure Key Vault for the Supported Services &gt; Attestation
- Azure &gt; CIS v3.0 &gt; 03 - Security &gt; Maximum Attestation Duration
- Azure &gt; CIS v3.0 &gt; 04 - Storage Accounts
- Azure &gt; CIS v3.0 &gt; 04 - Storage Accounts &gt; 04.01 - Ensure that &apos;Secure transfer required&apos; is set to &apos;Enabled&apos;
- Azure &gt; CIS v3.0 &gt; 04 - Storage Accounts &gt; 04.02 - Ensure that `Enable Infrastructure Encryption` for Each Storage Account in Azure Storage is Set to `enabled`
- Azure &gt; CIS v3.0 &gt; 04 - Storage Accounts &gt; 04.03 - Ensure that &apos;Enable key rotation reminders&apos; is enabled for each Storage Account
- Azure &gt; CIS v3.0 &gt; 04 - Storage Accounts &gt; 04.04 - Ensure that Storage Account Access Keys are Periodically Regenerated
- Azure &gt; CIS v3.0 &gt; 04 - Storage Accounts &gt; 04.04 - Ensure that Storage Account Access Keys are Periodically Regenerated &gt; Attestation
- Azure &gt; CIS v3.0 &gt; 04 - Storage Accounts &gt; 04.05 - Ensure that Shared Access Signature Tokens Expire Within an Hour
- Azure &gt; CIS v3.0 &gt; 04 - Storage Accounts &gt; 04.05 - Ensure that Shared Access Signature Tokens Expire Within an Hour &gt; Attestation
- Azure &gt; CIS v3.0 &gt; 04 - Storage Accounts &gt; 04.06 - Ensure that &apos;Public Network Access&apos; is &apos;Disabled&apos; for storage accounts
- Azure &gt; CIS v3.0 &gt; 04 - Storage Accounts &gt; 04.07 - Ensure Default Network Access Rule for Storage Accounts is Set to Deny
- Azure &gt; CIS v3.0 &gt; 04 - Storage Accounts &gt; 04.08 - Ensure &apos;Allow Azure services on the trusted services list to access this storage account&apos; is Enabled for Storage Account Access
- Azure &gt; CIS v3.0 &gt; 04 - Storage Accounts &gt; 04.09 - Ensure Private Endpoints are used to access Storage Accounts
- Azure &gt; CIS v3.0 &gt; 04 - Storage Accounts &gt; 04.10 - Ensure Soft Delete is Enabled for Azure Containers and Blob Storage
- Azure &gt; CIS v3.0 &gt; 04 - Storage Accounts &gt; 04.11 - Ensure Storage for Critical Data are Encrypted with Customer Managed Keys (CMK)
- Azure &gt; CIS v3.0 &gt; 04 - Storage Accounts &gt; 04.12 - Ensure Storage Logging is Enabled for Queue Service for &apos;Read&apos;, &apos;Write&apos;, and &apos;Delete&apos; requests
- Azure &gt; CIS v3.0 &gt; 04 - Storage Accounts &gt; 04.13 - Ensure Storage logging is Enabled for Blob Service for &apos;Read&apos;, &apos;Write&apos;, and &apos;Delete&apos; requests
- Azure &gt; CIS v3.0 &gt; 04 - Storage Accounts &gt; 04.14 - Ensure Storage Logging is Enabled for Table Service for &apos;Read&apos;, &apos;Write&apos;, and &apos;Delete&apos; Requests
- Azure &gt; CIS v3.0 &gt; 04 - Storage Accounts &gt; 04.15 - Ensure the &apos;Minimum TLS version&apos; for storage accounts is set to &apos;Version 1.2&apos;
- Azure &gt; CIS v3.0 &gt; 04 - Storage Accounts &gt; 04.16 - Ensure &apos;Cross Tenant Replication&apos; is not enabled
- Azure &gt; CIS v3.0 &gt; 04 - Storage Accounts &gt; 04.17 - Ensure that &apos;Allow Blob Anonymous Access&apos; is set to &apos;Disabled&apos;
- Azure &gt; CIS v3.0 &gt; 04 - Storage Accounts &gt; Maximum Attestation Duration
- Azure &gt; CIS v3.0 &gt; 05 - Database Services
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.01 - Azure SQL Database
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.01 - Azure SQL Database &gt; 05.01.01 - Ensure that &apos;Auditing&apos; is set to &apos;On&apos;
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.01 - Azure SQL Database &gt; 05.01.02 - Ensure no Azure SQL Databases allow ingress from 0.0.0.0/0 (ANY IP)
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.01 - Azure SQL Database &gt; 05.01.03 - Ensure SQL Server&apos;s Transparent Data Encryption (TDE) protector is encrypted with Customer-managed key
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.01 - Azure SQL Database &gt; 05.01.04 - Ensure that Microsoft Entra authentication is Configured for SQL Servers
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.01 - Azure SQL Database &gt; 05.01.05 - Ensure that &apos;Data encryption&apos; is set to &apos;On&apos; on a SQL Database
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.01 - Azure SQL Database &gt; 05.01.06 - Ensure that &apos;Auditing&apos; Retention is &apos;greater than 90 days&apos;
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.01 - Azure SQL Database &gt; 05.01.07 - Ensure Public Network Access is Disabled
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.02 - Azure Database for PostgreSQL
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.02 - Azure Database for PostgreSQL &gt; 05.02.01 - Ensure server parameter &apos;require_secure_transport&apos; is set to &apos;ON&apos; for PostgreSQL flexible server
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.02 - Azure Database for PostgreSQL &gt; 05.02.02 - Ensure server parameter &apos;log_checkpoints&apos; is set to &apos;ON&apos; for PostgreSQL flexible server
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.02 - Azure Database for PostgreSQL &gt; 05.02.03 - Ensure server parameter &apos;connection_throttle.enable&apos; is set to &apos;ON&apos; for PostgreSQL flexible server
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.02 - Azure Database for PostgreSQL &gt; 05.02.04 - Ensure server parameter &apos;logfiles.retention_days&apos; is greater than 3 days for PostgreSQL flexible server
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.02 - Azure Database for PostgreSQL &gt; 05.02.05 - Ensure &apos;Allow public access from any Azure service within Azure to this server&apos; for PostgreSQL flexible server is disabled
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.02 - Azure Database for PostgreSQL &gt; 05.02.07 - [LEGACY] Ensure server parameter &apos;log_disconnections&apos; is set to &apos;ON&apos; for PostgreSQL single server
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.02 - Azure Database for PostgreSQL &gt; 05.02.08 - [LEGACY] Ensure &apos;Infrastructure double encryption&apos; for PostgreSQL single server is &apos;Enabled&apos;
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.02 - Azure Database for PostgreSQL &gt; 5.2.6 - [LEGACY] Ensure server parameter &apos;log_connections&apos; is set to &apos;ON&apos; for PostgreSQL single server
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.03 - Azure Database for MySQL
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.03 - Azure Database for MySQL &gt; 05.03.01 - Ensure server parameter &apos;require_secure_transport&apos; is set to &apos;ON&apos; for MySQL flexible server
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.03 - Azure Database for MySQL &gt; 05.03.02 - Ensure server parameter &apos;tls_version&apos; is set to &apos;TLSv1.2&apos; (or higher) for MySQL flexible server
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.03 - Azure Database for MySQL &gt; 05.03.03 - Ensure server parameter &apos;audit_log_enabled&apos; is set to &apos;ON&apos; for MySQL flexible server
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.03 - Azure Database for MySQL &gt; 05.03.04 - Ensure server parameter &apos;audit_log_events&apos; has &apos;CONNECTION&apos; set for MySQL flexible server
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.04 - Azure Cosmos DB
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.04 - Azure Cosmos DB &gt; 05.04.01 - Ensure That &apos;Firewalls &amp; Networks&apos; Is Limited to Use Selected Networks Instead of All Networks
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.04 - Azure Cosmos DB &gt; 05.04.02 - Ensure That Private Endpoints Are Used Where Possible
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.04 - Azure Cosmos DB &gt; 05.04.03 - Use Entra ID Client Authentication and Azure RBAC where possible
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; 05.04 - Azure Cosmos DB &gt; 05.04.03 - Use Entra ID Client Authentication and Azure RBAC where possible &gt; Attestation
- Azure &gt; CIS v3.0 &gt; 05 - Database Services &gt; Maximum Attestation Duration
- Azure &gt; CIS v3.0 &gt; 06 - Logging &amp; Monitoring
- Azure &gt; CIS v3.0 &gt; 06 - Logging &amp; Monitoring &gt; 06.01 - Configuring Diagnostic Settings
- Azure &gt; CIS v3.0 &gt; 06 - Logging &amp; Monitoring &gt; 06.01 - Configuring Diagnostic Settings &gt; 06.01.01 - Ensure that a &apos;Diagnostic Setting&apos; exists for Subscription Activity Logs
- Azure &gt; CIS v3.0 &gt; 06 - Logging &amp; Monitoring &gt; 06.01 - Configuring Diagnostic Settings &gt; 06.01.01 - Ensure that a &apos;Diagnostic Setting&apos; exists for Subscription Activity Logs &gt; Attestation
- Azure &gt; CIS v3.0 &gt; 06 - Logging &amp; Monitoring &gt; 06.01 - Configuring Diagnostic Settings &gt; 06.01.02 - Ensure Diagnostic Setting captures appropriate categories
- Azure &gt; CIS v3.0 &gt; 06 - Logging &amp; Monitoring &gt; 06.01 - Configuring Diagnostic Settings &gt; 06.01.03 - Ensure the storage account containing the container with activity logs is encrypted with Customer Managed Key
- Azure &gt; CIS v3.0 &gt; 06 - Logging &amp; Monitoring &gt; 06.01 - Configuring Diagnostic Settings &gt; 06.01.04 - Ensure that logging for Azure Key Vault is &apos;Enabled&apos;
- Azure &gt; CIS v3.0 &gt; 06 - Logging &amp; Monitoring &gt; 06.01 - Configuring Diagnostic Settings &gt; 06.01.05 - Ensure that Network Security Group Flow logs are captured and sent to Log Analytics
- Azure &gt; CIS v3.0 &gt; 06 - Logging &amp; Monitoring &gt; 06.01 - Configuring Diagnostic Settings &gt; 06.01.06 - Ensure that logging for Azure AppService &apos;HTTP logs&apos; is enabled
- Azure &gt; CIS v3.0 &gt; 06 - Logging &amp; Monitoring &gt; 06.02 - Monitoring using Activity Log Alerts
- Azure &gt; CIS v3.0 &gt; 06 - Logging &amp; Monitoring &gt; 06.02 - Monitoring using Activity Log Alerts &gt; 06.02.01 - Ensure that Activity Log Alert exists for Create Policy Assignment
- Azure &gt; CIS v3.0 &gt; 06 - Logging &amp; Monitoring &gt; 06.02 - Monitoring using Activity Log Alerts &gt; 06.02.02 - Ensure that Activity Log Alert exists for Delete Policy Assignment
- Azure &gt; CIS v3.0 &gt; 06 - Logging &amp; Monitoring &gt; 06.02 - Monitoring using Activity Log Alerts &gt; 06.02.03 - Ensure that Activity Log Alert exists for Create or Update Network Security Group
- Azure &gt; CIS v3.0 &gt; 06 - Logging &amp; Monitoring &gt; 06.02 - Monitoring using Activity Log Alerts &gt; 06.02.04 - Ensure that Activity Log Alert exists for Delete Network Security Group
- Azure &gt; CIS v3.0 &gt; 06 - Logging &amp; Monitoring &gt; 06.02 - Monitoring using Activity Log Alerts &gt; 06.02.05 - Ensure that Activity Log Alert exists for Create or Update Security Solution
- Azure &gt; CIS v3.0 &gt; 06 - Logging &amp; Monitoring &gt; 06.02 - Monitoring using Activity Log Alerts &gt; 06.02.06 - Ensure that Activity Log Alert exists for Delete Security Solution
- Azure &gt; CIS v3.0 &gt; 06 - Logging &amp; Monitoring &gt; 06.02 - Monitoring using Activity Log Alerts &gt; 06.02.07 - Ensure that Activity Log Alert exists for Create or Update SQL Server Firewall Rule
- Azure &gt; CIS v3.0 &gt; 06 - Logging &amp; Monitoring &gt; 06.02 - Monitoring using Activity Log Alerts &gt; 06.02.08 - Ensure that Activity Log Alert exists for Delete SQL Server Firewall Rule
- Azure &gt; CIS v3.0 &gt; 06 - Logging &amp; Monitoring &gt; 06.02 - Monitoring using Activity Log Alerts &gt; 06.02.09 - Ensure that Activity Log Alert exists for Create or Update Public IP Address rule
- Azure &gt; CIS v3.0 &gt; 06 - Logging &amp; Monitoring &gt; 06.02 - Monitoring using Activity Log Alerts &gt; 06.02.10 - Ensure that Activity Log Alert exists for Delete Public IP Address rule
- Azure &gt; CIS v3.0 &gt; 06 - Logging &amp; Monitoring &gt; 06.03 - Configuring Application Insights
- Azure &gt; CIS v3.0 &gt; 06 - Logging &amp; Monitoring &gt; 06.03 - Configuring Application Insights &gt; 06.03.01 - Ensure Application Insights are Configured
- Azure &gt; CIS v3.0 &gt; 06 - Logging &amp; Monitoring &gt; 06.04 - Ensure that Azure Monitor Resource Logging is Enabled for All Services that Support it
- Azure &gt; CIS v3.0 &gt; 06 - Logging &amp; Monitoring &gt; 06.04 - Ensure that Azure Monitor Resource Logging is Enabled for All Services that Support it &gt; Attestation
- Azure &gt; CIS v3.0 &gt; 06 - Logging &amp; Monitoring &gt; 06.05 - Ensure that SKU Basic/Consumption is not used on artifacts that need to be monitored (Particularly for Production Workloads)
- Azure &gt; CIS v3.0 &gt; 06 - Logging &amp; Monitoring &gt; Maximum Attestation Duration
- Azure &gt; CIS v3.0 &gt; 07 - Networking
- Azure &gt; CIS v3.0 &gt; 07 - Networking &gt; 07.01 - Ensure that RDP access from the Internet is evaluated and restricted
- Azure &gt; CIS v3.0 &gt; 07 - Networking &gt; 07.02 - Ensure that SSH access from the Internet is evaluated and restricted
- Azure &gt; CIS v3.0 &gt; 07 - Networking &gt; 07.03 - Ensure that UDP access from the Internet is evaluated and restricted
- Azure &gt; CIS v3.0 &gt; 07 - Networking &gt; 07.04 - Ensure that HTTP(S) access from the Internet is evaluated and restricted
- Azure &gt; CIS v3.0 &gt; 07 - Networking &gt; 07.05 - Ensure that Network Security Group Flow Log retention period is &apos;greater than 90 days&apos;
- Azure &gt; CIS v3.0 &gt; 07 - Networking &gt; 07.06 - Ensure that Network Watcher is &apos;Enabled&apos; for Azure Regions that are in use
- Azure &gt; CIS v3.0 &gt; 07 - Networking &gt; 07.07 - Ensure that Public IP addresses are evaluated on a periodic basis
- Azure &gt; CIS v3.0 &gt; 07 - Networking &gt; Maximum Attestation Duration
- Azure &gt; CIS v3.0 &gt; 08 - Virtual Machines
- Azure &gt; CIS v3.0 &gt; 08 - Virtual Machines &gt; 08.01 - Ensure Virtual Machines are utilizing Managed Disks
- Azure &gt; CIS v3.0 &gt; 08 - Virtual Machines &gt; 08.02 - Ensure Virtual Machines are utilizing Managed Disks
- Azure &gt; CIS v3.0 &gt; 08 - Virtual Machines &gt; 08.03 - Ensure that &apos;OS and Data&apos; disks are encrypted with Customer Managed Key (CMK)
- Azure &gt; CIS v3.0 &gt; 08 - Virtual Machines &gt; 08.04 - Ensure that &apos;Unattached disks&apos; are encrypted with &apos;Customer Managed Key&apos; (CMK)
- Azure &gt; CIS v3.0 &gt; 08 - Virtual Machines &gt; 08.05 - Ensure that &apos;Disk Network Access&apos; is NOT set to &apos;Enable public access from all networks&apos;
- Azure &gt; CIS v3.0 &gt; 08 - Virtual Machines &gt; 08.06 - Ensure that &apos;Enable Data Access Authentication Mode&apos; is &apos;Checked&apos;
- Azure &gt; CIS v3.0 &gt; 08 - Virtual Machines &gt; 08.07 - Ensure that Only Approved Extensions Are Installed
- Azure &gt; CIS v3.0 &gt; 08 - Virtual Machines &gt; 08.07 - Ensure that Only Approved Extensions Are Installed &gt; Attestation
- Azure &gt; CIS v3.0 &gt; 08 - Virtual Machines &gt; 08.08 - Ensure that Endpoint Protection for all Virtual Machines is installed
- Azure &gt; CIS v3.0 &gt; 08 - Virtual Machines &gt; 08.08 - Ensure that Endpoint Protection for all Virtual Machines is installed &gt; Attestation
- Azure &gt; CIS v3.0 &gt; 08 - Virtual Machines &gt; 08.09 - [Legacy] Ensure that VHDs are Encrypted
- Azure &gt; CIS v3.0 &gt; 08 - Virtual Machines &gt; 08.09 - [Legacy] Ensure that VHDs are Encrypted &gt; Attestation
- Azure &gt; CIS v3.0 &gt; 08 - Virtual Machines &gt; 08.10 - Ensure only MFA enabled identities can access privileged Virtual Machine
- Azure &gt; CIS v3.0 &gt; 08 - Virtual Machines &gt; 08.10 - Ensure only MFA enabled identities can access privileged Virtual Machine &gt; Attestation
- Azure &gt; CIS v3.0 &gt; 08 - Virtual Machines &gt; 08.11 - Ensure Trusted Launch is enabled on Virtual Machines
- Azure &gt; CIS v3.0 &gt; 08 - Virtual Machines &gt; Maximum Attestation Duration
- Azure &gt; CIS v3.0 &gt; 09 - Application Services
- Azure &gt; CIS v3.0 &gt; 09 - Application Services &gt; 09.01 - Ensure &apos;HTTPS Only&apos; is set to `On`
- Azure &gt; CIS v3.0 &gt; 09 - Application Services &gt; 09.02 - Ensure App Service Authentication is set up for apps in Azure App Service
- Azure &gt; CIS v3.0 &gt; 09 - Application Services &gt; 09.03 - Ensure &apos;FTP State&apos; is set to &apos;FTPS Only&apos; or &apos;Disabled&apos;
- Azure &gt; CIS v3.0 &gt; 09 - Application Services &gt; 09.04 - Ensure Web App is using the latest version of TLS encryption
- Azure &gt; CIS v3.0 &gt; 09 - Application Services &gt; 09.05 - Ensure that Register with Entra ID is enabled on App Service
- Azure &gt; CIS v3.0 &gt; 09 - Application Services &gt; 09.06 - Ensure that &apos;Basic Authentication&apos; is &apos;Disabled&apos;
- Azure &gt; CIS v3.0 &gt; 09 - Application Services &gt; 09.06 - Ensure that &apos;Basic Authentication&apos; is &apos;Disabled&apos; &gt; Attestation
- Azure &gt; CIS v3.0 &gt; 09 - Application Services &gt; 09.07 - Ensure that &apos;PHP version&apos; is currently supported (if in use)
- Azure &gt; CIS v3.0 &gt; 09 - Application Services &gt; 09.07 - Ensure that &apos;PHP version&apos; is currently supported (if in use) &gt; Attestation
- Azure &gt; CIS v3.0 &gt; 09 - Application Services &gt; 09.08 - Ensure that &apos;Python version&apos; is currently supported (if in use)
- Azure &gt; CIS v3.0 &gt; 09 - Application Services &gt; 09.08 - Ensure that &apos;Python version&apos; is currently supported (if in use) &gt; Attestation
- Azure &gt; CIS v3.0 &gt; 09 - Application Services &gt; 09.09 - Ensure that &apos;Java version&apos; is currently supported (if in use)
- Azure &gt; CIS v3.0 &gt; 09 - Application Services &gt; 09.09 - Ensure that &apos;Java version&apos; is currently supported (if in use) &gt; Attestation
- Azure &gt; CIS v3.0 &gt; 09 - Application Services &gt; 09.10 - Ensure that &apos;HTTP20enabled&apos; is set to &apos;true&apos; (if in use)
- Azure &gt; CIS v3.0 &gt; 09 - Application Services &gt; 09.11 - Ensure Azure Key Vaults are Used to Store Secrets
- Azure &gt; CIS v3.0 &gt; 09 - Application Services &gt; 09.11 - Ensure Azure Key Vaults are Used to Store Secrets &gt; Attestation
- Azure &gt; CIS v3.0 &gt; 09 - Application Services &gt; 09.12 - Ensure that &apos;Remote debugging&apos; is set to &apos;Off&apos;
- Azure &gt; CIS v3.0 &gt; 09 - Application Services &gt; Maximum Attestation Duration
- Azure &gt; CIS v3.0 &gt; 10 - Miscellaneous
- Azure &gt; CIS v3.0 &gt; 10 - Miscellaneous &gt; 10.01 - Ensure that Resource Locks are set for Mission-Critical Azure Resources
- Azure &gt; CIS v3.0 &gt; 10 - Miscellaneous &gt; 10.01 - Ensure that Resource Locks are set for Mission-Critical Azure Resources &gt; Attestation
- Azure &gt; CIS v3.0 &gt; 10 - Miscellaneous &gt; Maximum Attestation Duration
- Azure &gt; CIS v3.0 &gt; Maximum Attestation Duration

_Note_

To ensure compatibility and proper functioning of the Guardrails Azure CIS v3 mod, we recommend updating all dependent mods to their latest versions.</description>
            <pubDate>Fri, 01 Aug 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/github-v5-2-0</guid>
            <title>github v5.2.0 - Added proxy support for GitHub API requests</title>
            <link>https://turbot.com/guardrails/changelog/github-v5-2-0</link>
            <description>_What&apos;s new?_

- Added proxy support for GitHub API requests.</description>
            <pubDate>Thu, 31 Jul 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-storage-v5-25-1</guid>
            <title>azure-storage v5.25.1 - Updated internal Node SDK package to fetch diagnostic settings for storage accounts correctly</title>
            <link>https://turbot.com/guardrails/changelog/azure-storage-v5-25-1</link>
            <description>_Bug fixes_

- Guardrails previously failed to fetch all `diagnosticSettings` details for storage accounts control due to limitations in the internal Node SDK package version. This has now been resolved, and the CMDB control will successfully fetch all details as expected.

Renamed:

- `diagnosticSettings.value` to `diagnosticSettings`</description>
            <pubDate>Thu, 31 Jul 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-keyvault-v5-17-1</guid>
            <title>azure-keyvault v5.17.1 - Updated internal Node SDK package to fetch diagnostic settings for key vaults correctly</title>
            <link>https://turbot.com/guardrails/changelog/azure-keyvault-v5-17-1</link>
            <description>_Bug fixes_

- Guardrails previously failed to fetch all `diagnosticSettings` details for vaults control due to limitations in the internal Node SDK package version. This has now been resolved, and the CMDB control will successfully fetch all details as expected.</description>
            <pubDate>Thu, 31 Jul 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-appservice-v5-15-1</guid>
            <title>azure-appservice v5.15.1 - Updated internal Node SDK package to fetch diagnostic settings for web apps correctly</title>
            <link>https://turbot.com/guardrails/changelog/azure-appservice-v5-15-1</link>
            <description>_Bug fixes_

- Guardrails previously failed to fetch all `diagnosticSettings` details for web apps control due to limitations in the internal Node SDK package version. This has now been resolved, and the CMDB control will successfully fetch all details as expected.</description>
            <pubDate>Thu, 31 Jul 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-storage-v5-25-0</guid>
            <title>azure-storage v5.25.0 - Diagnostic settings for blob, queue, and table will now be available in CMDB for storage accounts</title>
            <link>https://turbot.com/guardrails/changelog/azure-storage-v5-25-0</link>
            <description>_What&apos;s new?_

- Diagnostic Settings for blob, queue, and table will now be available in CMDB for storage accounts.
- Users can now update access tier to `cold` for storage accounts. To get started, set the `Azure &gt; Storage &gt; Storage Account &gt; Access Tier` policy to `Enforce: Cold`.

_Bug fixes_

- The `Azure &gt; Storage &gt; Storage Account &gt; Tags` control will no longer pass unnecessary arguments as parameter to the API call while updating tags for the resource.</description>
            <pubDate>Tue, 29 Jul 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-compute-v5-25-0</guid>
            <title>azure-compute v5.25.0 - Configure guest configuration extension for virtual machines</title>
            <link>https://turbot.com/guardrails/changelog/azure-compute-v5-25-0</link>
            <description>_What&apos;s new?_

- You can now configure guest configuration extension for virtual machines. To get started, set the `Azure &gt; Compute &gt; Virtual Machine &gt; Extensions &gt; Guest Configuration` policy.

_Control Types_

- Azure &gt; Compute &gt; Virtual Machine &gt; Extensions
- Azure &gt; Compute &gt; Virtual Machine &gt; Extensions &gt; Guest Configuration

_Policy Types_

- Azure &gt; Compute &gt; Virtual Machine &gt; Extensions
- Azure &gt; Compute &gt; Virtual Machine &gt; Extensions &gt; Guest Configuration

_Action Types_

- Azure &gt; Compute &gt; Virtual Machine &gt; Update Guest Configuration</description>
            <pubDate>Tue, 29 Jul 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-cisv2-0-v5-2-0</guid>
            <title>azure-cisv2-0 v5.2.0 - Added controls for sections 5.01.01, 5.01.02 and 7.01</title>
            <link>https://turbot.com/guardrails/changelog/azure-cisv2-0-v5-2-0</link>
            <description>_What&apos;s new?_

- Added controls for sections 5.01.01, 5.01.02 and 7.01.

_Control Types_

- Azure &gt; CIS v2.0 &gt; 05 - Logging and Monitoring &gt; 5.01 - Configuring Diagnostic Settings &gt; 5.01.01 - Ensure that a &apos;Diagnostic Setting&apos; exists
- Azure &gt; CIS v2.0 &gt; 05 - Logging and Monitoring &gt; 5.01 - Configuring Diagnostic Settings &gt; 5.01.02 - Ensure Diagnostic Setting captures appropriate categories
- Azure &gt; CIS v2.0 &gt; 07 - Virtual Machines &gt; 7.01 - Ensure an Azure Bastion Host Exists

_Policy Types_

- Azure &gt; CIS v2.0 &gt; 05 - Logging and Monitoring &gt; 5.01 - Configuring Diagnostic Settings &gt; 5.01.01 - Ensure that a &apos;Diagnostic Setting&apos; exists
- Azure &gt; CIS v2.0 &gt; 05 - Logging and Monitoring &gt; 5.01 - Configuring Diagnostic Settings &gt; 5.01.01 - Ensure that a &apos;Diagnostic Setting&apos; exists &gt; Attestation
- Azure &gt; CIS v2.0 &gt; 05 - Logging and Monitoring &gt; 5.01 - Configuring Diagnostic Settings &gt; 5.01.02 - Ensure Diagnostic Setting captures appropriate categories
- Azure &gt; CIS v2.0 &gt; 07 - Virtual Machines &gt; 7.01 - Ensure an Azure Bastion Host Exists

_Bug fixes_

- CIS controls previously entered an invalid or TBD state when the CMDB controls for associated resources were in a skipped or TBD state, even if the corresponding CIS policies were set to `Skip`. This issue has been resolved; such controls will now correctly transition to a skipped state.</description>
            <pubDate>Tue, 29 Jul 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-s3-v5-32-2</guid>
            <title>aws-s3 v5.32.2 - CMDB data now automatically refreshes when intelligent tiering configurations are removed from the buckets</title>
            <link>https://turbot.com/guardrails/changelog/aws-s3-v5-32-2</link>
            <description>_Bug fixes_

- The CMDB data for buckets did not refresh automatically when intelligent tiering configurations were removed from the buckets. This issue has now been fixed.</description>
            <pubDate>Fri, 25 Jul 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/ted-v1-51-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.51.0 -	Added support for PostgreSQL versions 15.9, 15.10, 15.11, 15.12 and 15.13</title>
            <link>https://turbot.com/guardrails/changelog/ted-v1-51-0</link>
            <description>_What&apos;s new?_

- Added support for PostgreSQL version 15.9, 15.10, 15.11, 15.12 and 15.13.</description>
            <pubDate>Thu, 24 Jul 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/terraform-provider-v1-12-4</guid>
            <title>Terraform Provider v1.12.4 - Improved handling of policy pack deletions with attachments</title>
            <link>https://turbot.com/guardrails/changelog/terraform-provider-v1-12-4</link>
            <description>_Bug fixes_

- Resolved a bug where destroying a policy pack via Terraform did not delete the policy pack if it was still attached to resources. The `terraform destroy` command now provides a clear and meaningful error message when such attachments exist.

  Minimum version requirements:
  - TE v5.52.1</description>
            <pubDate>Wed, 23 Jul 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-v5-32-0</guid>
            <title>azure v5.32.0 - Diagnostic settings details will now be available in CMDB for subscriptions</title>
            <link>https://turbot.com/guardrails/changelog/azure-v5-32-0</link>
            <description>_What&apos;s new?_

- Diagnostic Settings details will now be available in CMDB for Subscriptions.</description>
            <pubDate>Wed, 23 Jul 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-52-1</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.52.1 - Enhancements and fixes to improve core system reliability</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-52-1</link>
            <description>_What&apos;s new?_

- Server
  - Introduced `LAMBDA_IN_VPC_GITHUB` flag to enable deployment of GitHub mod lambdas inside a VPC.

_Bug Fixes_

- Server
  - Optimized mod type installation to distribute event execution more evenly over time, minimizing the risk of throttling.
  - Fixed an issue where controls or actions could get stuck if their notification templates were empty or failed to render correctly.
  - The Delete Policy Pack API now throws a clear error when attempting to delete a policy pack that still has attached resources.
  - The maintenance container now ensures the index_list table is populated with any missing indexes, improving database reliability.
  - Unused Lambda functions are now correctly deleted when no aliases remain.

_Note_

Upgrade to `5.52.1` requires your workspace to be on `5.51.x`; direct upgrades from older versions (e.g., 5.49.x) will fail.

_Requirements_

- TEF: 1.66.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Tue, 22 Jul 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-network-v5-26-0</guid>
            <title>azure-network v5.26.0 - Track and manage bastion hosts in CMDB</title>
            <link>https://turbot.com/guardrails/changelog/azure-network-v5-26-0</link>
            <description>_What&apos;s new?_

- Resource Types:
  - Azure &gt; Network &gt; Bastion Host

- Control Types:
  - Azure &gt; Network &gt; Bastion Host &gt; Active
  - Azure &gt; Network &gt; Bastion Host &gt; CMDB
  - Azure &gt; Network &gt; Bastion Host &gt; Discovery
  - Azure &gt; Network &gt; Bastion Host &gt; Tags

- Policy Types:
  - Azure &gt; Network &gt; Bastion Host &gt; Active
  - Azure &gt; Network &gt; Bastion Host &gt; Active &gt; Age
  - Azure &gt; Network &gt; Bastion Host &gt; Active &gt; Last Modified
  - Azure &gt; Network &gt; Bastion Host &gt; CMDB
  - Azure &gt; Network &gt; Bastion Host &gt; Regions
  - Azure &gt; Network &gt; Bastion Host &gt; Tags
  - Azure &gt; Network &gt; Bastion Host &gt; Tags &gt; Template

- Action Types:
  - Azure &gt; Network &gt; Bastion Host &gt; Delete
  - Azure &gt; Network &gt; Bastion Host &gt; Router
  - Azure &gt; Network &gt; Bastion Host &gt; Set Tags</description>
            <pubDate>Tue, 22 Jul 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-compute-v5-24-0</guid>
            <title>azure-compute v5.24.0 - HyperVGeneration details will now be available in the CMDB for virtual machines</title>
            <link>https://turbot.com/guardrails/changelog/azure-compute-v5-24-0</link>
            <description>_What&apos;s new?_

- `HyperVGeneration` details will now be available in the CMDB for Virtual Machines.</description>
            <pubDate>Tue, 22 Jul 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-activedirectory-v5-9-0</guid>
            <title>azure-activedirectory v5.9.0 - Conditional access policy and directory role details will now be available in CMDB for directories</title>
            <link>https://turbot.com/guardrails/changelog/azure-activedirectory-v5-9-0</link>
            <description>_What&apos;s new?_

- `Conditional Access Policy` and `Directory Role` details will now be available in CMDB for Directories.

_Action Types_

- Azure &gt; Active Directory &gt; Directory &gt; Router</description>
            <pubDate>Tue, 22 Jul 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-bedrock-v5-1-0</guid>
            <title>aws-bedrock v5.1.0 - Various new resource types for Bedrock are now available</title>
            <link>https://turbot.com/guardrails/changelog/aws-bedrock-v5-1-0</link>
            <description>_What&apos;s new?_

- Resource Types:

  - AWS &gt; Bedrock &gt; Agent
  - AWS &gt; Bedrock &gt; Custom Model
  - AWS &gt; Bedrock &gt; Foundation Model
  - AWS &gt; Bedrock &gt; Imported Model
  - AWS &gt; Bedrock &gt; Knowledge Base
  - AWS &gt; Bedrock &gt; Settings

- Control Types:

  - AWS &gt; Bedrock &gt; Agent &gt; Active
  - AWS &gt; Bedrock &gt; Agent &gt; CMDB
  - AWS &gt; Bedrock &gt; Agent &gt; Discovery
  - AWS &gt; Bedrock &gt; Agent &gt; Tags
  - AWS &gt; Bedrock &gt; Custom Model &gt; Active
  - AWS &gt; Bedrock &gt; Custom Model &gt; CMDB
  - AWS &gt; Bedrock &gt; Custom Model &gt; Discovery
  - AWS &gt; Bedrock &gt; Custom Model &gt; Tags
  - AWS &gt; Bedrock &gt; Foundation Model &gt; CMDB
  - AWS &gt; Bedrock &gt; Foundation Model &gt; Discovery
  - AWS &gt; Bedrock &gt; Imported Model &gt; Active
  - AWS &gt; Bedrock &gt; Imported Model &gt; CMDB
  - AWS &gt; Bedrock &gt; Imported Model &gt; Discovery
  - AWS &gt; Bedrock &gt; Imported Model &gt; Tags
  - AWS &gt; Bedrock &gt; Knowledge Base &gt; Active
  - AWS &gt; Bedrock &gt; Knowledge Base &gt; CMDB
  - AWS &gt; Bedrock &gt; Knowledge Base &gt; Discovery
  - AWS &gt; Bedrock &gt; Knowledge Base &gt; Tags
  - AWS &gt; Bedrock &gt; Settings &gt; CMDB
  - AWS &gt; Bedrock &gt; Settings &gt; Discovery
  - AWS &gt; Bedrock &gt; Settings &gt; Model Invocation Logging Configuration

- Policy Types:

  - AWS &gt; Bedrock &gt; Agent &gt; Active
  - AWS &gt; Bedrock &gt; Agent &gt; Active &gt; Age
  - AWS &gt; Bedrock &gt; Agent &gt; Active &gt; Last Modified
  - AWS &gt; Bedrock &gt; Agent &gt; CMDB
  - AWS &gt; Bedrock &gt; Agent &gt; Regions
  - AWS &gt; Bedrock &gt; Agent &gt; Tags
  - AWS &gt; Bedrock &gt; Agent &gt; Tags &gt; Template
  - AWS &gt; Bedrock &gt; Custom Model &gt; Active
  - AWS &gt; Bedrock &gt; Custom Model &gt; Active &gt; Age
  - AWS &gt; Bedrock &gt; Custom Model &gt; Active &gt; Last Modified
  - AWS &gt; Bedrock &gt; Custom Model &gt; CMDB
  - AWS &gt; Bedrock &gt; Custom Model &gt; Regions
  - AWS &gt; Bedrock &gt; Custom Model &gt; Tags
  - AWS &gt; Bedrock &gt; Custom Model &gt; Tags &gt; Template
  - AWS &gt; Bedrock &gt; Foundation Model &gt; CMDB
  - AWS &gt; Bedrock &gt; Foundation Model &gt; Regions
  - AWS &gt; Bedrock &gt; Imported Model &gt; Active
  - AWS &gt; Bedrock &gt; Imported Model &gt; Active &gt; Age
  - AWS &gt; Bedrock &gt; Imported Model &gt; Active &gt; Last Modified
  - AWS &gt; Bedrock &gt; Imported Model &gt; CMDB
  - AWS &gt; Bedrock &gt; Imported Model &gt; Regions
  - AWS &gt; Bedrock &gt; Imported Model &gt; Tags
  - AWS &gt; Bedrock &gt; Imported Model &gt; Tags &gt; Template
  - AWS &gt; Bedrock &gt; Knowledge Base &gt; Active
  - AWS &gt; Bedrock &gt; Knowledge Base &gt; Active &gt; Age
  - AWS &gt; Bedrock &gt; Knowledge Base &gt; Active &gt; Last Modified
  - AWS &gt; Bedrock &gt; Knowledge Base &gt; CMDB
  - AWS &gt; Bedrock &gt; Knowledge Base &gt; Regions
  - AWS &gt; Bedrock &gt; Knowledge Base &gt; Tags
  - AWS &gt; Bedrock &gt; Knowledge Base &gt; Tags &gt; Template
  - AWS &gt; Bedrock &gt; Settings &gt; CMDB
  - AWS &gt; Bedrock &gt; Settings &gt; Model Invocation Logging Configuration
  - AWS &gt; Bedrock &gt; Settings &gt; Model Invocation Logging Configuration &gt; Data Delivery
  - AWS &gt; Bedrock &gt; Settings &gt; Model Invocation Logging Configuration &gt; Logging Destination
  - AWS &gt; Bedrock &gt; Settings &gt; Model Invocation Logging Configuration &gt; Logging Destination &gt; CloudWatch Log Group Name
  - AWS &gt; Bedrock &gt; Settings &gt; Model Invocation Logging Configuration &gt; Logging Destination &gt; S3 Location
  - AWS &gt; Bedrock &gt; Settings &gt; Model Invocation Logging Configuration &gt; Logging Destination &gt; S3 Location for Large Data Delivery
  - AWS &gt; Bedrock &gt; Settings &gt; Model Invocation Logging Configuration &gt; Logging Destination &gt; Service Role ARN
  - AWS &gt; Bedrock &gt; Settings &gt; Regions
  - AWS &gt; Bedrock &gt; Tags Template [Default]
  - AWS &gt; Turbot &gt; Event Handlers &gt; Events &gt; Rules &gt; Custom Event Patterns &gt; @turbot/aws-bedrock

- Action Types:
  - AWS &gt; Bedrock &gt; Agent &gt; Delete
  - AWS &gt; Bedrock &gt; Agent &gt; Router
  - AWS &gt; Bedrock &gt; Agent &gt; Update Tags
  - AWS &gt; Bedrock &gt; Custom Model &gt; Delete
  - AWS &gt; Bedrock &gt; Custom Model &gt; Router
  - AWS &gt; Bedrock &gt; Custom Model &gt; Update Tags
  - AWS &gt; Bedrock &gt; Imported Model &gt; Delete
  - AWS &gt; Bedrock &gt; Imported Model &gt; Router
  - AWS &gt; Bedrock &gt; Imported Model &gt; Update Tags
  - AWS &gt; Bedrock &gt; Knowledge Base &gt; Delete
  - AWS &gt; Bedrock &gt; Knowledge Base &gt; Router
  - AWS &gt; Bedrock &gt; Knowledge Base &gt; Update Tags
  - AWS &gt; Bedrock &gt; Settings &gt; Router
  - AWS &gt; Bedrock &gt; Settings &gt; Update Model Invocation Logging Configuration</description>
            <pubDate>Tue, 22 Jul 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-apigateway-v5-12-2</guid>
            <title>aws-apigateway v5.12.2 - Real-time events for stage resources will now be processed more reliably</title>
            <link>https://turbot.com/guardrails/changelog/aws-apigateway-v5-12-2</link>
            <description>_Bug fixes_

- In previous versions, `apigateway:CreateDeployment` events were processed without validating the required stageName parameter, which could result in invalid stage resources in the CMDB. This issue is now fixed.</description>
            <pubDate>Mon, 21 Jul 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-apigateway-v5-12-1</guid>
            <title>aws-apigateway v5.12.1 - Enhanced real-time event handling for stage resources to accurately process events when a web ACL is attached</title>
            <link>https://turbot.com/guardrails/changelog/aws-apigateway-v5-12-1</link>
            <description>_Bug fixes_

- Resolved an issue with real-time event handling for `AWS &gt; API Gateway &gt; Stage` resources. Specifically, Guardrails was previously not receiving events when a Web ACL was attached to an API Gateway stage. This has now been fixed, and events for such actions are processed as expected.</description>
            <pubDate>Fri, 18 Jul 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-network-v5-16-0</guid>
            <title>gcp-network v5.16.0 - Configure private google access for subnetworks</title>
            <link>https://turbot.com/guardrails/changelog/gcp-network-v5-16-0</link>
            <description>_What&apos;s new?_

- Users can now configure the private google access settings for subnetworks. To get started, set the `GCP &gt; Network &gt; Subnetwork &gt; Private Google Access` policy.

_Control Types_

- GCP &gt; Network &gt; Subnetwork &gt; Private Google Access

_Policy Types_

- GCP &gt; Network &gt; Subnetwork &gt; Private Google Access

_Action Types_

- GCP &gt; Network &gt; Subnetwork &gt; Set Private Google Access</description>
            <pubDate>Fri, 11 Jul 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-dns-v5-9-1</guid>
            <title>gcp-dns v5.9.1 - Managed zone Labels control now correctly applies labels according to the template policy</title>
            <link>https://turbot.com/guardrails/changelog/gcp-dns-v5-9-1</link>
            <description>_Bug fixes_

- Previously, `GCP &gt; DNS &gt; Managed Zone &gt; Labels` control would fail when attempting to update labels on private DNS zones that were linked to a Service Directory namespace. This was caused by the control attempting to modify the `serviceDirectoryConfig` field, which is not allowed by the Google Cloud DNS API and resulted in an error. This issue has now been resolved.</description>
            <pubDate>Fri, 11 Jul 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-dynamodb-v5-16-0</guid>
            <title>aws-dynamodb v5.16.0 - Manage trusted access for tables</title>
            <link>https://turbot.com/guardrails/changelog/aws-dynamodb-v5-16-0</link>
            <description>_What&apos;s new?_

- Users can now manage trusted access for tables. To get started, set the `AWS &gt; DynamoDB &gt; Table &gt; Policy &gt; Trusted Access &gt; *` policies.
- Resource policy details will now be available in CMDB for tables.

_Control Types_

- AWS &gt; DynamoDB &gt; Table &gt; Policy
- AWS &gt; DynamoDB &gt; Table &gt; Policy &gt; Trusted Access

_Policy Types_

- AWS &gt; DynamoDB &gt; Table &gt; Policy
- AWS &gt; DynamoDB &gt; Table &gt; Policy &gt; Trusted Access
- AWS &gt; DynamoDB &gt; Table &gt; Policy &gt; Trusted Access &gt; Accounts
- AWS &gt; DynamoDB &gt; Table &gt; Policy &gt; Trusted Access &gt; CloudFront Origin Access Identities
- AWS &gt; DynamoDB &gt; Table &gt; Policy &gt; Trusted Access &gt; Organization Restrictions
- AWS &gt; DynamoDB &gt; Trusted Accounts [Default]
- AWS &gt; DynamoDB &gt; Trusted Organizations [Default]

_Action Types_

- AWS &gt; DynamoDB &gt; Table &gt; Set Policy Trusted Access</description>
            <pubDate>Fri, 11 Jul 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-computeengine-v5-22-0</guid>
            <title>gcp-computeengine v5.22.0 - Real time events are now processed for the regional disks</title>
            <link>https://turbot.com/guardrails/changelog/gcp-computeengine-v5-22-0</link>
            <description>_What&apos;s new?_

- Added support to process real-time events for `GCP &gt; Compute Engine &gt; Region Disk`.

_Action Types_

- GCP &gt; Compute Engine &gt; Region Disk &gt; Router</description>
            <pubDate>Mon, 07 Jul 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ec2-v5-46-1</guid>
            <title>aws-ec2 v5.46.1 - Removed dependency on workspace version policy for custom event patterns</title>
            <link>https://turbot.com/guardrails/changelog/aws-ec2-v5-46-1</link>
            <description>_Bug fixes_

- The `AWS &gt; Turbot &gt; Event Handlers &gt; Events &gt; Rules &gt; Custom Event Patterns &gt; @turbot/aws-ec2` policy previously depended on the `Turbot &gt; Workspace &gt; Workspace Version` policy, causing Event Handlers to run after a TE update. This dependency has been safely removed, improving the overall efficiency of the workspace.</description>
            <pubDate>Mon, 07 Jul 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-postgresql-v5-20-0</guid>
            <title>azure-postgresql v5.20.0 - Configure Intelligent Assessment control for dynamic, context-aware resource assessments</title>
            <link>https://turbot.com/guardrails/changelog/azure-postgresql-v5-20-0</link>
            <description>_What&apos;s new?_

- You can now use the `Intelligent Assessment` control, which enables dynamic, context-aware resource assessments and leverages AI capabilities to evaluate cloud resources based on user prompts. To get started, set the `Intelligent Assessment &gt; *` policies.

_Control Types_

- Azure &gt; PostgreSQL &gt; Flexible Server &gt; Intelligent Assessment

_Policy Types_

- Azure &gt; PostgreSQL &gt; Flexible Server &gt; Intelligent Assessment
- Azure &gt; PostgreSQL &gt; Flexible Server &gt; Intelligent Assessment &gt; Context
- Azure &gt; PostgreSQL &gt; Flexible Server &gt; Intelligent Assessment &gt; User Prompt</description>
            <pubDate>Thu, 03 Jul 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-events-v5-15-1</guid>
            <title>aws-events v5.15.1 - Improved handling of user prompts and updated GraphQL dependencies for the Intelligent Assessment controls</title>
            <link>https://turbot.com/guardrails/changelog/aws-events-v5-15-1</link>
            <description>_Bug fixes_

- Improved the internal handling of user prompts and updated GraphQL dependencies for the `Intelligent Assessment` controls.</description>
            <pubDate>Thu, 03 Jul 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-v5-32-0</guid>
            <title>gcp v5.32.0 - Configure Intelligent Assessment controls for dynamic, context-aware resource assessments</title>
            <link>https://turbot.com/guardrails/changelog/gcp-v5-32-0</link>
            <description>_What&apos;s new?_

- You can now use the `Intelligent Assessment` controls, which enables dynamic, context-aware resource assessments and leverages AI capabilities to evaluate cloud resources based on user prompts. To get started, set the `Intelligent Assessment &gt; *` policies.

_Control Types_

- GCP &gt; Folder &gt; Intelligent Assessment
- GCP &gt; Organization &gt; Intelligent Assessment
- GCP &gt; Project &gt; Intelligent Assessment

_Policy Types_

- GCP &gt; Folder &gt; Intelligent Assessment
- GCP &gt; Folder &gt; Intelligent Assessment &gt; Context
- GCP &gt; Folder &gt; Intelligent Assessment &gt; User Prompt
- GCP &gt; Organization &gt; Intelligent Assessment
- GCP &gt; Organization &gt; Intelligent Assessment &gt; Context
- GCP &gt; Organization &gt; Intelligent Assessment &gt; User Prompt
- GCP &gt; Project &gt; Intelligent Assessment
- GCP &gt; Project &gt; Intelligent Assessment &gt; Context
- GCP &gt; Project &gt; Intelligent Assessment &gt; User Prompt</description>
            <pubDate>Wed, 02 Jul 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-pubsub-v5-11-0</guid>
            <title>gcp-pubsub v5.11.0 - Configure Intelligent Assessment controls for dynamic, context-aware resource assessments</title>
            <link>https://turbot.com/guardrails/changelog/gcp-pubsub-v5-11-0</link>
            <description>_What&apos;s new?_

- You can now use the `Intelligent Assessment` controls, which enables dynamic, context-aware resource assessments and leverages AI capabilities to evaluate cloud resources based on user prompts. To get started, set the `Intelligent Assessment &gt; *` policies.

_Control Types_

- GCP &gt; Pub/Sub &gt; Snapshot &gt; Intelligent Assessment
- GCP &gt; Pub/Sub &gt; Subscription &gt; Intelligent Assessment
- GCP &gt; Pub/Sub &gt; Topic &gt; Intelligent Assessment

_Policy Types_

- GCP &gt; Pub/Sub &gt; Snapshot &gt; Intelligent Assessment
- GCP &gt; Pub/Sub &gt; Snapshot &gt; Intelligent Assessment &gt; Context
- GCP &gt; Pub/Sub &gt; Snapshot &gt; Intelligent Assessment &gt; User Prompt
- GCP &gt; Pub/Sub &gt; Subscription &gt; Intelligent Assessment
- GCP &gt; Pub/Sub &gt; Subscription &gt; Intelligent Assessment &gt; Context
- GCP &gt; Pub/Sub &gt; Subscription &gt; Intelligent Assessment &gt; User Prompt
- GCP &gt; Pub/Sub &gt; Topic &gt; Intelligent Assessment
- GCP &gt; Pub/Sub &gt; Topic &gt; Intelligent Assessment &gt; Context
- GCP &gt; Pub/Sub &gt; Topic &gt; Intelligent Assessment &gt; User Prompt</description>
            <pubDate>Wed, 02 Jul 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-logging-v5-7-0</guid>
            <title>gcp-logging v5.7.0 - Configure Intelligent Assessment controls for dynamic, context-aware resource assessments</title>
            <link>https://turbot.com/guardrails/changelog/gcp-logging-v5-7-0</link>
            <description>_What&apos;s new?_

- You can now use the `Intelligent Assessment` controls, which enables dynamic, context-aware resource assessments and leverages AI capabilities to evaluate cloud resources based on user prompts. To get started, set the `Intelligent Assessment &gt; *` policies.

_Control Types_

- GCP &gt; Logging &gt; Exclusion &gt; Intelligent Assessment
- GCP &gt; Logging &gt; Metric &gt; Intelligent Assessment
- GCP &gt; Logging &gt; Sink &gt; Intelligent Assessment

_Policy Types_

- GCP &gt; Logging &gt; Exclusion &gt; Intelligent Assessment
- GCP &gt; Logging &gt; Exclusion &gt; Intelligent Assessment &gt; Context
- GCP &gt; Logging &gt; Exclusion &gt; Intelligent Assessment &gt; User Prompt
- GCP &gt; Logging &gt; Metric &gt; Intelligent Assessment
- GCP &gt; Logging &gt; Metric &gt; Intelligent Assessment &gt; Context
- GCP &gt; Logging &gt; Metric &gt; Intelligent Assessment &gt; User Prompt
- GCP &gt; Logging &gt; Sink &gt; Intelligent Assessment
- GCP &gt; Logging &gt; Sink &gt; Intelligent Assessment &gt; Context
- GCP &gt; Logging &gt; Sink &gt; Intelligent Assessment &gt; User Prompt</description>
            <pubDate>Wed, 02 Jul 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-bigquerydatatransfer-v5-2-1</guid>
            <title>gcp-bigquerydatatransfer v5.2.1 - Improved handling of user prompts and updated GraphQL dependencies for the Intelligent Assessment control</title>
            <link>https://turbot.com/guardrails/changelog/gcp-bigquerydatatransfer-v5-2-1</link>
            <description>_Bug fixes_

- Improved the internal handling of user prompts and updated GraphQL dependencies for the `Intelligent Assessment` control.</description>
            <pubDate>Wed, 02 Jul 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-bigquery-v5-9-1</guid>
            <title>gcp-bigquery v5.9.1 - Improved handling of user prompts and updated GraphQL dependencies for the Intelligent Assessment controls</title>
            <link>https://turbot.com/guardrails/changelog/gcp-bigquery-v5-9-1</link>
            <description>_Bug fixes_

- Improved the internal handling of user prompts and updated GraphQL dependencies for the `Intelligent Assessment` controls.</description>
            <pubDate>Wed, 02 Jul 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-appengine-v5-5-0</guid>
            <title>gcp-appengine v5.5.0 - Configure Intelligent Assessment controls for dynamic, context-aware resource assessments</title>
            <link>https://turbot.com/guardrails/changelog/gcp-appengine-v5-5-0</link>
            <description>_What&apos;s new?_

- You can now use the `Intelligent Assessment` controls, which enables dynamic, context-aware resource assessments and leverages AI capabilities to evaluate cloud resources based on user prompts. To get started, set the `Intelligent Assessment &gt; *` policies.

_Control Types_

- GCP &gt; App Engine &gt; Application &gt; Intelligent Assessment
- GCP &gt; App Engine &gt; Firewall Rule &gt; Intelligent Assessment
- GCP &gt; App Engine &gt; Instance &gt; Intelligent Assessment
- GCP &gt; App Engine &gt; Service &gt; Intelligent Assessment
- GCP &gt; App Engine &gt; Version &gt; Intelligent Assessment

_Policy Types_

- GCP &gt; App Engine &gt; Application &gt; Intelligent Assessment
- GCP &gt; App Engine &gt; Application &gt; Intelligent Assessment &gt; Context
- GCP &gt; App Engine &gt; Application &gt; Intelligent Assessment &gt; User Prompt
- GCP &gt; App Engine &gt; Firewall Rule &gt; Intelligent Assessment
- GCP &gt; App Engine &gt; Firewall Rule &gt; Intelligent Assessment &gt; Context
- GCP &gt; App Engine &gt; Firewall Rule &gt; Intelligent Assessment &gt; User Prompt
- GCP &gt; App Engine &gt; Instance &gt; Intelligent Assessment
- GCP &gt; App Engine &gt; Instance &gt; Intelligent Assessment &gt; Context
- GCP &gt; App Engine &gt; Instance &gt; Intelligent Assessment &gt; User Prompt
- GCP &gt; App Engine &gt; Service &gt; Intelligent Assessment
- GCP &gt; App Engine &gt; Service &gt; Intelligent Assessment &gt; Context
- GCP &gt; App Engine &gt; Service &gt; Intelligent Assessment &gt; User Prompt
- GCP &gt; App Engine &gt; Version &gt; Intelligent Assessment
- GCP &gt; App Engine &gt; Version &gt; Intelligent Assessment &gt; Context
- GCP &gt; App Engine &gt; Version &gt; Intelligent Assessment &gt; User Prompt</description>
            <pubDate>Wed, 02 Jul 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-sql-v5-19-0</guid>
            <title>azure-sql v5.19.0 - Configure Intelligent Assessment controls for dynamic, context-aware resource assessments</title>
            <link>https://turbot.com/guardrails/changelog/azure-sql-v5-19-0</link>
            <description>_What&apos;s new?_

- You can now use the `Intelligent Assessment` controls, which enables dynamic, context-aware resource assessments and leverages AI capabilities to evaluate cloud resources based on user prompts. To get started, set the `Intelligent Assessment &gt; *` policies.

_Control Types_

- Azure &gt; SQL &gt; Database &gt; Intelligent Assessment
- Azure &gt; SQL &gt; Elastic Pool &gt; Intelligent Assessment
- Azure &gt; SQL &gt; Managed Instance &gt; Intelligent Assessment
- Azure &gt; SQL &gt; Server &gt; Intelligent Assessment

_Policy Types_

- Azure &gt; SQL &gt; Database &gt; Intelligent Assessment
- Azure &gt; SQL &gt; Database &gt; Intelligent Assessment &gt; Context
- Azure &gt; SQL &gt; Database &gt; Intelligent Assessment &gt; User Prompt
- Azure &gt; SQL &gt; Elastic Pool &gt; Intelligent Assessment
- Azure &gt; SQL &gt; Elastic Pool &gt; Intelligent Assessment &gt; Context
- Azure &gt; SQL &gt; Elastic Pool &gt; Intelligent Assessment &gt; User Prompt
- Azure &gt; SQL &gt; Managed Instance &gt; Intelligent Assessment
- Azure &gt; SQL &gt; Managed Instance &gt; Intelligent Assessment &gt; Context
- Azure &gt; SQL &gt; Managed Instance &gt; Intelligent Assessment &gt; User Prompt
- Azure &gt; SQL &gt; Server &gt; Intelligent Assessment
- Azure &gt; SQL &gt; Server &gt; Intelligent Assessment &gt; Context
- Azure &gt; SQL &gt; Server &gt; Intelligent Assessment &gt; User Prompt</description>
            <pubDate>Wed, 02 Jul 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-network-v5-25-0</guid>
            <title>azure-network v5.25.0 - Configure Intelligent Assessment controls for dynamic, context-aware resource assessments</title>
            <link>https://turbot.com/guardrails/changelog/azure-network-v5-25-0</link>
            <description>_What&apos;s new?_

- You can now use the `Intelligent Assessment` controls, which enables dynamic, context-aware resource assessments and leverages AI capabilities to evaluate cloud resources based on user prompts. To get started, set the `Intelligent Assessment &gt; *` policies.

_Control Types_

- Azure &gt; Network &gt; Application Security Group &gt; Intelligent Assessment
- Azure &gt; Network &gt; Express Route Circuits &gt; Intelligent Assessment
- Azure &gt; Network &gt; Network Interface &gt; Intelligent Assessment
- Azure &gt; Network &gt; Network Security Group &gt; Intelligent Assessment
- Azure &gt; Network &gt; Private DNS Zones &gt; Intelligent Assessment
- Azure &gt; Network &gt; Private Endpoints &gt; Intelligent Assessment
- Azure &gt; Network &gt; Private Link Service &gt; Intelligent Assessment
- Azure &gt; Network &gt; Public IP Address &gt; Intelligent Assessment
- Azure &gt; Network &gt; Route Table &gt; Intelligent Assessment
- Azure &gt; Network &gt; Subnet &gt; Intelligent Assessment
- Azure &gt; Network &gt; Virtual Network &gt; Intelligent Assessment
- Azure &gt; Network &gt; Virtual Network Gateway &gt; Intelligent Assessment

_Policy Types_

- Azure &gt; Network &gt; Application Security Group &gt; Intelligent Assessment
- Azure &gt; Network &gt; Application Security Group &gt; Intelligent Assessment &gt; Context
- Azure &gt; Network &gt; Application Security Group &gt; Intelligent Assessment &gt; User Prompt
- Azure &gt; Network &gt; Express Route Circuits &gt; Intelligent Assessment
- Azure &gt; Network &gt; Express Route Circuits &gt; Intelligent Assessment &gt; Context
- Azure &gt; Network &gt; Express Route Circuits &gt; Intelligent Assessment &gt; User Prompt
- Azure &gt; Network &gt; Network Interface &gt; Intelligent Assessment
- Azure &gt; Network &gt; Network Interface &gt; Intelligent Assessment &gt; Context
- Azure &gt; Network &gt; Network Interface &gt; Intelligent Assessment &gt; User Prompt
- Azure &gt; Network &gt; Network Security Group &gt; Intelligent Assessment
- Azure &gt; Network &gt; Network Security Group &gt; Intelligent Assessment &gt; Context
- Azure &gt; Network &gt; Network Security Group &gt; Intelligent Assessment &gt; User Prompt
- Azure &gt; Network &gt; Private DNS Zones &gt; Intelligent Assessment
- Azure &gt; Network &gt; Private DNS Zones &gt; Intelligent Assessment &gt; Context
- Azure &gt; Network &gt; Private DNS Zones &gt; Intelligent Assessment &gt; User Prompt
- Azure &gt; Network &gt; Private Endpoints &gt; Intelligent Assessment
- Azure &gt; Network &gt; Private Endpoints &gt; Intelligent Assessment &gt; Context
- Azure &gt; Network &gt; Private Endpoints &gt; Intelligent Assessment &gt; User Prompt
- Azure &gt; Network &gt; Private Link Service &gt; Intelligent Assessment
- Azure &gt; Network &gt; Private Link Service &gt; Intelligent Assessment &gt; Context
- Azure &gt; Network &gt; Private Link Service &gt; Intelligent Assessment &gt; User Prompt
- Azure &gt; Network &gt; Public IP Address &gt; Intelligent Assessment
- Azure &gt; Network &gt; Public IP Address &gt; Intelligent Assessment &gt; Context
- Azure &gt; Network &gt; Public IP Address &gt; Intelligent Assessment &gt; User Prompt
- Azure &gt; Network &gt; Route Table &gt; Intelligent Assessment
- Azure &gt; Network &gt; Route Table &gt; Intelligent Assessment &gt; Context
- Azure &gt; Network &gt; Route Table &gt; Intelligent Assessment &gt; User Prompt
- Azure &gt; Network &gt; Subnet &gt; Intelligent Assessment
- Azure &gt; Network &gt; Subnet &gt; Intelligent Assessment &gt; Context
- Azure &gt; Network &gt; Subnet &gt; Intelligent Assessment &gt; User Prompt
- Azure &gt; Network &gt; Virtual Network &gt; Intelligent Assessment
- Azure &gt; Network &gt; Virtual Network &gt; Intelligent Assessment &gt; Context
- Azure &gt; Network &gt; Virtual Network &gt; Intelligent Assessment &gt; User Prompt
- Azure &gt; Network &gt; Virtual Network Gateway &gt; Intelligent Assessment
- Azure &gt; Network &gt; Virtual Network Gateway &gt; Intelligent Assessment &gt; Context
- Azure &gt; Network &gt; Virtual Network Gateway &gt; Intelligent Assessment &gt; User Prompt</description>
            <pubDate>Wed, 02 Jul 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-mysql-v5-17-0</guid>
            <title>azure-mysql v5.17.0 - Configure Intelligent Assessment control for dynamic, context-aware resource assessments</title>
            <link>https://turbot.com/guardrails/changelog/azure-mysql-v5-17-0</link>
            <description>_What&apos;s new?_

- You can now use the `Intelligent Assessment` control, which enables dynamic, context-aware resource assessments and leverages AI capabilities to evaluate cloud resources based on user prompts. To get started, set the `Intelligent Assessment &gt; *` policies.

_Control Types_

- Azure &gt; MySQL &gt; Flexible Server &gt; Intelligent Assessment

_Policy Types_

- Azure &gt; MySQL &gt; Flexible Server &gt; Intelligent Assessment
- Azure &gt; MySQL &gt; Flexible Server &gt; Intelligent Assessment &gt; Context
- Azure &gt; MySQL &gt; Flexible Server &gt; Intelligent Assessment &gt; User Prompt</description>
            <pubDate>Wed, 02 Jul 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-monitor-v5-11-0</guid>
            <title>azure-monitor v5.11.0 - Configure Intelligent Assessment controls for dynamic, context-aware resource assessments</title>
            <link>https://turbot.com/guardrails/changelog/azure-monitor-v5-11-0</link>
            <description>_What&apos;s new?_

- You can now use the `Intelligent Assessment` controls, which enables dynamic, context-aware resource assessments and leverages AI capabilities to evaluate cloud resources based on user prompts. To get started, set the `Intelligent Assessment &gt; *` policies.

_Control Types_

- Azure &gt; Monitor &gt; Action Group &gt; Intelligent Assessment
- Azure &gt; Monitor &gt; Alerts &gt; Intelligent Assessment
- Azure &gt; Monitor &gt; Log Profile &gt; Intelligent Assessment
- Azure &gt; Monitor &gt; Metric Alert &gt; Intelligent Assessment

_Policy Types_

- Azure &gt; Monitor &gt; Action Group &gt; Intelligent Assessment
- Azure &gt; Monitor &gt; Action Group &gt; Intelligent Assessment &gt; Context
- Azure &gt; Monitor &gt; Action Group &gt; Intelligent Assessment &gt; User Prompt
- Azure &gt; Monitor &gt; Alerts &gt; Intelligent Assessment
- Azure &gt; Monitor &gt; Alerts &gt; Intelligent Assessment &gt; Context
- Azure &gt; Monitor &gt; Alerts &gt; Intelligent Assessment &gt; User Prompt
- Azure &gt; Monitor &gt; Log Profile &gt; Intelligent Assessment
- Azure &gt; Monitor &gt; Log Profile &gt; Intelligent Assessment &gt; Context
- Azure &gt; Monitor &gt; Log Profile &gt; Intelligent Assessment &gt; User Prompt
- Azure &gt; Monitor &gt; Metric Alert &gt; Intelligent Assessment
- Azure &gt; Monitor &gt; Metric Alert &gt; Intelligent Assessment &gt; Context
- Azure &gt; Monitor &gt; Metric Alert &gt; Intelligent Assessment &gt; User Prompt</description>
            <pubDate>Wed, 02 Jul 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-route53-v6-8-1</guid>
            <title>aws-route53 v6.8.1 - Improved handling of user prompts and updated GraphQL dependencies for the Intelligent Assessment controls</title>
            <link>https://turbot.com/guardrails/changelog/aws-route53-v6-8-1</link>
            <description>_Bug fixes_

- Improved the internal handling of user prompts and updated GraphQL dependencies for the `Intelligent Assessment` controls.</description>
            <pubDate>Wed, 02 Jul 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-redshift-v5-22-0</guid>
            <title>aws-redshift v5.22.0 - Configure Intelligent Assessment controls for dynamic, context-aware resource assessments</title>
            <link>https://turbot.com/guardrails/changelog/aws-redshift-v5-22-0</link>
            <description>_What&apos;s new?_

- You can now use the `Intelligent Assessment` controls, which enables dynamic, context-aware resource assessments and leverages AI capabilities to evaluate cloud resources based on user prompts. To get started, set the `Intelligent Assessment &gt; *` policies.

_Control Types_

- AWS &gt; Redshift &gt; Cluster &gt; Intelligent Assessment
- AWS &gt; Redshift &gt; Cluster Parameter Group &gt; Intelligent Assessment
- AWS &gt; Redshift &gt; Cluster Subnet Group &gt; Intelligent Assessment
- AWS &gt; Redshift &gt; Manual Cluster Snapshot &gt; Intelligent Assessment

_Policy Types_

- AWS &gt; Redshift &gt; Cluster &gt; Intelligent Assessment
- AWS &gt; Redshift &gt; Cluster &gt; Intelligent Assessment &gt; Context
- AWS &gt; Redshift &gt; Cluster &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; Redshift &gt; Cluster Parameter Group &gt; Intelligent Assessment
- AWS &gt; Redshift &gt; Cluster Parameter Group &gt; Intelligent Assessment &gt; Context
- AWS &gt; Redshift &gt; Cluster Parameter Group &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; Redshift &gt; Cluster Subnet Group &gt; Intelligent Assessment
- AWS &gt; Redshift &gt; Cluster Subnet Group &gt; Intelligent Assessment &gt; Context
- AWS &gt; Redshift &gt; Cluster Subnet Group &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; Redshift &gt; Manual Cluster Snapshot &gt; Intelligent Assessment
- AWS &gt; Redshift &gt; Manual Cluster Snapshot &gt; Intelligent Assessment &gt; Context
- AWS &gt; Redshift &gt; Manual Cluster Snapshot &gt; Intelligent Assessment &gt; User Prompt</description>
            <pubDate>Wed, 02 Jul 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-rds-v5-32-0</guid>
            <title>aws-rds v5.32.0 - Configure Intelligent Assessment controls for dynamic, context-aware resource assessments</title>
            <link>https://turbot.com/guardrails/changelog/aws-rds-v5-32-0</link>
            <description>_What&apos;s new?_

- You can now use the `Intelligent Assessment` controls, which enables dynamic, context-aware resource assessments and leverages AI capabilities to evaluate cloud resources based on user prompts. To get started, set the `Intelligent Assessment &gt; *` policies.

_Control Types_

- AWS &gt; RDS &gt; DB Cluster &gt; Intelligent Assessment
- AWS &gt; RDS &gt; DB Cluster Parameter Group &gt; Intelligent Assessment
- AWS &gt; RDS &gt; DB Cluster Snapshot [Manual] &gt; Intelligent Assessment
- AWS &gt; RDS &gt; DB Instance &gt; Intelligent Assessment
- AWS &gt; RDS &gt; DB Parameter Group &gt; Intelligent Assessment
- AWS &gt; RDS &gt; DB Snapshot [Manual] &gt; Intelligent Assessment
- AWS &gt; RDS &gt; Global Cluster &gt; Intelligent Assessment
- AWS &gt; RDS &gt; Option Group &gt; Intelligent Assessment
- AWS &gt; RDS &gt; Subnet Group &gt; Intelligent Assessment

_Policy Types_

- AWS &gt; RDS &gt; DB Cluster &gt; Intelligent Assessment
- AWS &gt; RDS &gt; DB Cluster &gt; Intelligent Assessment &gt; Context
- AWS &gt; RDS &gt; DB Cluster &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; RDS &gt; DB Cluster Parameter Group &gt; Intelligent Assessment
- AWS &gt; RDS &gt; DB Cluster Parameter Group &gt; Intelligent Assessment &gt; Context
- AWS &gt; RDS &gt; DB Cluster Parameter Group &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; RDS &gt; DB Cluster Snapshot [Manual] &gt; Intelligent Assessment
- AWS &gt; RDS &gt; DB Cluster Snapshot [Manual] &gt; Intelligent Assessment &gt; Context
- AWS &gt; RDS &gt; DB Cluster Snapshot [Manual] &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; RDS &gt; DB Instance &gt; Intelligent Assessment
- AWS &gt; RDS &gt; DB Instance &gt; Intelligent Assessment &gt; Context
- AWS &gt; RDS &gt; DB Instance &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; RDS &gt; DB Parameter Group &gt; Intelligent Assessment
- AWS &gt; RDS &gt; DB Parameter Group &gt; Intelligent Assessment &gt; Context
- AWS &gt; RDS &gt; DB Parameter Group &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; RDS &gt; DB Snapshot [Manual] &gt; Intelligent Assessment
- AWS &gt; RDS &gt; DB Snapshot [Manual] &gt; Intelligent Assessment &gt; Context
- AWS &gt; RDS &gt; DB Snapshot [Manual] &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; RDS &gt; Global Cluster &gt; Intelligent Assessment
- AWS &gt; RDS &gt; Global Cluster &gt; Intelligent Assessment &gt; Context
- AWS &gt; RDS &gt; Global Cluster &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; RDS &gt; Option Group &gt; Intelligent Assessment
- AWS &gt; RDS &gt; Option Group &gt; Intelligent Assessment &gt; Context
- AWS &gt; RDS &gt; Option Group &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; RDS &gt; Subnet Group &gt; Intelligent Assessment
- AWS &gt; RDS &gt; Subnet Group &gt; Intelligent Assessment &gt; Context
- AWS &gt; RDS &gt; Subnet Group &gt; Intelligent Assessment &gt; User Prompt</description>
            <pubDate>Wed, 02 Jul 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-organizations-v5-5-0</guid>
            <title>aws-organizations v5.5.0 - Configure Intelligent Assessment controls for dynamic, context-aware resource assessments</title>
            <link>https://turbot.com/guardrails/changelog/aws-organizations-v5-5-0</link>
            <description>_What&apos;s new?_

- You can now use the `Intelligent Assessment` controls, which enables dynamic, context-aware resource assessments and leverages AI capabilities to evaluate cloud resources based on user prompts. To get started, set the `Intelligent Assessment &gt; *` policies.

_Control Types_

- AWS &gt; Organizations &gt; Organization &gt; Intelligent Assessment
- AWS &gt; Organizations &gt; Organization Root &gt; Intelligent Assessment
- AWS &gt; Organizations &gt; Organizational Account &gt; Intelligent Assessment
- AWS &gt; Organizations &gt; Organizational Unit &gt; Intelligent Assessment

_Policy Types_

- AWS &gt; Organizations &gt; Organization &gt; Intelligent Assessment
- AWS &gt; Organizations &gt; Organization &gt; Intelligent Assessment &gt; Context
- AWS &gt; Organizations &gt; Organization &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; Organizations &gt; Organization Root &gt; Intelligent Assessment
- AWS &gt; Organizations &gt; Organization Root &gt; Intelligent Assessment &gt; Context
- AWS &gt; Organizations &gt; Organization Root &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; Organizations &gt; Organizational Account &gt; Intelligent Assessment
- AWS &gt; Organizations &gt; Organizational Account &gt; Intelligent Assessment &gt; Context
- AWS &gt; Organizations &gt; Organizational Account &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; Organizations &gt; Organizational Unit &gt; Intelligent Assessment
- AWS &gt; Organizations &gt; Organizational Unit &gt; Intelligent Assessment &gt; Context
- AWS &gt; Organizations &gt; Organizational Unit &gt; Intelligent Assessment &gt; User Prompt</description>
            <pubDate>Wed, 02 Jul 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-kms-v5-20-1</guid>
            <title>aws-kms v5.20.1 - Improved handling of user prompts and updated GraphQL dependencies for the Intelligent Assessment control</title>
            <link>https://turbot.com/guardrails/changelog/aws-kms-v5-20-1</link>
            <description>_Bug fixes_

- Improved the internal handling of user prompts and updated GraphQL dependencies for the `Intelligent Assessment` control.</description>
            <pubDate>Wed, 02 Jul 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-iam-v5-44-0</guid>
            <title>aws-iam v5.44.0 - Configure Intelligent Assessment controls for dynamic, context-aware resource assessments</title>
            <link>https://turbot.com/guardrails/changelog/aws-iam-v5-44-0</link>
            <description>_What&apos;s new?_

- You can now use the `Intelligent Assessment` controls, which enables dynamic, context-aware resource assessments and leverages AI capabilities to evaluate cloud resources based on user prompts. To get started, set the `Intelligent Assessment &gt; *` policies.

_Control Types_

- AWS &gt; IAM &gt; Access Analyzer &gt; Intelligent Assessment
- AWS &gt; IAM &gt; Access Key &gt; Intelligent Assessment
- AWS &gt; IAM &gt; Account Password Policy &gt; Intelligent Assessment
- AWS &gt; IAM &gt; Account Summary &gt; Intelligent Assessment
- AWS &gt; IAM &gt; Credential Report &gt; Intelligent Assessment
- AWS &gt; IAM &gt; Group &gt; Group Policy Attachments &gt; Intelligent Assessment
- AWS &gt; IAM &gt; Group &gt; Inline Policy &gt; Intelligent Assessment
- AWS &gt; IAM &gt; Group &gt; Intelligent Assessment
- AWS &gt; IAM &gt; Instance Profile &gt; Intelligent Assessment
- AWS &gt; IAM &gt; MFA Virtual &gt; Intelligent Assessment
- AWS &gt; IAM &gt; OpenID Connect &gt; Intelligent Assessment
- AWS &gt; IAM &gt; Policy &gt; Intelligent Assessment
- AWS &gt; IAM &gt; Role &gt; Inline Policy &gt; Intelligent Assessment
- AWS &gt; IAM &gt; Role &gt; Intelligent Assessment
- AWS &gt; IAM &gt; Role &gt; Role Policy Attachments &gt; Intelligent Assessment
- AWS &gt; IAM &gt; Root &gt; Intelligent Assessment
- AWS &gt; IAM &gt; Server Certificate &gt; Intelligent Assessment
- AWS &gt; IAM &gt; User &gt; Group Memberships &gt; Intelligent Assessment
- AWS &gt; IAM &gt; User &gt; Inline Policy &gt; Intelligent Assessment
- AWS &gt; IAM &gt; User &gt; Intelligent Assessment
- AWS &gt; IAM &gt; User &gt; User Policy Attachments &gt; Intelligent Assessment

_Policy Types_

- AWS &gt; IAM &gt; Access Analyzer &gt; Intelligent Assessment
- AWS &gt; IAM &gt; Access Analyzer &gt; Intelligent Assessment &gt; Context
- AWS &gt; IAM &gt; Access Analyzer &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; IAM &gt; Access Key &gt; Intelligent Assessment
- AWS &gt; IAM &gt; Access Key &gt; Intelligent Assessment &gt; Context
- AWS &gt; IAM &gt; Access Key &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; IAM &gt; Account Password Policy &gt; Intelligent Assessment
- AWS &gt; IAM &gt; Account Password Policy &gt; Intelligent Assessment &gt; Context
- AWS &gt; IAM &gt; Account Password Policy &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; IAM &gt; Account Summary &gt; Intelligent Assessment
- AWS &gt; IAM &gt; Account Summary &gt; Intelligent Assessment &gt; Context
- AWS &gt; IAM &gt; Account Summary &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; IAM &gt; Credential Report &gt; Intelligent Assessment
- AWS &gt; IAM &gt; Credential Report &gt; Intelligent Assessment &gt; Context
- AWS &gt; IAM &gt; Credential Report &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; IAM &gt; Group &gt; Group Policy Attachments &gt; Intelligent Assessment
- AWS &gt; IAM &gt; Group &gt; Group Policy Attachments &gt; Intelligent Assessment &gt; Context
- AWS &gt; IAM &gt; Group &gt; Group Policy Attachments &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; IAM &gt; Group &gt; Inline Policy &gt; Intelligent Assessment
- AWS &gt; IAM &gt; Group &gt; Inline Policy &gt; Intelligent Assessment &gt; Context
- AWS &gt; IAM &gt; Group &gt; Inline Policy &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; IAM &gt; Group &gt; Intelligent Assessment
- AWS &gt; IAM &gt; Group &gt; Intelligent Assessment &gt; Context
- AWS &gt; IAM &gt; Group &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; IAM &gt; Instance Profile &gt; Intelligent Assessment
- AWS &gt; IAM &gt; Instance Profile &gt; Intelligent Assessment &gt; Context
- AWS &gt; IAM &gt; Instance Profile &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; IAM &gt; MFA Virtual &gt; Intelligent Assessment
- AWS &gt; IAM &gt; MFA Virtual &gt; Intelligent Assessment &gt; Context
- AWS &gt; IAM &gt; MFA Virtual &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; IAM &gt; OpenID Connect &gt; Intelligent Assessment
- AWS &gt; IAM &gt; OpenID Connect &gt; Intelligent Assessment &gt; Context
- AWS &gt; IAM &gt; OpenID Connect &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; IAM &gt; Policy &gt; Intelligent Assessment
- AWS &gt; IAM &gt; Policy &gt; Intelligent Assessment &gt; Context
- AWS &gt; IAM &gt; Policy &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; IAM &gt; Role &gt; Inline Policy &gt; Intelligent Assessment
- AWS &gt; IAM &gt; Role &gt; Inline Policy &gt; Intelligent Assessment &gt; Context
- AWS &gt; IAM &gt; Role &gt; Inline Policy &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; IAM &gt; Role &gt; Intelligent Assessment
- AWS &gt; IAM &gt; Role &gt; Intelligent Assessment &gt; Context
- AWS &gt; IAM &gt; Role &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; IAM &gt; Role &gt; Role Policy Attachments &gt; Intelligent Assessment
- AWS &gt; IAM &gt; Role &gt; Role Policy Attachments &gt; Intelligent Assessment &gt; Context
- AWS &gt; IAM &gt; Role &gt; Role Policy Attachments &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; IAM &gt; Root &gt; Intelligent Assessment
- AWS &gt; IAM &gt; Root &gt; Intelligent Assessment &gt; Context
- AWS &gt; IAM &gt; Root &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; IAM &gt; Server Certificate &gt; Intelligent Assessment
- AWS &gt; IAM &gt; Server Certificate &gt; Intelligent Assessment &gt; Context
- AWS &gt; IAM &gt; Server Certificate &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; IAM &gt; User &gt; Group Memberships &gt; Intelligent Assessment
- AWS &gt; IAM &gt; User &gt; Group Memberships &gt; Intelligent Assessment &gt; Context
- AWS &gt; IAM &gt; User &gt; Group Memberships &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; IAM &gt; User &gt; Inline Policy &gt; Intelligent Assessment
- AWS &gt; IAM &gt; User &gt; Inline Policy &gt; Intelligent Assessment &gt; Context
- AWS &gt; IAM &gt; User &gt; Inline Policy &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; IAM &gt; User &gt; Intelligent Assessment
- AWS &gt; IAM &gt; User &gt; Intelligent Assessment &gt; Context
- AWS &gt; IAM &gt; User &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; IAM &gt; User &gt; User Policy Attachments &gt; Intelligent Assessment
- AWS &gt; IAM &gt; User &gt; User Policy Attachments &gt; Intelligent Assessment &gt; Context
- AWS &gt; IAM &gt; User &gt; User Policy Attachments &gt; Intelligent Assessment &gt; User Prompt</description>
            <pubDate>Wed, 02 Jul 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-glue-v5-13-0</guid>
            <title>aws-glue v5.13.0 - Configure Intelligent Assessment controls for dynamic, context-aware resource assessments</title>
            <link>https://turbot.com/guardrails/changelog/aws-glue-v5-13-0</link>
            <description>_What&apos;s new?_

- You can now use the `Intelligent Assessment` controls, which enables dynamic, context-aware resource assessments and leverages AI capabilities to evaluate cloud resources based on user prompts. To get started, set the `Intelligent Assessment &gt; *` policies.

_Control Types_

- AWS &gt; Glue &gt; Crawler &gt; Intelligent Assessment
- AWS &gt; Glue &gt; Data Catalog &gt; Intelligent Assessment
- AWS &gt; Glue &gt; Database &gt; Intelligent Assessment
- AWS &gt; Glue &gt; Job &gt; Intelligent Assessment
- AWS &gt; Glue &gt; ML Transform &gt; Intelligent Assessment
- AWS &gt; Glue &gt; Security Configuration &gt; Intelligent Assessment
- AWS &gt; Glue &gt; Table &gt; Intelligent Assessment
- AWS &gt; Glue &gt; Trigger &gt; Intelligent Assessment
- AWS &gt; Glue &gt; Workflow &gt; Intelligent Assessment

_Policy Types_

- AWS &gt; Glue &gt; Crawler &gt; Intelligent Assessment
- AWS &gt; Glue &gt; Crawler &gt; Intelligent Assessment &gt; Context
- AWS &gt; Glue &gt; Crawler &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; Glue &gt; Data Catalog &gt; Intelligent Assessment
- AWS &gt; Glue &gt; Data Catalog &gt; Intelligent Assessment &gt; Context
- AWS &gt; Glue &gt; Data Catalog &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; Glue &gt; Database &gt; Intelligent Assessment
- AWS &gt; Glue &gt; Database &gt; Intelligent Assessment &gt; Context
- AWS &gt; Glue &gt; Database &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; Glue &gt; Job &gt; Intelligent Assessment
- AWS &gt; Glue &gt; Job &gt; Intelligent Assessment &gt; Context
- AWS &gt; Glue &gt; Job &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; Glue &gt; ML Transform &gt; Intelligent Assessment
- AWS &gt; Glue &gt; ML Transform &gt; Intelligent Assessment &gt; Context
- AWS &gt; Glue &gt; ML Transform &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; Glue &gt; Security Configuration &gt; Intelligent Assessment
- AWS &gt; Glue &gt; Security Configuration &gt; Intelligent Assessment &gt; Context
- AWS &gt; Glue &gt; Security Configuration &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; Glue &gt; Table &gt; Intelligent Assessment
- AWS &gt; Glue &gt; Table &gt; Intelligent Assessment &gt; Context
- AWS &gt; Glue &gt; Table &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; Glue &gt; Trigger &gt; Intelligent Assessment
- AWS &gt; Glue &gt; Trigger &gt; Intelligent Assessment &gt; Context
- AWS &gt; Glue &gt; Trigger &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; Glue &gt; Workflow &gt; Intelligent Assessment
- AWS &gt; Glue &gt; Workflow &gt; Intelligent Assessment &gt; Context
- AWS &gt; Glue &gt; Workflow &gt; Intelligent Assessment &gt; User Prompt</description>
            <pubDate>Wed, 02 Jul 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-dynamodb-v5-15-1</guid>
            <title>aws-dynamodb v5.15.1 - Improved handling of user prompts and updated GraphQL dependencies for the Intelligent Assessment controls</title>
            <link>https://turbot.com/guardrails/changelog/aws-dynamodb-v5-15-1</link>
            <description>_Bug fixes_

- Improved the internal handling of user prompts and updated GraphQL dependencies for the `Intelligent Assessment` controls.</description>
            <pubDate>Wed, 02 Jul 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-directconnect-v5-6-1</guid>
            <title>aws-directconnect v5.6.1 - Improved handling of user prompts and updated GraphQL dependencies for the Intelligent Assessment controls</title>
            <link>https://turbot.com/guardrails/changelog/aws-directconnect-v5-6-1</link>
            <description>_Bug fixes_

- Improved the internal handling of user prompts and updated GraphQL dependencies for the `Intelligent Assessment` controls.</description>
            <pubDate>Wed, 02 Jul 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-cloudtrail-v5-13-0</guid>
            <title>aws-cloudtrail v5.13.0 - Configure Intelligent Assessment controls for dynamic, context-aware resource assessments</title>
            <link>https://turbot.com/guardrails/changelog/aws-cloudtrail-v5-13-0</link>
            <description>_What&apos;s new?_

- You can now use the `Intelligent Assessment` controls, which enables dynamic, context-aware resource assessments and leverages AI capabilities to evaluate cloud resources based on user prompts. To get started, set the `Intelligent Assessment &gt; *` policies.

_Control Types_

- AWS &gt; CloudTrail &gt; Shadow Trail &gt; Intelligent Assessment
- AWS &gt; CloudTrail &gt; Trail &gt; Intelligent Assessment

_Policy Types_

- AWS &gt; CloudTrail &gt; Shadow Trail &gt; Intelligent Assessment
- AWS &gt; CloudTrail &gt; Shadow Trail &gt; Intelligent Assessment &gt; Context
- AWS &gt; CloudTrail &gt; Shadow Trail &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; CloudTrail &gt; Trail &gt; Intelligent Assessment
- AWS &gt; CloudTrail &gt; Trail &gt; Intelligent Assessment &gt; Context
- AWS &gt; CloudTrail &gt; Trail &gt; Intelligent Assessment &gt; User Prompt</description>
            <pubDate>Wed, 02 Jul 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-backup-v5-13-1</guid>
            <title>aws-backup v5.13.1 - Improved handling of user prompts and updated GraphQL dependencies for the Intelligent Assessment controls</title>
            <link>https://turbot.com/guardrails/changelog/aws-backup-v5-13-1</link>
            <description>_Bug fixes_

- Improved the internal handling of user prompts and updated GraphQL dependencies for the `Intelligent Assessment` controls.</description>
            <pubDate>Wed, 02 Jul 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-dataproc-v5-10-0</guid>
            <title>gcp-dataproc v5.10.0 - Configure Intelligent Assessment controls for dynamic, context-aware resource assessments</title>
            <link>https://turbot.com/guardrails/changelog/gcp-dataproc-v5-10-0</link>
            <description>_What&apos;s new?_

- You can now use the `Intelligent Assessment` controls, which enables dynamic, context-aware resource assessments and leverages AI capabilities to evaluate cloud resources based on user prompts. To get started, set the `Intelligent Assessment &gt; *` policies.

_Control Types_

- GCP &gt; Dataproc &gt; Cluster &gt; Intelligent Assessment
- GCP &gt; Dataproc &gt; Job &gt; Intelligent Assessment
- GCP &gt; Dataproc &gt; Workflow Template &gt; Intelligent Assessment

_Policy Types_

- GCP &gt; Dataproc &gt; Cluster &gt; Intelligent Assessment
- GCP &gt; Dataproc &gt; Cluster &gt; Intelligent Assessment &gt; Context
- GCP &gt; Dataproc &gt; Cluster &gt; Intelligent Assessment &gt; User Prompt
- GCP &gt; Dataproc &gt; Job &gt; Intelligent Assessment
- GCP &gt; Dataproc &gt; Job &gt; Intelligent Assessment &gt; Context
- GCP &gt; Dataproc &gt; Job &gt; Intelligent Assessment &gt; User Prompt
- GCP &gt; Dataproc &gt; Workflow Template &gt; Intelligent Assessment
- GCP &gt; Dataproc &gt; Workflow Template &gt; Intelligent Assessment &gt; Context
- GCP &gt; Dataproc &gt; Workflow Template &gt; Intelligent Assessment &gt; User Prompt</description>
            <pubDate>Tue, 01 Jul 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-v5-31-0</guid>
            <title>azure v5.31.0 - Configure Intelligent Assessment controls for dynamic, context-aware resource assessments</title>
            <link>https://turbot.com/guardrails/changelog/azure-v5-31-0</link>
            <description>_What&apos;s new?_

- You can now use the `Intelligent Assessment` controls, which enables dynamic, context-aware resource assessments and leverages AI capabilities to evaluate cloud resources based on user prompts. To get started, set the `Intelligent Assessment &gt; *` policies.

_Control Types_

- Azure &gt; Management Group &gt; Intelligent Assessment
- Azure &gt; Resource Group &gt; Intelligent Assessment
- Azure &gt; Subscription &gt; Intelligent Assessment
- Azure &gt; Tenant &gt; Intelligent Assessment

_Policy Types_

- Azure &gt; Management Group &gt; Intelligent Assessment
- Azure &gt; Management Group &gt; Intelligent Assessment &gt; Context
- Azure &gt; Management Group &gt; Intelligent Assessment &gt; User Prompt
- Azure &gt; Resource Group &gt; Intelligent Assessment
- Azure &gt; Resource Group &gt; Intelligent Assessment &gt; Context
- Azure &gt; Resource Group &gt; Intelligent Assessment &gt; User Prompt
- Azure &gt; Subscription &gt; Intelligent Assessment
- Azure &gt; Subscription &gt; Intelligent Assessment &gt; Context
- Azure &gt; Subscription &gt; Intelligent Assessment &gt; User Prompt
- Azure &gt; Tenant &gt; Intelligent Assessment
- Azure &gt; Tenant &gt; Intelligent Assessment &gt; Context
- Azure &gt; Tenant &gt; Intelligent Assessment &gt; User Prompt</description>
            <pubDate>Tue, 01 Jul 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-v5-38-0</guid>
            <title>aws v5.38.0 - Configure Intelligent Assessment controls for dynamic, context-aware resource assessments</title>
            <link>https://turbot.com/guardrails/changelog/aws-v5-38-0</link>
            <description>_What&apos;s new?_

- You can now use the `Intelligent Assessment` controls, which enables dynamic, context-aware resource assessments and leverages AI capabilities to evaluate cloud resources based on user prompts. To get started, set the `Intelligent Assessment &gt; *` policies.

_Control Types_

- AWS &gt; Account &gt; Intelligent Assessment
- AWS &gt; Organization &gt; Intelligent Assessment
- AWS &gt; Organization Root &gt; Intelligent Assessment
- AWS &gt; Organizational Unit &gt; Intelligent Assessment

_Policy Types_

- AWS &gt; Account &gt; Intelligent Assessment
- AWS &gt; Account &gt; Intelligent Assessment &gt; Context
- AWS &gt; Account &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; Organization &gt; Intelligent Assessment
- AWS &gt; Organization &gt; Intelligent Assessment &gt; Context
- AWS &gt; Organization &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; Organization Root &gt; Intelligent Assessment
- AWS &gt; Organization Root &gt; Intelligent Assessment &gt; Context
- AWS &gt; Organization Root &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; Organizational Unit &gt; Intelligent Assessment
- AWS &gt; Organizational Unit &gt; Intelligent Assessment &gt; Context
- AWS &gt; Organizational Unit &gt; Intelligent Assessment &gt; User Prompt</description>
            <pubDate>Tue, 01 Jul 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-cloudwatch-v5-11-1</guid>
            <title>aws-cloudwatch v5.11.1 - Improved handling of user prompts and updated GraphQL dependencies for the Intelligent Assessment control</title>
            <link>https://turbot.com/guardrails/changelog/aws-cloudwatch-v5-11-1</link>
            <description>_Bug fixes_

- Improved the internal handling of user prompts and updated GraphQL dependencies for the `Intelligent Assessment` control.</description>
            <pubDate>Tue, 01 Jul 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-apigateway-v5-12-0</guid>
            <title>aws-apigateway v5.12.0 - Configure Intelligent Assessment controls for dynamic, context-aware resource assessments</title>
            <link>https://turbot.com/guardrails/changelog/aws-apigateway-v5-12-0</link>
            <description>_What&apos;s new?_

- You can now use the `Intelligent Assessment` controls, which enables dynamic, context-aware resource assessments and leverages AI capabilities to evaluate cloud resources based on user prompts. To get started, set the `Intelligent Assessment &gt; *` policies.

_Control Types_

- AWS &gt; API Gateway &gt; API &gt; Intelligent Assessment
- AWS &gt; API Gateway &gt; API Key &gt; Intelligent Assessment
- AWS &gt; API Gateway &gt; API V2 &gt; Intelligent Assessment
- AWS &gt; API Gateway &gt; Account &gt; Intelligent Assessment
- AWS &gt; API Gateway &gt; Authorizer &gt; Intelligent Assessment
- AWS &gt; API Gateway &gt; Authorizer V2 &gt; Intelligent Assessment
- AWS &gt; API Gateway &gt; Domain Name V2 &gt; Intelligent Assessment
- AWS &gt; API Gateway &gt; Integration V2 &gt; Intelligent Assessment
- AWS &gt; API Gateway &gt; Resource &gt; Intelligent Assessment
- AWS &gt; API Gateway &gt; Stage &gt; Intelligent Assessment
- AWS &gt; API Gateway &gt; Stage v2 &gt; Intelligent Assessment
- AWS &gt; API Gateway &gt; Usage Plan &gt; Intelligent Assessment

_Policy Types_

- AWS &gt; API Gateway &gt; API &gt; Intelligent Assessment
- AWS &gt; API Gateway &gt; API &gt; Intelligent Assessment &gt; Context
- AWS &gt; API Gateway &gt; API &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; API Gateway &gt; API Key &gt; Intelligent Assessment
- AWS &gt; API Gateway &gt; API Key &gt; Intelligent Assessment &gt; Context
- AWS &gt; API Gateway &gt; API Key &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; API Gateway &gt; API V2 &gt; Intelligent Assessment
- AWS &gt; API Gateway &gt; API V2 &gt; Intelligent Assessment &gt; Context
- AWS &gt; API Gateway &gt; API V2 &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; API Gateway &gt; Account &gt; Intelligent Assessment
- AWS &gt; API Gateway &gt; Account &gt; Intelligent Assessment &gt; Context
- AWS &gt; API Gateway &gt; Account &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; API Gateway &gt; Authorizer &gt; Intelligent Assessment
- AWS &gt; API Gateway &gt; Authorizer &gt; Intelligent Assessment &gt; Context
- AWS &gt; API Gateway &gt; Authorizer &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; API Gateway &gt; Authorizer V2 &gt; Intelligent Assessment
- AWS &gt; API Gateway &gt; Authorizer V2 &gt; Intelligent Assessment &gt; Context
- AWS &gt; API Gateway &gt; Authorizer V2 &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; API Gateway &gt; Domain Name V2 &gt; Intelligent Assessment
- AWS &gt; API Gateway &gt; Domain Name V2 &gt; Intelligent Assessment &gt; Context
- AWS &gt; API Gateway &gt; Domain Name V2 &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; API Gateway &gt; Integration V2 &gt; Intelligent Assessment
- AWS &gt; API Gateway &gt; Integration V2 &gt; Intelligent Assessment &gt; Context
- AWS &gt; API Gateway &gt; Integration V2 &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; API Gateway &gt; Resource &gt; Intelligent Assessment
- AWS &gt; API Gateway &gt; Resource &gt; Intelligent Assessment &gt; Context
- AWS &gt; API Gateway &gt; Resource &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; API Gateway &gt; Stage &gt; Intelligent Assessment
- AWS &gt; API Gateway &gt; Stage &gt; Intelligent Assessment &gt; Context
- AWS &gt; API Gateway &gt; Stage &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; API Gateway &gt; Stage v2 &gt; Intelligent Assessment
- AWS &gt; API Gateway &gt; Stage v2 &gt; Intelligent Assessment &gt; Context
- AWS &gt; API Gateway &gt; Stage v2 &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; API Gateway &gt; Usage Plan &gt; Intelligent Assessment
- AWS &gt; API Gateway &gt; Usage Plan &gt; Intelligent Assessment &gt; Context
- AWS &gt; API Gateway &gt; Usage Plan &gt; Intelligent Assessment &gt; User Prompt</description>
            <pubDate>Tue, 01 Jul 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-68-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.68.0 - Added support for PgBouncer</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-68-0</link>
            <description>_What&apos;s new?_

- Workspace Manager can now access log buckets encrypted with customer-managed KMS keys, improving support for secure logging setups.
- The initial setup for PgBouncer support is now available. When enabled, the stack automatically creates the networking and discovery components—like Security Groups and CloudMap—needed for PgBouncer to work.</description>
            <pubDate>Mon, 30 Jun 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/ted-v1-50-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.50.0 -	Support for PgBouncer and Valkey now available</title>
            <link>https://turbot.com/guardrails/changelog/ted-v1-50-0</link>
            <description>_What&apos;s new?_

- PgBouncer support is now available.
- Support for Valkey has been introduced, offering a simpler and more cost-effective option than Redis.

_PgBouncer_

PgBouncer support has been introduced to improve database connection efficiency through lightweight connection pooling. This enhancement benefits high-throughput environments by reducing the overhead of frequent PostgreSQL connections.

Minimum version requirements:

- TE v5.52.0
- TEF v1.68.0
- TED v1.50.0</description>
            <pubDate>Mon, 30 Jun 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-52-0</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.52.0 - Introduced AI-Powered control remediation steps and policy pack summary</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-52-0</link>
            <description>_What&apos;s new?_

- Server
  - Introduced a new GraphQL resolver that generates AI-driven remediation steps for controls.

- UI
  - Enhanced the UI to display AI-generated remediation steps within the control details view.
  - Added a summary view to the UI for Policy Packs to provide a quick overview of key settings.

_Note_

Upgrade to `5.52.0` requires your workspace to be on `5.51.x`; direct upgrades from older versions (e.g., 5.49.x) will fail.

_Requirements_

- TEF: 1.66.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Mon, 30 Jun 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-storage-v5-13-0</guid>
            <title>gcp-storage v5.13.0 - Configure Intelligent Assessment controls for dynamic, context-aware resource assessments</title>
            <link>https://turbot.com/guardrails/changelog/gcp-storage-v5-13-0</link>
            <description>_What&apos;s new?_

- You can now use the `Intelligent Assessment` controls, which enables dynamic, context-aware resource assessments and leverages AI capabilities to evaluate cloud resources based on user prompts. To get started, set the `Intelligent Assessment &gt; *` policies.

_Control Types_

- GCP &gt; Storage &gt; Bucket &gt; Intelligent Assessment
- GCP &gt; Storage &gt; Object &gt; Intelligent Assessment

_Policy Types_

- GCP &gt; Storage &gt; Bucket &gt; Intelligent Assessment
- GCP &gt; Storage &gt; Bucket &gt; Intelligent Assessment &gt; Context
- GCP &gt; Storage &gt; Bucket &gt; Intelligent Assessment &gt; User Prompt
- GCP &gt; Storage &gt; Object &gt; Intelligent Assessment
- GCP &gt; Storage &gt; Object &gt; Intelligent Assessment &gt; Context
- GCP &gt; Storage &gt; Object &gt; Intelligent Assessment &gt; User Prompt</description>
            <pubDate>Mon, 30 Jun 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-iam-v5-18-0</guid>
            <title>gcp-iam v5.18.0 - Configure Intelligent Assessment controls for dynamic, context-aware resource assessments</title>
            <link>https://turbot.com/guardrails/changelog/gcp-iam-v5-18-0</link>
            <description>_What&apos;s new?_

- You can now use the `Intelligent Assessment` controls, which enables dynamic, context-aware resource assessments and leverages AI capabilities to evaluate cloud resources based on user prompts. To get started, set the `Intelligent Assessment &gt; *` policies.

_Bug fixes_

- We have improved the internal handling of user prompts to ensure better and more consistent evaluations for the Intelligent Assessment control(s).

_Control Types_

- GCP &gt; IAM &gt; API Key &gt; Intelligent Assessment
- GCP &gt; IAM &gt; Project Role &gt; Intelligent Assessment
- GCP &gt; IAM &gt; Project User &gt; Intelligent Assessment
- GCP &gt; IAM &gt; Service Account &gt; Intelligent Assessment
- GCP &gt; IAM &gt; Service Account Key &gt; Intelligent Assessment
- GCP &gt; Project &gt; Policy &gt; Intelligent Assessment

_Policy Types_

- GCP &gt; IAM &gt; API Key &gt; Intelligent Assessment
- GCP &gt; IAM &gt; API Key &gt; Intelligent Assessment &gt; Context
- GCP &gt; IAM &gt; API Key &gt; Intelligent Assessment &gt; User Prompt
- GCP &gt; IAM &gt; Project Role &gt; Intelligent Assessment
- GCP &gt; IAM &gt; Project Role &gt; Intelligent Assessment &gt; Context
- GCP &gt; IAM &gt; Project Role &gt; Intelligent Assessment &gt; User Prompt
- GCP &gt; IAM &gt; Project User &gt; Intelligent Assessment
- GCP &gt; IAM &gt; Project User &gt; Intelligent Assessment &gt; Context
- GCP &gt; IAM &gt; Project User &gt; Intelligent Assessment &gt; User Prompt
- GCP &gt; IAM &gt; Service Account &gt; Intelligent Assessment
- GCP &gt; IAM &gt; Service Account &gt; Intelligent Assessment &gt; Context
- GCP &gt; IAM &gt; Service Account &gt; Intelligent Assessment &gt; User Prompt
- GCP &gt; IAM &gt; Service Account Key &gt; Intelligent Assessment
- GCP &gt; IAM &gt; Service Account Key &gt; Intelligent Assessment &gt; Context
- GCP &gt; IAM &gt; Service Account Key &gt; Intelligent Assessment &gt; User Prompt
- GCP &gt; Project &gt; Policy &gt; Intelligent Assessment
- GCP &gt; Project &gt; Policy &gt; Intelligent Assessment &gt; Context
- GCP &gt; Project &gt; Policy &gt; Intelligent Assessment &gt; User Prompt</description>
            <pubDate>Mon, 30 Jun 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-functions-v5-10-1</guid>
            <title>gcp-functions v5.10.1 - Improved handling of user prompts and updated GraphQL dependencies for the Intelligent Assessment controls</title>
            <link>https://turbot.com/guardrails/changelog/gcp-functions-v5-10-1</link>
            <description>_Bug fixes_

- We have improved the internal handling of user prompts to ensure better and more consistent evaluations for the Intelligent Assessment controls.</description>
            <pubDate>Mon, 30 Jun 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-computeengine-v5-21-0</guid>
            <title>gcp-computeengine v5.21.0 - Configure Intelligent Assessment controls for dynamic, context-aware resource assessments</title>
            <link>https://turbot.com/guardrails/changelog/gcp-computeengine-v5-21-0</link>
            <description>_What&apos;s new?_

- You can now use the `Intelligent Assessment` controls, which enables dynamic, context-aware resource assessments and leverages AI capabilities to evaluate cloud resources based on user prompts. To get started, set the `Intelligent Assessment &gt; *` policies.

_Control Types_

- GCP &gt; Compute Engine &gt; Disk &gt; Intelligent Assessment
- GCP &gt; Compute Engine &gt; HTTP Health Check &gt; Intelligent Assessment
- GCP &gt; Compute Engine &gt; HTTPS Health Check &gt; Intelligent Assessment
- GCP &gt; Compute Engine &gt; Health Check &gt; Intelligent Assessment
- GCP &gt; Compute Engine &gt; Image &gt; Intelligent Assessment
- GCP &gt; Compute Engine &gt; Instance &gt; Intelligent Assessment
- GCP &gt; Compute Engine &gt; Instance Template &gt; Intelligent Assessment
- GCP &gt; Compute Engine &gt; Node Group &gt; Intelligent Assessment
- GCP &gt; Compute Engine &gt; Node template &gt; Intelligent Assessment
- GCP &gt; Compute Engine &gt; Project &gt; Intelligent Assessment
- GCP &gt; Compute Engine &gt; Region Disk &gt; Intelligent Assessment
- GCP &gt; Compute Engine &gt; Region Health Check &gt; Intelligent Assessment
- GCP &gt; Compute Engine &gt; Snapshot &gt; Intelligent Assessment

_Policy Types_

- GCP &gt; Compute Engine &gt; Disk &gt; Intelligent Assessment
- GCP &gt; Compute Engine &gt; Disk &gt; Intelligent Assessment &gt; Context
- GCP &gt; Compute Engine &gt; Disk &gt; Intelligent Assessment &gt; User Prompt
- GCP &gt; Compute Engine &gt; HTTP Health Check &gt; Intelligent Assessment
- GCP &gt; Compute Engine &gt; HTTP Health Check &gt; Intelligent Assessment &gt; Context
- GCP &gt; Compute Engine &gt; HTTP Health Check &gt; Intelligent Assessment &gt; User Prompt
- GCP &gt; Compute Engine &gt; HTTPS Health Check &gt; Intelligent Assessment
- GCP &gt; Compute Engine &gt; HTTPS Health Check &gt; Intelligent Assessment &gt; Context
- GCP &gt; Compute Engine &gt; HTTPS Health Check &gt; Intelligent Assessment &gt; User Prompt
- GCP &gt; Compute Engine &gt; Health Check &gt; Intelligent Assessment
- GCP &gt; Compute Engine &gt; Health Check &gt; Intelligent Assessment &gt; Context
- GCP &gt; Compute Engine &gt; Health Check &gt; Intelligent Assessment &gt; User Prompt
- GCP &gt; Compute Engine &gt; Image &gt; Intelligent Assessment
- GCP &gt; Compute Engine &gt; Image &gt; Intelligent Assessment &gt; Context
- GCP &gt; Compute Engine &gt; Image &gt; Intelligent Assessment &gt; User Prompt
- GCP &gt; Compute Engine &gt; Instance &gt; Intelligent Assessment
- GCP &gt; Compute Engine &gt; Instance &gt; Intelligent Assessment &gt; Context
- GCP &gt; Compute Engine &gt; Instance &gt; Intelligent Assessment &gt; User Prompt
- GCP &gt; Compute Engine &gt; Instance Template &gt; Intelligent Assessment
- GCP &gt; Compute Engine &gt; Instance Template &gt; Intelligent Assessment &gt; Context
- GCP &gt; Compute Engine &gt; Instance Template &gt; Intelligent Assessment &gt; User Prompt
- GCP &gt; Compute Engine &gt; Node Group &gt; Intelligent Assessment
- GCP &gt; Compute Engine &gt; Node Group &gt; Intelligent Assessment &gt; Context
- GCP &gt; Compute Engine &gt; Node Group &gt; Intelligent Assessment &gt; User Prompt
- GCP &gt; Compute Engine &gt; Node template &gt; Intelligent Assessment
- GCP &gt; Compute Engine &gt; Node template &gt; Intelligent Assessment &gt; Context
- GCP &gt; Compute Engine &gt; Node template &gt; Intelligent Assessment &gt; User Prompt
- GCP &gt; Compute Engine &gt; Project &gt; Intelligent Assessment
- GCP &gt; Compute Engine &gt; Project &gt; Intelligent Assessment &gt; Context
- GCP &gt; Compute Engine &gt; Project &gt; Intelligent Assessment &gt; User Prompt
- GCP &gt; Compute Engine &gt; Region Disk &gt; Intelligent Assessment
- GCP &gt; Compute Engine &gt; Region Disk &gt; Intelligent Assessment &gt; Context
- GCP &gt; Compute Engine &gt; Region Disk &gt; Intelligent Assessment &gt; User Prompt
- GCP &gt; Compute Engine &gt; Region Health Check &gt; Intelligent Assessment
- GCP &gt; Compute Engine &gt; Region Health Check &gt; Intelligent Assessment &gt; Context
- GCP &gt; Compute Engine &gt; Region Health Check &gt; Intelligent Assessment &gt; User Prompt
- GCP &gt; Compute Engine &gt; Snapshot &gt; Intelligent Assessment
- GCP &gt; Compute Engine &gt; Snapshot &gt; Intelligent Assessment &gt; Context
- GCP &gt; Compute Engine &gt; Snapshot &gt; Intelligent Assessment &gt; User Prompt</description>
            <pubDate>Mon, 30 Jun 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-storage-v5-24-0</guid>
            <title>azure-storage v5.24.0 - Configure Intelligent Assessment controls for dynamic, context-aware resource assessments</title>
            <link>https://turbot.com/guardrails/changelog/azure-storage-v5-24-0</link>
            <description>_What&apos;s new?_

- You can now use the `Intelligent Assessment` controls, which enables dynamic, context-aware resource assessments and leverages AI capabilities to evaluate cloud resources based on user prompts. To get started, set the `Intelligent Assessment &gt; *` policies.

_Control Types_

- Azure &gt; Storage &gt; Access Key &gt; Intelligent Assessment
- Azure &gt; Storage &gt; Container &gt; Intelligent Assessment
- Azure &gt; Storage &gt; FileShare &gt; Intelligent Assessment
- Azure &gt; Storage &gt; Queue &gt; Intelligent Assessment
- Azure &gt; Storage &gt; Storage Account &gt; Intelligent Assessment

_Policy Types_

- Azure &gt; Storage &gt; Access Key &gt; Intelligent Assessment
- Azure &gt; Storage &gt; Access Key &gt; Intelligent Assessment &gt; Context
- Azure &gt; Storage &gt; Access Key &gt; Intelligent Assessment &gt; User Prompt
- Azure &gt; Storage &gt; Container &gt; Intelligent Assessment
- Azure &gt; Storage &gt; Container &gt; Intelligent Assessment &gt; Context
- Azure &gt; Storage &gt; Container &gt; Intelligent Assessment &gt; User Prompt
- Azure &gt; Storage &gt; FileShare &gt; Intelligent Assessment
- Azure &gt; Storage &gt; FileShare &gt; Intelligent Assessment &gt; Context
- Azure &gt; Storage &gt; FileShare &gt; Intelligent Assessment &gt; User Prompt
- Azure &gt; Storage &gt; Queue &gt; Intelligent Assessment
- Azure &gt; Storage &gt; Queue &gt; Intelligent Assessment &gt; Context
- Azure &gt; Storage &gt; Queue &gt; Intelligent Assessment &gt; User Prompt
- Azure &gt; Storage &gt; Storage Account &gt; Intelligent Assessment
- Azure &gt; Storage &gt; Storage Account &gt; Intelligent Assessment &gt; Context
- Azure &gt; Storage &gt; Storage Account &gt; Intelligent Assessment &gt; User Prompt</description>
            <pubDate>Mon, 30 Jun 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-iam-v5-15-0</guid>
            <title>azure-iam v5.15.0 - Configure Intelligent Assessment controls for dynamic, context-aware resource assessments</title>
            <link>https://turbot.com/guardrails/changelog/azure-iam-v5-15-0</link>
            <description>_What&apos;s new?_

- You can now use the `Intelligent Assessment` controls, which enables dynamic, context-aware resource assessments and leverages AI capabilities to evaluate cloud resources based on user prompts. To get started, set the `Intelligent Assessment &gt; *` policies.

_Control Types_

- Azure &gt; IAM &gt; Role Assignment &gt; Intelligent Assessment
- Azure &gt; IAM &gt; Role Definition &gt; Intelligent Assessment

_Policy Types_

- Azure &gt; IAM &gt; Role Assignment &gt; Intelligent Assessment
- Azure &gt; IAM &gt; Role Assignment &gt; Intelligent Assessment &gt; Context
- Azure &gt; IAM &gt; Role Assignment &gt; Intelligent Assessment &gt; User Prompt
- Azure &gt; IAM &gt; Role Definition &gt; Intelligent Assessment
- Azure &gt; IAM &gt; Role Definition &gt; Intelligent Assessment &gt; Context
- Azure &gt; IAM &gt; Role Definition &gt; Intelligent Assessment &gt; User Prompt</description>
            <pubDate>Mon, 30 Jun 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-compute-v5-23-0</guid>
            <title>azure-compute v5.23.0 - Configure Intelligent Assessment controls for dynamic, context-aware resource assessments</title>
            <link>https://turbot.com/guardrails/changelog/azure-compute-v5-23-0</link>
            <description>_What&apos;s new?_

- You can now use the `Intelligent Assessment` controls, which enables dynamic, context-aware resource assessments and leverages AI capabilities to evaluate cloud resources based on user prompts. To get started, set the `Intelligent Assessment &gt; *` policies.

_Control Types_

- Azure &gt; Compute &gt; Availability Set &gt; Intelligent Assessment
- Azure &gt; Compute &gt; Disk &gt; Intelligent Assessment
- Azure &gt; Compute &gt; Disk Encryption Set &gt; Intelligent Assessment
- Azure &gt; Compute &gt; Image &gt; Intelligent Assessment
- Azure &gt; Compute &gt; Snapshot &gt; Intelligent Assessment
- Azure &gt; Compute &gt; Ssh Public Key &gt; Intelligent Assessment
- Azure &gt; Compute &gt; Virtual Machine &gt; Intelligent Assessment
- Azure &gt; Compute &gt; Virtual Machine Scale Set &gt; Intelligent Assessment

_Policy Types_

- Azure &gt; Compute &gt; Availability Set &gt; Intelligent Assessment
- Azure &gt; Compute &gt; Availability Set &gt; Intelligent Assessment &gt; Context
- Azure &gt; Compute &gt; Availability Set &gt; Intelligent Assessment &gt; User Prompt
- Azure &gt; Compute &gt; Disk &gt; Intelligent Assessment
- Azure &gt; Compute &gt; Disk &gt; Intelligent Assessment &gt; Context
- Azure &gt; Compute &gt; Disk &gt; Intelligent Assessment &gt; User Prompt
- Azure &gt; Compute &gt; Disk Encryption Set &gt; Intelligent Assessment
- Azure &gt; Compute &gt; Disk Encryption Set &gt; Intelligent Assessment &gt; Context
- Azure &gt; Compute &gt; Disk Encryption Set &gt; Intelligent Assessment &gt; User Prompt
- Azure &gt; Compute &gt; Image &gt; Intelligent Assessment
- Azure &gt; Compute &gt; Image &gt; Intelligent Assessment &gt; Context
- Azure &gt; Compute &gt; Image &gt; Intelligent Assessment &gt; User Prompt
- Azure &gt; Compute &gt; Snapshot &gt; Intelligent Assessment
- Azure &gt; Compute &gt; Snapshot &gt; Intelligent Assessment &gt; Context
- Azure &gt; Compute &gt; Snapshot &gt; Intelligent Assessment &gt; User Prompt
- Azure &gt; Compute &gt; Ssh Public Key &gt; Intelligent Assessment
- Azure &gt; Compute &gt; Ssh Public Key &gt; Intelligent Assessment &gt; Context
- Azure &gt; Compute &gt; Ssh Public Key &gt; Intelligent Assessment &gt; User Prompt
- Azure &gt; Compute &gt; Virtual Machine &gt; Intelligent Assessment
- Azure &gt; Compute &gt; Virtual Machine &gt; Intelligent Assessment &gt; Context
- Azure &gt; Compute &gt; Virtual Machine &gt; Intelligent Assessment &gt; User Prompt
- Azure &gt; Compute &gt; Virtual Machine Scale Set &gt; Intelligent Assessment
- Azure &gt; Compute &gt; Virtual Machine Scale Set &gt; Intelligent Assessment &gt; Context
- Azure &gt; Compute &gt; Virtual Machine Scale Set &gt; Intelligent Assessment &gt; User Prompt</description>
            <pubDate>Mon, 30 Jun 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-vpc-security-v5-14-0</guid>
            <title>aws-vpc-security v5.14.0 - Configure Intelligent Assessment controls for dynamic, context-aware resource assessments</title>
            <link>https://turbot.com/guardrails/changelog/aws-vpc-security-v5-14-0</link>
            <description>_What&apos;s new?_

- You can now use the `Intelligent Assessment` controls, which enables dynamic, context-aware resource assessments and leverages AI capabilities to evaluate cloud resources based on user prompts. To get started, set the `Intelligent Assessment &gt; *` policies.

_Control Types_

- AWS &gt; VPC &gt; Flow Log &gt; Intelligent Assessment
- AWS &gt; VPC &gt; Network ACL &gt; Intelligent Assessment
- AWS &gt; VPC &gt; Security Group &gt; Intelligent Assessment
- AWS &gt; VPC &gt; Security Group Rule &gt; Intelligent Assessment

_Policy Types_

- AWS &gt; VPC &gt; Flow Log &gt; Intelligent Assessment
- AWS &gt; VPC &gt; Flow Log &gt; Intelligent Assessment &gt; Context
- AWS &gt; VPC &gt; Flow Log &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; VPC &gt; Network ACL &gt; Intelligent Assessment
- AWS &gt; VPC &gt; Network ACL &gt; Intelligent Assessment &gt; Context
- AWS &gt; VPC &gt; Network ACL &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; VPC &gt; Security Group &gt; Intelligent Assessment
- AWS &gt; VPC &gt; Security Group &gt; Intelligent Assessment &gt; Context
- AWS &gt; VPC &gt; Security Group &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; VPC &gt; Security Group Rule &gt; Intelligent Assessment
- AWS &gt; VPC &gt; Security Group Rule &gt; Intelligent Assessment &gt; Context
- AWS &gt; VPC &gt; Security Group Rule &gt; Intelligent Assessment &gt; User Prompt</description>
            <pubDate>Mon, 30 Jun 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-vpc-internet-v5-13-0</guid>
            <title>aws-vpc-internet v5.13.0 - Configure Intelligent Assessment controls for dynamic, context-aware resource assessments</title>
            <link>https://turbot.com/guardrails/changelog/aws-vpc-internet-v5-13-0</link>
            <description>_What&apos;s new?_

- You can now use the `Intelligent Assessment` controls, which enables dynamic, context-aware resource assessments and leverages AI capabilities to evaluate cloud resources based on user prompts. To get started, set the `Intelligent Assessment &gt; *` policies.

_Control Types_

- AWS &gt; VPC &gt; Egress Only Internet Gateway &gt; Intelligent Assessment
- AWS &gt; VPC &gt; Elastic IP &gt; Intelligent Assessment
- AWS &gt; VPC &gt; Endpoint &gt; Intelligent Assessment
- AWS &gt; VPC &gt; Endpoint Service &gt; Intelligent Assessment
- AWS &gt; VPC &gt; Internet Gateway &gt; Intelligent Assessment
- AWS &gt; VPC &gt; NAT Gateway &gt; Intelligent Assessment

_Policy Types_

- AWS &gt; VPC &gt; Egress Only Internet Gateway &gt; Intelligent Assessment
- AWS &gt; VPC &gt; Egress Only Internet Gateway &gt; Intelligent Assessment &gt; Context
- AWS &gt; VPC &gt; Egress Only Internet Gateway &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; VPC &gt; Elastic IP &gt; Intelligent Assessment
- AWS &gt; VPC &gt; Elastic IP &gt; Intelligent Assessment &gt; Context
- AWS &gt; VPC &gt; Elastic IP &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; VPC &gt; Endpoint &gt; Intelligent Assessment
- AWS &gt; VPC &gt; Endpoint &gt; Intelligent Assessment &gt; Context
- AWS &gt; VPC &gt; Endpoint &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; VPC &gt; Endpoint Service &gt; Intelligent Assessment
- AWS &gt; VPC &gt; Endpoint Service &gt; Intelligent Assessment &gt; Context
- AWS &gt; VPC &gt; Endpoint Service &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; VPC &gt; Internet Gateway &gt; Intelligent Assessment
- AWS &gt; VPC &gt; Internet Gateway &gt; Intelligent Assessment &gt; Context
- AWS &gt; VPC &gt; Internet Gateway &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; VPC &gt; NAT Gateway &gt; Intelligent Assessment
- AWS &gt; VPC &gt; NAT Gateway &gt; Intelligent Assessment &gt; Context
- AWS &gt; VPC &gt; NAT Gateway &gt; Intelligent Assessment &gt; User Prompt</description>
            <pubDate>Mon, 30 Jun 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-vpc-core-v5-22-1</guid>
            <title>aws-vpc-core v5.22.1 - Improved handling of user prompts and updated GraphQL dependencies for the Intelligent Assessment controls</title>
            <link>https://turbot.com/guardrails/changelog/aws-vpc-core-v5-22-1</link>
            <description>_Bug fixes_

- Improved the internal handling of user prompts and updated GraphQL dependencies for the `Intelligent Assessment` controls.</description>
            <pubDate>Mon, 30 Jun 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-vpc-connect-v5-11-0</guid>
            <title>aws-vpc-connect v5.11.0 - Configure Intelligent Assessment controls for dynamic, context-aware resource assessments</title>
            <link>https://turbot.com/guardrails/changelog/aws-vpc-connect-v5-11-0</link>
            <description>_What&apos;s new?_

- You can now use the `Intelligent Assessment` controls, which enables dynamic, context-aware resource assessments and leverages AI capabilities to evaluate cloud resources based on user prompts. To get started, set the `Intelligent Assessment &gt; *` policies.
- Users can now create and manage tags for VPC transit gateway attachments. To get started, set the `AWS &gt; VPC &gt; Transit Gateway Attachment &gt; Tags &gt; *` policies.

_Control Types_

- AWS &gt; VPC &gt; Customer Gateway &gt; Intelligent Assessment
- AWS &gt; VPC &gt; Peering Connection &gt; Intelligent Assessment
- AWS &gt; VPC &gt; Transit Gateway &gt; Intelligent Assessment
- AWS &gt; VPC &gt; Transit Gateway Attachment &gt; Intelligent Assessment
- AWS &gt; VPC &gt; Transit Gateway Attachment &gt; Intelligent Assessment
- AWS &gt; VPC &gt; Transit Gateway Attachment &gt; Tags
- AWS &gt; VPC &gt; Transit Gateway Route Table &gt; Intelligent Assessment
- AWS &gt; VPC &gt; VPN Connection &gt; Intelligent Assessment
- AWS &gt; VPC &gt; VPN Gateway &gt; Intelligent Assessment

_Policy Types_

- AWS &gt; VPC &gt; Customer Gateway &gt; Intelligent Assessment
- AWS &gt; VPC &gt; Customer Gateway &gt; Intelligent Assessment &gt; Context
- AWS &gt; VPC &gt; Customer Gateway &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; VPC &gt; Peering Connection &gt; Intelligent Assessment
- AWS &gt; VPC &gt; Peering Connection &gt; Intelligent Assessment &gt; Context
- AWS &gt; VPC &gt; Peering Connection &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; VPC &gt; Transit Gateway &gt; Intelligent Assessment
- AWS &gt; VPC &gt; Transit Gateway &gt; Intelligent Assessment &gt; Context
- AWS &gt; VPC &gt; Transit Gateway &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; VPC &gt; Transit Gateway Attachment &gt; Intelligent Assessment
- AWS &gt; VPC &gt; Transit Gateway Attachment &gt; Intelligent Assessment &gt; Context
- AWS &gt; VPC &gt; Transit Gateway Attachment &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; VPC &gt; Transit Gateway Attachment &gt; Tags
- AWS &gt; VPC &gt; Transit Gateway Attachment &gt; Tags &gt; Template
- AWS &gt; VPC &gt; Transit Gateway Route Table &gt; Intelligent Assessment
- AWS &gt; VPC &gt; Transit Gateway Route Table &gt; Intelligent Assessment &gt; Context
- AWS &gt; VPC &gt; Transit Gateway Route Table &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; VPC &gt; VPN Connection &gt; Intelligent Assessment
- AWS &gt; VPC &gt; VPN Connection &gt; Intelligent Assessment &gt; Context
- AWS &gt; VPC &gt; VPN Connection &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; VPC &gt; VPN Gateway &gt; Intelligent Assessment
- AWS &gt; VPC &gt; VPN Gateway &gt; Intelligent Assessment &gt; Context
- AWS &gt; VPC &gt; VPN Gateway &gt; Intelligent Assessment &gt; User Prompt

_Action Types_

- AWS &gt; VPC &gt; Transit Gateway Attachment &gt; Set Tags
- AWS &gt; VPC &gt; Transit Gateway Attachment &gt; Skip alarm for Tags control
- AWS &gt; VPC &gt; Transit Gateway Attachment &gt; Skip alarm for Tags control [90 days]
- AWS &gt; VPC &gt; Transit Gateway Attachment &gt; Update Tags</description>
            <pubDate>Mon, 30 Jun 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-sqs-v5-18-1</guid>
            <title>aws-sqs v5.18.1 - Improved handling of user prompts and updated GraphQL dependencies for the Intelligent Assessment control</title>
            <link>https://turbot.com/guardrails/changelog/aws-sqs-v5-18-1</link>
            <description>_Bug fixes_

- Improved the internal handling of user prompts and updated GraphQL dependencies for the `Intelligent Assessment` control.</description>
            <pubDate>Mon, 30 Jun 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-sns-v5-18-1</guid>
            <title>aws-sns v5.18.1 - Improved handling of user prompts and updated GraphQL dependencies for the Intelligent Assessment controls</title>
            <link>https://turbot.com/guardrails/changelog/aws-sns-v5-18-1</link>
            <description>_Bug fixes_

- Improved the internal handling of user prompts and updated GraphQL dependencies for the `Intelligent Assessment` controls.</description>
            <pubDate>Mon, 30 Jun 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-s3-v5-32-1</guid>
            <title>aws-s3 v5.32.1 - Improved handling of user prompts and updated GraphQL dependencies for the Intelligent Assessment controls</title>
            <link>https://turbot.com/guardrails/changelog/aws-s3-v5-32-1</link>
            <description>_Bug fixes_

- Improved the internal handling of user prompts and updated GraphQL dependencies for the `Intelligent Assessment` controls.</description>
            <pubDate>Mon, 30 Jun 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-lambda-v5-15-1</guid>
            <title>aws-lambda v5.15.1 - Improved handling of user prompts and updated GraphQL dependencies for the Intelligent Assessment controls</title>
            <link>https://turbot.com/guardrails/changelog/aws-lambda-v5-15-1</link>
            <description>_Bug fixes_

- Improved the internal handling of user prompts and updated GraphQL dependencies for the `Intelligent Assessment` controls.</description>
            <pubDate>Mon, 30 Jun 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ec2-v5-46-0</guid>
            <title>aws-ec2 v5.46.0 - Configure Intelligent Assessment controls for dynamic, context-aware resource assessments</title>
            <link>https://turbot.com/guardrails/changelog/aws-ec2-v5-46-0</link>
            <description>_What&apos;s new?_

- You can now use the `Intelligent Assessment` controls, which enables dynamic, context-aware resource assessments and leverages AI capabilities to evaluate cloud resources based on user prompts. To get started, set the `Intelligent Assessment &gt; *` policies.

_Control Types_

- AWS &gt; EC2 &gt; AMI &gt; Intelligent Assessment
- AWS &gt; EC2 &gt; Account Attributes &gt; Intelligent Assessment
- AWS &gt; EC2 &gt; Application Load Balancer &gt; Intelligent Assessment
- AWS &gt; EC2 &gt; Auto Scaling Group &gt; Intelligent Assessment
- AWS &gt; EC2 &gt; Classic Load Balancer &gt; Intelligent Assessment
- AWS &gt; EC2 &gt; Classic Load Balancer Listener &gt; Intelligent Assessment
- AWS &gt; EC2 &gt; Gateway Load Balancer &gt; Intelligent Assessment
- AWS &gt; EC2 &gt; Instance &gt; Intelligent Assessment
- AWS &gt; EC2 &gt; Key Pair &gt; Intelligent Assessment
- AWS &gt; EC2 &gt; Launch Configuration &gt; Intelligent Assessment
- AWS &gt; EC2 &gt; Launch Template &gt; Intelligent Assessment
- AWS &gt; EC2 &gt; Launch Template Version &gt; Intelligent Assessment
- AWS &gt; EC2 &gt; Listener Rule &gt; Intelligent Assessment
- AWS &gt; EC2 &gt; Load Balancer Listener &gt; Intelligent Assessment
- AWS &gt; EC2 &gt; Network Interface &gt; Intelligent Assessment
- AWS &gt; EC2 &gt; Network Load Balancer &gt; Intelligent Assessment
- AWS &gt; EC2 &gt; Snapshot &gt; Intelligent Assessment
- AWS &gt; EC2 &gt; Target Group &gt; Intelligent Assessment
- AWS &gt; EC2 &gt; Volume &gt; Intelligent Assessment

_Policy Types_

- AWS &gt; EC2 &gt; AMI &gt; Intelligent Assessment
- AWS &gt; EC2 &gt; AMI &gt; Intelligent Assessment &gt; Context
- AWS &gt; EC2 &gt; AMI &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; EC2 &gt; Account Attributes &gt; Intelligent Assessment
- AWS &gt; EC2 &gt; Account Attributes &gt; Intelligent Assessment &gt; Context
- AWS &gt; EC2 &gt; Account Attributes &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; EC2 &gt; Application Load Balancer &gt; Intelligent Assessment
- AWS &gt; EC2 &gt; Application Load Balancer &gt; Intelligent Assessment &gt; Context
- AWS &gt; EC2 &gt; Application Load Balancer &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; EC2 &gt; Auto Scaling Group &gt; Intelligent Assessment
- AWS &gt; EC2 &gt; Auto Scaling Group &gt; Intelligent Assessment &gt; Context
- AWS &gt; EC2 &gt; Auto Scaling Group &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; EC2 &gt; Classic Load Balancer &gt; Intelligent Assessment
- AWS &gt; EC2 &gt; Classic Load Balancer &gt; Intelligent Assessment &gt; Context
- AWS &gt; EC2 &gt; Classic Load Balancer &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; EC2 &gt; Classic Load Balancer Listener &gt; Intelligent Assessment
- AWS &gt; EC2 &gt; Classic Load Balancer Listener &gt; Intelligent Assessment &gt; Context
- AWS &gt; EC2 &gt; Classic Load Balancer Listener &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; EC2 &gt; Gateway Load Balancer &gt; Intelligent Assessment
- AWS &gt; EC2 &gt; Gateway Load Balancer &gt; Intelligent Assessment &gt; Context
- AWS &gt; EC2 &gt; Gateway Load Balancer &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; EC2 &gt; Instance &gt; Intelligent Assessment
- AWS &gt; EC2 &gt; Instance &gt; Intelligent Assessment &gt; Context
- AWS &gt; EC2 &gt; Instance &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; EC2 &gt; Key Pair &gt; Intelligent Assessment
- AWS &gt; EC2 &gt; Key Pair &gt; Intelligent Assessment &gt; Context
- AWS &gt; EC2 &gt; Key Pair &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; EC2 &gt; Launch Configuration &gt; Intelligent Assessment
- AWS &gt; EC2 &gt; Launch Configuration &gt; Intelligent Assessment &gt; Context
- AWS &gt; EC2 &gt; Launch Configuration &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; EC2 &gt; Launch Template &gt; Intelligent Assessment
- AWS &gt; EC2 &gt; Launch Template &gt; Intelligent Assessment &gt; Context
- AWS &gt; EC2 &gt; Launch Template &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; EC2 &gt; Launch Template Version &gt; Intelligent Assessment
- AWS &gt; EC2 &gt; Launch Template Version &gt; Intelligent Assessment &gt; Context
- AWS &gt; EC2 &gt; Launch Template Version &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; EC2 &gt; Listener Rule &gt; Intelligent Assessment
- AWS &gt; EC2 &gt; Listener Rule &gt; Intelligent Assessment &gt; Context
- AWS &gt; EC2 &gt; Listener Rule &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; EC2 &gt; Load Balancer Listener &gt; Intelligent Assessment
- AWS &gt; EC2 &gt; Load Balancer Listener &gt; Intelligent Assessment &gt; Context
- AWS &gt; EC2 &gt; Load Balancer Listener &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; EC2 &gt; Network Interface &gt; Intelligent Assessment
- AWS &gt; EC2 &gt; Network Interface &gt; Intelligent Assessment &gt; Context
- AWS &gt; EC2 &gt; Network Interface &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; EC2 &gt; Network Load Balancer &gt; Intelligent Assessment
- AWS &gt; EC2 &gt; Network Load Balancer &gt; Intelligent Assessment &gt; Context
- AWS &gt; EC2 &gt; Network Load Balancer &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; EC2 &gt; Snapshot &gt; Intelligent Assessment
- AWS &gt; EC2 &gt; Snapshot &gt; Intelligent Assessment &gt; Context
- AWS &gt; EC2 &gt; Snapshot &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; EC2 &gt; Target Group &gt; Intelligent Assessment
- AWS &gt; EC2 &gt; Target Group &gt; Intelligent Assessment &gt; Context
- AWS &gt; EC2 &gt; Target Group &gt; Intelligent Assessment &gt; User Prompt
- AWS &gt; EC2 &gt; Volume &gt; Intelligent Assessment
- AWS &gt; EC2 &gt; Volume &gt; Intelligent Assessment &gt; Context
- AWS &gt; EC2 &gt; Volume &gt; Intelligent Assessment &gt; User Prompt</description>
            <pubDate>Mon, 30 Jun 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/turbot-v5-54-2</guid>
            <title>turbot v5.54.2 - Improved system prompts for Intelligent Assessment, Intelligent Fixes and Policy Pack Summary</title>
            <link>https://turbot.com/guardrails/changelog/turbot-v5-54-2</link>
            <description>_What&apos;s new?_

- Improved system prompts for Intelligent Assessment, Intelligent Fixes and Policy Pack Summary.

_Requirements_

- TE: 5.35.4</description>
            <pubDate>Fri, 27 Jun 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/terraform-provider-v1-12-3</guid>
            <title>Terraform Provider v1.12.3 - Terraform SAML directory updates now processed correctly</title>
            <link>https://turbot.com/guardrails/changelog/terraform-provider-v1-12-3</link>
            <description>_Bug fixes_

- Fixed an issue where SAML directory certificate updates applied via Terraform appeared successful but did not persist in the backend. These updates are now correctly processed and retained.
- Resolved an issue where the log message for policySetting resources was unclear when attempting to create policy settings for non-existent or uninstalled policy types. The log output is now more informative and precise.</description>
            <pubDate>Wed, 25 Jun 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/turbot-v5-54-1</guid>
            <title>turbot v5.54.1 - Improved system prompt for Intelligent Assessment control</title>
            <link>https://turbot.com/guardrails/changelog/turbot-v5-54-1</link>
            <description>_What&apos;s new?_

- Improved `Turbot &gt; AI &gt; Control &gt; Intelligent Assessment &gt; System Prompt` policy for better responses from the AI provider.
- Updated the default value for `Turbot &gt; AI &gt; Configuration &gt; Max Tokens [Default]` policy to 1000.

_Requirements_

- TE: 5.35.4</description>
            <pubDate>Tue, 24 Jun 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/turbot-v5-54-0</guid>
            <title>turbot v5.54.0 - AI-generated Policy Pack summaries are now available</title>
            <link>https://turbot.com/guardrails/changelog/turbot-v5-54-0</link>
            <description>_What&apos;s new?_

- AI-generated Policy Pack summaries are now available. To get started, set the `Turbot &gt; AI &gt; Policy Pack &gt; *` policies.

__Control Types__

- Turbot &gt; Policy Pack &gt; Summary

_Requirements_

- TE: 5.35.4</description>
            <pubDate>Tue, 24 Jun 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/intelligent-assessment-15-mods</guid>
            <title>Configure Intelligent Assessment controls for dynamic, context-aware resource assessments for 15 mods</title>
            <link>https://turbot.com/guardrails/changelog/intelligent-assessment-15-mods</link>
            <description>_What&apos;s new?_

- The following 15 mods now have the `Intelligent Assessment` control(s), which enables dynamic, context-aware resource assessments and leverages AI capabilities to evaluate cloud resources based on user prompts.

- aws-backup `v5.13.0`
- aws-cloudwatch `v5.11.0`
- aws-directconnect `v5.6.0`
- aws-dynamodb `v5.15.0`
- aws-events `v5.15.0`
- aws-kms `v5.20.0`
- aws-lambda `v5.15.0`
- aws-route53 `v6.8.0`
- aws-s3 `v5.32.0`
- aws-sns `v5.18.0`
- aws-sqs `v5.18.0`
- aws-vpc-core `v5.22.0`
- gcp-bigquery `v5.9.0`
- gcp-bigquerydatatransfer `v5.2.0`
- gcp-functions `v5.10.0`</description>
            <pubDate>Tue, 24 Jun 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-51-8</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.51.8 - Version bump to align with deployment requirements</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-51-8</link>
            <description>Version bump to align with deployment requirements.

_Requirements_

- TEF: 1.66.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Mon, 23 Jun 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-67-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.67.0 - Enhanced EC2 customization: launch template tags, encrypted AMI support, and dynamic user data via SSM</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-67-0</link>
            <description>_What&apos;s new?_

  - Added support for five optional EC2 Launch Template tags (LaunchTemplateTag1–LaunchTemplateTag5) via SSM parameters. These tags are automatically applied to EC2 instances, EBS volumes, and network interfaces for improved resource classification and automation.
  - Introduced the `AmiKmsKeyArn` parameter to allow specifying a custom AWS KMS Key ARN for encrypting EBS volumes attached to EC2 instances. This enables support for custom encrypted AMIs.
  - Added a new `EC2InstanceCustomUserData` parameter that appends additional UserData from SSM. This allows for dynamic EC2 initialization without needing changes to the CloudFormation template.</description>
            <pubDate>Fri, 20 Jun 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-51-7</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.51.7 - Version bump to align with deployment requirements</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-51-7</link>
            <description>Version bump to align with deployment requirements.

_Requirements_

- TEF: 1.66.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Fri, 20 Jun 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/turbot-v5-53-0</guid>
            <title>turbot v5.53.0 - Bring your own AI to Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/turbot-v5-53-0</link>
            <description>_What&apos;s new?_

- You can now configure your preferred provider to use AI capabilities in your workspace.

__Policy Types__

- Turbot &gt; AI
- Turbot &gt; AI &gt; Configuration
- Turbot &gt; AI &gt; Configuration &gt; API Key [Default]
- Turbot &gt; AI &gt; Configuration &gt; Enabled [Default]
- Turbot &gt; AI &gt; Configuration &gt; Max Tokens [Default]
- Turbot &gt; AI &gt; Configuration &gt; Model [Default]
- Turbot &gt; AI &gt; Configuration &gt; Provider [Default]
- Turbot &gt; AI &gt; Configuration &gt; Temperature [Default]
- Turbot &gt; AI &gt; Control
- Turbot &gt; AI &gt; Control &gt; Intelligent Assessment
- Turbot &gt; AI &gt; Control &gt; Intelligent Assessment &gt; Enabled
- Turbot &gt; AI &gt; Control &gt; Intelligent Assessment &gt; System Prompt
- Turbot &gt; AI &gt; Control &gt; Intelligent Fixes
- Turbot &gt; AI &gt; Control &gt; Intelligent Fixes &gt; Enabled
- Turbot &gt; AI &gt; Control &gt; Intelligent Fixes &gt; System Prompt
- Turbot &gt; AI &gt; Policy Pack
- Turbot &gt; AI &gt; Policy Pack &gt; Summary
- Turbot &gt; AI &gt; Policy Pack &gt; Summary &gt; Enabled
- Turbot &gt; AI &gt; Policy Pack &gt; Summary &gt; System Prompt

__Control Categories__

- Resource &gt; Allowed
- Resource &gt; Intelligent Assessment

_Requirements_

- TE: 5.35.4</description>
            <pubDate>Fri, 20 Jun 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-storage-v5-23-0</guid>
            <title>azure-storage v5.23.0 - Configure shared key access for storage accounts</title>
            <link>https://turbot.com/guardrails/changelog/azure-storage-v5-23-0</link>
            <description>_What&apos;s new?_

- You can now configure shared key access for storage accounts. To get started, set the `Azure &gt; Storage &gt; Storage Account &gt; Shared Key Access` policy.

_Control Types_

- Azure &gt; Storage &gt; Storage Account &gt; Shared Key Access

_Policy Types_

- Azure &gt; Storage &gt; Storage Account &gt; Shared Key Access

_Action Types_

- Azure &gt; Storage &gt; Storage Account &gt; Set Shared Key Access</description>
            <pubDate>Thu, 19 Jun 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-cisv3-0-v5-0-5</guid>
            <title>aws-cisv3-0 v5.0.5 - Controls 3.08 and 3.09 will now evaluate the outcome correctly</title>
            <link>https://turbot.com/guardrails/changelog/aws-cisv3-0-v5-0-5</link>
            <description>_Bug fixes_

- The `AWS &gt; CIS v3.0 &gt; 3 - Logging &gt; 3.08 - Ensure that Object-level logging for write events is enabled for S3 bucket` control previously failed to evaluate correctly when there were more than one `FieldSelectors` present under `AdvancedEventSelectors`. This issue is now fixed.
- The `AWS &gt; CIS v3.0 &gt; 3 - Logging &gt; 3.09 - Ensure that Object-level logging for read events is enabled for S3 bucket` control has been enhanced to evaluate both `EventSelectors` and `AdvancedEventSelectors` when determining whether object-level logging is enabled. Previously, the control evaluated only `EventSelectors`, which could result in false alarms when logging was configured using `AdvancedEventSelectors`.</description>
            <pubDate>Wed, 18 Jun 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-cisv2-0-v5-0-4</guid>
            <title>aws-cisv2-0 v5.0.4 - Controls 3.10 and 3.11 will now evaluate the outcome correctly</title>
            <link>https://turbot.com/guardrails/changelog/aws-cisv2-0-v5-0-4</link>
            <description>_Bug fixes_

- The `AWS &gt; CIS v2.0 &gt; 3 - Logging &gt; 3.10 - Ensure that Object-level logging for write events is enabled for S3 bucket` control previously failed to evaluate correctly when there were more than one `FieldSelectors` present under `AdvancedEventSelectors`. This issue is now fixed.
- The `AWS &gt; CIS v2.0 &gt; 3 - Logging &gt; 3.11 - Ensure that Object-level logging for read events is enabled for S3 bucket` control has been enhanced to evaluate both `EventSelectors` and `AdvancedEventSelectors` when determining whether object-level logging is enabled. Previously, the control evaluated only `EventSelectors`, which could result in false alarms when logging was configured using `AdvancedEventSelectors`.</description>
            <pubDate>Wed, 18 Jun 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-cisv1-4-v5-0-9</guid>
            <title>aws-cisv1-4 v5.0.9 - Controls 3.10 and 3.11 will now evaluate the outcome correctly</title>
            <link>https://turbot.com/guardrails/changelog/aws-cisv1-4-v5-0-9</link>
            <description>_Bug fixes_

- The `AWS &gt; CIS v1.4 &gt; 3 - Logging &gt; 3.10 - Ensure that Object-level logging for write events is enabled for S3 bucket (Automated)` control previously failed to evaluate correctly when there were more than one `FieldSelectors` present under `AdvancedEventSelectors`. This issue is now fixed.
- The `AWS &gt; CIS v1.4 &gt; 3 - Logging &gt; 3.11 - Ensure that Object-level logging for read events is enabled for S3 bucket (Automated)` control has been enhanced to evaluate both `EventSelectors` and `AdvancedEventSelectors` when determining whether object-level logging is enabled. Previously, the control evaluated only `EventSelectors`, which could result in false alarms when logging was configured using `AdvancedEventSelectors`.</description>
            <pubDate>Wed, 18 Jun 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-51-6</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.51.6 - Version bump to align with deployment requirements</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-51-6</link>
            <description>Version bump to align with deployment requirements.

_Requirements_

- TEF: 1.66.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Mon, 16 Jun 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-kms-v5-19-1</guid>
            <title>aws-kms v5.19.1 - Policy Statements &gt; Approved control will now be skipped for AWS-managed keys</title>
            <link>https://turbot.com/guardrails/changelog/aws-kms-v5-19-1</link>
            <description>_Bug fixes_

- The `AWS &gt; KMS &gt; Key &gt; Policy Statements &gt; Approved` control will now be skipped for AWS-managed KMS keys.</description>
            <pubDate>Fri, 13 Jun 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-cisv3-0-v5-0-4</guid>
            <title>aws-cisv3-0 v5.0.4 - `3.08 Ensure that Object-level logging for write events is enabled for S3 bucket` control will now evaluate the outcome correctly</title>
            <link>https://turbot.com/guardrails/changelog/aws-cisv3-0-v5-0-4</link>
            <description>_Bug fixes_

- The `AWS &gt; CIS v3.0 &gt; 3 - Logging &gt; 3.08 - Ensure that Object-level logging for write events is enabled for S3 bucket` control has been enhanced to evaluate both `EventSelectors` and `AdvancedEventSelectors` when determining whether object-level logging is enabled. Previously, the control evaluated only `EventSelectors`, which could result in false alarms when logging was configured using `AdvancedEventSelectors`.</description>
            <pubDate>Fri, 13 Jun 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-51-5</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.51.5 - Fixed access issue in policy pack management.</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-51-5</link>
            <description>_Bug fixes_

- Server
  - Fixed access issue in policy pack management.

- UI
  - Fixed an issue where importing a GCP Organization via the UI did not automatically create the required `Private Key` setting.

_Security Updates_

Fixed access issue in policy pack management

In version 5.51.3, a security issue was introduced that mistakenly allowed users with any `Turbot/*` permissions — at the `Turbot` level, when using the API — to:
  - Create or update policy associations within a policy pack
  - Delete a policy pack if it was not attached to any resource

This has now been fixed, and the correct permission model has been restored — only users with `Turbot/Admin` permissions can perform these operations.

_Requirements_

- TEF: 1.66.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Thu, 12 Jun 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-cloudtrail-v5-12-1</guid>
            <title>aws-cloudtrail v5.12.1 - CMDB data now accurately refreshes the state of `EventSelectors` and `AdvancedEventSelectors` trail configurations</title>
            <link>https://turbot.com/guardrails/changelog/aws-cloudtrail-v5-12-1</link>
            <description>_Bug fixes_

- The `AWS &gt; CloudTrail &gt; Trail &gt; CMDB` control has been updated to correctly refresh the `EventSelectors` and `AdvancedEventSelectors` details when these settings are removed in AWS. This update ensures that the CMDB data accurately reflects the current state of the trail configuration.</description>
            <pubDate>Thu, 12 Jun 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-cisv2-0-v5-0-3</guid>
            <title>aws-cisv2-0 v5.0.3 - `3.10 - Ensure that Object-level logging for write events is enabled for S3 bucket` control will now evaluate the outcome correctly</title>
            <link>https://turbot.com/guardrails/changelog/aws-cisv2-0-v5-0-3</link>
            <description>_Bug fixes_

- The `AWS &gt; CIS v2.0 &gt; 3 - Logging &gt; 3.10 - Ensure that Object-level logging for write events is enabled for S3 bucket` control has been enhanced to evaluate both `EventSelectors` and `AdvancedEventSelectors` when determining whether object-level logging is enabled. Previously, the control evaluated only `EventSelectors`, which could result in false alarms when logging was configured using `AdvancedEventSelectors`.</description>
            <pubDate>Thu, 12 Jun 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-cisv1-4-v5-0-8</guid>
            <title>aws-cisv1-4 v5.0.8 - `3.10 - Ensure that Object-level logging for write events is enabled for S3 bucket (Automated)` control will now evaluate the outcome correctly</title>
            <link>https://turbot.com/guardrails/changelog/aws-cisv1-4-v5-0-8</link>
            <description>_Bug fixes_

- The `AWS &gt; CIS v1.4 &gt; 3 - Logging &gt; 3.10 - Ensure that Object-level logging for write events is enabled for S3 bucket (Automated)` control has been enhanced to evaluate both `EventSelectors` and `AdvancedEventSelectors` when determining whether object-level logging is enabled. Previously, the control evaluated only `EventSelectors`, which could result in false alarms when logging was configured using `AdvancedEventSelectors`.</description>
            <pubDate>Thu, 12 Jun 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ec2-v5-45-2</guid>
            <title>aws-ec2 v5.45.2 - Real-time event handling for load balancer listener has been enhanced to accurately populate `createTimestamp` and `createdBy` details in the metadata</title>
            <link>https://turbot.com/guardrails/changelog/aws-ec2-v5-45-2</link>
            <description>_Bug fixes_

- Load Balancer listeners upserted in Guardrails along with their parent Load Balancers occasionally lacked `createTimestamp` and `createdBy` metadata. This omission caused the `AWS &gt; EC2 &gt; Load Balancer Listener &gt; Approved` control to evaluate incorrectly. We have enhanced our real-time event handling to ensure metadata is accurately populated in such scenarios.</description>
            <pubDate>Tue, 10 Jun 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-51-4</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.51.4 - Added support for custom webhook URLs in notifications</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-51-4</link>
            <description>_What&apos;s new?_

- Server
  - Added support for custom webhook URLs in notifications, allowing integration with any third-party systems beyond Slack and Microsoft Teams.
  - ECS tasks now include no-new-privileges for enhanced security posture.

_Bug fixes_

- Server
  - Email notifications now list recipients in the To field instead of BCC for improved clarity.
  - Resolved an issue where resource-level policy settings could fail when a large number of policy packs were attached.

_Requirements_

- TEF: 1.66.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Thu, 05 Jun 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/turbot-v5-52-0</guid>
            <title>turbot v5.52.0 - Added support for generic webhooks in notifications</title>
            <link>https://turbot.com/guardrails/changelog/turbot-v5-52-0</link>
            <description>_What&apos;s new?_

- Policy Types:
  - Turbot &gt; Notifications &gt; Webhook
  - Turbot &gt; Notifications &gt; Webhook &gt; Authorization Header
  - Turbot &gt; Notifications &gt; Webhook &gt; Action Template
  - Turbot &gt; Notifications &gt; Webhook &gt; Action Template &gt; Body
  - Turbot &gt; Notifications &gt; Webhook &gt; Control Template
  - Turbot &gt; Notifications &gt; Webhook &gt; Control Template &gt; Body

_Requirements_

- TE: 5.35.4</description>
            <pubDate>Thu, 05 Jun 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-s3table-v5-0-0</guid>
            <title>aws-s3table v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/aws-s3table-v5-0-0</link>
            <description>_Resource Types_

- AWS &gt; S3 Table
- AWS &gt; S3 Table &gt; Namespace
- AWS &gt; S3 Table &gt; Table
- AWS &gt; S3 Table &gt; Table Bucket

_Control Types_

- AWS &gt; S3 Table &gt; Namespace &gt; Active
- AWS &gt; S3 Table &gt; Namespace &gt; CMDB
- AWS &gt; S3 Table &gt; Namespace &gt; Discovery
- AWS &gt; S3 Table &gt; Table &gt; Active
- AWS &gt; S3 Table &gt; Table &gt; CMDB
- AWS &gt; S3 Table &gt; Table &gt; Discovery
- AWS &gt; S3 Table &gt; Table Bucket &gt; Active
- AWS &gt; S3 Table &gt; Table Bucket &gt; CMDB
- AWS &gt; S3 Table &gt; Table Bucket &gt; Discovery
- AWS &gt; S3 Table &gt; Table Bucket &gt; Policy
- AWS &gt; S3 Table &gt; Table Bucket &gt; Policy &gt; Trusted Access

_Policy Types_

- AWS &gt; S3 Table &gt; API Enabled
- AWS &gt; S3 Table &gt; Approved Regions [Default]
- AWS &gt; S3 Table &gt; Enabled
- AWS &gt; S3 Table &gt; Namespace &gt; Active
- AWS &gt; S3 Table &gt; Namespace &gt; Active &gt; Age
- AWS &gt; S3 Table &gt; Namespace &gt; Active &gt; Last Modified
- AWS &gt; S3 Table &gt; Namespace &gt; CMDB
- AWS &gt; S3 Table &gt; Namespace &gt; Regions
- AWS &gt; S3 Table &gt; Permissions
- AWS &gt; S3 Table &gt; Permissions &gt; Levels
- AWS &gt; S3 Table &gt; Permissions &gt; Levels &gt; Modifiers
- AWS &gt; S3 Table &gt; Permissions &gt; Lockdown
- AWS &gt; S3 Table &gt; Permissions &gt; Lockdown &gt; API Boundary
- AWS &gt; S3 Table &gt; Regions
- AWS &gt; S3 Table &gt; Table &gt; Active
- AWS &gt; S3 Table &gt; Table &gt; Active &gt; Age
- AWS &gt; S3 Table &gt; Table &gt; Active &gt; Last Modified
- AWS &gt; S3 Table &gt; Table &gt; CMDB
- AWS &gt; S3 Table &gt; Table &gt; Regions
- AWS &gt; S3 Table &gt; Table Bucket &gt; Active
- AWS &gt; S3 Table &gt; Table Bucket &gt; Active &gt; Age
- AWS &gt; S3 Table &gt; Table Bucket &gt; Active &gt; Last Modified
- AWS &gt; S3 Table &gt; Table Bucket &gt; CMDB
- AWS &gt; S3 Table &gt; Table Bucket &gt; Policy
- AWS &gt; S3 Table &gt; Table Bucket &gt; Policy &gt; Trusted Access
- AWS &gt; S3 Table &gt; Table Bucket &gt; Policy &gt; Trusted Access &gt; Accounts
- AWS &gt; S3 Table &gt; Table Bucket &gt; Regions
- AWS &gt; S3 Table &gt; Trusted Accounts [Default]
- AWS &gt; Turbot &gt; Permissions &gt; Compiled &gt; API Boundary &gt; @turbot/aws-s3table
- AWS &gt; Turbot &gt; Permissions &gt; Compiled &gt; Levels &gt; @turbot/aws-s3table
- AWS &gt; Turbot &gt; Permissions &gt; Compiled &gt; Service Permissions &gt; @turbot/aws-s3table

_Action Types_

- AWS &gt; S3 Table &gt; Namespace &gt; Delete
- AWS &gt; S3 Table &gt; Table &gt; Delete
- AWS &gt; S3 Table &gt; Table Bucket &gt; Delete
- AWS &gt; S3 Table &gt; Table Bucket &gt; Set Policy Trusted Access</description>
            <pubDate>Thu, 05 Jun 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/ted-v1-49-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.49.0 - Added PostgreSQL 17</title>
            <link>https://turbot.com/guardrails/changelog/ted-v1-49-0</link>
            <description>_What&apos;s new?_

- Added support for PostgreSQL 17, including the new hive parameter group.</description>
            <pubDate>Wed, 04 Jun 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-sns-v5-17-1</guid>
            <title>aws-sns v5.17.1 - Cross-account subscriptions will no longer be upserted into Guardrails CMDB to prevent the CMDB control from entering an error state</title>
            <link>https://turbot.com/guardrails/changelog/aws-sns-v5-17-1</link>
            <description>_Bug fixes_

- The `AWS &gt; SNS &gt; Subscription &gt; CMDB` control previously entered an error state for cross-account subscriptions upserted in Guardrails CMDB. These subscriptions will no longer be upserted into CMDB, preventing the control from entering an error state.
- The `AWS &gt; SNS &gt; Subscription &gt; CMDB` control did not automatically re-run when a subscription was in the `PendingConfirmation` state. This issue has now been resolved.</description>
            <pubDate>Wed, 04 Jun 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-vpc-security-v5-13-0</guid>
            <title>aws-vpc-security v5.13.0 - Configure CMDB policy for flow logs at VPC, subnet, or network interface level</title>
            <link>https://turbot.com/guardrails/changelog/aws-vpc-security-v5-13-0</link>
            <description>_What&apos;s new?_

- The `AWS &gt; VPC &gt; Flow Log &gt; CMDB` policy now also targets the `AWS &gt; VPC &gt; VPC`, `AWS &gt; VPC &gt; Subnet`, and `AWS &gt; EC2 &gt; Network Interface` resource types, enabling more granular policy setting options.</description>
            <pubDate>Mon, 02 Jun 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-sql-v5-2-0</guid>
            <title>servicenow-azure-sql v5.2.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-sql-v5-2-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Tue, 27 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-networkwatcher-v5-1-0</guid>
            <title>servicenow-azure-networkwatcher v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-networkwatcher-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Tue, 27 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-network-v5-5-0</guid>
            <title>servicenow-azure-network v5.5.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-network-v5-5-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Tue, 27 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-monitor-v5-1-0</guid>
            <title>servicenow-azure-monitor v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-monitor-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Tue, 27 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-keyvault-v5-1-0</guid>
            <title>servicenow-azure-keyvault v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-keyvault-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Tue, 27 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-datafactory-v5-1-0</guid>
            <title>servicenow-azure-datafactory v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-datafactory-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Tue, 27 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-cosmosdb-v5-1-0</guid>
            <title>servicenow-azure-cosmosdb v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-cosmosdb-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Tue, 27 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-compute-v5-3-0</guid>
            <title>servicenow-azure-compute v5.3.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-compute-v5-3-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Tue, 27 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-appservice-v5-1-0</guid>
            <title>servicenow-azure-appservice v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-appservice-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Tue, 27 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-compute-v5-21-1</guid>
            <title>azure-compute v5.21.1 - Discovery control for disks will no longer be triggered unnecessarily by the virtual machine CMDB control</title>
            <link>https://turbot.com/guardrails/changelog/azure-compute-v5-21-1</link>
            <description>_Bug fixes_

- The `Azure &gt; Compute &gt; Virtual Machine &gt; CMDB` control previously triggered the `Azure &gt; Compute &gt; Disk &gt; Discovery` control on the VM&apos;s resource group, resulting in unnecessary control re-runs within the workspace. We&apos;ve now improved the VM&apos;s CMDB control to prevent such unnecessary re-runs.</description>
            <pubDate>Tue, 27 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-kubernetes-v5-6-0</guid>
            <title>servicenow-kubernetes v5.6.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-kubernetes-v5-6-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.</description>
            <pubDate>Mon, 26 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-synapseanalytics-v5-1-0</guid>
            <title>servicenow-azure-synapseanalytics v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-synapseanalytics-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Mon, 26 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-storage-v5-5-0</guid>
            <title>servicenow-azure-storage v5.5.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-storage-v5-5-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Mon, 26 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-servicebus-v5-1-0</guid>
            <title>servicenow-azure-servicebus v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-servicebus-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Mon, 26 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-recoveryservice-v5-1-0</guid>
            <title>servicenow-azure-recoveryservice v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-recoveryservice-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Mon, 26 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-postgresql-v5-2-0</guid>
            <title>servicenow-azure-postgresql v5.2.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-postgresql-v5-2-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Mon, 26 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-mysql-v5-2-0</guid>
            <title>servicenow-azure-mysql v5.2.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-mysql-v5-2-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Mon, 26 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-loganalytics-v5-1-0</guid>
            <title>servicenow-azure-loganalytics v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-loganalytics-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Mon, 26 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-iam-v5-1-0</guid>
            <title>servicenow-azure-iam v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-iam-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Mon, 26 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-activedirectory-v5-1-0</guid>
            <title>servicenow-azure-activedirectory v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-activedirectory-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Mon, 26 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-v5-7-0</guid>
            <title>servicenow-azure v5.7.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-v5-7-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Fri, 23 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-searchmanagement-v5-1-0</guid>
            <title>servicenow-azure-searchmanagement v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-searchmanagement-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Fri, 23 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-loadbalancer-v5-1-0</guid>
            <title>servicenow-azure-loadbalancer v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-loadbalancer-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Fri, 23 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-51-3</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.51.3 - Resolved a crash in policy setting expiration control</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-51-3</link>
            <description>_Bug fixes_

- Server
  - Resolved a crash in policy setting expiration control.

_Requirements_

- TEF: 1.66.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Thu, 22 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/osquery-v5-1-0</guid>
            <title>osquery v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/osquery-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.</description>
            <pubDate>Thu, 22 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-51-2</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.51.2 - Resolved an issue that was preventing users from creating new workspace</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-51-2</link>
            <description>_Bug fixes_

- Server
  - Resolved an issue that was preventing users from creating new workspace.

_Requirements_

- TEF: 1.66.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Wed, 21 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-securitycenter-v5-1-0</guid>
            <title>servicenow-azure-securitycenter v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-securitycenter-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Wed, 21 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-relay-v5-1-0</guid>
            <title>servicenow-azure-relay v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-relay-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Tue, 20 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-dns-v5-1-0</guid>
            <title>servicenow-azure-dns v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-dns-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Tue, 20 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-51-1</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.51.1 - Fixed a permission issue affecting visibility of policy packs</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-51-1</link>
            <description>_Bug fixes_

- Server
  - Fixed a permission issue affecting visibility of policy packs.

_Requirements_

- TEF: 1.66.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Mon, 19 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-sqlvirtualmachine-v5-1-0</guid>
            <title>servicenow-azure-sqlvirtualmachine v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-sqlvirtualmachine-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Mon, 19 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-signalr-v5-1-0</guid>
            <title>servicenow-azure-signalr v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-signalr-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Mon, 19 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-applicationgateway-v5-1-0</guid>
            <title>servicenow-azure-applicationgateway v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-applicationgateway-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Mon, 19 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-apimanagement-v5-1-0</guid>
            <title>servicenow-azure-apimanagement v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-apimanagement-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Mon, 19 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-aks-v5-2-0</guid>
            <title>servicenow-azure-aks v5.2.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-aks-v5-2-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Mon, 19 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-iam-v5-43-0</guid>
            <title>aws-iam v5.43.0 - Configure active control for virtual MFA devices based on their age</title>
            <link>https://turbot.com/guardrails/changelog/aws-iam-v5-43-0</link>
            <description>_What&apos;s new?_

- You can now configure the `AWS &gt; IAM &gt; MFA Virtual &gt; Active` control for virtual MFA devices based on their age. To get started, set the `AWS &gt; IAM &gt; MFA Virtual &gt; Active &gt; Age` policy. As part of this enhancement, a new value of `45 days` has been applied to all relevant Active policies.

_Policy Types_

- AWS &gt; IAM &gt; MFA Virtual &gt; Active &gt; Age

_Action Types_

- AWS &gt; IAM &gt; MFA Virtual &gt; Delete</description>
            <pubDate>Mon, 19 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-frontdoorservice-v5-1-0</guid>
            <title>servicenow-azure-frontdoorservice v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-frontdoorservice-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Fri, 16 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-firewall-v5-1-0</guid>
            <title>servicenow-azure-firewall v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-firewall-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Fri, 16 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-databricks-v5-1-0</guid>
            <title>servicenow-azure-databricks v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-databricks-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Fri, 16 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-automation-v5-1-0</guid>
            <title>servicenow-azure-automation v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-automation-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Fri, 16 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-applicationinsights-v5-1-0</guid>
            <title>servicenow-azure-applicationinsights v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-applicationinsights-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Fri, 16 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-51-0</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.51.0 - Users can now see all policy packs defined within the resource hierarchy where they have access</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-51-0</link>
            <description>_What&apos;s new?_

- Server
  - Introduced support for initializing a new encryption key baseline for workspaces.
  - Users can now see all policy packs defined within the resource hierarchy where they have access, providing clearer insight into inherited policies.

- UI
  - The page title now dynamically includes the workspace name, helping users distinguish tabs when working across multiple environments.

_Bug fixes_

- Server
  - Refined the backup flow for tenant master keys, improving error handling, increasing stability.

_Note_

This is a checkpoint version. Guardrails must be updated to **v5.51.x** first before continuing. It can be any version in **v5.51.x** series.

_Requirements_

- TEF: 1.66.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Thu, 15 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-network-v5-3-0</guid>
            <title>servicenow-gcp-network v5.3.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-network-v5-3-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Thu, 15 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-dataplex-v5-1-0</guid>
            <title>servicenow-gcp-dataplex v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-dataplex-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Thu, 15 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-computeengine-v5-5-0</guid>
            <title>servicenow-gcp-computeengine v5.5.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-computeengine-v5-5-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Thu, 15 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-vertexai-v5-1-0</guid>
            <title>servicenow-gcp-vertexai v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-vertexai-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.</description>
            <pubDate>Wed, 14 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-v5-8-0</guid>
            <title>servicenow-gcp v5.8.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-v5-8-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Wed, 14 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-storage-v5-6-0</guid>
            <title>servicenow-gcp-storage v5.6.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-storage-v5-6-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.</description>
            <pubDate>Wed, 14 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-sql-v5-2-0</guid>
            <title>servicenow-gcp-sql v5.2.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-sql-v5-2-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Wed, 14 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-spanner-v5-1-0</guid>
            <title>servicenow-gcp-spanner v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-spanner-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Wed, 14 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-secretmanager-v5-1-0</guid>
            <title>servicenow-gcp-secretmanager v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-secretmanager-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Wed, 14 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-scheduler-v5-1-0</guid>
            <title>servicenow-gcp-scheduler v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-scheduler-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Wed, 14 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-run-v5-1-0</guid>
            <title>servicenow-gcp-run v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-run-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Wed, 14 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-pubsub-v5-1-0</guid>
            <title>servicenow-gcp-pubsub v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-pubsub-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Wed, 14 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-monitoring-v5-1-0</guid>
            <title>servicenow-gcp-monitoring v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-monitoring-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Wed, 14 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-memorystore-v5-1-0</guid>
            <title>servicenow-gcp-memorystore v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-memorystore-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Wed, 14 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-logging-v5-1-0</guid>
            <title>servicenow-gcp-logging v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-logging-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Wed, 14 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-kubernetesengine-v5-2-0</guid>
            <title>servicenow-gcp-kubernetesengine v5.2.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-kubernetesengine-v5-2-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Wed, 14 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-kms-v5-1-0</guid>
            <title>servicenow-gcp-kms v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-kms-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Wed, 14 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-iam-v5-1-0</guid>
            <title>servicenow-gcp-iam v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-iam-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Wed, 14 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-functions-v5-1-0</guid>
            <title>servicenow-gcp-functions v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-functions-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Wed, 14 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-firebase-v5-1-0</guid>
            <title>servicenow-gcp-firebase v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-firebase-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Wed, 14 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-dns-v5-1-0</guid>
            <title>servicenow-gcp-dns v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-dns-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Wed, 14 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-dataproc-v5-1-0</guid>
            <title>servicenow-gcp-dataproc v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-dataproc-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Wed, 14 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-datapipeline-v5-1-0</guid>
            <title>servicenow-gcp-datapipeline v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-datapipeline-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Wed, 14 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-dataflow-v5-1-0</guid>
            <title>servicenow-gcp-dataflow v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-dataflow-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Wed, 14 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-composer-v5-1-0</guid>
            <title>servicenow-gcp-composer v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-composer-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Wed, 14 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-bigtable-v5-1-0</guid>
            <title>servicenow-gcp-bigtable v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-bigtable-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Wed, 14 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-bigquery-v5-1-0</guid>
            <title>servicenow-gcp-bigquery v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-bigquery-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Wed, 14 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-appengine-v5-1-0</guid>
            <title>servicenow-gcp-appengine v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-appengine-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Wed, 14 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-v5-30-1</guid>
            <title>azure v5.30.1 - Improved real-time event processing logic to prevent unnecessary reruns</title>
            <link>https://turbot.com/guardrails/changelog/azure-v5-30-1</link>
            <description>_Bug fixes_

- The `Azure &gt; Subscription &gt; Event Poller` control previously processed some real-time events multiple times, resulting in unnecessary Lambda churn. The event processing logic has been improved to ensure each event is handled only once, enhancing overall efficiency.
- The `Azure &gt; Subscription &gt; CMDB` control previously ran unnecessarily when Guardrails received real-time `Microsoft.Resources/tags/write` events for resources other than subscriptions or resource groups. These events will no longer be processed, preventing unnecessary CMDB control runs.</description>
            <pubDate>Wed, 14 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-apigateway-v5-11-0</guid>
            <title>aws-apigateway v5.11.0 - Track and manage API Gateway account resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/aws-apigateway-v5-11-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
  _Resource Types_

- AWS &gt; API Gateway &gt; Account

_Control Types_

- AWS &gt; API Gateway &gt; Account &gt; CMDB
- AWS &gt; API Gateway &gt; Account &gt; Discovery

_Policy Types_

- AWS &gt; API Gateway &gt; Account &gt; CMDB
- AWS &gt; API Gateway &gt; Account &gt; Regions

_Action Types_

- AWS &gt; API Gateway &gt; Account &gt; Router</description>
            <pubDate>Wed, 14 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/terraform-provider-v1-12-2</guid>
            <title>Terraform Provider v1.12.2 - Improved sensitive data masking in log outputs to include additional value types</title>
            <link>https://turbot.com/guardrails/changelog/terraform-provider-v1-12-2</link>
            <description>_Bug fixes_

- Improved sensitive data masking in log outputs to include additional value types.</description>
            <pubDate>Mon, 12 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-50-7</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.50.7 -  Improvements to discovery process flow</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-50-7</link>
            <description>_Bug fixes_

- Server
  -	Discovery controls now run more reliably, reducing interruptions caused by premature termination.
  - Addressed a race condition that could occasionally result in missed priority events during policy value processing.

- UI
  - Resolved an issue where resource type values were hard-coded in a hook, improving flexibility and maintainability.

_Requirements_

- TEF: 1.66.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Fri, 09 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/terraform-provider-v1-12-1</guid>
            <title>Terraform Provider v1.12.1 - Updates to the parent attribute in the `resource_turbot_file` resource are now processed correctly</title>
            <link>https://turbot.com/guardrails/changelog/terraform-provider-v1-12-1</link>
            <description>_Bug fixes_

- Resolved an issue where parent updates in `resource_turbot_file` were silently ignored. These updates are now processed correctly to ensure changes are properly applied.</description>
            <pubDate>Thu, 08 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-waf-v5-9-0</guid>
            <title>aws-waf v5.9.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-waf-v5-9-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.
- Web ACL resource type is now deprecated and will be removed in the next major version. Please refer [Migrate workloads from AWS WAF Classic](https://aws.amazon.com/blogs/security/migrating-rules-from-aws-waf-classic-to-new-aws-waf) for more information.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.

_Resource Types_

_Renamed_

- AWS &gt; WAF &gt; Web ACL to AWS &gt; WAF &gt; Web ACL [Deprecated]

_Control Types_

_Renamed_

- AWS &gt; WAF &gt; Web ACL &gt; Active to AWS &gt; WAF &gt; Web ACL [Deprecated] &gt; Active
- AWS &gt; WAF &gt; Web ACL &gt; Approved to AWS &gt; WAF &gt; Web ACL [Deprecated] &gt; Approved
- AWS &gt; WAF &gt; Web ACL &gt; CMDB to AWS &gt; WAF &gt; Web ACL [Deprecated] &gt; CMDB
- AWS &gt; WAF &gt; Web ACL &gt; Discovery to AWS &gt; WAF &gt; Web ACL [Deprecated] &gt; Discovery
- AWS &gt; WAF &gt; Web ACL &gt; Tags to AWS &gt; WAF &gt; Web ACL [Deprecated] &gt; Tags
- AWS &gt; WAF &gt; Web ACL &gt; Usage to AWS &gt; WAF &gt; Web ACL [Deprecated] &gt; Usage

_Policy Types_

_Renamed_

- AWS &gt; WAF &gt; Web ACL &gt; Active to AWS &gt; WAF &gt; Web ACL [Deprecated] &gt; Active
- AWS &gt; WAF &gt; Web ACL &gt; Active &gt; Age to AWS &gt; WAF &gt; Web ACL [Deprecated] &gt; Active &gt; Age
- AWS &gt; WAF &gt; Web ACL &gt; Active &gt; Budget to AWS &gt; WAF &gt; Web ACL [Deprecated] &gt; Active &gt; Budget
- AWS &gt; WAF &gt; Web ACL &gt; Active &gt; Last Modified to AWS &gt; WAF &gt; Web ACL [Deprecated] &gt; Active &gt; Last Modified
- AWS &gt; WAF &gt; Web ACL &gt; Approved to AWS &gt; WAF &gt; Web ACL [Deprecated] &gt; Approved
- AWS &gt; WAF &gt; Web ACL &gt; Approved &gt; Budget to AWS &gt; WAF &gt; Web ACL [Deprecated] &gt; Approved &gt; Budget
- AWS &gt; WAF &gt; Web ACL &gt; Approved &gt; Custom to AWS &gt; WAF &gt; Web ACL [Deprecated] &gt; Approved &gt; Custom
- AWS &gt; WAF &gt; Web ACL &gt; Approved &gt; Usage to AWS &gt; WAF &gt; Web ACL [Deprecated] &gt; Approved &gt; Usage
- AWS &gt; WAF &gt; Web ACL &gt; CMDB to AWS &gt; WAF &gt; Web ACL [Deprecated] &gt; CMDB
- AWS &gt; WAF &gt; Web ACL &gt; Tags to AWS &gt; WAF &gt; Web ACL [Deprecated] &gt; Tags
- AWS &gt; WAF &gt; Web ACL &gt; Tags &gt; Template to AWS &gt; WAF &gt; Web ACL [Deprecated] &gt; Tags &gt; Template
- AWS &gt; WAF &gt; Web ACL &gt; Usage to AWS &gt; WAF &gt; Web ACL [Deprecated] &gt; Usage
- AWS &gt; WAF &gt; Web ACL &gt; Usage &gt; Limit to AWS &gt; WAF &gt; Web ACL [Deprecated] &gt; Usage &gt; Limit

_Action Types_

_Renamed_

- AWS &gt; WAF &gt; Web ACL &gt; Delete to AWS &gt; WAF &gt; Web ACL [Deprecated] &gt; Delete
- AWS &gt; WAF &gt; Web ACL &gt; Delete from AWS to AWS &gt; WAF &gt; Web ACL [Deprecated] &gt; Delete from AWS
- AWS &gt; WAF &gt; Web ACL &gt; Router to AWS &gt; WAF &gt; Web ACL [Deprecated] &gt; Router
- AWS &gt; WAF &gt; Web ACL &gt; Set Tags to AWS &gt; WAF &gt; Web ACL [Deprecated] &gt; Set Tags
- AWS &gt; WAF &gt; Web ACL &gt; Skip alarm for Active control to AWS &gt; WAF &gt; Web ACL [Deprecated] &gt; Skip alarm for Active control
- AWS &gt; WAF &gt; Web ACL &gt; Skip alarm for Active control [90 days] to AWS &gt; WAF &gt; Web ACL [Deprecated] &gt; Skip alarm for Active control [90 days]
- AWS &gt; WAF &gt; Web ACL &gt; Skip alarm for Approved control to AWS &gt; WAF &gt; Web ACL [Deprecated] &gt; Skip alarm for Approved control
- AWS &gt; WAF &gt; Web ACL &gt; Skip alarm for Approved control [90 days] to AWS &gt; WAF &gt; Web ACL [Deprecated] &gt; Skip alarm for Approved control [90 days]
- AWS &gt; WAF &gt; Web ACL &gt; Skip alarm for Tags control to AWS &gt; WAF &gt; Web ACL [Deprecated] &gt; Skip alarm for Tags control
- AWS &gt; WAF &gt; Web ACL &gt; Skip alarm for Tags control [90 days] to AWS &gt; WAF &gt; Web ACL [Deprecated] &gt; Skip alarm for Tags control [90 days]
- AWS &gt; WAF &gt; Web ACL &gt; Update Tags to AWS &gt; WAF &gt; Web ACL [Deprecated] &gt; Update Tags</description>
            <pubDate>Thu, 08 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-secretsmanager-v5-10-1</guid>
            <title>aws-secretsmanager v5.10.1 - Stack [Native] control will now correctly import and manage resources outside the `us-east-1` region</title>
            <link>https://turbot.com/guardrails/changelog/aws-secretsmanager-v5-10-1</link>
            <description>_Bug fixes_

- The `AWS &gt; Secrets Manager &gt; Secret &gt; Stack [Native]` control previously failed to import and manage resources outside the `us-east-1` region. This issue has now been resolved.</description>
            <pubDate>Thu, 08 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-datapipeline-v5-4-0</guid>
            <title>aws-datapipeline v5.4.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-datapipeline-v5-4-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.
- Pipeline resource type is now deprecated and will be removed in the next major version. Please refer [Migrate workloads from AWS Data Pipeline](https://aws.amazon.com/blogs/big-data/migrate-workloads-from-aws-data-pipeline) for more information.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.

_Resource Types_

_Renamed_

- AWS &gt; Data Pipeline &gt; Pipeline to AWS &gt; Data Pipeline &gt; Pipeline [Deprecated]

_Control Types_

_Renamed_

- AWS &gt; Data Pipeline &gt; Pipeline &gt; Active to AWS &gt; Data Pipeline &gt; Pipeline [Deprecated] &gt; Active
- AWS &gt; Data Pipeline &gt; Pipeline &gt; Approved to AWS &gt; Data Pipeline &gt; Pipeline [Deprecated] &gt; Approved
- AWS &gt; Data Pipeline &gt; Pipeline &gt; CMDB to AWS &gt; Data Pipeline &gt; Pipeline [Deprecated] &gt; CMDB
- AWS &gt; Data Pipeline &gt; Pipeline &gt; Discovery to AWS &gt; Data Pipeline &gt; Pipeline [Deprecated] &gt; Discovery
- AWS &gt; Data Pipeline &gt; Pipeline &gt; Tags to AWS &gt; Data Pipeline &gt; Pipeline [Deprecated] &gt; Tags

_Policy Types_

_Renamed_

- AWS &gt; Data Pipeline &gt; Pipeline &gt; Active to AWS &gt; Data Pipeline &gt; Pipeline [Deprecated] &gt; Active
- AWS &gt; Data Pipeline &gt; Pipeline &gt; Active &gt; Age to AWS &gt; Data Pipeline &gt; Pipeline [Deprecated] &gt; Active &gt; Age
- AWS &gt; Data Pipeline &gt; Pipeline &gt; Active &gt; Last Modified to AWS &gt; Data Pipeline &gt; Pipeline [Deprecated] &gt; Active &gt; Last Modified
- AWS &gt; Data Pipeline &gt; Pipeline &gt; Approved to AWS &gt; Data Pipeline &gt; Pipeline [Deprecated] &gt; Approved
- AWS &gt; Data Pipeline &gt; Pipeline &gt; Approved &gt; Custom to AWS &gt; Data Pipeline &gt; Pipeline [Deprecated] &gt; Approved &gt; Custom
- AWS &gt; Data Pipeline &gt; Pipeline &gt; Approved &gt; Regions to AWS &gt; Data Pipeline &gt; Pipeline [Deprecated] &gt; Approved &gt; Regions
- AWS &gt; Data Pipeline &gt; Pipeline &gt; Approved &gt; Usage to AWS &gt; Data Pipeline &gt; Pipeline [Deprecated] &gt; Approved &gt; Usage
- AWS &gt; Data Pipeline &gt; Pipeline &gt; CMDB to AWS &gt; Data Pipeline &gt; Pipeline [Deprecated] &gt; CMDB
- AWS &gt; Data Pipeline &gt; Pipeline &gt; Regions to AWS &gt; Data Pipeline &gt; Pipeline [Deprecated] &gt; Regions
- AWS &gt; Data Pipeline &gt; Pipeline &gt; Tags to AWS &gt; Data Pipeline &gt; Pipeline [Deprecated] &gt; Tags
- AWS &gt; Data Pipeline &gt; Pipeline &gt; Tags &gt; Template to AWS &gt; Data Pipeline &gt; Pipeline [Deprecated] &gt; Tags &gt; Template

_Action Types_

_Renamed_

- AWS &gt; Data Pipeline &gt; Pipeline &gt; Delete to AWS &gt; Data Pipeline &gt; Pipeline [Deprecated] &gt; Delete
- AWS &gt; Data Pipeline &gt; Pipeline &gt; Delete from AWS to AWS &gt; Data Pipeline &gt; Pipeline [Deprecated] &gt; Delete from AWS
- AWS &gt; Data Pipeline &gt; Pipeline &gt; Router to AWS &gt; Data Pipeline &gt; Pipeline [Deprecated] &gt; Router
- AWS &gt; Data Pipeline &gt; Pipeline &gt; Set Tags to AWS &gt; Data Pipeline &gt; Pipeline [Deprecated] &gt; Set Tags
- AWS &gt; Data Pipeline &gt; Pipeline &gt; Skip alarm for Active control to AWS &gt; Data Pipeline &gt; Pipeline [Deprecated] &gt; Skip alarm for Active control
- AWS &gt; Data Pipeline &gt; Pipeline &gt; Skip alarm for Active control [90 days] to AWS &gt; Data Pipeline &gt; Pipeline [Deprecated] &gt; Skip alarm for Active control [90 days]
- AWS &gt; Data Pipeline &gt; Pipeline &gt; Skip alarm for Approved control to AWS &gt; Data Pipeline &gt; Pipeline [Deprecated] &gt; Skip alarm for Approved control
- AWS &gt; Data Pipeline &gt; Pipeline &gt; Skip alarm for Approved control [90 days] to AWS &gt; Data Pipeline &gt; Pipeline [Deprecated] &gt; Skip alarm for Approved control [90 days]
- AWS &gt; Data Pipeline &gt; Pipeline &gt; Skip alarm for Tags control to AWS &gt; Data Pipeline &gt; Pipeline [Deprecated] &gt; Skip alarm for Tags control
- AWS &gt; Data Pipeline &gt; Pipeline &gt; Skip alarm for Tags control [90 days] to AWS &gt; Data Pipeline &gt; Pipeline [Deprecated] &gt; Skip alarm for Tags control [90 days]
- AWS &gt; Data Pipeline &gt; Pipeline &gt; Update Tags to AWS &gt; Data Pipeline &gt; Pipeline [Deprecated] &gt; Update Tags</description>
            <pubDate>Thu, 08 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-v5-30-0</guid>
            <title>azure v5.30.0 - Create and manage cloud resources via Stack [Native] controls</title>
            <link>https://turbot.com/guardrails/changelog/azure-v5-30-0</link>
            <description>_What&apos;s new?_

- Users can now create and manage cloud resources using OpenTofu 1.x (open source Terraform) via Guardrails, fully leveraging all features available in this version. To get started, set the `Stack [Native] &gt; *` policies.

_Control Types_

- Azure &gt; Resource Group &gt; Stack [Native]

_Policy Types_

- Azure &gt; Resource Group &gt; Stack [Native]
- Azure &gt; Resource Group &gt; Stack [Native] &gt; Drift Detection
- Azure &gt; Resource Group &gt; Stack [Native] &gt; Drift Detection &gt; Interval
- Azure &gt; Resource Group &gt; Stack [Native] &gt; Modifier
- Azure &gt; Resource Group &gt; Stack [Native] &gt; Secret Variables
- Azure &gt; Resource Group &gt; Stack [Native] &gt; Source
- Azure &gt; Resource Group &gt; Stack [Native] &gt; Timeout
- Azure &gt; Resource Group &gt; Stack [Native] &gt; Variables
- Azure &gt; Resource Group &gt; Stack [Native] &gt; Version</description>
            <pubDate>Wed, 07 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-wellarchitected-v5-8-0</guid>
            <title>aws-wellarchitected v5.8.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-wellarchitected-v5-8-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Wed, 07 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-wellarchitected-framework-v5-1-0</guid>
            <title>aws-wellarchitected-framework v5.1.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-wellarchitected-framework-v5-1-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.</description>
            <pubDate>Wed, 07 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-v5-37-2</guid>
            <title>aws v5.37.2 - EventBridge rules created via Event Handlers now exclude events containing errors</title>
            <link>https://turbot.com/guardrails/changelog/aws-v5-37-2</link>
            <description>_Bug fixes_

- EventBridge rules configured via Event Handlers have been improved to exclude real-time events containing errors from being sent to the Guardrails endpoint. This prevents Guardrails from processing unnecessary error events.
- The default value for the `AWS &gt; Region &gt; Connection Region` policy did not evaluate correctly for AWS GovCloud accounts. This issue has been resolved.</description>
            <pubDate>Wed, 07 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-secretsmanager-v5-10-0</guid>
            <title>aws-secretsmanager v5.10.0 - Create and manage cloud resources via Stack [Native] controls</title>
            <link>https://turbot.com/guardrails/changelog/aws-secretsmanager-v5-10-0</link>
            <description>_What&apos;s new?_

- Users can now create and manage cloud resources using OpenTofu 1.x (open source Terraform) via Guardrails, fully leveraging all features available in this version. To get started, set the `Stack [Native] &gt; *` policies.

_Control Types_

- AWS &gt; Secrets Manager &gt; Secret &gt; Stack [Native]

_Policy Types_

- AWS &gt; Secrets Manager &gt; Secret &gt; Stack [Native]
- AWS &gt; Secrets Manager &gt; Secret &gt; Stack [Native] &gt; Drift Detection
- AWS &gt; Secrets Manager &gt; Secret &gt; Stack [Native] &gt; Drift Detection &gt; Interval
- AWS &gt; Secrets Manager &gt; Secret &gt; Stack [Native] &gt; Modifier
- AWS &gt; Secrets Manager &gt; Secret &gt; Stack [Native] &gt; Secret Variables
- AWS &gt; Secrets Manager &gt; Secret &gt; Stack [Native] &gt; Source
- AWS &gt; Secrets Manager &gt; Secret &gt; Stack [Native] &gt; Timeout
- AWS &gt; Secrets Manager &gt; Secret &gt; Stack [Native] &gt; Variables
- AWS &gt; Secrets Manager &gt; Secret &gt; Stack [Native] &gt; Version</description>
            <pubDate>Wed, 07 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-sagemaker-v5-12-0</guid>
            <title>aws-sagemaker v5.12.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-sagemaker-v5-12-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Wed, 07 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-iam-v5-42-0</guid>
            <title>aws-iam v5.42.0 - Configure default region when logging in to AWS accounts via Guardrails using Role mode</title>
            <link>https://turbot.com/guardrails/changelog/aws-iam-v5-42-0</link>
            <description>_What&apos;s new?_

- Users can now select the default region when logging in to AWS accounts via Guardrails using Role mode. To get started, set the `AWS &gt; Account &gt; Permissions &gt; Default Region` policy.

_Policy Types_

- AWS &gt; Account &gt; Permissions &gt; Default Region</description>
            <pubDate>Wed, 07 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-elasticache-v5-11-0</guid>
            <title>aws-elasticache v5.11.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-elasticache-v5-11-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Wed, 07 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ecs-v5-9-0</guid>
            <title>aws-ecs v5.9.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-ecs-v5-9-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Wed, 07 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-docdb-v5-3-0</guid>
            <title>aws-docdb v5.3.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-docdb-v5-3-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Wed, 07 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-cloudfront-v5-7-0</guid>
            <title>aws-cloudfront v5.7.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-cloudfront-v5-7-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Wed, 07 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/guardrails-mcp-v0-1-2</guid>
            <title>Guardrails MCP v0.1.2 - Initial release</title>
            <link>https://turbot.com/guardrails/changelog/guardrails-mcp-v0-1-2</link>
            <description>_What&apos;s new_

* Initial version of Turbot Guardrails MCP server
* Query resources, controls and types
* Mock and test policy settings and policy packs</description>
            <pubDate>Tue, 06 May 2025 10:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-storagegateway-v5-5-0</guid>
            <title>aws-storagegateway v5.5.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-storagegateway-v5-5-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Tue, 06 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-outposts-v5-4-0</guid>
            <title>aws-outposts v5.4.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-outposts-v5-4-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Tue, 06 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-lightsail-v5-6-0</guid>
            <title>aws-lightsail v5.6.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-lightsail-v5-6-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Tue, 06 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-guardduty-v5-10-0</guid>
            <title>aws-guardduty v5.10.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-guardduty-v5-10-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Tue, 06 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-codecommit-v5-6-0</guid>
            <title>aws-codecommit v5.6.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-codecommit-v5-6-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Tue, 06 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-codebuild-v5-7-0</guid>
            <title>aws-codebuild v5.7.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-codebuild-v5-7-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Tue, 06 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-acm-v5-10-0</guid>
            <title>aws-acm v5.10.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-acm-v5-10-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Tue, 06 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-workspaces-v5-4-0</guid>
            <title>aws-workspaces v5.4.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-workspaces-v5-4-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Mon, 05 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-swf-v5-6-0</guid>
            <title>aws-swf v5.6.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-swf-v5-6-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Mon, 05 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-securityhub-v5-4-0</guid>
            <title>aws-securityhub v5.4.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-securityhub-v5-4-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Mon, 05 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-route53resolver-v5-5-0</guid>
            <title>aws-route53resolver v5.5.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-route53resolver-v5-5-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Mon, 05 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-kinesis-v5-10-0</guid>
            <title>aws-kinesis v5.10.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-kinesis-v5-10-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Mon, 05 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-emr-v5-9-0</guid>
            <title>aws-emr v5.9.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-emr-v5-9-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Mon, 05 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-elasticsearch-v5-7-0</guid>
            <title>aws-elasticsearch v5.7.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-elasticsearch-v5-7-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Mon, 05 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-eks-v5-8-0</guid>
            <title>aws-eks v5.8.0 - Manage endpoint access for clusters</title>
            <link>https://turbot.com/guardrails/changelog/aws-eks-v5-8-0</link>
            <description>_What&apos;s new?_

- Users can now manage endpoint access for clusters. To get started, set the `AWS &gt; EKS &gt; Cluster &gt; Endpoint Access &gt; *` policies.
- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Control Types_

- AWS &gt; EKS &gt; Cluster &gt; Endpoint Access

_Policy Types_

- AWS &gt; EKS &gt; Cluster &gt; Endpoint Access
- AWS &gt; EKS &gt; Cluster &gt; Endpoint Access &gt; CIDR Ranges

_Action Types_

- AWS &gt; EKS &gt; Cluster &gt; Set Endpoint Access

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Mon, 05 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-efs-v5-10-0</guid>
            <title>aws-efs v5.10.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-efs-v5-10-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Mon, 05 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ecr-v5-14-0</guid>
            <title>aws-ecr v5.14.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-ecr-v5-14-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Mon, 05 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-dms-v5-7-0</guid>
            <title>aws-dms v5.7.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-dms-v5-7-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Mon, 05 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-rds-v5-31-2</guid>
            <title>aws-rds v5.31.2 - Identifiers for DB Instances will now be modified more reliably</title>
            <link>https://turbot.com/guardrails/changelog/aws-rds-v5-31-2</link>
            <description>_Bug fixes_

- Previously, modifying instance identifiers to use different casing while retaining the same name caused Guardrails to incorrectly update the `DBInstanceIdentifier` and the AKA for the resource. Guardrails will now be smarter to avoid updating these details in CMDB data in such scenarios.</description>
            <pubDate>Fri, 02 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ec2-v5-45-1</guid>
            <title>aws-ec2 v5.45.1 - Fixed pagination in AMI discovery control to fetch all AMIs correctly</title>
            <link>https://turbot.com/guardrails/changelog/aws-ec2-v5-45-1</link>
            <description>_Bug fixes_

- The `AWS &gt; EC2 &gt; AMI &gt; Discovery` control previously failed to fetch all resources, due to the lack of pagination support. This issue has been fixed, and the control will now correctly fetch all available AMIs.</description>
            <pubDate>Fri, 02 May 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/kubernetes-v5-2-1</guid>
            <title>kubernetes v5.2.1 - Removed unnecessary attributes from default value of `Configuration &gt; Columns` policy for pods to prevent unnecessary triggering of CMDB control</title>
            <link>https://turbot.com/guardrails/changelog/kubernetes-v5-2-1</link>
            <description>_Bug fixes_

- Removed unnecessary attributes from the default value of the `Kubernetes &gt; Pod &gt; osquery &gt; Configuration &gt; Columns` policy, which previously caused churn by unnecessarily triggering the `Kubernetes &gt; Pod &gt; CMDB` control.</description>
            <pubDate>Wed, 30 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-50-6</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.50.6 - Removed stray debug logs</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-50-6</link>
            <description>_Bug fixes_

- Server
  -	Removed stray debug logs.

_Requirements_

- TEF: 1.66.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Mon, 28 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-50-5</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.50.5 - Improved error handling for Runnable Monitor and Event Monitor to catch uncaught exceptions</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-50-5</link>
            <description>_Bug fixes_

- Server
  -	Improved error handling for Runnable Monitor and Event Monitor to catch uncaught exceptions.

_Requirements_

- TEF: 1.66.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Mon, 28 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/turbot-v5-51-2</guid>
            <title>turbot v5.51.2 - Adjusted the sequence of operations for Turbot &gt; Workspace &gt; Background Tasks to ensure a more reliable and consistent execution flow</title>
            <link>https://turbot.com/guardrails/changelog/turbot-v5-51-2</link>
            <description>_Bug fixes_

- Control Types:
  - Adjusted the sequence of operations for `Turbot &gt; Workspace &gt; Background Tasks` to ensure a more reliable and consistent execution flow.

_Requirements_

- TE: 5.35.4</description>
            <pubDate>Mon, 28 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-secretsmanager-v5-9-0</guid>
            <title>aws-secretsmanager v5.9.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-secretsmanager-v5-9-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Mon, 28 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ram-v5-4-0</guid>
            <title>aws-ram v5.4.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-ram-v5-4-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Mon, 28 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-dax-v5-5-0</guid>
            <title>aws-dax v5.5.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-dax-v5-5-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Mon, 28 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-cloudformation-v5-12-0</guid>
            <title>aws-cloudformation v5.12.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-cloudformation-v5-12-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Mon, 28 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-athena-v5-5-0</guid>
            <title>aws-athena v5.5.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-athena-v5-5-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Mon, 28 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-aws-vpc-security-v5-2-0</guid>
            <title>servicenow-aws-vpc-security v5.2.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-aws-vpc-security-v5-2-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.</description>
            <pubDate>Fri, 25 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-aws-vpc-internet-v5-2-0</guid>
            <title>servicenow-aws-vpc-internet v5.2.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-aws-vpc-internet-v5-2-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.</description>
            <pubDate>Fri, 25 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-aws-vpc-core-v5-2-0</guid>
            <title>servicenow-aws-vpc-core v5.2.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-aws-vpc-core-v5-2-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.</description>
            <pubDate>Fri, 25 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-aws-vpc-connect-v5-1-0</guid>
            <title>servicenow-aws-vpc-connect v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-aws-vpc-connect-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.</description>
            <pubDate>Fri, 25 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-aws-v5-4-0</guid>
            <title>servicenow-aws v5.4.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-aws-v5-4-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.</description>
            <pubDate>Fri, 25 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-aws-s3-v5-3-0</guid>
            <title>servicenow-aws-s3 v5.3.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-aws-s3-v5-3-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.</description>
            <pubDate>Fri, 25 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-aws-rds-v5-1-0</guid>
            <title>servicenow-aws-rds v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-aws-rds-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Fri, 25 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-aws-kms-v5-1-0</guid>
            <title>servicenow-aws-kms v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-aws-kms-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.</description>
            <pubDate>Fri, 25 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-aws-iam-v5-1-0</guid>
            <title>servicenow-aws-iam v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-aws-iam-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Fri, 25 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-aws-ec2-v5-2-0</guid>
            <title>servicenow-aws-ec2 v5.2.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-aws-ec2-v5-2-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.</description>
            <pubDate>Fri, 25 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-aws-cloudwatch-v5-1-0</guid>
            <title>servicenow-aws-cloudwatch v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-aws-cloudwatch-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Fri, 25 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-aws-cloudtrail-v5-1-0</guid>
            <title>servicenow-aws-cloudtrail v5.1.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-aws-cloudtrail-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Improved the logic in the Table and Configuration Item controls to avoid querying credentials unnecessarily when those controls are skipped.
- Improved the GraphQL input query for the `Configuration Item &gt; Record` policy to retrieve only the essential details required for the policy&apos;s functionality. This enhancement enables Guardrails to evaluate policies more efficiently, improving performance and reducing processing load.</description>
            <pubDate>Fri, 25 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-cisv2-0-v5-1-1</guid>
            <title>gcp-cisv2-0 v5.1.1 - Controls will no longer enter invalid or TBD state when corresponding CIS policies are set to `Skip`</title>
            <link>https://turbot.com/guardrails/changelog/gcp-cisv2-0-v5-1-1</link>
            <description>_Bug fixes_

- CIS controls previously entered an invalid or TBD state when the CMDB controls for associated resources were in a skipped or TBD state, even if the corresponding CIS policies were set to `Skip`. This issue has been resolved; such controls will now correctly transition to a skipped state.</description>
            <pubDate>Fri, 25 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-storage-v5-22-1</guid>
            <title>azure-storage v5.22.1 - Tags will now be updated correctly for storage accounts of type `StandardV2_LRS`</title>
            <link>https://turbot.com/guardrails/changelog/azure-storage-v5-22-1</link>
            <description>_Bug fixes_

- The `Azure &gt; Storage &gt; Storage Account &gt; Tags` control previously failed to update tags for storage accounts of type `StandardV2_LRS`. This issue has been resolved, and the control now correctly updates tags for this storage account type.
- The `Azure &gt; Storage &gt; Queue &gt; Discovery` control previously entered an error state for storage accounts of kind `FileStorage`. This issue has been resolved, and the control will now be skipped for such storage accounts.</description>
            <pubDate>Fri, 25 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ssm-v5-16-0</guid>
            <title>aws-ssm v5.16.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-ssm-v5-16-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Fri, 25 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-secretsmanager-v5-8-0</guid>
            <title>aws-secretsmanager v5.8.0 - Configure and manage rotation for secrets</title>
            <link>https://turbot.com/guardrails/changelog/aws-secretsmanager-v5-8-0</link>
            <description>_What&apos;s new?_

- You can now configure and manage rotation for secrets. To get started, set the `AWS &gt; Secrets Manager &gt; Secret &gt; Rotation &gt; *` policies.

_Control Types_

- AWS &gt; Secrets Manager &gt; Secret &gt; Rotation

_Policy Types_

- AWS &gt; Secrets Manager &gt; Secret &gt; Rotation
- AWS &gt; Secrets Manager &gt; Secret &gt; Rotation &gt; Schedule Expression

_Action Types_

- AWS &gt; Secrets Manager &gt; Secret &gt; Set Rotation</description>
            <pubDate>Fri, 25 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-s3multiregionaccesspoint-v5-1-0</guid>
            <title>aws-s3multiregionaccesspoint v5.1.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-s3multiregionaccesspoint-v5-1-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Fri, 25 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-50-4</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.50.4 - Improvements to performance, stability, and UI experience</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-50-4</link>
            <description>_Bug fixes_

- Server
  -	Reduced the time taken to collect and process data in Account &gt; Statistics, resulting in noticeably faster and a smoother experience.
  - Enhanced the reliability of Turbot &gt; Mod &gt; Runnable Monitor and Turbot &gt; Mod Event Monitor by improving how they handle temporary lock conflicts, ensuring more consistent operation.
  - Fixed an issue where moving a resource between parents could create an incorrect path.
  - Policy packs can now only be attached to resources where it is feasible to attach.

- UI
  - Resolved a layout issue where long resource names could break the detail headers on the Control, Process, and Policy pages.

_Requirements_

- TEF: 1.66.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Thu, 24 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-kubernetesengine-v5-7-0</guid>
            <title>gcp-kubernetesengine v5.7.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/gcp-kubernetesengine-v5-7-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- We&apos;ve enhanced event handling to dynamically filter cloud provider events based on the CMDB policy for each resource type. If a resource&apos;s CMDB policy is not set to `Enforce: Enabled`, events for that resource type will be excluded from the event handling configuration. This enhancement significantly reduces the number of unnecessary events processed by Guardrails.</description>
            <pubDate>Thu, 24 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-xray-v5-5-0</guid>
            <title>aws-xray v5.5.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-xray-v5-5-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Thu, 24 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-wafregional-v5-5-0</guid>
            <title>aws-wafregional v5.5.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-wafregional-v5-5-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Thu, 24 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-stepfunctions-v5-7-0</guid>
            <title>aws-stepfunctions v5.7.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-stepfunctions-v5-7-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Thu, 24 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-rds-v5-31-1</guid>
            <title>aws-rds v5.31.1 - DB parameter groups will now be correctly upserted into the CMDB irrespective of their casing</title>
            <link>https://turbot.com/guardrails/changelog/aws-rds-v5-31-1</link>
            <description>_Bug fixes_

- Guardrails previously upserted DB parameter groups into the CMDB with incorrect casing when they were created using uppercase letters in AWS. This occasionally caused the `AWS &gt; RDS &gt; DB Parameter Group &gt; CMDB` control to enter an error state due to duplicate AKAs. We have improved the handling of create and copy real-time events for parameter groups to ensure they are now upserted correctly and more reliably.</description>
            <pubDate>Thu, 24 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-qldb-v5-4-0</guid>
            <title>aws-qldb v5.4.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-qldb-v5-4-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Thu, 24 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-neptune-v5-5-0</guid>
            <title>aws-neptune v5.5.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-neptune-v5-5-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Thu, 24 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-msk-v5-5-0</guid>
            <title>aws-msk v5.5.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-msk-v5-5-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Thu, 24 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-mq-v5-3-0</guid>
            <title>aws-mq v5.3.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-mq-v5-3-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Thu, 24 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-logs-v5-15-0</guid>
            <title>aws-logs v5.15.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-logs-v5-15-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Thu, 24 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-inspector-v5-3-0</guid>
            <title>aws-inspector v5.3.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-inspector-v5-3-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Thu, 24 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-glacier-v5-7-0</guid>
            <title>aws-glacier v5.7.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-glacier-v5-7-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Thu, 24 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-fsx-v5-4-0</guid>
            <title>aws-fsx v5.4.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-fsx-v5-4-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Thu, 24 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-elasticbeanstalk-v5-4-0</guid>
            <title>aws-elasticbeanstalk v5.4.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-elasticbeanstalk-v5-4-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Thu, 24 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-directoryservice-v5-5-0</guid>
            <title>aws-directoryservice v5.5.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-directoryservice-v5-5-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Thu, 24 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-config-v5-11-0</guid>
            <title>aws-config v5.11.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-config-v5-11-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Thu, 24 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-shield-v5-3-0</guid>
            <title>aws-shield v5.3.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-shield-v5-3-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Wed, 23 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ses-v5-5-0</guid>
            <title>aws-ses v5.5.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-ses-v5-5-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Wed, 23 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-batch-v5-7-0</guid>
            <title>aws-batch v5.7.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-batch-v5-7-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Wed, 23 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-appstream-v5-4-0</guid>
            <title>aws-appstream v5.4.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-appstream-v5-4-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Wed, 23 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-appmesh-v5-5-0</guid>
            <title>aws-appmesh v5.5.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-appmesh-v5-5-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Wed, 23 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-amplify-v5-5-0</guid>
            <title>aws-amplify v5.5.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-amplify-v5-5-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Wed, 23 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-scheduler-v5-5-0</guid>
            <title>gcp-scheduler v5.5.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/gcp-scheduler-v5-5-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.</description>
            <pubDate>Tue, 22 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-memorystore-v5-4-0</guid>
            <title>gcp-memorystore v5.4.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/gcp-memorystore-v5-4-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- We&apos;ve enhanced event handling to dynamically filter cloud provider events based on the CMDB policy for each resource type. If a resource&apos;s CMDB policy is not set to `Enforce: Enabled`, events for that resource type will be excluded from the event handling configuration. This enhancement significantly reduces the number of unnecessary events processed by Guardrails.</description>
            <pubDate>Tue, 22 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-datapipeline-v5-2-0</guid>
            <title>gcp-datapipeline v5.2.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/gcp-datapipeline-v5-2-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- We&apos;ve enhanced event handling to dynamically filter cloud provider events based on the CMDB policy for each resource type. If a resource&apos;s CMDB policy is not set to `Enforce: Enabled`, events for that resource type will be excluded from the event handling configuration. This enhancement significantly reduces the number of unnecessary events processed by Guardrails.</description>
            <pubDate>Tue, 22 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-bigtable-v5-9-0</guid>
            <title>gcp-bigtable v5.9.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/gcp-bigtable-v5-9-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- We&apos;ve enhanced event handling to dynamically filter cloud provider events based on the CMDB policy for each resource type. If a resource&apos;s CMDB policy is not set to `Enforce: Enabled`, events for that resource type will be excluded from the event handling configuration. This enhancement significantly reduces the number of unnecessary events processed by Guardrails.</description>
            <pubDate>Tue, 22 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-vpc-connect-v5-10-1</guid>
            <title>aws-vpc-connect v5.10.1 - CMDB control for transit gateway attachments will no longer enter an error state when `ResourceOwnerId` for resources is not available in the CMDB data</title>
            <link>https://turbot.com/guardrails/changelog/aws-vpc-connect-v5-10-1</link>
            <description>_Bug fixes_

- The `AWS &gt; VPC &gt; Transit Gateway Attachment &gt; CMDB` control would sometimes go into an error state when `ResourceOwnerId` for the resource was not available in the CMDB data. This is fixed and the control will now work correctly, as expected.</description>
            <pubDate>Tue, 22 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-iam-v5-41-1</guid>
            <title>aws-iam v5.41.1 - Removed conflicting default value for `force_detach_policies` for IAM roles managed via Guardrails stack controls</title>
            <link>https://turbot.com/guardrails/changelog/aws-iam-v5-41-1</link>
            <description>_Bug fixes_

- Guardrails stack controls that created or claimed IAM roles would sometimes run unnecessarily due to a mismatch in the default value for `force_detach_policies` in the Terraform mapping for the resource type. We have now removed the conflicting default to prevent such unnecessary executions. You now need to explicitly define `force_detach_policies` to override the existing Terraform default value (if required by your use case).</description>
            <pubDate>Mon, 21 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-logs-v5-14-0</guid>
            <title>aws-logs v5.14.0 - Configure retention period for log groups</title>
            <link>https://turbot.com/guardrails/changelog/aws-logs-v5-14-0</link>
            <description>_What&apos;s new?_

- You can now configure retention period for log groups. To get started, set the `AWS &gt; Logs &gt; Log Group &gt; Retention &gt; *` policies.

_Control Types_

- AWS &gt; Logs &gt; Log Group &gt; Retention

_Policy Types_

- AWS &gt; Logs &gt; Log Group &gt; Retention
- AWS &gt; Logs &gt; Log Group &gt; Retention &gt; Period

_Action Types_

- AWS &gt; Logs &gt; Log Group &gt; Update Retention</description>
            <pubDate>Thu, 17 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-50-3</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.50.3 - Multiple query support in calculated policy</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-50-3</link>
            <description>_What&apos;s new?_

- UI
  - Added support for multiple input queries (with ability to use Nunjucks template functionality) in the calculated policy editor allowing teams to create complex calculated policies involving a pipeline of GraphQL queries.

_Bug fixes_

- Server
  -	Turbot/ReadOnly permission is now sufficient to create, delete, and update favorites.
  - Resolved an issue that was blocking users from running quick actions due to incorrect permission checks.
  - Tightened permissions for smart folder attachments and detachments to prevent unauthorized access.
  - Account/ReadOnly users can now successfully manage favorites, including creation, deletion, and updates.

- UI
  - Policy settings can now be created by users with Account/Admin permission, as intended, instead of incorrectly requiring Account/Owner.
  - Quick action runs no longer fail for users with a single grant due to a UI permission check issue.

_Requirements_

- TEF: 1.66.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Wed, 16 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-sql-v5-11-0</guid>
            <title>gcp-sql v5.11.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/gcp-sql-v5-11-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- We&apos;ve enhanced event handling to dynamically filter cloud provider events based on the CMDB policy for each resource type. If a resource&apos;s CMDB policy is not set to `Enforce: Enabled`, events for that resource type will be excluded from the event handling configuration. This enhancement significantly reduces the number of unnecessary events processed by Guardrails.</description>
            <pubDate>Tue, 15 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-network-v5-15-0</guid>
            <title>gcp-network v5.15.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/gcp-network-v5-15-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- We&apos;ve enhanced event handling to dynamically filter cloud provider events based on the CMDB policy for each resource type. If a resource&apos;s CMDB policy is not set to `Enforce: Enabled`, events for that resource type will be excluded from the event handling configuration. This enhancement significantly reduces the number of unnecessary events processed by Guardrails.</description>
            <pubDate>Tue, 15 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-firebase-v5-2-0</guid>
            <title>gcp-firebase v5.2.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/gcp-firebase-v5-2-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.</description>
            <pubDate>Tue, 15 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-cloudfront-v5-6-0</guid>
            <title>aws-cloudfront v5.6.0 - Create and manage cloud resources via Stack [Native] controls</title>
            <link>https://turbot.com/guardrails/changelog/aws-cloudfront-v5-6-0</link>
            <description>_What&apos;s new?_

- Users can now create and manage cloud resources using Terraform 1.x via Guardrails, fully leveraging all features available in this version. To get started, set the `Stack [Native] &gt; *` policies.

_Control Types_

- AWS &gt; CloudFront &gt; Distribution &gt; Stack [Native]

_Policy Types_

- AWS &gt; CloudFront &gt; Distribution &gt; Stack [Native]
- AWS &gt; CloudFront &gt; Distribution &gt; Stack [Native] &gt; Drift Detection
- AWS &gt; CloudFront &gt; Distribution &gt; Stack [Native] &gt; Drift Detection &gt; Interval
- AWS &gt; CloudFront &gt; Distribution &gt; Stack [Native] &gt; Modifier
- AWS &gt; CloudFront &gt; Distribution &gt; Stack [Native] &gt; Secret Variables
- AWS &gt; CloudFront &gt; Distribution &gt; Stack [Native] &gt; Source
- AWS &gt; CloudFront &gt; Distribution &gt; Stack [Native] &gt; Timeout
- AWS &gt; CloudFront &gt; Distribution &gt; Stack [Native] &gt; Variables
- AWS &gt; CloudFront &gt; Distribution &gt; Stack [Native] &gt; Version</description>
            <pubDate>Tue, 15 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-iam-v5-17-1</guid>
            <title>gcp-iam v5.17.1 - Configured control for Logging sinks created via Event Handlers now work as expected</title>
            <link>https://turbot.com/guardrails/changelog/gcp-iam-v5-17-1</link>
            <description>_Bug fixes_

- The `GCP &gt; Turbot &gt; Event Handlers &gt; Logging &gt; Sink &gt; Compiled Filter &gt; @turbot/gcp-iam` rendered the real-time events filter for Project User resource type incorrectly, which caused the `GCP &gt; Logging &gt; Sink &gt; Configured` control for Logging sinks created via Event Handlers to go into an error state. This issue is now fixed.
- The `GCP &gt; IAM &gt; Project User &gt; CMDB` control entered an error state due to incorrect internal references introduced in the previous version of the mod (v5.17.0). This issue has been fixed, and the control now works as expected.</description>
            <pubDate>Mon, 14 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-secretmanager-v5-2-0</guid>
            <title>gcp-secretmanager v5.2.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/gcp-secretmanager-v5-2-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- We&apos;ve enhanced event handling to dynamically filter cloud provider events based on the CMDB policy for each resource type. If a resource&apos;s CMDB policy is not set to `Enforce: Enabled`, events for that resource type will be excluded from the event handling configuration. This enhancement significantly reduces the number of unnecessary events processed by Guardrails.</description>
            <pubDate>Mon, 14 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-notebook-v5-2-0</guid>
            <title>gcp-notebook v5.2.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/gcp-notebook-v5-2-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.</description>
            <pubDate>Mon, 14 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-monitoring-v5-8-0</guid>
            <title>gcp-monitoring v5.8.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/gcp-monitoring-v5-8-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- We&apos;ve enhanced event handling to dynamically filter cloud provider events based on the CMDB policy for each resource type. If a resource&apos;s CMDB policy is not set to `Enforce: Enabled`, events for that resource type will be excluded from the event handling configuration. This enhancement significantly reduces the number of unnecessary events processed by Guardrails.</description>
            <pubDate>Mon, 14 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-kms-v5-9-0</guid>
            <title>gcp-kms v5.9.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/gcp-kms-v5-9-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- We&apos;ve enhanced event handling to dynamically filter cloud provider events based on the CMDB policy for each resource type. If a resource&apos;s CMDB policy is not set to `Enforce: Enabled`, events for that resource type will be excluded from the event handling configuration. This enhancement significantly reduces the number of unnecessary events processed by Guardrails.</description>
            <pubDate>Mon, 14 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-dns-v5-9-0</guid>
            <title>gcp-dns v5.9.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/gcp-dns-v5-9-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- We&apos;ve enhanced event handling to dynamically filter cloud provider events based on the CMDB policy for each resource type. If a resource&apos;s CMDB policy is not set to `Enforce: Enabled`, events for that resource type will be excluded from the event handling configuration. This enhancement significantly reduces the number of unnecessary events processed by Guardrails.</description>
            <pubDate>Mon, 14 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/turbot-v5-51-1</guid>
            <title>turbot v5.51.1 - Updates to quick actions, notifications and GovCloud compatibility</title>
            <link>https://turbot.com/guardrails/changelog/turbot-v5-51-1</link>
            <description>_What&apos;s new?_

- Policy Types:
  - Turbot &gt; Quick Actions &gt; Permission Levels to allow `account`, `azure` and `gcp` as a permission type.
  - Added `class: ACCOUNT` to Turbot &gt; Notifications &gt; CC &gt; Tag and Turbot &gt; Notifications &gt; CC &gt; Tag &gt; Name.

_Bug fixes_

- Control Types:
  - The `Turbot &gt; Workspace &gt; Usage` control will be skipped in GovCloud deployments.

_Requirements_

- TE: 5.35.4</description>
            <pubDate>Fri, 11 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-vertexai-v5-1-0</guid>
            <title>gcp-vertexai v5.1.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/gcp-vertexai-v5-1-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- We&apos;ve enhanced event handling to dynamically filter cloud provider events based on the CMDB policy for each resource type. If a resource&apos;s CMDB policy is not set to `Enforce: Enabled`, events for that resource type will be excluded from the event handling configuration. This enhancement significantly reduces the number of unnecessary events processed by Guardrails.</description>
            <pubDate>Fri, 11 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-v5-31-1</guid>
            <title>gcp v5.31.1 - Project labels control now correctly applies labels according to template policy</title>
            <link>https://turbot.com/guardrails/changelog/gcp-v5-31-1</link>
            <description>_Bug fixes_

- The `GCP &gt; Project &gt; Labels` control failed to apply labels to projects according to the `GCP &gt; Project &gt; Labels &gt; Template` policy. This issue has been fixed.</description>
            <pubDate>Fri, 11 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-spanner-v5-9-0</guid>
            <title>gcp-spanner v5.9.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/gcp-spanner-v5-9-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- We&apos;ve enhanced event handling to dynamically filter cloud provider events based on the CMDB policy for each resource type. If a resource&apos;s CMDB policy is not set to `Enforce: Enabled`, events for that resource type will be excluded from the event handling configuration. This enhancement significantly reduces the number of unnecessary events processed by Guardrails.</description>
            <pubDate>Fri, 11 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-run-v5-2-0</guid>
            <title>gcp-run v5.2.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/gcp-run-v5-2-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- We&apos;ve enhanced event handling to dynamically filter cloud provider events based on the CMDB policy for each resource type. If a resource&apos;s CMDB policy is not set to `Enforce: Enabled`, events for that resource type will be excluded from the event handling configuration. This enhancement significantly reduces the number of unnecessary events processed by Guardrails.</description>
            <pubDate>Fri, 11 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-dataplex-v5-1-0</guid>
            <title>gcp-dataplex v5.1.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/gcp-dataplex-v5-1-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- We&apos;ve enhanced event handling to dynamically filter cloud provider events based on the CMDB policy for each resource type. If a resource&apos;s CMDB policy is not set to `Enforce: Enabled`, events for that resource type will be excluded from the event handling configuration. This enhancement significantly reduces the number of unnecessary events processed by Guardrails.</description>
            <pubDate>Fri, 11 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-dataflow-v5-6-0</guid>
            <title>gcp-dataflow v5.6.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/gcp-dataflow-v5-6-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- We&apos;ve enhanced event handling to dynamically filter cloud provider events based on the CMDB policy for each resource type. If a resource&apos;s CMDB policy is not set to `Enforce: Enabled`, events for that resource type will be excluded from the event handling configuration. This enhancement significantly reduces the number of unnecessary events processed by Guardrails.</description>
            <pubDate>Fri, 11 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-datacatalog-v5-3-0</guid>
            <title>gcp-datacatalog v5.3.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/gcp-datacatalog-v5-3-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.</description>
            <pubDate>Fri, 11 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-composer-v5-5-0</guid>
            <title>gcp-composer v5.5.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/gcp-composer-v5-5-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- We&apos;ve enhanced event handling to dynamically filter cloud provider events based on the CMDB policy for each resource type. If a resource&apos;s CMDB policy is not set to `Enforce: Enabled`, events for that resource type will be excluded from the event handling configuration. This enhancement significantly reduces the number of unnecessary events processed by Guardrails.</description>
            <pubDate>Fri, 11 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-build-v5-3-0</guid>
            <title>gcp-build v5.3.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/gcp-build-v5-3-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.</description>
            <pubDate>Fri, 11 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-v5-37-1</guid>
            <title>aws v5.37.1 - Updated internal definitions for organization resource type</title>
            <link>https://turbot.com/guardrails/changelog/aws-v5-37-1</link>
            <description>_Bug fixes_

- Internal definitions for the `AWS &gt; Organization` resource type have been updated. All functionality will continue to work smoothly as before.</description>
            <pubDate>Fri, 11 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-s3-v5-31-1</guid>
            <title>aws-s3 v5.31.1 - Updated internal definitions for Quick Actions on `Public Access Block` control for buckets</title>
            <link>https://turbot.com/guardrails/changelog/aws-s3-v5-31-1</link>
            <description>_Bug fixes_

- We&apos;ve updated internal definitions for Quick Actions on the `AWS &gt; S3 &gt; Bucket &gt; Public Access Block` control type. All functionality will continue to work smoothly as before.</description>
            <pubDate>Fri, 11 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ec2-v5-45-0</guid>
            <title>aws-ec2 v5.45.0 - Guardrails can now discover and manage target groups for gateway load balancers across all supported regions</title>
            <link>https://turbot.com/guardrails/changelog/aws-ec2-v5-45-0</link>
            <description>_What&apos;s new?_

- The `AWS &gt; EC2 &gt; Target Group &gt; Discovery` control sometimes failed to upsert target groups under gateway load balancers that were not present in the CMDB. This occurred because Guardrails was unable to discover those gateway load balancers due to an outdated list of supported regions. The list has been refreshed for the `AWS &gt; EC2 &gt; Gateway Load Balancer` resource type, enabling Guardrails to discover and manage these resources across all supported AWS regions.</description>
            <pubDate>Fri, 11 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-50-2</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.50.2 - Improved how policy values are selected for the priority queue, resulting in faster and more efficient processing</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-50-2</link>
            <description>_Bug fixes_

- Server
  - Improved how policy values are selected for the priority queue, resulting in faster and more efficient processing.

- UI
  - Pagination and title-based sorting are now supported in policy targets, making navigation smoother.
  - The Permissions modal is more stable and won’t crash if some data is missing.

_Requirements_

- TEF: 1.66.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Thu, 10 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-custom-v5-0-1</guid>
            <title>servicenow-custom v5.0.1 - CMDB controls for custom tables and records now update data in the CMDB more consistently</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-custom-v5-0-1</link>
            <description>_Bug fixes_

- CMDB controls for custom tables and records occasionally failed to update data in the CMDB correctly. This issue has been resolved.</description>
            <pubDate>Thu, 10 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-iam-v5-17-0</guid>
            <title>gcp-iam v5.17.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/gcp-iam-v5-17-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- We&apos;ve enhanced event handling to dynamically filter cloud provider events based on the CMDB policy for each resource type. If a resource&apos;s CMDB policy is not set to `Enforce: Enabled`, events for that resource type will be excluded from the event handling configuration. This enhancement significantly reduces the number of unnecessary events processed by Guardrails.</description>
            <pubDate>Thu, 10 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-computeengine-v5-20-0</guid>
            <title>gcp-computeengine v5.20.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/gcp-computeengine-v5-20-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- We&apos;ve enhanced event handling to dynamically filter cloud provider events based on the CMDB policy for each resource type. If a resource&apos;s CMDB policy is not set to `Enforce: Enabled`, events for that resource type will be excluded from the event handling configuration. This enhancement significantly reduces the number of unnecessary events processed by Guardrails.</description>
            <pubDate>Thu, 10 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-50-1</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.50.1 - Resolved an issue that was preventing users from logging in via SAML</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-50-1</link>
            <description>_Bug fixes_

- Server
  - Resolved an issue that was preventing users from logging in via SAML.

- UI
  - Action buttons now show up correctly on the process logs page, whether you’re viewing control or policy.

_Requirements_

- TEF: 1.66.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Wed, 09 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-v5-31-0</guid>
            <title>gcp v5.31.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/gcp-v5-31-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.</description>
            <pubDate>Wed, 09 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-storage-v5-12-0</guid>
            <title>gcp-storage v5.12.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/gcp-storage-v5-12-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- We&apos;ve enhanced event handling to dynamically filter cloud provider events based on the CMDB policy for each resource type. If a resource&apos;s CMDB policy is not set to `Enforce: Enabled`, events for that resource type will be excluded from the event handling configuration. This enhancement significantly reduces the number of unnecessary events processed by Guardrails.</description>
            <pubDate>Wed, 09 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-pubsub-v5-10-0</guid>
            <title>gcp-pubsub v5.10.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/gcp-pubsub-v5-10-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- We&apos;ve enhanced event handling to dynamically filter cloud provider events based on the CMDB policy for each resource type. If a resource&apos;s CMDB policy is not set to `Enforce: Enabled`, events for that resource type will be excluded from the event handling configuration. This enhancement significantly reduces the number of unnecessary events processed by Guardrails.</description>
            <pubDate>Wed, 09 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-logging-v5-6-0</guid>
            <title>gcp-logging v5.6.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/gcp-logging-v5-6-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- We&apos;ve enhanced event handling to dynamically filter cloud provider events based on the CMDB policy for each resource type. If a resource&apos;s CMDB policy is not set to `Enforce: Enabled`, events for that resource type will be excluded from the event handling configuration. This enhancement significantly reduces the number of unnecessary events processed by Guardrails.</description>
            <pubDate>Wed, 09 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-functions-v5-9-0</guid>
            <title>gcp-functions v5.9.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/gcp-functions-v5-9-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- We&apos;ve enhanced event handling to dynamically filter cloud provider events based on the CMDB policy for each resource type. If a resource&apos;s CMDB policy is not set to `Enforce: Enabled`, events for that resource type will be excluded from the event handling configuration. This enhancement significantly reduces the number of unnecessary events processed by Guardrails.</description>
            <pubDate>Wed, 09 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-dataproc-v5-9-0</guid>
            <title>gcp-dataproc v5.9.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/gcp-dataproc-v5-9-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- We&apos;ve enhanced event handling to dynamically filter cloud provider events based on the CMDB policy for each resource type. If a resource&apos;s CMDB policy is not set to `Enforce: Enabled`, events for that resource type will be excluded from the event handling configuration. This enhancement significantly reduces the number of unnecessary events processed by Guardrails.</description>
            <pubDate>Wed, 09 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-bigquerydatatransfer-v5-1-0</guid>
            <title>gcp-bigquerydatatransfer v5.1.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/gcp-bigquerydatatransfer-v5-1-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- We&apos;ve enhanced event handling to dynamically filter cloud provider events based on the CMDB policy for each resource type. If a resource&apos;s CMDB policy is not set to `Enforce: Enabled`, events for that resource type will be excluded from the event handling configuration. This enhancement significantly reduces the number of unnecessary events processed by Guardrails.</description>
            <pubDate>Wed, 09 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-bigquery-v5-8-0</guid>
            <title>gcp-bigquery v5.8.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/gcp-bigquery-v5-8-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- We&apos;ve enhanced event handling to dynamically filter cloud provider events based on the CMDB policy for each resource type. If a resource&apos;s CMDB policy is not set to `Enforce: Enabled`, events for that resource type will be excluded from the event handling configuration. This enhancement significantly reduces the number of unnecessary events processed by Guardrails.</description>
            <pubDate>Wed, 09 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-appengine-v5-4-0</guid>
            <title>gcp-appengine v5.4.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/gcp-appengine-v5-4-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- We&apos;ve enhanced event handling to dynamically filter cloud provider events based on the CMDB policy for each resource type. If a resource&apos;s CMDB policy is not set to `Enforce: Enabled`, events for that resource type will be excluded from the event handling configuration. This enhancement significantly reduces the number of unnecessary events processed by Guardrails.</description>
            <pubDate>Wed, 09 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-v5-4-0</guid>
            <title>servicenow v5.4.0 - Added support to process real-time events for ServiceNow custom tables and their records</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-v5-4-0</link>
            <description>_What&apos;s new?_

- Added support to process real-time events for ServiceNow custom tables and their records.
- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.</description>
            <pubDate>Tue, 08 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-custom-v5-0-0</guid>
            <title>servicenow-custom v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-custom-v5-0-0</link>
            <description>_What&apos;s new?_

_Resource Types_

- ServiceNow &gt; Custom
- ServiceNow &gt; Custom &gt; Record
- ServiceNow &gt; Custom &gt; Table

_Control Types_

- ServiceNow &gt; Custom &gt; Record &gt; CMDB
- ServiceNow &gt; Custom &gt; Record &gt; Discovery
- ServiceNow &gt; Custom &gt; Table &gt; Business Rule
- ServiceNow &gt; Custom &gt; Table &gt; CMDB
- ServiceNow &gt; Custom &gt; Table &gt; Discovery

_Policy Types_

- ServiceNow &gt; Custom &gt; Record &gt; CMDB
- ServiceNow &gt; Custom &gt; Record &gt; CMDB &gt; Query
- ServiceNow &gt; Custom &gt; Record &gt; CMDB &gt; Title
- ServiceNow &gt; Custom &gt; Table &gt; Business Rule
- ServiceNow &gt; Custom &gt; Table &gt; Business Rule &gt; Name
- ServiceNow &gt; Custom &gt; Table &gt; CMDB
- ServiceNow &gt; Custom &gt; Table &gt; CMDB &gt; Tables

_Action Types_

- ServiceNow &gt; Custom &gt; Record &gt; Router</description>
            <pubDate>Tue, 08 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-v5-37-0</guid>
            <title>aws v5.37.0 - Configure default connection region to fetch details for global resources in CMDB</title>
            <link>https://turbot.com/guardrails/changelog/aws-v5-37-0</link>
            <description>_What&apos;s new?_

- The `AWS &gt; Region &gt; Discovery &gt; Connection Region` policy has been deprecated and will be removed in the next major version of the mod (v6.0.0). Two new policies, `AWS &gt; Account &gt; Connection Region [Default]` and `AWS &gt; Region &gt; Connection Region`, have been introduced. These policies streamline connection region management across all global resource types in various services. For the deprecated `AWS &gt; Region &gt; Discovery &gt; Connection Region` policy, we recommend migrating existing settings to the `AWS &gt; Region &gt; Connection Region` policy if you intend to define a connection region for discovering Region resources. Alternatively, you may configure the `AWS &gt; Account &gt; Connection Region [Default]` policy, which serves as the default region for discovering all global resources across services in your account.

_Policy Types_

- AWS &gt; Account &gt; Connection Region [Default]
- AWS &gt; Region &gt; Connection Region

_Renamed_

- AWS &gt; Region &gt; Discovery &gt; Connection Region to AWS &gt; Region &gt; Discovery &gt; Connection Region [Deprecated]</description>
            <pubDate>Tue, 08 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-s3-v5-31-0</guid>
            <title>aws-s3 v5.31.0 - Configure connection region to fetch details for S3 accounts in CMDB</title>
            <link>https://turbot.com/guardrails/changelog/aws-s3-v5-31-0</link>
            <description>_What&apos;s new?_

- You can now configure a connection region to allow Guardrails to fetch details for S3 accounts in CMDB. To get started, set the `AWS &gt; S3 &gt; Connection Region` policy. This policy defaults to the value of the `AWS &gt; Account &gt; Connection Region [Default]` policy, which can be used to define a default connection region for all global resources in an account.

_Policy Types_

- AWS &gt; S3 &gt; Connection Region</description>
            <pubDate>Tue, 08 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-iam-v5-41-0</guid>
            <title>aws-iam v5.41.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-iam-v5-41-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Mon, 07 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-glue-v5-12-0</guid>
            <title>aws-glue v5.12.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-glue-v5-12-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Mon, 07 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-v5-36-1</guid>
            <title>aws v5.36.1 - Real-time event for moving accounts in an organization is now processed correctly, ensuring individually imported management accounts are not deleted from the CMDB</title>
            <link>https://turbot.com/guardrails/changelog/aws-v5-36-1</link>
            <description>_Bug fixes_

- Guardrails previously processed the `organizations:MoveAccount` real-time event incorrectly for individually imported management accounts, inadvertently deleting them from the CMDB. We have tightened the validation checks to prevent such deletions in these cases.</description>
            <pubDate>Fri, 04 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-sagemaker-v5-11-1</guid>
            <title>aws-sagemaker v5.11.1 - Discovery controls now use higher API limits to prevent throttling errors when many resources exist in the account</title>
            <link>https://turbot.com/guardrails/changelog/aws-sagemaker-v5-11-1</link>
            <description>_Bug fixes_

- Discovery controls for various SageMaker resources previously attempted to fetch a maximum of 10 resources per API call, which occasionally led to throttling when a high number of resources existed in the account. This limit has now been increased to 100 (the maximum supported by the APIs) to enable the Discovery controls to retrieve all resources without errors and upsert them into the CMDB.</description>
            <pubDate>Fri, 04 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-rds-v5-31-0</guid>
            <title>aws-rds v5.31.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-rds-v5-31-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Thu, 03 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-organizations-v5-4-1</guid>
            <title>aws-organizations v5.4.1 - Guardrails will now process only relevant real-time events for Organizations resource types when the CMDB policy is set to `Enforce: Enabled`</title>
            <link>https://turbot.com/guardrails/changelog/aws-organizations-v5-4-1</link>
            <description>_Bug fixes_

- We have improved event handling configuration to filter AWS Organization events that Guardrails listens for, based on the CMDB policies for resource types. If the CMDB policy for a resource type is not set to `Enforce: Enabled`, the EventBridge rule for Organizations will exclude events for that resource type.</description>
            <pubDate>Thu, 03 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ec2-v5-44-0</guid>
            <title>aws-ec2 v5.44.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-ec2-v5-44-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Thu, 03 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-50-0</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.50.0 - Introducing scoped Account/* permissions to help application teams manage their own accounts</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-50-0</link>
            <description>_What&apos;s new?_

- Server
  - Introducing scoped Account/* permissions to help application teams manage their own accounts.
  - Notifications routing based on permissions.

_Bug fixes_

- Server
  - Controls no longer crashes when there&apos;s a parsing issue in rule-based notifications. Instead, it logs the error gracefully and continues running.
  - Fixed a problem where certain operations could trigger a &quot;callback already called&quot; error, improving overall reliability of caching.
  - The `Type Installed` control now spreads events over time to reduce the likelihood of API throttling during large-scale installations or updates.
  - Guardrails now skips storing resource tags larger than 1 KB to ensure only valid tags are saved and to avoid potential issues later.
  - The osquery worker now correctly uses the TURBOT_RDS_SSL_FILE environment variable to point to the right certificate file, fixing an issue where it previously referenced the wrong path.
  - To improve reliability and performance, Guardrails prioritizes events in the order `Type Installed` &gt; `Policies` &gt; `Scheduled Actions` &gt; `Controls`.
  - Resolved an issue where authenticated users without the appropriate permissions were able to access process logs.

- UI
  - Switching between self and descendant modes no longer clears existing filter configurations — your selections will now persist as expected.


_Account Permissions_

Introduced a new category of permissions — Account/* — designed specifically for application teams who need limited visibility and control over resources within their own accounts. These are distinct from the Turbot/* permissions used by governance teams.

- Account levels:
  - Account/Owner
  - Account/Admin
  - Account/Operator
  - Account/ReadOnly

- These levels are now explained alongside Turbot/* levels, with clear usage guidance:
	- Turbot/* — for managing the Guardrails platform
	- Account/* — for managing resources and notifications within cloud accounts


_Notification Routing to Guardrails Profiles_

You can now route notifications to Guardrails user profiles dynamically based on resource permissions — a major upgrade from static email/webhook targeting. This allows for context-aware delivery to users like Account Owners or Admins.

- Supported formats:
	- Specific roles like Account/Owner, Turbot/Owner
	- Wildcards like Account/*
	- Special role Account/CC for tagging-based routing
	- Use case:
    - Automatically notify account teams responsible for a resource, based on their assigned permission

_Access Controls Refined for Process Logs_

Access to process logs is now restricted to users with appropriate permissions, specifically those with Turbot/Metadata or higher.

Previously, any authenticated user could retrieve process logs via the API. This behavior has been corrected to align with expected permission boundaries and prevent overexposure of operational data.

_Requirements_

- TEF: 1.66.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Wed, 02 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-vpc-security-v5-12-1</guid>
            <title>aws-vpc-security v5.12.1 - Cleaned up unnecessary help messages from VPC Security Group Rule CMDB control</title>
            <link>https://turbot.com/guardrails/changelog/aws-vpc-security-v5-12-1</link>
            <description>_Bug fixes_

- Cleaned up unnecessary help messages from `AWS &gt; VPC &gt; Security Group Rule &gt; CMDB` control.</description>
            <pubDate>Wed, 02 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-iam-v5-16-4</guid>
            <title>gcp-iam v5.16.4 - CMDB control for Service Account will now wait for the IAM service&apos;s CMDB data to be correctly updated before attempting to fetch details for service accounts in newly imported projects</title>
            <link>https://turbot.com/guardrails/changelog/gcp-iam-v5-16-4</link>
            <description>_Bug fixes_

- The `GCP &gt; IAM &gt; Service Account &gt; CMDB` control would sometimes enter a skipped state for newly imported projects if certain required attributes were missing from the IAM service&apos;s CMDB data. The control will now go into a TBD state instead and rerun after five minutes to allow the IAM service&apos;s CMDB data to populate correctly for newly imported projects.</description>
            <pubDate>Tue, 01 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-vpc-security-v5-12-0</guid>
            <title>aws-vpc-security v5.12.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-vpc-security-v5-12-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Tue, 01 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-vpc-internet-v5-12-0</guid>
            <title>aws-vpc-internet v5.12.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-vpc-internet-v5-12-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Tue, 01 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-apigateway-v5-10-0</guid>
            <title>aws-apigateway v5.10.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-apigateway-v5-10-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Tue, 01 Apr 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-bigquery-v5-7-2</guid>
            <title>gcp-bigquery v5.7.2 - Table resources will no longer be upserted in CMDB via real-time events when CMDB policy is set to `Enforce: Disabled`</title>
            <link>https://turbot.com/guardrails/changelog/gcp-bigquery-v5-7-2</link>
            <description>_Bug fixes_

- Guardrails would sometimes ignore the `GCP &gt; BigQuery &gt; Table &gt; CMDB` policy set to `Enforce: Disabled` and still upsert table resources via real-time events in CMDB. These resources were subsequently cleaned up by the CMDB control. This issue has been resolved, and the CMDB policy will now be correctly respected before upserting resources.</description>
            <pubDate>Mon, 31 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-vpc-connect-v5-10-0</guid>
            <title>aws-vpc-connect v5.10.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-vpc-connect-v5-10-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Mon, 31 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-route53-v6-7-0</guid>
            <title>aws-route53 v6.7.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-route53-v6-7-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Mon, 31 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-backup-v5-12-0</guid>
            <title>aws-backup v5.12.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-backup-v5-12-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Mon, 31 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/turbot-v5-51-0</guid>
            <title>turbot v5.51.0 - Updated Turbot &gt; Workspace &gt; Retention &gt; Activity Retention to 90 days</title>
            <link>https://turbot.com/guardrails/changelog/turbot-v5-51-0</link>
            <description>_What&apos;s new?_

- Policy Types:
  - Turbot &gt; Notifications &gt; Email &gt; CC
  - Turbot &gt; Notifications &gt; Email &gt; CC &gt; Tag
  - Turbot &gt; Notifications &gt; Email &gt; CC &gt; Tag &gt; Name
  - Updated Turbot &gt; Workspace &gt; Retention &gt; Activity Retention to 90 days
  - Updated default policy for Turbot &gt; Notifications &gt; Rule-Based Routing updated to use `Account/*` as the default recipient profile.
  - Relaxed the regex for MS teams webhook URL in Turbot &gt; Notifications &gt; Rule-Based Routing to allow broader URL formats.

_Turbot &gt; Workspace &gt; Retention &gt; Activity Retention_

The default retention period for activity has been updated to 90 days (previously unlimited)

Storing too much historical activity data can slow down the system and increase storage costs. By setting a 90-day default, we ensure:
  - Faster queries and improved UI performance
  - A better balance between data retention and storage efficiency

Need more or less retention? You can adjust based on your needs:

| Retention Period | Ideal For                                  |
|------------------|---------------------------------------------|
| **30 days**      | High-performance environments               |
| **60 days**      | Balanced usage, recommended for most users  |
| **90 days**      | **New default** — standard compliance needs |
| **180 / 365 days** | Long-term auditing or retention policies  |

For self-hosted environments, the 90-day default will apply when upgrading to @turbot/turbot version 5.51.0 or higher, unless a custom retention policy is set.

_Requirements_

- TE: 5.35.4</description>
            <pubDate>Thu, 27 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-vpc-core-v5-21-0</guid>
            <title>aws-vpc-core v5.21.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-vpc-core-v5-21-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Thu, 27 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-v5-36-0</guid>
            <title>aws v5.36.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-v5-36-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Thu, 27 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-sns-v5-17-0</guid>
            <title>aws-sns v5.17.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-sns-v5-17-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Thu, 27 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-redshift-v5-21-0</guid>
            <title>aws-redshift v5.21.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-redshift-v5-21-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Thu, 27 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-directconnect-v5-5-0</guid>
            <title>aws-directconnect v5.5.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-directconnect-v5-5-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Thu, 27 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-sqs-v5-17-0</guid>
            <title>aws-sqs v5.17.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-sqs-v5-17-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Wed, 26 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-s3-v5-30-0</guid>
            <title>aws-s3 v5.30.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-s3-v5-30-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Wed, 26 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-lambda-v5-14-0</guid>
            <title>aws-lambda v5.14.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-lambda-v5-14-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.
- Added support for `af-south-1`, `ap-east-1`, `ap-southeast-3`, `ap-southeast-5`, `ap-southeast-7`, `ca-west-1`, `eu-central-2`, `eu-south-1`, `eu-south-2`, `il-central-1`, `me-central-1` and `me-south-1` regions in the `AWS &gt; Lambda &gt; Regions` policy.
- Corrected the region in the `AWS &gt; Lambda &gt; Function Alias &gt; Regions` policy by updating us-west-3 to the correct region, us-west-2.</description>
            <pubDate>Wed, 26 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-events-v5-14-0</guid>
            <title>aws-events v5.14.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-events-v5-14-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Wed, 26 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-dynamodb-v5-14-0</guid>
            <title>aws-dynamodb v5.14.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-dynamodb-v5-14-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Wed, 26 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-cloudwatch-v5-10-0</guid>
            <title>aws-cloudwatch v5.10.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-cloudwatch-v5-10-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Wed, 26 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-cloudtrail-v5-12-0</guid>
            <title>aws-cloudtrail v5.12.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-cloudtrail-v5-12-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Wed, 26 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-securitycenter-v5-8-0</guid>
            <title>azure-securitycenter v5.8.0 - Controls and Actions now use latest Azure SDK versions to discover and manage Security Center resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-securitycenter-v5-8-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated internal dependencies and now use newer Azure SDK versions to discover and manage Security Center resources in Guardrails. This release includes breaking changes in the CMDB data for security center. We recommend updating your existing settings to refer to the updated attributes as mentioned below:

Added:

- `policy.enforcementMode`
- `policy.nonComplianceMessages`
- `policy.systemData`

Removed:

- `policy.sku`

Renamed:

- `settings[*].properties.enabled` to `settings[*].enabled`</description>
            <pubDate>Tue, 25 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-organizations-v5-4-0</guid>
            <title>aws-organizations v5.4.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-organizations-v5-4-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Tue, 25 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-kms-v5-19-0</guid>
            <title>aws-kms v5.19.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/aws-kms-v5-19-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The CMDB control for various resource types inadvertently removed the partition value from a resource&apos;s metadata when the `AWS &gt; Account &gt; Partition` policy value was null, resulting in a malformed AKA. We have tightened checks on partition values to ensure the control no longer updates resources with incorrect partition details.</description>
            <pubDate>Tue, 25 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-pubsub-v5-9-2</guid>
            <title>gcp-pubsub v5.9.2 - Real-time delete events for topics will no longer delete subscriptions under a different topic in the CMDB</title>
            <link>https://turbot.com/guardrails/changelog/gcp-pubsub-v5-9-2</link>
            <description>_Bug fixes_

- Real-time delete events for topics would sometimes result in the deletion of subscriptions under a different topic in the CMDB. This issue has been fixed, and subscriptions are now cleaned up more reliably than before.</description>
            <pubDate>Fri, 21 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-mysql-v5-16-0</guid>
            <title>azure-mysql v5.16.0 - Single server resource type is now deprecated and will be removed in the next major version</title>
            <link>https://turbot.com/guardrails/changelog/azure-mysql-v5-16-0</link>
            <description>_Bug fixes_

- The `AWS &gt; MySQL &gt; Server &gt; CMDB` policy will now be set to `Skip` by default because the resource type has been deprecated and will be removed in the next major version. Please check [Single Server retirement](https://techcommunity.microsoft.com/blog/adformysql/azure-database-for-mysql---single-server-retirement---key-updates-and-migration-/4055198) for more information.

_Resource Types_

_Renamed_

- Azure &gt; MySQL &gt; Server to Azure &gt; MySQL &gt; Server [Deprecated]

_Control Types_

_Renamed_

- Azure &gt; MySQL &gt; Server &gt; Active to Azure &gt; MySQL &gt; Server [Deprecated] &gt; Active
- Azure &gt; MySQL &gt; Server &gt; Approved to Azure &gt; MySQL &gt; Server [Deprecated] &gt; Approved
- Azure &gt; MySQL &gt; Server &gt; CMDB to Azure &gt; MySQL &gt; Server [Deprecated] &gt; CMDB
- Azure &gt; MySQL &gt; Server &gt; Discovery to Azure &gt; MySQL &gt; Server [Deprecated] &gt; Discovery
- Azure &gt; MySQL &gt; Server &gt; Encryption in Transit to Azure &gt; MySQL &gt; Server [Deprecated] &gt; Encryption in Transit
- Azure &gt; MySQL &gt; Server &gt; Tags to Azure &gt; MySQL &gt; Server [Deprecated] &gt; Tags

_Policy Types_

_Renamed_

- Azure &gt; MySQL &gt; Server &gt; Active to Azure &gt; MySQL &gt; Server [Deprecated] &gt; Active
- Azure &gt; MySQL &gt; Server &gt; Active &gt; Age to Azure &gt; MySQL &gt; Server [Deprecated] &gt; Active &gt; Age
- Azure &gt; MySQL &gt; Server &gt; Active &gt; Last Modified to Azure &gt; MySQL &gt; Server [Deprecated] &gt; Active &gt; Last Modified
- Azure &gt; MySQL &gt; Server &gt; Approved to Azure &gt; MySQL &gt; Server [Deprecated] &gt; Approved
- Azure &gt; MySQL &gt; Server &gt; Approved &gt; Custom to Azure &gt; MySQL &gt; Server [Deprecated] &gt; Approved &gt; Custom
- Azure &gt; MySQL &gt; Server &gt; Approved &gt; Regions to Azure &gt; MySQL &gt; Server [Deprecated] &gt; Approved &gt; Regions
- Azure &gt; MySQL &gt; Server &gt; Approved &gt; Usage to Azure &gt; MySQL &gt; Server [Deprecated] &gt; Approved &gt; Usage
- Azure &gt; MySQL &gt; Server &gt; CMDB to Azure &gt; MySQL &gt; Server [Deprecated] &gt; CMDB
- Azure &gt; MySQL &gt; Server &gt; Encryption in Transit to Azure &gt; MySQL &gt; Server [Deprecated] &gt; Encryption in Transit
- Azure &gt; MySQL &gt; Server &gt; Regions to Azure &gt; MySQL &gt; Server [Deprecated] &gt; Regions
- Azure &gt; MySQL &gt; Server &gt; Tags to Azure &gt; MySQL &gt; Server [Deprecated] &gt; Tags
- Azure &gt; MySQL &gt; Server &gt; Tags &gt; Template to Azure &gt; MySQL &gt; Server [Deprecated] &gt; Tags &gt; Template

_Action Types_

_Removed_

- Azure &gt; MySQL &gt; Server &gt; Delete
- Azure &gt; MySQL &gt; Server &gt; Router
- Azure &gt; MySQL &gt; Server &gt; Set Tags
- Azure &gt; MySQL &gt; Server &gt; Update Encryption in Transit</description>
            <pubDate>Fri, 21 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-sql-v5-18-0</guid>
            <title>azure-sql v5.18.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/azure-sql-v5-18-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Added support for Contactable interface in various resource types.</description>
            <pubDate>Thu, 20 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-provider-v5-16-0</guid>
            <title>azure-provider v5.16.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/azure-provider-v5-16-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.</description>
            <pubDate>Thu, 20 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-network-v5-24-0</guid>
            <title>azure-network v5.24.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/azure-network-v5-24-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.</description>
            <pubDate>Thu, 20 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-cosmosdb-v5-10-0</guid>
            <title>azure-cosmosdb v5.10.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/azure-cosmosdb-v5-10-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Added support for Contactable interface in various resource types.</description>
            <pubDate>Thu, 20 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-activedirectory-v5-8-0</guid>
            <title>azure-activedirectory v5.8.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/azure-activedirectory-v5-8-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.</description>
            <pubDate>Thu, 20 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-recoveryservice-v5-9-0</guid>
            <title>azure-recoveryservice v5.9.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/azure-recoveryservice-v5-9-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Added support for Contactable interface in various resource types.</description>
            <pubDate>Wed, 19 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-monitor-v5-10-0</guid>
            <title>azure-monitor v5.10.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/azure-monitor-v5-10-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Added support for Contactable interface in various resource types.</description>
            <pubDate>Wed, 19 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-loadbalancer-v5-10-0</guid>
            <title>azure-loadbalancer v5.10.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/azure-loadbalancer-v5-10-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Added support for Contactable interface in various resource types.</description>
            <pubDate>Wed, 19 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-iam-v5-14-0</guid>
            <title>azure-iam v5.14.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/azure-iam-v5-14-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.</description>
            <pubDate>Wed, 19 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-appservice-v5-15-0</guid>
            <title>azure-appservice v5.15.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/azure-appservice-v5-15-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Added support for Contactable interface in various resource types.</description>
            <pubDate>Wed, 19 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-apimanagement-v5-6-0</guid>
            <title>azure-apimanagement v5.6.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/azure-apimanagement-v5-6-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Added support for Contactable interface in various resource types.</description>
            <pubDate>Wed, 19 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-sqs-v5-16-0</guid>
            <title>aws-sqs v5.16.0 - Guardrails will now process only relevant real-time events for queues when the CMDB policy is set to `Enforce: Enabled`</title>
            <link>https://turbot.com/guardrails/changelog/aws-sqs-v5-16-0</link>
            <description>_What&apos;s new?_

- We have improved our event handling configuration to filter AWS SQS events that Guardrails listens for based on the `AWS &gt; SQS &gt; Queue &gt; CMDB` policy. If the CMDB policy is not set to `Enforce: Enabled`, the EventBridge rule for SQS will not be configured, preventing events for that resource type. This enhancement significantly reduces the number of unnecessary events processed by Guardrails.

_Policy Types_

- AWS &gt; Turbot &gt; Event Handlers &gt; Events &gt; Rules &gt; Custom Event Patterns &gt; @turbot/aws-sqs

_Removed_

- AWS &gt; Turbot &gt; Event Handlers &gt; Events &gt; Rules &gt; Event Sources &gt; @turbot/aws-sqs</description>
            <pubDate>Wed, 19 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/ted-v1-48-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.48.0 - Added S3 Lifecycle rules for Hive bucket.</title>
            <link>https://turbot.com/guardrails/changelog/ted-v1-48-0</link>
            <description>_What&apos;s new?_

- Added S3 Lifecycle rules for Hive bucket.</description>
            <pubDate>Tue, 18 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-synapseanalytics-v5-11-0</guid>
            <title>azure-synapseanalytics v5.11.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/azure-synapseanalytics-v5-11-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Added support for Contactable interface in various resource types.</description>
            <pubDate>Tue, 18 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-storage-v5-22-0</guid>
            <title>azure-storage v5.22.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/azure-storage-v5-22-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.</description>
            <pubDate>Tue, 18 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-signalr-v5-5-0</guid>
            <title>azure-signalr v5.5.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/azure-signalr-v5-5-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Added support for Contactable interface in various resource types.</description>
            <pubDate>Tue, 18 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-servicebus-v5-4-0</guid>
            <title>azure-servicebus v5.4.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/azure-servicebus-v5-4-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Added support for Contactable interface in various resource types.</description>
            <pubDate>Tue, 18 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-mysql-v5-15-0</guid>
            <title>azure-mysql v5.15.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/azure-mysql-v5-15-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Added support for Contactable interface in various resource types.</description>
            <pubDate>Tue, 18 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-keyvault-v5-17-0</guid>
            <title>azure-keyvault v5.17.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/azure-keyvault-v5-17-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Added support for Contactable interface in various resource types.</description>
            <pubDate>Tue, 18 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-automation-v5-3-0</guid>
            <title>azure-automation v5.3.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/azure-automation-v5-3-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Added support for Contactable interface in various resource types.</description>
            <pubDate>Tue, 18 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-sqlvirtualmachine-v5-3-0</guid>
            <title>azure-sqlvirtualmachine v5.3.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/azure-sqlvirtualmachine-v5-3-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Added support for Contactable interface in various resource types.</description>
            <pubDate>Mon, 17 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-relay-v5-5-0</guid>
            <title>azure-relay v5.5.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/azure-relay-v5-5-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Added support for Contactable interface in various resource types.</description>
            <pubDate>Mon, 17 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-networkwatcher-v5-13-0</guid>
            <title>azure-networkwatcher v5.13.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/azure-networkwatcher-v5-13-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Added support for Contactable interface in various resource types.</description>
            <pubDate>Mon, 17 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-datafactory-v5-10-0</guid>
            <title>azure-datafactory v5.10.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/azure-datafactory-v5-10-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Added support for Contactable interface in various resource types.</description>
            <pubDate>Mon, 17 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-applicationgateway-v5-10-0</guid>
            <title>azure-applicationgateway v5.10.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/azure-applicationgateway-v5-10-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Added support for Contactable interface in various resource types.</description>
            <pubDate>Mon, 17 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-iam-v5-40-2</guid>
            <title>aws-iam v5.40.2 - Guardrails-managed IAM stack control can now attach tags with special characters to Guardrails-managed users and roles</title>
            <link>https://turbot.com/guardrails/changelog/aws-iam-v5-40-2</link>
            <description>_Bug fixes_

- The `AWS &gt; Turbot &gt; IAM` stack control occasionally encountered an error while attaching tags with special characters to Guardrails-managed users and roles. This issue is now fixed.</description>
            <pubDate>Mon, 17 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-v5-29-0</guid>
            <title>azure v5.29.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/azure-v5-29-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Added support for Contactable interface in various resource types.</description>
            <pubDate>Thu, 13 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-securitycenter-v5-7-0</guid>
            <title>azure-securitycenter v5.7.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/azure-securitycenter-v5-7-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.</description>
            <pubDate>Thu, 13 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-searchmanagement-v5-11-0</guid>
            <title>azure-searchmanagement v5.11.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/azure-searchmanagement-v5-11-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Added support for Contactable interface in various resource types.</description>
            <pubDate>Thu, 13 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-postgresql-v5-19-0</guid>
            <title>azure-postgresql v5.19.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/azure-postgresql-v5-19-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Added support for Contactable interface in various resource types.</description>
            <pubDate>Thu, 13 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-managedidentity-v5-4-0</guid>
            <title>azure-managedidentity v5.4.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/azure-managedidentity-v5-4-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Added support for Contactable interface in various resource types.</description>
            <pubDate>Thu, 13 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-loganalytics-v5-12-0</guid>
            <title>azure-loganalytics v5.12.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/azure-loganalytics-v5-12-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Added support for Contactable interface in various resource types.</description>
            <pubDate>Thu, 13 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-frontdoorservice-v5-10-0</guid>
            <title>azure-frontdoorservice v5.10.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/azure-frontdoorservice-v5-10-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.</description>
            <pubDate>Thu, 13 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-firewall-v5-10-0</guid>
            <title>azure-firewall v5.10.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/azure-firewall-v5-10-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Added support for Contactable interface in various resource types.</description>
            <pubDate>Thu, 13 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-dns-v5-11-0</guid>
            <title>azure-dns v5.11.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/azure-dns-v5-11-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Added support for Contactable interface in various resource types.</description>
            <pubDate>Thu, 13 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-databricks-v5-7-0</guid>
            <title>azure-databricks v5.7.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/azure-databricks-v5-7-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Added support for Contactable interface in various resource types.</description>
            <pubDate>Thu, 13 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-containerregistry-v5-4-0</guid>
            <title>azure-containerregistry v5.4.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/azure-containerregistry-v5-4-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Added support for Contactable interface in various resource types.</description>
            <pubDate>Thu, 13 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-applicationinsights-v5-11-0</guid>
            <title>azure-applicationinsights v5.11.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/azure-applicationinsights-v5-11-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Added support for Contactable interface in various resource types.</description>
            <pubDate>Thu, 13 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-aks-v5-10-0</guid>
            <title>azure-aks v5.10.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/azure-aks-v5-10-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Added support for Contactable interface in various resource types.</description>
            <pubDate>Thu, 13 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-compute-v5-21-0</guid>
            <title>azure-compute v5.21.0 - Expand relationship mappings in Policy Type, Control Type, and Action Type definitions</title>
            <link>https://turbot.com/guardrails/changelog/azure-compute-v5-21-0</link>
            <description>_What&apos;s new?_

- Policy Type, Control Type, and Action Type definitions now also include their mapping details to establish clear relationships between them.
- Updated the default permissions required to run Quick Actions to include Account-type permissions in addition to the existing Turbot-type permissions.
- Added support for Contactable interface in various resource types.

_Bug fixes_

- The `Azure &gt; Compute &gt; Disk &gt; Discovery` control occasionally encountered an error while upserting attached disks under VMs that were not available in Guardrails CMDB. Now, all disks will be upserted under their respective resource groups, ensuring the Discovery control functions more smoothly and reliably than before.</description>
            <pubDate>Wed, 12 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/ted-v1-47-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.47.0 - Database &amp; cache configuration updates</title>
            <link>https://turbot.com/guardrails/changelog/ted-v1-47-0</link>
            <description>_What&apos;s new?_

- Added a new SSM parameter to forward the DB logs to CloudWatch log group.
- Added support for postgres version  16.5, 16.6, 16.7 and 16.8.
- Updated defaults for database and cache instances
	- Database instance type: Default updated to db.m6g.large.
	- Allocated database storage: Default increased to 400 GB.
	- Storage throughput: Default set to 500 MB/s.
	- Database engine parameter group family: Now defaults to postgres16.
	- Database engine version: Updated to 16.4.
	- Cache node type: Default updated to cache.r6g.large.
	- Allocated IOPS: Default increased to 12,000.
	- DB parameter group: Now defaults to HiveParamGroup16.
	- Shared buffer: Default set to {DBInstanceClassMemory/20480} for optimized performance.
	- Maximum statement duration: Default updated to 600,000 ms (10 minutes) to improve query execution limits.</description>
            <pubDate>Wed, 12 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-66-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.66.0 - Enhancements and new configuration parameters</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-66-0</link>
            <description>_What&apos;s new?_

  - Added parameter to manage ALB timeout, allowing better control over request handling.
  - Added parameter to customize API Gateway domain name. For backward compatibility, the default value remains `gateway`.
  - Added parameter to control message rate in the queue, enabling better queue message management.
  - S3 Lifecycle Rules now automatically enable ‘Expired Object Delete Markers’ for cleanup and remove incomplete multipart uploads after 7 days to prevent storage waste.
  - HOP limit increased to 2 for improved request forwarding.
  - Route53 Record for API Gateway now includes the GatewayPrefix to enhance routing accuracy.</description>
            <pubDate>Mon, 10 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-v5-28-1</guid>
            <title>azure v5.28.1 - Real-time delete events for subscriptions will now be processed correctly</title>
            <link>https://turbot.com/guardrails/changelog/azure-v5-28-1</link>
            <description>_Bug fixes_

- Guardrails would fail to process real-time delete events for subscriptions. This is now fixed.
- Fixed pagination for `Azure &gt; Turbot &gt; Event Poller` control.
- Real-time `Microsoft.Resources` tagging events will now be processed only for subscriptions and resource groups, and will be ignored for other resource types. This will avoid unnecessary triggers for subscription &amp; resource group router actions.</description>
            <pubDate>Tue, 04 Mar 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-49-0</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.49.0 - Added multi region KMS encryption for Tenant Master Key</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-49-0</link>
            <description>_What&apos;s new?_

- Server
  - Added multi region KMS encryption for Tenant Master Key.
  - Guardrails now provides an override parameter at the TE level to configure API and Event container memory reservations, improving ECS task scaling and resource flexibility.

_Multi Region KMS Key_

Starting from TEF v1.65.0 and TE v5.49.0, a new multi-region KMS key is created at the TEF level.

When workspaces are upgraded to TE v5.49.0, Guardrails use this new key to re-encrypt the existing *Tenant Master Key* within the workspaces. The *Tenant Master Key* itself remains unchanged-only its encryption is updated. The previous version, encrypted with a regional KMS key, remains available.

If a workspace is downgraded to TE v5.48.0, the multi-region encryption persists. Upon re-upgrading to TE v5.49.0, re-encryption does not occur again.

This process works seamlessly unless TEF is downgraded to a version earlier than v1.65.0.

_Requirements_

- TEF: 1.65.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Thu, 27 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/turbot-v5-50-0</guid>
            <title>turbot v5.50.0 - Added contactable interface</title>
            <link>https://turbot.com/guardrails/changelog/turbot-v5-50-0</link>
            <description>_What&apos;s new?_

- Added contactable interface.
- New policy type classes GUARDRAIL, SETTING, and ACCOUNT have been introduced to define the scope of policies.

_Requirements_

- TE: 5.35.4</description>
            <pubDate>Thu, 27 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-48-10</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.48.10 - Update controls trend graph to use the latest counts</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-48-10</link>
            <description>_What&apos;s new?_

- UI
  - Update controls trend graph to use the latest counts.


_Requirements_

- TEF: 1.59.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Tue, 25 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-servicebus-v5-3-0</guid>
            <title>azure-servicebus v5.3.0 - Real-time update events for resources will now be processed more reliably</title>
            <link>https://turbot.com/guardrails/changelog/azure-servicebus-v5-3-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Guardrails would sometimes update resource metadata details inadvertently in CMDB due to incorrect handling of real-time update events. This issue has been fixed, and real-time update events are now processed more reliably.
- Controls and their associated actions previously retried unnecessarily when their API calls returned an error. This issue has now been fixed.</description>
            <pubDate>Tue, 25 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-recoveryservice-v5-8-0</guid>
            <title>azure-recoveryservice v5.8.0 - Real-time update events for resources will now be processed more reliably</title>
            <link>https://turbot.com/guardrails/changelog/azure-recoveryservice-v5-8-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Guardrails would sometimes update resource metadata details inadvertently in CMDB due to incorrect handling of real-time update events. This issue has been fixed, and real-time update events are now processed more reliably.
- Controls and their associated actions previously retried unnecessarily when their API calls returned an error. This issue has now been fixed.</description>
            <pubDate>Tue, 25 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-frontdoorservice-v5-9-0</guid>
            <title>azure-frontdoorservice v5.9.0 - Real-time update events for resources will now be processed more reliably</title>
            <link>https://turbot.com/guardrails/changelog/azure-frontdoorservice-v5-9-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Guardrails would sometimes update resource metadata details inadvertently in CMDB due to incorrect handling of real-time update events. This issue has been fixed, and real-time update events are now processed more reliably.
- Controls and their associated actions previously retried unnecessarily when their API calls returned an error. This issue has now been fixed.</description>
            <pubDate>Tue, 25 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-firewall-v5-9-0</guid>
            <title>azure-firewall v5.9.0 - Real-time update events for resources will now be processed more reliably</title>
            <link>https://turbot.com/guardrails/changelog/azure-firewall-v5-9-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Guardrails would sometimes update resource metadata details inadvertently in CMDB due to incorrect handling of real-time update events. This issue has been fixed, and real-time update events are now processed more reliably.
- Controls and their associated actions previously retried unnecessarily when their API calls returned an error. This issue has now been fixed.</description>
            <pubDate>Tue, 25 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-datafactory-v5-9-0</guid>
            <title>azure-datafactory v5.9.0 - Real-time update events for resources will now be processed more reliably</title>
            <link>https://turbot.com/guardrails/changelog/azure-datafactory-v5-9-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Guardrails would sometimes update resource metadata details inadvertently in CMDB due to incorrect handling of real-time update events. This issue has been fixed, and real-time update events are now processed more reliably.
- Controls and their associated actions previously retried unnecessarily when their API calls returned an error. This issue has now been fixed.</description>
            <pubDate>Tue, 25 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-containerregistry-v5-3-0</guid>
            <title>azure-containerregistry v5.3.0 - Real-time update events for resources will now be processed more reliably</title>
            <link>https://turbot.com/guardrails/changelog/azure-containerregistry-v5-3-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Guardrails would sometimes update resource metadata details inadvertently in CMDB due to incorrect handling of real-time update events. This issue has been fixed, and real-time update events are now processed more reliably.
- Controls and their associated actions previously retried unnecessarily when their API calls returned an error. This issue has now been fixed.</description>
            <pubDate>Tue, 25 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-applicationgateway-v5-9-0</guid>
            <title>azure-applicationgateway v5.9.0 - Real-time update events for resources will now be processed more reliably</title>
            <link>https://turbot.com/guardrails/changelog/azure-applicationgateway-v5-9-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Guardrails would sometimes update resource metadata details inadvertently in CMDB due to incorrect handling of real-time update events. This issue has been fixed, and real-time update events are now processed more reliably.
- Controls and their associated actions previously retried unnecessarily when their API calls returned an error. This issue has now been fixed.</description>
            <pubDate>Tue, 25 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-aks-v5-9-0</guid>
            <title>azure-aks v5.9.0 - Real-time update events for resources will now be processed more reliably</title>
            <link>https://turbot.com/guardrails/changelog/azure-aks-v5-9-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Guardrails would sometimes update resource metadata details inadvertently in CMDB due to incorrect handling of real-time update events. This issue has been fixed, and real-time update events are now processed more reliably.
- Controls and their associated actions previously retried unnecessarily when their API calls returned an error. This issue has now been fixed.</description>
            <pubDate>Tue, 25 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-activedirectory-v5-7-0</guid>
            <title>azure-activedirectory v5.7.0 - Real-time update events for resources will now be processed more reliably</title>
            <link>https://turbot.com/guardrails/changelog/azure-activedirectory-v5-7-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Guardrails would sometimes update resource metadata details inadvertently in CMDB due to incorrect handling of real-time update events. This issue has been fixed, and real-time update events are now processed more reliably.
- Controls and their associated actions previously retried unnecessarily when their API calls returned an error. This issue has now been fixed.</description>
            <pubDate>Tue, 25 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-v5-3-0</guid>
            <title>servicenow v5.3.0 - Filter ServiceNow records using encoded query strings and discover them in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-v5-3-0</link>
            <description>_What&apos;s new?_

- You can now filter ServiceNow records using encoded query strings and discover them in Guardrails. To get started, set the `CMDB &gt; Query` policy for various resource types. For more details, refer to the [ServiceNow documentation on encoded query strings](https://www.servicenow.com/docs/bundle/yokohama-platform-user-interface/page/use/using-lists/concept/c_EncodedQueryStrings.html).

_Policy Types_

- ServiceNow &gt; Application &gt; CMDB &gt; Query
- ServiceNow &gt; Cost Center &gt; CMDB &gt; Query
- ServiceNow &gt; User &gt; CMDB &gt; Query</description>
            <pubDate>Mon, 24 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-securitycenter-v5-6-0</guid>
            <title>azure-securitycenter v5.6.0 - Real-time update events for resources will now be processed more reliably</title>
            <link>https://turbot.com/guardrails/changelog/azure-securitycenter-v5-6-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Guardrails would sometimes update resource metadata details inadvertently in CMDB due to incorrect handling of real-time update events. This issue has been fixed, and real-time update events are now processed more reliably.
- Controls and their associated actions previously retried unnecessarily when their API calls returned an error. This issue has now been fixed.</description>
            <pubDate>Mon, 24 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-relay-v5-4-0</guid>
            <title>azure-relay v5.4.0 - Real-time update events for resources will now be processed more reliably</title>
            <link>https://turbot.com/guardrails/changelog/azure-relay-v5-4-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Guardrails would sometimes update resource metadata details inadvertently in CMDB due to incorrect handling of real-time update events. This issue has been fixed, and real-time update events are now processed more reliably.
- Controls and their associated actions previously retried unnecessarily when their API calls returned an error. This issue has now been fixed.</description>
            <pubDate>Mon, 24 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-databricks-v5-6-0</guid>
            <title>azure-databricks v5.6.0 - Real-time update events for resources will now be processed more reliably</title>
            <link>https://turbot.com/guardrails/changelog/azure-databricks-v5-6-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Guardrails would sometimes update resource metadata details inadvertently in CMDB due to incorrect handling of real-time update events. This issue has been fixed, and real-time update events are now processed more reliably.
- Controls and their associated actions previously retried unnecessarily when their API calls returned an error. This issue has now been fixed.</description>
            <pubDate>Mon, 24 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-applicationinsights-v5-10-0</guid>
            <title>azure-applicationinsights v5.10.0 - Real-time update events for resources will now be processed more reliably</title>
            <link>https://turbot.com/guardrails/changelog/azure-applicationinsights-v5-10-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Guardrails would sometimes update resource metadata details inadvertently in CMDB due to incorrect handling of real-time update events. This issue has been fixed, and real-time update events are now processed more reliably.
- Controls and their associated actions previously retried unnecessarily when their API calls returned an error. This issue has now been fixed.</description>
            <pubDate>Mon, 24 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-v5-30-2</guid>
            <title>gcp v5.30.2 - Filter policies for real-time events will now evaluate correctly if CMDB policies for resource types are set to `Skip` or `Enforce: Disabled`</title>
            <link>https://turbot.com/guardrails/changelog/gcp-v5-30-2</link>
            <description>_Bug fixes_

- Filter policies for real-time events will now evaluate correctly if CMDB policies for resource types are set to `Skip` or `Enforce: Disabled`.</description>
            <pubDate>Fri, 21 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-storage-v5-11-5</guid>
            <title>gcp-storage v5.11.5 - Real-time storage events filter will now filters out resource specific events if their CMDB policy is set to `Skip` or `Enforce: Disabled`</title>
            <link>https://turbot.com/guardrails/changelog/gcp-storage-v5-11-5</link>
            <description>_Bug fixes_

- The `GCP &gt; Turbot &gt; Event Handlers &gt; Logging &gt; Sink &gt; Compiled Filter &gt; @turbot/gcp-storage` policy now respects CMDB policy settings for resource types and filters out real-time events when the policies are set to `Skip` or `Enforce: Disabled`. We recommend upgrading the `gcp` mod to v5.30.2 or higher in order to process real-time events correctly.</description>
            <pubDate>Fri, 21 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-provider-v5-15-0</guid>
            <title>azure-provider v5.15.0 - Lambda runtimes now powered by Node 22</title>
            <link>https://turbot.com/guardrails/changelog/azure-provider-v5-15-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Controls and their associated actions previously retried unnecessarily when their API calls returned an error. This issue has now been fixed.</description>
            <pubDate>Fri, 21 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-loganalytics-v5-11-0</guid>
            <title>azure-loganalytics v5.11.0 - Real-time update events for resources will now be processed more reliably</title>
            <link>https://turbot.com/guardrails/changelog/azure-loganalytics-v5-11-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Guardrails would sometimes update resource metadata details inadvertently in CMDB due to incorrect handling of real-time update events. This issue has been fixed, and real-time update events are now processed more reliably.
- Controls and their associated actions previously retried unnecessarily when their API calls returned an error. This issue has now been fixed.</description>
            <pubDate>Fri, 21 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-keyvault-v5-16-0</guid>
            <title>azure-keyvault v5.16.0 - Real-time update events for resources will now be processed more reliably</title>
            <link>https://turbot.com/guardrails/changelog/azure-keyvault-v5-16-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Guardrails would sometimes update resource metadata details inadvertently in CMDB due to incorrect handling of real-time update events. This issue has been fixed, and real-time update events are now processed more reliably.
- Controls and their associated actions previously retried unnecessarily when their API calls returned an error. This issue has now been fixed.</description>
            <pubDate>Fri, 21 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-dns-v5-10-0</guid>
            <title>azure-dns v5.10.0 - Real-time update events for resources will now be processed more reliably</title>
            <link>https://turbot.com/guardrails/changelog/azure-dns-v5-10-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Guardrails would sometimes update resource metadata details inadvertently in CMDB due to incorrect handling of real-time update events. This issue has been fixed, and real-time update events are now processed more reliably.
- Controls and their associated actions previously retried unnecessarily when their API calls returned an error. This issue has now been fixed.</description>
            <pubDate>Fri, 21 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-cosmosdb-v5-9-0</guid>
            <title>azure-cosmosdb v5.9.0 - Real-time update events for resources will now be processed more reliably</title>
            <link>https://turbot.com/guardrails/changelog/azure-cosmosdb-v5-9-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Guardrails would sometimes update resource metadata details inadvertently in CMDB due to incorrect handling of real-time update events. This issue has been fixed, and real-time update events are now processed more reliably.
- Controls and their associated actions previously retried unnecessarily when their API calls returned an error. This issue has now been fixed.</description>
            <pubDate>Fri, 21 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-automation-v5-2-0</guid>
            <title>azure-automation v5.2.0 - Real-time update events for resources will now be processed more reliably</title>
            <link>https://turbot.com/guardrails/changelog/azure-automation-v5-2-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Guardrails would sometimes update resource metadata details inadvertently in CMDB due to incorrect handling of real-time update events. This issue has been fixed, and real-time update events are now processed more reliably.
- Controls and their associated actions previously retried unnecessarily when their API calls returned an error. This issue has now been fixed.</description>
            <pubDate>Fri, 21 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-appservice-v5-14-0</guid>
            <title>azure-appservice v5.14.0 - Real-time update events for resources will now be processed more reliably</title>
            <link>https://turbot.com/guardrails/changelog/azure-appservice-v5-14-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Guardrails would sometimes update resource metadata details inadvertently in CMDB due to incorrect handling of real-time update events. This issue has been fixed, and real-time update events are now processed more reliably.
- Controls and their associated actions previously retried unnecessarily when their API calls returned an error. This issue has now been fixed.</description>
            <pubDate>Fri, 21 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-apimanagement-v5-5-0</guid>
            <title>azure-apimanagement v5.5.0 - Real-time update events for resources will now be processed more reliably</title>
            <link>https://turbot.com/guardrails/changelog/azure-apimanagement-v5-5-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Guardrails would sometimes update resource metadata details inadvertently in CMDB due to incorrect handling of real-time update events. This issue has been fixed, and real-time update events are now processed more reliably.
- Controls and their associated actions previously retried unnecessarily when their API calls returned an error. This issue has now been fixed.</description>
            <pubDate>Fri, 21 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-v5-28-0</guid>
            <title>azure v5.28.0 - Real-time update events for resources will now be processed more reliably</title>
            <link>https://turbot.com/guardrails/changelog/azure-v5-28-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Guardrails would sometimes update resource metadata details inadvertently in CMDB due to incorrect handling of real-time update events. This issue has been fixed, and real-time update events are now processed more reliably.
- Controls and their associated actions previously retried unnecessarily when their API calls returned an error. This issue has now been fixed.</description>
            <pubDate>Thu, 20 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-synapseanalytics-v5-10-0</guid>
            <title>azure-synapseanalytics v5.10.0 - Real-time update events for resources will now be processed more reliably</title>
            <link>https://turbot.com/guardrails/changelog/azure-synapseanalytics-v5-10-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Guardrails would sometimes update resource metadata details inadvertently in CMDB due to incorrect handling of real-time update events. This issue has been fixed, and real-time update events are now processed more reliably.
- Controls and their associated actions previously retried unnecessarily when their API calls returned an error. This issue has now been fixed.</description>
            <pubDate>Thu, 20 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-sqlvirtualmachine-v5-2-0</guid>
            <title>azure-sqlvirtualmachine v5.2.0 - Real-time update events for resources will now be processed more reliably</title>
            <link>https://turbot.com/guardrails/changelog/azure-sqlvirtualmachine-v5-2-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Guardrails would sometimes update resource metadata details inadvertently in CMDB due to incorrect handling of real-time update events. This issue has been fixed, and real-time update events are now processed more reliably.
- Controls and their associated actions previously retried unnecessarily when their API calls returned an error. This issue has now been fixed.</description>
            <pubDate>Thu, 20 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-sql-v5-17-0</guid>
            <title>azure-sql v5.17.0 - Real-time update events for resources will now be processed more reliably</title>
            <link>https://turbot.com/guardrails/changelog/azure-sql-v5-17-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Guardrails would sometimes update resource metadata details inadvertently in CMDB due to incorrect handling of real-time update events. This issue has been fixed, and real-time update events are now processed more reliably.
- Controls and their associated actions previously retried unnecessarily when their API calls returned an error. This issue has now been fixed.</description>
            <pubDate>Thu, 20 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-signalr-v5-4-0</guid>
            <title>azure-signalr v5.4.0 - Real-time update events for resources will now be processed more reliably</title>
            <link>https://turbot.com/guardrails/changelog/azure-signalr-v5-4-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Guardrails would sometimes update resource metadata details inadvertently in CMDB due to incorrect handling of real-time update events. This issue has been fixed, and real-time update events are now processed more reliably.
- Controls and their associated actions previously retried unnecessarily when their API calls returned an error. This issue has now been fixed.</description>
            <pubDate>Thu, 20 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-searchmanagement-v5-10-0</guid>
            <title>azure-searchmanagement v5.10.0 - Real-time update events for resources will now be processed more reliably</title>
            <link>https://turbot.com/guardrails/changelog/azure-searchmanagement-v5-10-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Guardrails would sometimes update resource metadata details inadvertently in CMDB due to incorrect handling of real-time update events. This issue has been fixed, and real-time update events are now processed more reliably.
- Controls and their associated actions previously retried unnecessarily when their API calls returned an error. This issue has now been fixed.</description>
            <pubDate>Thu, 20 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-postgresql-v5-18-0</guid>
            <title>azure-postgresql v5.18.0 - Real-time update events for resources will now be processed more reliably</title>
            <link>https://turbot.com/guardrails/changelog/azure-postgresql-v5-18-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Guardrails would sometimes update resource metadata details inadvertently in CMDB due to incorrect handling of real-time update events. This issue has been fixed, and real-time update events are now processed more reliably.
- Controls and their associated actions previously retried unnecessarily when their API calls returned an error. This issue has now been fixed.</description>
            <pubDate>Thu, 20 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-mysql-v5-14-0</guid>
            <title>azure-mysql v5.14.0 - Real-time update events for resources will now be processed more reliably</title>
            <link>https://turbot.com/guardrails/changelog/azure-mysql-v5-14-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Guardrails would sometimes update resource metadata details inadvertently in CMDB due to incorrect handling of real-time update events. This issue has been fixed, and real-time update events are now processed more reliably.
- Controls and their associated actions previously retried unnecessarily when their API calls returned an error. This issue has now been fixed.</description>
            <pubDate>Thu, 20 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-monitor-v5-9-0</guid>
            <title>azure-monitor v5.9.0 - Real-time update events for resources will now be processed more reliably</title>
            <link>https://turbot.com/guardrails/changelog/azure-monitor-v5-9-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Guardrails would sometimes update resource metadata details inadvertently in CMDB due to incorrect handling of real-time update events. This issue has been fixed, and real-time update events are now processed more reliably.
- Controls and their associated actions previously retried unnecessarily when their API calls returned an error. This issue has now been fixed.</description>
            <pubDate>Thu, 20 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-managedidentity-v5-3-0</guid>
            <title>azure-managedidentity v5.3.0 - Real-time update events for resources will now be processed more reliably</title>
            <link>https://turbot.com/guardrails/changelog/azure-managedidentity-v5-3-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Guardrails would sometimes update resource metadata details inadvertently in CMDB due to incorrect handling of real-time update events. This issue has been fixed, and real-time update events are now processed more reliably.
- Controls and their associated actions previously retried unnecessarily when their API calls returned an error. This issue has now been fixed.</description>
            <pubDate>Thu, 20 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-loadbalancer-v5-9-0</guid>
            <title>azure-loadbalancer v5.9.0 - Real-time update events for resources will now be processed more reliably</title>
            <link>https://turbot.com/guardrails/changelog/azure-loadbalancer-v5-9-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Guardrails would sometimes update resource metadata details inadvertently in CMDB due to incorrect handling of real-time update events. This issue has been fixed, and real-time update events are now processed more reliably.
- Controls and their associated actions previously retried unnecessarily when their API calls returned an error. This issue has now been fixed.</description>
            <pubDate>Thu, 20 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-iam-v5-13-0</guid>
            <title>azure-iam v5.13.0 - Real-time update events for resources will now be processed more reliably</title>
            <link>https://turbot.com/guardrails/changelog/azure-iam-v5-13-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Guardrails would sometimes update resource metadata details inadvertently in CMDB due to incorrect handling of real-time update events. This issue has been fixed, and real-time update events are now processed more reliably.
- Controls and their associated actions previously retried unnecessarily when their API calls returned an error. This issue has now been fixed.</description>
            <pubDate>Thu, 20 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/terraform-provider-v1-12-0</guid>
            <title>Terraform Provider v1.12.0 - Added support for `turbot_control_mute` resource</title>
            <link>https://turbot.com/guardrails/changelog/terraform-provider-v1-12-0</link>
            <description>_What&apos;s new?_

- Mute controls if you want to ignore them. The `turbot_control_mute` allows muting a control to help streamline operations without compromising security policies.

_Bug fixes_

- Fixed typo in an error message while calling Guardrails APIs.

_Documentation_

- Updated example for `turbot_policy_pack` resource.
- Fixed spacing in `turbot_turbot_directory` documentation.</description>
            <pubDate>Wed, 19 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-storage-v5-21-0</guid>
            <title>azure-storage v5.21.0 - Real-time update events for resources will now be processed more reliably</title>
            <link>https://turbot.com/guardrails/changelog/azure-storage-v5-21-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Guardrails would sometimes update resource metadata details inadvertently in CMDB due to incorrect handling of real-time update events. This issue has been fixed, and real-time update events are now processed more reliably.
- Controls and their associated actions previously retried unnecessarily when their API calls returned an error. This issue has now been fixed.</description>
            <pubDate>Wed, 19 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-networkwatcher-v5-12-0</guid>
            <title>azure-networkwatcher v5.12.0 - Real-time update events for resources will now be processed more reliably</title>
            <link>https://turbot.com/guardrails/changelog/azure-networkwatcher-v5-12-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Guardrails would sometimes update resource metadata details inadvertently in CMDB due to incorrect handling of real-time update events. This issue has been fixed, and real-time update events are now processed more reliably.
- Controls and their associated actions previously retried unnecessarily when their API calls returned an error. This issue has now been fixed.</description>
            <pubDate>Tue, 18 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-48-9</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.48.9 - Improvements and bug fixes</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-48-9</link>
            <description>_What&apos;s new?_

- UI
  - Users can now select permissions (ReadOnly + Global Event Handlers or Full Remediation) to apply to the IAM role in the CFN template when importing an AWS Organization or Account.

_Bug fixes_

- UI
  - Fixed an issue where the terminate process call sometimes received an empty input when terminating a queued process.

_Requirements_

- TEF: 1.59.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Tue, 18 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-network-v5-23-0</guid>
            <title>azure-network v5.23.0 - Real-time update events for resources will now be processed more reliably</title>
            <link>https://turbot.com/guardrails/changelog/azure-network-v5-23-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- `Stack [Native]` controls now run faster when in `skipped` state. We&apos;ve added Precheck conditions in such controls to avoid running GraphQL input queries when skipped, resulting in faster and lighter control runs.

_Bug fixes_

- Guardrails would sometimes update resource metadata details inadvertently in CMDB due to incorrect handling of real-time update events. This issue has been fixed, and real-time update events are now processed more reliably.
- Controls and their associated actions previously retried unnecessarily when their API calls returned an error. This issue has now been fixed.</description>
            <pubDate>Tue, 18 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-compute-v5-20-0</guid>
            <title>azure-compute v5.20.0 - Real-time update events for resources will now be processed more reliably</title>
            <link>https://turbot.com/guardrails/changelog/azure-compute-v5-20-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 22. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Bug fixes_

- Guardrails would sometimes update resource metadata details inadvertently in CMDB due to incorrect handling of real-time update events. This issue has been fixed, and real-time update events are now processed more reliably.
- Controls and their associated actions previously retried unnecessarily when their API calls returned an error. This issue has now been fixed.</description>
            <pubDate>Tue, 18 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-48-8</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.48.8 - Improvements and bug fixes</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-48-8</link>
            <description>_What&apos;s new?_

- Server
  - Updated Workspace Manager Lambda to automatically populate the Turbot &gt; Workspace &gt; Guardrails Master Account policy for improved management.

_Bug fixes_

- UI
  - Adjusted stats limit to 30 days, ensuring a full month of data visibility.

_Requirements_

- TEF: 1.59.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Mon, 17 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-vpc-connect-v5-9-3</guid>
            <title>aws-vpc-connect v5.9.3 - Cross-Account Discovery control for Transit Gateway Attachments would no longer upsert resources in a `deleted` or `deleting` state</title>
            <link>https://turbot.com/guardrails/changelog/aws-vpc-connect-v5-9-3</link>
            <description>_Bug fixes_

- The `AWS &gt; VPC &gt; Transit Gateway Attachment &gt; Discovery [Cross-Account]` control would sometimes upsert transit gateway attachments in a `deleted` or `deleting` state. This issue is now fixed.</description>
            <pubDate>Mon, 17 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-vpc-connect-v5-9-2</guid>
            <title>aws-vpc-connect v5.9.2 - Cross-account Transit Gateway Attachments will no longer be deleted from the CMDB</title>
            <link>https://turbot.com/guardrails/changelog/aws-vpc-connect-v5-9-2</link>
            <description>_Bug fixes_

- The `AWS &gt; VPC &gt; Transit Gateway Attachment &gt; CMDB` control previously, in some cases, inadvertently deleted cross-account transit gateway attachments from Guardrails CMDB. This issue has now been fixed.</description>
            <pubDate>Mon, 17 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-rds-v5-30-0</guid>
            <title>aws-rds v5.30.0 - Configure a custom tag name to start/stop DB clusters via the Schedule control</title>
            <link>https://turbot.com/guardrails/changelog/aws-rds-v5-30-0</link>
            <description>_What&apos;s new?_

- You can now configure a custom tag name to start/stop DB clusters via the `AWS &gt; RDS &gt; DB Cluster &gt; Schedule` control. To get started, set the `AWS &gt; RDS &gt; DB Cluster &gt; Schedule Tag &gt; Name` policy.

_Policy Types_

- AWS &gt; RDS &gt; DB Cluster &gt; Schedule Tag &gt; Name</description>
            <pubDate>Mon, 17 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-v5-27-0</guid>
            <title>azure v5.27.0 - Guardrails would fail to process real-time tagging events for subscriptions</title>
            <link>https://turbot.com/guardrails/changelog/azure-v5-27-0</link>
            <description>_What&apos;s new?_

_Action Types_

- Azure &gt; Subscription &gt; Router

_Bug fixes_

- Guardrails would fail to process real-time tagging events for subscriptions. This is now fixed.
- The default template input in `Azure &gt; Subscription &gt; Tags &gt; Template` policy referred to an incorrect policy for its value. This is now fixed.</description>
            <pubDate>Fri, 14 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/turbot-v5-49-1</guid>
            <title>turbot v5.49.1 - Resolved a race condition in Turbot &gt; Smart Retention to ensure smoother execution</title>
            <link>https://turbot.com/guardrails/changelog/turbot-v5-49-1</link>
            <description>_Bug fixes_

- Resolved a race condition in Turbot &gt; Smart Retention to ensure smoother execution.

_Requirements_

- TE: 5.35.4</description>
            <pubDate>Thu, 13 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-v5-35-6</guid>
            <title>aws v5.35.6 - Fixed the naming convention for EventBridge rule for organization level events</title>
            <link>https://turbot.com/guardrails/changelog/aws-v5-35-6</link>
            <description>_Bug fixes_

- Fixed the naming convention for EventBridge rule for organization level events.</description>
            <pubDate>Thu, 13 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-v5-35-5</guid>
            <title>aws v5.35.5 - Real-time events for the aws-organizations mod will now be processed correctly</title>
            <link>https://turbot.com/guardrails/changelog/aws-v5-35-5</link>
            <description>_Bug fixes_

- In version 5.35.0, we added support for importing an AWS organization into Guardrails but inadvertently introduced a bug that prevented real-time events for the aws-organizations mod from being processed correctly. This issue has now been fixed.

_Policy Types_

_Renamed_

- AWS &gt; Turbot &gt; Event Handlers &gt; Events &gt; Rules &gt; Custom Event Patterns &gt; @turbot/aws-organizations to AWS &gt; Turbot &gt; Event Handlers &gt; Events &gt; Rules &gt; Custom Event Patterns &gt; @turbot/aws</description>
            <pubDate>Wed, 12 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-organizations-v5-3-0</guid>
            <title>aws-organizations v5.3.0 - Guardrails failed to handle real-time creation and tagging events for organizational account resources</title>
            <link>https://turbot.com/guardrails/changelog/aws-organizations-v5-3-0</link>
            <description>_Bug fixes_

- Guardrails failed to handle real-time creation and tagging events for organizational account resources. This is now fixed.

_Policy Types_

- AWS &gt; Turbot &gt; Event Handlers &gt; Events &gt; Rules &gt; Custom Event Patterns &gt; @turbot/aws-organizations

_Removed_

- AWS &gt; Turbot &gt; Event Handlers &gt; Events &gt; Rules &gt; Event Sources &gt; @turbot/aws-organizations</description>
            <pubDate>Wed, 12 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-48-7</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.48.7 - Rolled back dynamic queueing adjustments to restore previous behavior</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-48-7</link>
            <description>_Bug fixes_

- Server
  - Rolled back dynamic queueing adjustments to restore previous behavior.

_Requirements_

- TEF: 1.59.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Mon, 10 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-48-6</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.48.6 - Version bump to align with deployment requirements</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-48-6</link>
            <description>Version bump to align with deployment requirements.

_Requirements_

- TEF: 1.59.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Mon, 10 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-48-5</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.48.5 - Improvements and bug fixes</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-48-5</link>
            <description>_Bug fixes_

- UI
  - Addressed an issue where resource card links on the Resources dashboard were not working as expected.

- Server
  - Prevented the runnable monitor from entering an infinite loop.

_Requirements_

- TEF: 1.59.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Mon, 10 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-48-4</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.48.4 - UI enhancements and bug fixes for better usability</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-48-4</link>
            <description>_What&apos;s new?_

- UI
  - Policy pack descriptions are now visible in the list view and detail page header for better clarity.

_Bug fixes_

- UI
  - Run and Terminate buttons now appear properly on the process detail page, ensuring a smoother experience.

_Requirements_

- TEF: 1.59.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Fri, 07 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-storage-v5-11-4</guid>
            <title>gcp-storage v5.11.4 - Bucket Policy Trusted Access control failed to evaluate correctly when IAM policy binding details were not available in CMDB</title>
            <link>https://turbot.com/guardrails/changelog/gcp-storage-v5-11-4</link>
            <description>_Bug fixes_

- The `GCP &gt; Storage &gt; Bucket &gt; Policy &gt; Trusted Access` control previously failed to evaluate results correctly and caused internal process timeouts when Guardrails was denied access to fetch IAM policy bindings for buckets. This issue has been resolved, ensuring that the control now evaluates results and terminates correctly as expected.</description>
            <pubDate>Fri, 07 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-compute-v5-19-2</guid>
            <title>azure-compute v5.19.2 - Virtual Machine tags control sometimes failed to update tags on spot instances</title>
            <link>https://turbot.com/guardrails/changelog/azure-compute-v5-19-2</link>
            <description>_Bug fixes_

- The `Azure &gt; Compute &gt; Virtual Machine &gt; Tags` control would sometimes failed to update tags on spot instances. This is now fixed.</description>
            <pubDate>Fri, 07 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-s3-v5-29-2</guid>
            <title>aws-s3 v5.29.2 - Bucket CMDB control would go into an error state if CMDB policy was set to ignore permission errors</title>
            <link>https://turbot.com/guardrails/changelog/aws-s3-v5-29-2</link>
            <description>_Bug fixes_

- The `AWS &gt; S3 &gt; Bucket &gt; Discovery` control incorrectly went into a skipped state when the `AWS &gt; S3 &gt; Bucket &gt; CMDB` policy was set to `Enforce: Enabled but ignore permission errors`. This is fixed and control will now work as expected.</description>
            <pubDate>Fri, 07 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-48-3</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.48.3 - Optimize message queue dispatch based on DB CPU usage, connections, and queue load</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-48-3</link>
            <description>_What&apos;s new?_

- UI
  - Added &apos;Resource Type&apos; column to activity ledger CSV exports.
  - Improved usability of the Resource trend graph.

_Bug fixes_

- Server
  - Recursive loops in Lambda are now handled seamlessly without termination.
  - Optimize message queue dispatch based on DB CPU usage, connections, and queue load.

_Requirements_

- TEF: 1.59.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Thu, 06 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/turbot-v5-49-0</guid>
            <title>turbot v5.49.0 - Added policy for Guardrails master account</title>
            <link>https://turbot.com/guardrails/changelog/turbot-v5-49-0</link>
            <description>_What&apos;s new?_

- Policy Types:
  - Turbot &gt; Workspace &gt; Guardrails Master Account

_Requirements_

- TE: 5.35.4</description>
            <pubDate>Thu, 06 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-sql-v5-16-2</guid>
            <title>azure-sql v5.16.2 - Server CMDB control sometimes failed to fetch data for the associated firewall rules</title>
            <link>https://turbot.com/guardrails/changelog/azure-sql-v5-16-2</link>
            <description>_Bug fixes_

- The `Azure &gt; SQL &gt; Server &gt; CMDB` control sometimes failed to fetch data for the associated firewall rules. This issue has now been fixed.</description>
            <pubDate>Tue, 04 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-cisv2-0-v5-1-1</guid>
            <title>azure-cisv2-0 v5.1.1 - Control for benchmark 4.01.02 sometimes failed to evaluate the outcome correctly</title>
            <link>https://turbot.com/guardrails/changelog/azure-cisv2-0-v5-1-1</link>
            <description>_Bug fixes_

- The `Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.01 SQL Server - Auditing &gt; 4.01.02 - Ensure no Azure SQL Databases allow ingress from 0.0.0.0/0 (ANY IP)` control sometimes failed to evaluate the control state correctly. This issue is now fixed.</description>
            <pubDate>Tue, 04 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-rds-v5-29-0</guid>
            <title>aws-rds v5.29.0 - Configure a custom tag name to start/stop DB instances</title>
            <link>https://turbot.com/guardrails/changelog/aws-rds-v5-29-0</link>
            <description>_What&apos;s new?_

- You can now configure a custom tag name to start/stop DB instances via the `AWS &gt; RDS &gt; DB Instance &gt; Schedule` control. To get started, set the `AWS &gt; RDS &gt; DB Instance &gt; Schedule Tag &gt; Name` policy.

_Policy Types_

- AWS &gt; RDS &gt; DB Instance &gt; Schedule Tag &gt; Name</description>
            <pubDate>Mon, 03 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-cloudsearch-v5-4-1</guid>
            <title>aws-cloudsearch v5.4.1 - CMDB policy will now default to Skip</title>
            <link>https://turbot.com/guardrails/changelog/aws-cloudsearch-v5-4-1</link>
            <description>_Bug fixes_

- The `AWS &gt; CloudSearch &gt; Domain &gt; CMDB` policy will now be set to `Skip` by default because the resource type has been deprecated and will be removed in the next major version. Please check [end of support](https://docs.aws.amazon.com/cloudsearch/latest/developerguide/what-is-cloudsearch.html) for more information.</description>
            <pubDate>Mon, 03 Feb 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-v5-30-1</guid>
            <title>gcp v5.30.1 - Stack [Native] controls will now run lighter and quicker than before</title>
            <link>https://turbot.com/guardrails/changelog/gcp-v5-30-1</link>
            <description>_Bug fixes_

- `Stack [Native]` controls now run faster when in `skipped` state. We&apos;ve added Precheck conditions in such controls to avoid running GraphQL input queries when skipped, resulting in faster and lighter control runs.</description>
            <pubDate>Fri, 31 Jan 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-v5-26-1</guid>
            <title>azure v5.26.1 - Stack [Native] controls will now run lighter and quicker than before</title>
            <link>https://turbot.com/guardrails/changelog/azure-v5-26-1</link>
            <description>_Bug fixes_

- `Stack [Native]` controls now run faster when in `skipped` state. We&apos;ve added Precheck conditions in such controls to avoid running GraphQL input queries when skipped, resulting in faster and lighter control runs.</description>
            <pubDate>Fri, 31 Jan 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-vpc-core-v5-20-1</guid>
            <title>aws-vpc-core v5.20.1 - Stack [Native] controls will now run lighter and quicker than before</title>
            <link>https://turbot.com/guardrails/changelog/aws-vpc-core-v5-20-1</link>
            <description>_Bug fixes_

- `Stack [Native]` controls now run faster when in `skipped` state. We&apos;ve added Precheck conditions in such controls to avoid running GraphQL input queries when skipped, resulting in faster and lighter control runs.</description>
            <pubDate>Fri, 31 Jan 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-v5-35-4</guid>
            <title>aws v5.35.4 - Stack [Native] controls will now run lighter and quicker than before</title>
            <link>https://turbot.com/guardrails/changelog/aws-v5-35-4</link>
            <description>_Bug fixes_

- `Stack [Native]` controls now run faster when in `skipped` state. We&apos;ve added Precheck conditions in such controls to avoid running GraphQL input queries when skipped, resulting in faster and lighter control runs.</description>
            <pubDate>Fri, 31 Jan 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-s3-v5-29-1</guid>
            <title>aws-s3 v5.29.1 - Stack [Native] controls will now run lighter and quicker than before</title>
            <link>https://turbot.com/guardrails/changelog/aws-s3-v5-29-1</link>
            <description>_Bug fixes_

- `Stack [Native]` controls now run faster when in `skipped` state. We&apos;ve added Precheck conditions in such controls to avoid running GraphQL input queries when skipped, resulting in faster and lighter control runs.</description>
            <pubDate>Fri, 31 Jan 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-iam-v5-40-1</guid>
            <title>aws-iam v5.40.1 - Stack [Native] controls will now run lighter and quicker than before</title>
            <link>https://turbot.com/guardrails/changelog/aws-iam-v5-40-1</link>
            <description>_Bug fixes_

- `Stack [Native]` controls now run faster when in `skipped` state. We&apos;ve added Precheck conditions in such controls to avoid running GraphQL input queries when skipped, resulting in faster and lighter control runs.</description>
            <pubDate>Fri, 31 Jan 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-48-2</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.48.2 - Enhanced visibility with summary cards on Resources and Controls tab.</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-48-2</link>
            <description>_What&apos;s new?_

- UI
  - Resources and Controls tab now features summary cards for better visibility.

_Bug fixes_

- UI
  - No more NaN values in summary cards; they now display correctly.
  - Mute and Run Control buttons now respect proper permission checks in the Control Detail page.

_Requirements_

- TEF: 1.59.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Thu, 30 Jan 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-v5-35-3</guid>
            <title>aws v5.35.3 - Account CMDB control would sometimes go into an error state while fetching tagging details for accounts</title>
            <link>https://turbot.com/guardrails/changelog/aws-v5-35-3</link>
            <description>_Bug fixes_

- The `AWS &gt; Account &gt; CMDB` control occasionally encountered an error state while fetching tagging details for accounts. This issue has now been fixed.</description>
            <pubDate>Wed, 29 Jan 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-v5-35-2</guid>
            <title>aws v5.35.2 - Tags added to account resources in Guardrails were removed on CMDB control reruns</title>
            <link>https://turbot.com/guardrails/changelog/aws-v5-35-2</link>
            <description>_Bug fixes_

- In the previous version, we introduced support for fetching AWS tags on accounts imported as part of an organization. However, this inadvertently caused a bug that removed tags added via the Guardrails API or Terraform on existing account resources. This issue has now been fixed, ensuring that tags added via Guardrails are preserved for individual accounts that are not part of any organization.
- Fixed pattern validation for `AWS &gt; Turbot &gt; Event Handlers [Global] &gt; Events &gt; Target &gt; IAM Role ARN` policy.</description>
            <pubDate>Wed, 29 Jan 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-64-1</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.64.1 - Minor internal improvements</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-64-1</link>
            <description>_Bug fixes_

  - Minor internal improvements.</description>
            <pubDate>Tue, 28 Jan 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-48-1</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.48.1 - The role name was not updating correctly in the CFN template for AWS Org import and has now been fixed.</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-48-1</link>
            <description>_Bug fixes_

- UI
  - The role name was not updating correctly in the CFN template for AWS Org import and has now been fixed.

_Requirements_

- TEF: 1.59.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Tue, 28 Jan 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-v5-35-1</guid>
            <title>aws v5.35.1 - Real-time event handlers did not process account level events for organizations imported via delegated accounts</title>
            <link>https://turbot.com/guardrails/changelog/aws-v5-35-1</link>
            <description>_Bug fixes_

- The real-time event handlers did not process account level events if the associated organization was imported using a delegated account. This is now fixed.</description>
            <pubDate>Tue, 28 Jan 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-65-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.65.0 - Added support for Node.js 22 in the Lambda runtime</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-65-0</link>
            <description>_What&apos;s new?_

  - Guardrails now supports configurable soft limits for API and Event container memory reservations in TEF, improving ECS task scaling and resource flexibility.
  - Added Guardrails KMS key, a multi-region KMS key for encrypting internal Turbot Guardrails data.
  - Added support for Node.js 22 in the Lambda runtime.</description>
            <pubDate>Mon, 27 Jan 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-64-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.64.0 - Support for IAM based authentication in Redis</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-64-0</link>
            <description>_What&apos;s new?_

  - Support for IAM based authentication in Redis.</description>
            <pubDate>Mon, 27 Jan 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/ted-v1-46-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.46.0 - Introduced Redis-based IAM authentication support</title>
            <link>https://turbot.com/guardrails/changelog/ted-v1-46-0</link>
            <description>_What&apos;s new?_

- Added a new SSM parameter to enable GCP organization import.
- Introduced Redis-based IAM authentication support.</description>
            <pubDate>Mon, 27 Jan 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-48-0</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.48.0 - Enhanced policy pack management, control muting and improved visibility with insightful stats</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-48-0</link>
            <description>_What&apos;s new?_

- Server

  - **Deprecation Notice:** The SmartFolder API has been deprecated and replaced with a new Policy Pack API:
    - `createSmartFolder` → Use `createPolicyPack` instead.
    - `deleteSmartFolders` → Use `deletePolicyPacks` instead.
    - `attachSmartFolders` → Use `attachPolicyPacks` instead.
    - `putSmartFolderAttachments` → Use `putPolicyPackAttachments` instead.
    - `updateSmartFolders` → Use `updatePolicyPacks` instead.
    - `detachSmartFolders` → Use `detachPolicyPacks` instead.
  - The new Policy Pack API introduces targeted resource types, allowing policy packs to be associated only with specific resource types. This is an optional feature, providing more control over policy pack applicability.
  - Added Mute/Un-mute Controls, an alternative to policy setting exceptions. When a control is muted, it will still run in the background but will not affect compliance or trigger alerts.
  - Introduced the Daily Stats API, which tracks daily statistics for each account, helping users monitor trends and activity over time.
  - Added two new policies:
    - **Policy Setting Levels**: Defines where policy settings can be created.
    - **Policy Pack Levels**: Specifies where policy packs can be attached.

- UI

  - Added support for muting/un-muting controls directly from the interface.
  - The Import Page UI has been redesigned and now supports:
    - AWS organization import
    - GitHub organization import
    - GCP organization import using service-account-impersonation
  - Added new metrics with separate charts for resources, controls, and actions, making it easier to track compliance and trends.

_Bug fixes_

- Server
  - Fixed native stack (OpenTofu) and stack (Terraform) log order.

- UI
  - Fixed log message indentation issues for improved readability.


_Requirements_

- TEF: 1.59.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Mon, 27 Jan 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/turbot-v5-48-0</guid>
            <title>turbot v5.48.0 - Added control to collect stats for accountable resources</title>
            <link>https://turbot.com/guardrails/changelog/turbot-v5-48-0</link>
            <description>_What&apos;s new?_

- Policy Types:
  - Turbot &gt; Workspace &gt; Retention &gt; Account Statistics Retention
  - Turbot &gt; Workspace &gt; Retention &gt; Account Statistics Retention &gt; Purge Limit
  - Turbot &gt; Workspace &gt; Policy Pack Attachment Levels
  - Turbot &gt; Workspace &gt; Policy Setting Levels

- Control Types:
  - Turbot &gt; Statistics &gt; Accounts

_Requirements_

- TE: 5.35.4</description>
            <pubDate>Mon, 27 Jan 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-v5-30-0</guid>
            <title>gcp v5.30.0 - Discover folders, projects and resources under your organization</title>
            <link>https://turbot.com/guardrails/changelog/gcp-v5-30-0</link>
            <description>_What&apos;s new?_

- Users can now discover folders, projects and resources under your organization. To get started, [import an organization](https://turbot.com/guardrails/docs/guides/gcp/import-gcp-organization) in your Guardrails workspace.

_Resource Types_

- GCP &gt; Organization
- GCP &gt; Folder

_Control Types_

- GCP &gt; Folder &gt; CMDB
- GCP &gt; Folder &gt; Discovery
- GCP &gt; Organization &gt; CMDB
- GCP &gt; Project &gt; Discovery
- GCP &gt; Turbot &gt; Folder Event Poller
- GCP &gt; Turbot &gt; Organization Event Poller

_Policy Types_

- GCP &gt; External ID Label Name
- GCP &gt; Organization &gt; CMDB
- GCP &gt; Organization &gt; CMDB &gt; Exclude
- GCP &gt; Folder &gt; CMDB
- GCP &gt; Turbot &gt; Folder Event Poller
- GCP &gt; Turbot &gt; Folder Event Poller &gt; Filter
- GCP &gt; Turbot &gt; Folder Event Poller &gt; Interval
- GCP &gt; Turbot &gt; Folder Event Poller &gt; Window
- GCP &gt; Turbot &gt; Organization Event Poller
- GCP &gt; Turbot &gt; Organization Event Poller &gt; Filter
- GCP &gt; Turbot &gt; Organization Event Poller &gt; Interval
- GCP &gt; Turbot &gt; Organization Event Poller &gt; Window

_Action Types_

- GCP &gt; Folder &gt; Event Poller
- GCP &gt; Folder &gt; Folder Event Handler
- GCP &gt; Folder &gt; Router
- GCP &gt; Organization &gt; Event Poller
- GCP &gt; Organization &gt; Organization Event Handler
- GCP &gt; Organization &gt; Router</description>
            <pubDate>Mon, 27 Jan 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-v5-26-0</guid>
            <title>azure v5.26.0 - Exclude subscriptions while importing a tenant in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-v5-26-0</link>
            <description>_What&apos;s new?_

- Users can now exclude subscriptions that they do not wish to import while importing a tenant in Guardrails. To get started, set the `Azure &gt; Tenant &gt; CMDB &gt; Exclude` policy.

- Users can now create and manage tags for subscriptions. To get started, set the` Azure &gt; Subscription &gt; Tags &gt; *` policies.

_Control Types_

- Azure &gt; Subscription &gt; Tags

_Policy Types_

- Azure &gt; Subscription &gt; Tags
- Azure &gt; Subscription &gt; Tags &gt; Template
- Azure &gt; Tenant &gt; CMDB &gt; Exclude

_Action Types_

- Azure &gt; Subscription &gt; Set Tags</description>
            <pubDate>Mon, 27 Jan 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-v5-35-0</guid>
            <title>aws v5.35.0 - Discover OUs, accounts and resources under your organization</title>
            <link>https://turbot.com/guardrails/changelog/aws-v5-35-0</link>
            <description>_What&apos;s new?_

- Users can now discover OUs, accounts and resources under your organization. To get started, [import an organization](https://turbot.com/guardrails/docs/guides/aws/import-aws-organization) in your Guardrails workspace.

_Resource Types_

- AWS &gt; Organization
- AWS &gt; Organization Root
- AWS &gt; Organizational Unit

_Control Types_

- AWS &gt; Account &gt; Discovery
- AWS &gt; Organization &gt; CMDB
- AWS &gt; Organization Root &gt; CMDB
- AWS &gt; Organization Root &gt; Discovery
- AWS &gt; Organizational Unit &gt; CMDB
- AWS &gt; Organizational Unit &gt; Discovery
- AWS &gt; Turbot &gt; Organization Event Poller

_Policy Types_

- AWS &gt; Account &gt; Turbot IAM Role &gt; External ID [Default]
- AWS &gt; Account &gt; Turbot IAM Role &gt; Name [Default]
- AWS &gt; Organization &gt; CMDB
- AWS &gt; Organization &gt; CMDB &gt; Exclude
- AWS &gt; Organization &gt; Turbot IAM Role
- AWS &gt; Organization &gt; Turbot IAM Role &gt; External ID
- AWS &gt; Organization Root &gt; CMDB
- AWS &gt; Organizational Unit &gt; CMDB
- AWS &gt; Turbot &gt; Event Handlers &gt; Events &gt; Rules &gt; Custom Event Patterns &gt; @turbot/aws-organizations
- AWS &gt; Turbot &gt; Organization Event Poller
- AWS &gt; Turbot &gt; Organization Event Poller &gt; Interval
- AWS &gt; Turbot &gt; Organization Event Poller &gt; Window

_Action Types_

- AWS &gt; Organization &gt; Organization Event Handler
- AWS &gt; Organization &gt; Organization Event Poller
- AWS &gt; Organization Root &gt; Router
- AWS &gt; Organizational Unit &gt; Router</description>
            <pubDate>Mon, 27 Jan 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/github-v5-1-0</guid>
            <title>github v5.1.0 - Added support for new secret value for Event Handlers webhook</title>
            <link>https://turbot.com/guardrails/changelog/github-v5-1-0</link>
            <description>_Bug fixes_

- The `GitHub &gt; Organization &gt; Event Handlers` control will now use `Turbot &gt; Workspace &gt; GitHub &gt; Secrets` policy to set the webhook secret.</description>
            <pubDate>Mon, 27 Jan 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/github-v5-0-0</guid>
            <title>github v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/github-v5-0-0</link>
            <description>_What&apos;s new?_

_Resource Types_

- GitHub
- GitHub &gt; Organization
- GitHub &gt; Repository

_Control Types_

- GitHub &gt; Organization &gt; Blocked Users
- GitHub &gt; Organization &gt; CMDB
- GitHub &gt; Organization &gt; Deploy Keys
- GitHub &gt; Organization &gt; Deploy Keys &gt; Enabled
- GitHub &gt; Organization &gt; Event Handlers
- GitHub &gt; Organization &gt; Member Privileges
- GitHub &gt; Organization &gt; Member Privileges &gt; Base Permissions
- GitHub &gt; Organization &gt; Member Privileges &gt; Pages Creation
- GitHub &gt; Organization &gt; Member Privileges &gt; Repository Creation
- GitHub &gt; Organization &gt; Member Privileges &gt; Repository Forking
- GitHub &gt; Repository &gt; CMDB
- GitHub &gt; Repository &gt; Code Security
- GitHub &gt; Repository &gt; Code Security &gt; Push Protection
- GitHub &gt; Repository &gt; Code Security &gt; Secret Scanning
- GitHub &gt; Repository &gt; Default Branch
- GitHub &gt; Repository &gt; Dependabot
- GitHub &gt; Repository &gt; Dependabot &gt; Alerts
- GitHub &gt; Repository &gt; Dependabot &gt; Security Updates
- GitHub &gt; Repository &gt; Discovery
- GitHub &gt; Repository &gt; Discussions
- GitHub &gt; Repository &gt; Discussions &gt; Enabled
- GitHub &gt; Repository &gt; Forking
- GitHub &gt; Repository &gt; Forking &gt; Enabled
- GitHub &gt; Repository &gt; Projects
- GitHub &gt; Repository &gt; Projects &gt; Enabled
- GitHub &gt; Repository &gt; Pull Request
- GitHub &gt; Repository &gt; Pull Request &gt; Delete Branch on Merge
- GitHub &gt; Repository &gt; Pull Request &gt; Merge Configuration
- GitHub &gt; Repository &gt; Visibility
- GitHub &gt; Repository &gt; Wikis
- GitHub &gt; Repository &gt; Wikis &gt; Enabled

_Policy Types_

- GitHub &gt; Config
- GitHub &gt; Config &gt; Personal Access Token
- GitHub &gt; Login Names
- GitHub &gt; Organization &gt; Blocked Users
- GitHub &gt; Organization &gt; Blocked Users &gt; Usernames
- GitHub &gt; Organization &gt; CMDB
- GitHub &gt; Organization &gt; Deploy Keys
- GitHub &gt; Organization &gt; Deploy Keys &gt; Enabled
- GitHub &gt; Organization &gt; Event Handlers
- GitHub &gt; Organization &gt; Event Handlers &gt; Events
- GitHub &gt; Organization &gt; Member Privileges
- GitHub &gt; Organization &gt; Member Privileges &gt; Base Permissions
- GitHub &gt; Organization &gt; Member Privileges &gt; Pages Creation
- GitHub &gt; Organization &gt; Member Privileges &gt; Repository Creation
- GitHub &gt; Organization &gt; Member Privileges &gt; Repository Forking
- GitHub &gt; Repository &gt; CMDB
- GitHub &gt; Repository &gt; Code Security
- GitHub &gt; Repository &gt; Code Security &gt; Push Protection
- GitHub &gt; Repository &gt; Code Security &gt; Secret Scanning
- GitHub &gt; Repository &gt; Default Branch
- GitHub &gt; Repository &gt; Default Branch &gt; Name
- GitHub &gt; Repository &gt; Dependabot
- GitHub &gt; Repository &gt; Dependabot &gt; Alerts
- GitHub &gt; Repository &gt; Dependabot &gt; Security Updates
- GitHub &gt; Repository &gt; Discussions
- GitHub &gt; Repository &gt; Discussions &gt; Enabled
- GitHub &gt; Repository &gt; Forking
- GitHub &gt; Repository &gt; Forking &gt; Enabled
- GitHub &gt; Repository &gt; Projects
- GitHub &gt; Repository &gt; Projects &gt; Enabled
- GitHub &gt; Repository &gt; Pull Request
- GitHub &gt; Repository &gt; Pull Request &gt; Delete Branch on Merge
- GitHub &gt; Repository &gt; Pull Request &gt; Merge Configuration
- GitHub &gt; Repository &gt; Pull Request &gt; Merge Configuration &gt; Settings
- GitHub &gt; Repository &gt; Visibility
- GitHub &gt; Repository &gt; Wikis
- GitHub &gt; Repository &gt; Wikis &gt; Enabled

_Action Types_

- GitHub &gt; Organization &gt; Event Handlers
- GitHub &gt; Organization &gt; Router
- GitHub &gt; Organization &gt; Update
- GitHub &gt; Organization &gt; Update Blocked Users
- GitHub &gt; Repository &gt; Router
- GitHub &gt; Repository &gt; Update
- GitHub &gt; Repository &gt; Update Dependabot</description>
            <pubDate>Fri, 24 Jan 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-sql-v5-16-1</guid>
            <title>azure-sql v5.16.1 - SQL servers using SQL authentication method will not be deleted from Guardrails CMDB</title>
            <link>https://turbot.com/guardrails/changelog/azure-sql-v5-16-1</link>
            <description>_Bug fixes_

- The `Azure &gt; SQL &gt; Server &gt; CMDB` control occasionally deleted servers from Guardrails CMDB when they used the SQL authentication method. This issue has been fixed, and such resources will no longer be removed from the CMDB.</description>
            <pubDate>Thu, 16 Jan 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-network-v5-22-0</guid>
            <title>azure-network v5.22.0 - Added support for Drift Detection, Version and Timeout policies for the `Stack [Native]` controls</title>
            <link>https://turbot.com/guardrails/changelog/azure-network-v5-22-0</link>
            <description>_What&apos;s new?_

- Added support for Drift Detection, Version and Timeout policies for the `Stack [Native]` controls.

_Policy Types_

- Azure &gt; Network &gt; Virtual Network &gt; Stack [Native] &gt; Drift Detection
- Azure &gt; Network &gt; Virtual Network &gt; Stack [Native] &gt; Drift Detection &gt; Interval
- Azure &gt; Network &gt; Virtual Network &gt; Stack [Native] &gt; Timeout
- Azure &gt; Network &gt; Virtual Network &gt; Stack [Native] &gt; Version</description>
            <pubDate>Thu, 16 Jan 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-vpc-core-v5-20-0</guid>
            <title>aws-vpc-core v5.20.0 - Added support for Drift Detection, Version and Timeout policies for the `Stack [Native]` controls</title>
            <link>https://turbot.com/guardrails/changelog/aws-vpc-core-v5-20-0</link>
            <description>_What&apos;s new?_

- Added support for Drift Detection, Version and Timeout policies for the `Stack [Native]` controls.

_Policy Types_

- AWS &gt; VPC &gt; Stack [Native] &gt; Drift Detection
- AWS &gt; VPC &gt; Stack [Native] &gt; Drift Detection &gt; Interval
- AWS &gt; VPC &gt; Stack [Native] &gt; Timeout
- AWS &gt; VPC &gt; Stack [Native] &gt; Version
- AWS &gt; VPC &gt; VPC &gt; Stack [Native] &gt; Drift Detection
- AWS &gt; VPC &gt; VPC &gt; Stack [Native] &gt; Drift Detection &gt; Interval
- AWS &gt; VPC &gt; VPC &gt; Stack [Native] &gt; Timeout
- AWS &gt; VPC &gt; VPC &gt; Stack [Native] &gt; Version</description>
            <pubDate>Thu, 16 Jan 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-s3-v5-29-0</guid>
            <title>aws-s3 v5.29.0 - Added support for Drift Detection, Version and Timeout policies for the `Stack [Native]` controls</title>
            <link>https://turbot.com/guardrails/changelog/aws-s3-v5-29-0</link>
            <description>_What&apos;s new?_

- Added support for Drift Detection, Version and Timeout policies for the `Stack [Native]` controls.

_Policy Types_

- AWS &gt; S3 &gt; Bucket &gt; Stack [Native] &gt; Drift Detection
- AWS &gt; S3 &gt; Bucket &gt; Stack [Native] &gt; Drift Detection &gt; Interval
- AWS &gt; S3 &gt; Bucket &gt; Stack [Native] &gt; Timeout
- AWS &gt; S3 &gt; Bucket &gt; Stack [Native] &gt; Version</description>
            <pubDate>Thu, 16 Jan 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-iam-v5-39-0</guid>
            <title>aws-iam v5.39.0 - Added support for Drift Detection, Version and Timeout policies for the `Stack [Native]` controls</title>
            <link>https://turbot.com/guardrails/changelog/aws-iam-v5-39-0</link>
            <description>_What&apos;s new?_

- Added support for Drift Detection, Version and Timeout policies for the `Stack [Native]` controls.

_Policy Types_

- AWS &gt; IAM &gt; Stack [Native] &gt; Drift Detection
- AWS &gt; IAM &gt; Stack [Native] &gt; Drift Detection &gt; Interval
- AWS &gt; IAM &gt; Stack [Native] &gt; Timeout
- AWS &gt; IAM &gt; Stack [Native] &gt; Version</description>
            <pubDate>Thu, 16 Jan 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-v5-29-0</guid>
            <title>gcp v5.29.0 - Added support for Drift Detection, Version and Timeout policies for the `Stack [Native]` controls</title>
            <link>https://turbot.com/guardrails/changelog/gcp-v5-29-0</link>
            <description>_What&apos;s new?_

- Added support for Drift Detection, Version and Timeout policies for the `Stack [Native]` controls.

_Policy Types_

- GCP &gt; Project &gt; Stack [Native] &gt; Drift Detection
- GCP &gt; Project &gt; Stack [Native] &gt; Drift Detection &gt; Interval
- GCP &gt; Project &gt; Stack [Native] &gt; Timeout
- GCP &gt; Project &gt; Stack [Native] &gt; Version</description>
            <pubDate>Wed, 15 Jan 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-v5-25-0</guid>
            <title>azure v5.25.0 - Added support for Drift Detection, Version and Timeout policies for the `Stack [Native]` controls</title>
            <link>https://turbot.com/guardrails/changelog/azure-v5-25-0</link>
            <description>_What&apos;s new?_

- Added support for Drift Detection, Version and Timeout policies for the `Stack [Native]` controls.

_Policy Types_

- Azure &gt; Subscription &gt; Stack [Native] &gt; Drift Detection
- Azure &gt; Subscription &gt; Stack [Native] &gt; Drift Detection &gt; Interval
- Azure &gt; Subscription &gt; Stack [Native] &gt; Timeout
- Azure &gt; Subscription &gt; Stack [Native] &gt; Version</description>
            <pubDate>Wed, 15 Jan 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-v5-33-0</guid>
            <title>aws v5.33.0 - Added support for Drift Detection, Version and Timeout policies for the `Stack [Native]` controls</title>
            <link>https://turbot.com/guardrails/changelog/aws-v5-33-0</link>
            <description>_What&apos;s new?_

- Added support for Drift Detection, Version and Timeout policies for the `Stack [Native]` controls.

_Policy Types_

- AWS &gt; Account &gt; Stack [Native] &gt; Drift Detection
- AWS &gt; Account &gt; Stack [Native] &gt; Drift Detection &gt; Interval
- AWS &gt; Account &gt; Stack [Native] &gt; Timeout
- AWS &gt; Account &gt; Stack [Native] &gt; Version
- AWS &gt; Region &gt; Stack [Native] &gt; Drift Detection
- AWS &gt; Region &gt; Stack [Native] &gt; Drift Detection &gt; Interval
- AWS &gt; Region &gt; Stack [Native] &gt; Timeout
- AWS &gt; Region &gt; Stack [Native] &gt; Version</description>
            <pubDate>Wed, 15 Jan 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-47-8</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.47.8 - Added support for drift detection in OpenTofu 1.x (open-source Terraform) integration via Guardrail.</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-47-8</link>
            <description>_Bug fixes_

- Server
  - Added support for drift detection in OpenTofu 1.x (open-source Terraform) integration via Guardrail.

_Requirements_

- TEF: 1.59.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Mon, 13 Jan 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-47-7</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.47.7 - Added container support for Stack [Native] controls</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-47-7</link>
            <description>_Bug fixes_

- Server
  - Added support for OpenTofu v1.8.3 (open source Terraform) container to run Stack [Native] controls.

_Requirements_

- TEF: 1.59.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Fri, 10 Jan 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-v5-28-0</guid>
            <title>gcp v5.28.0 - Create and manage cloud resources via Stack [Native] controls</title>
            <link>https://turbot.com/guardrails/changelog/gcp-v5-28-0</link>
            <description>_What&apos;s new?_

- Users can now create and manage cloud resources using OpenTofu 1.x (open source Terraform) via Guardrails, fully leveraging all features available in this version. To get started, set the `Stack [Native] &gt; *` policies.

_Control Types_

- GCP &gt; Project &gt; Stack [Native]

_Policy Types_

- GCP &gt; Project &gt; Stack [Native]
- GCP &gt; Project &gt; Stack [Native] &gt; Modifier
- GCP &gt; Project &gt; Stack [Native] &gt; Secret Variables
- GCP &gt; Project &gt; Stack [Native] &gt; Source
- GCP &gt; Project &gt; Stack [Native] &gt; Variables</description>
            <pubDate>Fri, 10 Jan 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-v5-24-0</guid>
            <title>azure v5.24.0 - Create and manage cloud resources via Stack [Native] controls</title>
            <link>https://turbot.com/guardrails/changelog/azure-v5-24-0</link>
            <description>_What&apos;s new?_

- Users can now create and manage cloud resources using OpenTofu 1.x (open source Terraform) via Guardrails, fully leveraging all features available in this version. To get started, set the `Stack [Native] &gt; *` policies.

_Control Types_

- Azure &gt; Subscription &gt; Stack [Native]

_Policy Types_

- Azure &gt; Subscription &gt; Stack [Native]
- Azure &gt; Subscription &gt; Stack [Native] &gt; Modifier
- Azure &gt; Subscription &gt; Stack [Native] &gt; Secret Variables
- Azure &gt; Subscription &gt; Stack [Native] &gt; Source
- Azure &gt; Subscription &gt; Stack [Native] &gt; Variables</description>
            <pubDate>Fri, 10 Jan 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-network-v5-21-0</guid>
            <title>azure-network v5.21.0 - Create and manage cloud resources via Stack [Native] controls</title>
            <link>https://turbot.com/guardrails/changelog/azure-network-v5-21-0</link>
            <description>_What&apos;s new?_

- Users can now create and manage cloud resources using OpenTofu 1.x (open source Terraform) via Guardrails, fully leveraging all features available in this version. To get started, set the `Stack [Native] &gt; *` policies.

_Control Types_

- Azure &gt; Network &gt; Virtual Network &gt; Stack [Native]

_Policy Types_

- Azure &gt; Network &gt; Virtual Network &gt; Stack [Native]
- Azure &gt; Network &gt; Virtual Network &gt; Stack [Native] &gt; Modifier
- Azure &gt; Network &gt; Virtual Network &gt; Stack [Native] &gt; Secret Variables
- Azure &gt; Network &gt; Virtual Network &gt; Stack [Native] &gt; Source
- Azure &gt; Network &gt; Virtual Network &gt; Stack [Native] &gt; Variables</description>
            <pubDate>Fri, 10 Jan 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-vpc-core-v5-19-0</guid>
            <title>aws-vpc-core v5.19.0 - Create and manage cloud resources via Stack [Native] controls</title>
            <link>https://turbot.com/guardrails/changelog/aws-vpc-core-v5-19-0</link>
            <description>_What&apos;s new?_

- Users can now create and manage cloud resources using OpenTofu 1.x (open source Terraform) via Guardrails, fully leveraging all features available in this version. To get started, set the `Stack [Native] &gt; *` policies.

_Control Types_

- AWS &gt; VPC &gt; Stack [Native]
- AWS &gt; VPC &gt; VPC &gt; Stack [Native]

_Policy Types_

- AWS &gt; VPC &gt; Stack [Native]
- AWS &gt; VPC &gt; Stack [Native] &gt; Modifier
- AWS &gt; VPC &gt; Stack [Native] &gt; Secret Variables
- AWS &gt; VPC &gt; Stack [Native] &gt; Source
- AWS &gt; VPC &gt; Stack [Native] &gt; Variables
- AWS &gt; VPC &gt; VPC &gt; Stack [Native]
- AWS &gt; VPC &gt; VPC &gt; Stack [Native] &gt; Modifier
- AWS &gt; VPC &gt; VPC &gt; Stack [Native] &gt; Secret Variables
- AWS &gt; VPC &gt; VPC &gt; Stack [Native] &gt; Source
- AWS &gt; VPC &gt; VPC &gt; Stack [Native] &gt; Variables</description>
            <pubDate>Fri, 10 Jan 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-v5-32-0</guid>
            <title>aws v5.32.0 - Create and manage cloud resources via Stack [Native] controls</title>
            <link>https://turbot.com/guardrails/changelog/aws-v5-32-0</link>
            <description>_What&apos;s new?_

- Users can now create and manage cloud resources using OpenTofu 1.x (open source Terraform) via Guardrails, fully leveraging all features available in this version. To get started, set the `Stack [Native] &gt; *` policies.

_Control Types_

- AWS &gt; Account &gt; Stack [Native]
- AWS &gt; Region &gt; Stack [Native]

_Policy Types_

- AWS &gt; Account &gt; Stack [Native]
- AWS &gt; Account &gt; Stack [Native] &gt; Modifier
- AWS &gt; Account &gt; Stack [Native] &gt; Secret Variables
- AWS &gt; Account &gt; Stack [Native] &gt; Source
- AWS &gt; Account &gt; Stack [Native] &gt; Variables
- AWS &gt; Region &gt; Stack [Native]
- AWS &gt; Region &gt; Stack [Native] &gt; Modifier
- AWS &gt; Region &gt; Stack [Native] &gt; Secret Variables
- AWS &gt; Region &gt; Stack [Native] &gt; Source
- AWS &gt; Region &gt; Stack [Native] &gt; Variables</description>
            <pubDate>Fri, 10 Jan 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-s3-v5-28-0</guid>
            <title>aws-s3 v5.28.0 - Create and manage cloud resources via Stack [Native] controls</title>
            <link>https://turbot.com/guardrails/changelog/aws-s3-v5-28-0</link>
            <description>_What&apos;s new?_

- Users can now create and manage cloud resources using OpenTofu 1.x (open source Terraform) via Guardrails, fully leveraging all features available in this version. To get started, set the `Stack [Native] &gt; *` policies.

_Control Types_

- AWS &gt; S3 &gt; Bucket &gt; Stack [Native]

_Policy Types_

- AWS &gt; S3 &gt; Bucket [Native]
- AWS &gt; S3 &gt; Bucket [Native] &gt; Modifier
- AWS &gt; S3 &gt; Bucket [Native] &gt; Secret Variables
- AWS &gt; S3 &gt; Bucket [Native] &gt; Source
- AWS &gt; S3 &gt; Bucket [Native] &gt; Variables</description>
            <pubDate>Fri, 10 Jan 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-iam-v5-38-0</guid>
            <title>aws-iam v5.38.0 - Create and manage cloud resources via Stack [Native] controls</title>
            <link>https://turbot.com/guardrails/changelog/aws-iam-v5-38-0</link>
            <description>_What&apos;s new?_

- Users can now create and manage cloud resources using OpenTofu 1.x (open source Terraform) via Guardrails, fully leveraging all features available in this version. To get started, set the `Stack [Native] &gt; *` policies.

_Control Types_

- AWS &gt; IAM &gt; Stack [Native]

_Policy Types_

- AWS &gt; IAM &gt; Stack [Native]
- AWS &gt; IAM &gt; Stack [Native] &gt; Modifier
- AWS &gt; IAM &gt; Stack [Native] &gt; Secret Variables
- AWS &gt; IAM &gt; Stack [Native] &gt; Source
- AWS &gt; IAM &gt; Stack [Native] &gt; Variables</description>
            <pubDate>Fri, 10 Jan 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-54-6</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.54.6 - Enforced PostgreSQL 15+ and policy pack optimization</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-54-6</link>
            <description>_What&apos;s new?_

- Server
  - Workspace creation and upgrade are now blocked if the RDS PostgreSQL version is lower than 15.

_Bug fixes_

- Server
  - Prevent policy pack summary control from querying AI credentials when the summary policy is disabled.  

_Requirements_

- Upgrade to `5.54.6` requires your workspace to be on `5.53.x`
- PostgreSQL (RDS engine): &gt;= 15
- TEF: 1.66.0
- TED: 1.37.0
- Mods:
  - @turbot/turbot: 5.56.0

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Thu, 09 Jan 2025 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-networkwatcher-v5-11-1</guid>
            <title>azure-networkwatcher v5.11.1 - The real-time Event Handlers would fail to update details for Flow Logs attached to Virtual Networks</title>
            <link>https://turbot.com/guardrails/changelog/azure-networkwatcher-v5-11-1</link>
            <description>_Bug fixes_

- The real-time Event Handlers would fail to update details for Flow Logs attached to Virtual Networks. This is now fixed.</description>
            <pubDate>Fri, 20 Dec 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-network-v5-20-1</guid>
            <title>azure-network v5.20.1 - Guardrails would fail to update CMDB for virtual networks when flow logs were created or removed from such resources</title>
            <link>https://turbot.com/guardrails/changelog/azure-network-v5-20-1</link>
            <description>_Bug fixes_

- Guardrails would fail to update CMDB for virtual networks when flow logs were created or removed from such resources. This is now fixed.</description>
            <pubDate>Fri, 20 Dec 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-vpc-core-v5-18-2</guid>
            <title>aws-vpc-core v5.18.2 - Flow Logging control would destroy and recreate flow logs unnecessarily</title>
            <link>https://turbot.com/guardrails/changelog/aws-vpc-core-v5-18-2</link>
            <description>_Bug fixes_

- The `AWS &gt; VPC &gt; VPC &gt; Flow Logging` control previously attempted to destroy and recreate flow logs with CloudWatch log groups as the destination on successive runs due to an incorrect ARN reference to the log destination. This issue is now fixed, and the control will no longer unnecessarily destroy and recreate flow logs in such cases.</description>
            <pubDate>Mon, 16 Dec 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-47-6</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.47.6 - Minor internal improvements</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-47-6</link>
            <description>_Bug fixes_

- Server
  - Minor internal improvements.

_Requirements_

- TEF: 1.59.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Fri, 13 Dec 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-v5-27-1</guid>
            <title>gcp v5.27.1 - Updated Terraform Version policy to prevent unnecessary stack control reruns</title>
            <link>https://turbot.com/guardrails/changelog/gcp-v5-27-1</link>
            <description>_Bug fixes_

- We have updated internal dependencies for the Terraform Version policy across various stack controls to prevent unnecessary control reruns. You wouldn&apos;t notice any difference and things will run more smoothly and reliably than before.</description>
            <pubDate>Fri, 13 Dec 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-iam-v5-16-3</guid>
            <title>gcp-iam v5.16.3 - Updated Terraform Version policy to prevent unnecessary stack control reruns</title>
            <link>https://turbot.com/guardrails/changelog/gcp-iam-v5-16-3</link>
            <description>_Bug fixes_

- We have updated internal dependencies for the Terraform Version policy across various stack controls to prevent unnecessary control reruns. You wouldn&apos;t notice any difference and things will run more smoothly and reliably than before.</description>
            <pubDate>Fri, 13 Dec 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-iam-v5-12-1</guid>
            <title>azure-iam v5.12.1 - Updated Terraform Version policy to prevent unnecessary stack control reruns</title>
            <link>https://turbot.com/guardrails/changelog/azure-iam-v5-12-1</link>
            <description>_Bug fixes_

- We have updated internal dependencies for the Terraform Version policy across various stack controls to prevent unnecessary control reruns. You wouldn&apos;t notice any difference and things will run more smoothly and reliably than before.</description>
            <pubDate>Fri, 13 Dec 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-compute-v5-19-1</guid>
            <title>azure-compute v5.19.1 - The Virtual Machine Scale Set Tags control will now update tags correctly for Scale Sets launched via the Azure Marketplace</title>
            <link>https://turbot.com/guardrails/changelog/azure-compute-v5-19-1</link>
            <description>_Bug fixes_

- In a previous version, we resolved an issue in the `Azure &gt; Compute &gt; Virtual Machine Scale Set &gt; Tags` control to ensure tags were updated correctly for Scale Sets launched via the Azure Marketplace. However, the control occasionally failed to update tags for Scale Sets on certain purchase plans. This issue has now been addressed, and the control will update tags correctly and reliably for all types of Scale Sets.</description>
            <pubDate>Fri, 13 Dec 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-v5-31-1</guid>
            <title>aws v5.31.1 - Updated Terraform Version policy to prevent unnecessary stack control reruns</title>
            <link>https://turbot.com/guardrails/changelog/aws-v5-31-1</link>
            <description>_Bug fixes_

- We have updated internal dependencies for the Terraform Version policy across various stack controls to prevent unnecessary control reruns. You wouldn&apos;t notice any difference and things will run more smoothly and reliably than before.</description>
            <pubDate>Fri, 13 Dec 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-kms-v5-18-1</guid>
            <title>aws-kms v5.18.1 - Updated Terraform Version policy to prevent unnecessary stack control reruns</title>
            <link>https://turbot.com/guardrails/changelog/aws-kms-v5-18-1</link>
            <description>_Bug fixes_

- We have updated internal dependencies for the Terraform Version policy across various stack controls to prevent unnecessary control reruns. You wouldn&apos;t notice any difference and things will run more smoothly and reliably than before.</description>
            <pubDate>Fri, 13 Dec 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-iam-v5-37-1</guid>
            <title>aws-iam v5.37.1 - Updated Terraform Version policy to prevent unnecessary stack control reruns</title>
            <link>https://turbot.com/guardrails/changelog/aws-iam-v5-37-1</link>
            <description>_Bug fixes_

- We have updated internal dependencies for the Terraform Version policy across various stack controls to prevent unnecessary control reruns. You wouldn&apos;t notice any difference and things will run more smoothly and reliably than before.</description>
            <pubDate>Fri, 13 Dec 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-47-5</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.47.5 - UI bug fixes and enhancements</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-47-5</link>
            <description>_Bug fixes_

- UI
  - Updated the filter logic on the Reports page for more accurate results.
  - Resolved an issue where resource links in the Permissions section redirected to the profile page instead of the resource page when grouped by resources.

_Requirements_

- TEF: 1.59.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Wed, 11 Dec 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-v5-23-0</guid>
            <title>azure v5.23.0 - Filter out specific real-time events while polling using the Azure Event Poller</title>
            <link>https://turbot.com/guardrails/changelog/azure-v5-23-0</link>
            <description>_What&apos;s new?_

- Users can now define a list of events to filter out while polling for events using the `Azure &gt; Turbot &gt; Event Poller`. To get started, set the `Azure &gt; Turbot &gt; Event Poller &gt; Excluded Events` policy.

_Policy Types_

- Azure &gt; Turbot &gt; Event Poller &gt; Excluded Events</description>
            <pubDate>Wed, 11 Dec 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-sqs-v5-15-0</guid>
            <title>aws-sqs v5.15.0 - Check and enforce SQS SSE for queue encryption</title>
            <link>https://turbot.com/guardrails/changelog/aws-sqs-v5-15-0</link>
            <description>_What&apos;s new?_

- Users can now check and enforce SQS SSE for queue encryption. To get started, configure the `AWS &gt; SQS &gt; Queue &gt; Encryption at Rest` policy to one of the following values: `Check: SQS SSE`, `Check: SQS SSE or higher`, `Enforce: SQS SSE` or `Enforce: SQS SSE or higher`.</description>
            <pubDate>Wed, 11 Dec 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/kubernetes-v5-2-0</guid>
            <title>kubernetes v5.2.0 - Check if Kubernetes clusters are approved for use via Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/kubernetes-v5-2-0</link>
            <description>_What&apos;s new?_

- Check if Kubernetes clusters are approved for use via Guardrails. To get started, set the `Kubernetes &gt; Cluster &gt; Approved &gt; *` policies.

_Control Types_

- Kubernetes &gt; Cluster &gt; Approved

_Policy Types_

- Kubernetes &gt; Cluster &gt; Approved
- Kubernetes &gt; Cluster &gt; Approved &gt; Custom</description>
            <pubDate>Tue, 10 Dec 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-appservice-v5-13-1</guid>
            <title>azure-appservice v5.13.1 - The `HTTPS Only` control would sometime fail to enable the setting in Azure</title>
            <link>https://turbot.com/guardrails/changelog/azure-appservice-v5-13-1</link>
            <description>_Bug fixes_

- The `Azure &gt; App Service &gt; Function App &gt; HTTPS Only` control would sometime fail to enable the setting in Azure. This is now fixed.</description>
            <pubDate>Fri, 06 Dec 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-computeengine-v5-19-2</guid>
            <title>gcp-computeengine v5.19.2 - The `Serial Port Access` and `Block Project Wide SSH Keys` controls for Compute Engine Instances would sometimes go into an error state due to incorrect references to CMDB attributes</title>
            <link>https://turbot.com/guardrails/changelog/gcp-computeengine-v5-19-2</link>
            <description>_Bug fixes_

- The `GCP &gt; Compute Engine &gt; Instance &gt; Serial Port Access` and `GCP &gt; Compute Engine &gt; Instance &gt; Block Project Wide SSH Keys` controls would sometimes go into an error state due to incorrect references to CMDB attributes. This is fixed and the controls will now work as expected.</description>
            <pubDate>Thu, 05 Dec 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-network-v5-20-0</guid>
            <title>azure-network v5.20.0 - Guardrails can now discover and manage Network resources across all supported regions in Azure</title>
            <link>https://turbot.com/guardrails/changelog/azure-network-v5-20-0</link>
            <description>_What&apos;s new?_

- The list of supported regions for various resource types has been refreshed. This update enables Guardrails to discover and manage resources across all supported regions for these resource types in Azure.

_Bug fixes_

- Guardrails would fail to delete unapproved ingress rules when the `Azure &gt; Network &gt; Network Security Group &gt; Ingress Rules &gt; Approved` policy was set to `Enforce: Delete unapproved`. This is now fixed.</description>
            <pubDate>Wed, 04 Dec 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-cosmosdb-v5-8-0</guid>
            <title>azure-cosmosdb v5.8.0 - Guardrails can now discover and manage Cosmos DB resources across all supported regions in Azure</title>
            <link>https://turbot.com/guardrails/changelog/azure-cosmosdb-v5-8-0</link>
            <description>_What&apos;s new?_

- The list of supported regions for various resource types has been refreshed. This update enables Guardrails to discover and manage resources across all supported regions for these resource types in Azure.</description>
            <pubDate>Wed, 04 Dec 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-appservice-v5-13-0</guid>
            <title>azure-appservice v5.13.0 - Guardrails can now discover and manage App Service resources across all supported regions in Azure</title>
            <link>https://turbot.com/guardrails/changelog/azure-appservice-v5-13-0</link>
            <description>_What&apos;s new?_

- The list of supported regions for various resource types has been refreshed. This update enables Guardrails to discover and manage resources across all supported regions for these resource types in Azure.

_Bug fixes_

- Guardrails would sometimes update the `createTimestamp` for Web Apps and Function Apps incorrectly when processing update events for these resources. We have updated the internal logic to ensure the `createTimestamp` is now updated correctly and more reliably than before.</description>
            <pubDate>Wed, 04 Dec 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-synapseanalytics-v5-9-0</guid>
            <title>azure-synapseanalytics v5.9.0 - Guardrails can now discover and manage Synapse Analytics resources across all supported regions in Azure</title>
            <link>https://turbot.com/guardrails/changelog/azure-synapseanalytics-v5-9-0</link>
            <description>_What&apos;s new?_

- The list of supported regions for various resource types has been refreshed. This update enables Guardrails to discover and manage resources across all supported regions for these resource types in Azure.</description>
            <pubDate>Tue, 03 Dec 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-recoveryservice-v5-7-0</guid>
            <title>azure-recoveryservice v5.7.0 - Guardrails can now discover and manage Recovery Service resources across all supported regions in Azure</title>
            <link>https://turbot.com/guardrails/changelog/azure-recoveryservice-v5-7-0</link>
            <description>_What&apos;s new?_

- The list of supported regions for various resource types has been refreshed. This update enables Guardrails to discover and manage resources across all supported regions for these resource types in Azure.</description>
            <pubDate>Tue, 03 Dec 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-keyvault-v5-15-0</guid>
            <title>azure-keyvault v5.15.0 - Guardrails can now discover and manage Key Vault resources across all supported regions in Azure</title>
            <link>https://turbot.com/guardrails/changelog/azure-keyvault-v5-15-0</link>
            <description>_What&apos;s new?_

- The list of supported regions for various resource types has been refreshed. This update enables Guardrails to discover and manage resources across all supported regions for these resource types in Azure.</description>
            <pubDate>Tue, 03 Dec 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-firewall-v5-8-0</guid>
            <title>azure-firewall v5.8.0 - Guardrails can now discover and manage Firewall resources across all supported regions in Azure</title>
            <link>https://turbot.com/guardrails/changelog/azure-firewall-v5-8-0</link>
            <description>_What&apos;s new?_

- The list of supported regions for various resource types has been refreshed. This update enables Guardrails to discover and manage resources across all supported regions for these resource types in Azure.</description>
            <pubDate>Tue, 03 Dec 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-datafactory-v5-8-0</guid>
            <title>azure-datafactory v5.8.0 - Guardrails can now discover and manage Data Factory resources across all supported regions in Azure</title>
            <link>https://turbot.com/guardrails/changelog/azure-datafactory-v5-8-0</link>
            <description>_What&apos;s new?_

- The list of supported regions for various resource types has been refreshed. This update enables Guardrails to discover and manage resources across all supported regions for these resource types in Azure.</description>
            <pubDate>Tue, 03 Dec 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-compute-v5-19-0</guid>
            <title>azure-compute v5.19.0 - Guardrails can now discover and manage Compute resources across all supported regions in Azure</title>
            <link>https://turbot.com/guardrails/changelog/azure-compute-v5-19-0</link>
            <description>_What&apos;s new?_

- The list of supported regions for various resource types has been refreshed. This update enables Guardrails to discover and manage resources across all supported regions for these resource types in Azure.

_Bug fixes_

- Disks created alongside VMs sometimes lacked `createdBy` details in their metadata. The internal logic has been updated to ensure `createdBy` details are added more reliably for these disks.</description>
            <pubDate>Tue, 03 Dec 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-signalr-v5-3-0</guid>
            <title>azure-signalr v5.3.0 - Guardrails can now discover and manage signalR resources across all supported regions in Azure</title>
            <link>https://turbot.com/guardrails/changelog/azure-signalr-v5-3-0</link>
            <description>_What&apos;s new?_

- The list of supported regions for various resource types has been refreshed. This update enables Guardrails to discover and manage resources across all supported regions for these resource types in Azure.</description>
            <pubDate>Mon, 02 Dec 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-searchmanagement-v5-9-0</guid>
            <title>azure-searchmanagement v5.9.0 - Guardrails can now discover and manage Search Management resources across all supported regions in Azure</title>
            <link>https://turbot.com/guardrails/changelog/azure-searchmanagement-v5-9-0</link>
            <description>_What&apos;s new?_

- The list of supported regions for various resource types has been refreshed. This update enables Guardrails to discover and manage resources across all supported regions for these resource types in Azure.</description>
            <pubDate>Mon, 02 Dec 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-relay-v5-3-0</guid>
            <title>azure-relay v5.3.0 - Guardrails can now discover and manage Relay resources across all supported regions in Azure</title>
            <link>https://turbot.com/guardrails/changelog/azure-relay-v5-3-0</link>
            <description>_What&apos;s new?_

- The list of supported regions for various resource types has been refreshed. This update enables Guardrails to discover and manage resources across all supported regions for these resource types in Azure.</description>
            <pubDate>Mon, 02 Dec 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-postgresql-v5-17-0</guid>
            <title>azure-postgresql v5.17.0 - Guardrails can now discover and manage PostgreSql resources across all supported regions in Azure</title>
            <link>https://turbot.com/guardrails/changelog/azure-postgresql-v5-17-0</link>
            <description>_What&apos;s new?_

- The list of supported regions for various resource types has been refreshed. This update enables Guardrails to discover and manage resources across all supported regions for these resource types in Azure.</description>
            <pubDate>Mon, 02 Dec 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-networkwatcher-v5-11-0</guid>
            <title>azure-networkwatcher v5.11.0 - Guardrails can now discover and manage Network Watcher resources across all supported regions in Azure</title>
            <link>https://turbot.com/guardrails/changelog/azure-networkwatcher-v5-11-0</link>
            <description>_What&apos;s new?_

- The list of supported regions for various resource types has been refreshed. This update enables Guardrails to discover and manage resources across all supported regions for these resource types in Azure.</description>
            <pubDate>Mon, 02 Dec 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-mysql-v5-13-0</guid>
            <title>azure-mysql v5.13.0 - Guardrails can now discover and manage MySql resources across all supported regions in Azure</title>
            <link>https://turbot.com/guardrails/changelog/azure-mysql-v5-13-0</link>
            <description>_What&apos;s new?_

- The list of supported regions for various resource types has been refreshed. This update enables Guardrails to discover and manage resources across all supported regions for these resource types in Azure.</description>
            <pubDate>Mon, 02 Dec 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-managedidentity-v5-2-0</guid>
            <title>azure-managedidentity v5.2.0 - Guardrails can now discover and manage Managed Identity resources across all supported regions in Azure</title>
            <link>https://turbot.com/guardrails/changelog/azure-managedidentity-v5-2-0</link>
            <description>_What&apos;s new?_

- The list of supported regions for various resource types has been refreshed. This update enables Guardrails to discover and manage resources across all supported regions for these resource types in Azure.</description>
            <pubDate>Mon, 02 Dec 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-loganalytics-v5-10-0</guid>
            <title>azure-loganalytics v5.10.0 - Guardrails can now discover and manage Log Analytics resources across all supported regions in Azure</title>
            <link>https://turbot.com/guardrails/changelog/azure-loganalytics-v5-10-0</link>
            <description>_What&apos;s new?_

- The list of supported regions for various resource types has been refreshed. This update enables Guardrails to discover and manage resources across all supported regions for these resource types in Azure.</description>
            <pubDate>Mon, 02 Dec 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-databricks-v5-5-0</guid>
            <title>azure-databricks v5.5.0 - Guardrails can now discover and manage Databricks resources across all supported regions in Azure</title>
            <link>https://turbot.com/guardrails/changelog/azure-databricks-v5-5-0</link>
            <description>_What&apos;s new?_

- The list of supported regions for various resource types has been refreshed. This update enables Guardrails to discover and manage resources across all supported regions for these resource types in Azure.</description>
            <pubDate>Mon, 02 Dec 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-containerregistry-v5-2-0</guid>
            <title>azure-containerregistry v5.2.0 - Guardrails can now discover and manage Container Registry resources across all supported regions in Azure</title>
            <link>https://turbot.com/guardrails/changelog/azure-containerregistry-v5-2-0</link>
            <description>_What&apos;s new?_

- The list of supported regions for various resource types has been refreshed. This update enables Guardrails to discover and manage resources across all supported regions for these resource types in Azure.</description>
            <pubDate>Mon, 02 Dec 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-aks-v5-8-0</guid>
            <title>azure-aks v5.8.0 - Guardrails can now discover and manage Kubernetes resources across all supported regions in Azure</title>
            <link>https://turbot.com/guardrails/changelog/azure-aks-v5-8-0</link>
            <description>_What&apos;s new?_

- The list of supported regions for various resource types has been refreshed. This update enables Guardrails to discover and manage resources across all supported regions for these resource types in Azure.</description>
            <pubDate>Mon, 02 Dec 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-iam-v5-16-2</guid>
            <title>gcp-iam v5.16.2 - The service account key active control has been updated to use `validAfterTime` instead of `metadata.createTimestamp` to accurately evaluate the age of the resource</title>
            <link>https://turbot.com/guardrails/changelog/gcp-iam-v5-16-2</link>
            <description>_Bug fixes_

- The `GCP &gt; IAM &gt; Service Account Key &gt; Active` control has been updated to use `validAfterTime` instead of `metadata.createTimestamp` to accurately evaluate the age of the resource.</description>
            <pubDate>Thu, 28 Nov 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-applicationinsights-v5-9-0</guid>
            <title>azure-applicationinsights v5.9.0 - Guardrails can now discover and manage Application Insights resources across all supported regions in Azure</title>
            <link>https://turbot.com/guardrails/changelog/azure-applicationinsights-v5-9-0</link>
            <description>_What&apos;s new?_

- The list of supported regions for various resource types has been refreshed. This update enables Guardrails to discover and manage resources across all supported regions for these resource types in Azure.</description>
            <pubDate>Thu, 28 Nov 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-rds-v5-28-0</guid>
            <title>aws-rds v5.28.0 - Users can now check and delete DB clusters that are not approved for use if they lack encryption at rest</title>
            <link>https://turbot.com/guardrails/changelog/aws-rds-v5-28-0</link>
            <description>_What&apos;s new?_

- Users can now check and delete DB clusters that are not approved for use if they lack encryption at rest. To get started, set the `AWS &gt; RDS &gt; DB Cluster &gt; Approved &gt; Encryption at Rest &gt; *` policies.

_Policy Types_

- AWS &gt; RDS &gt; DB Cluster &gt; Approved &gt; Encryption at Rest
- AWS &gt; RDS &gt; DB Cluster &gt; Approved &gt; Encryption at Rest &gt; Customer Managed Key</description>
            <pubDate>Thu, 28 Nov 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-v5-31-0</guid>
            <title>aws v5.31.0 - Users can now check if their account spend is `On Target` per Budget</title>
            <link>https://turbot.com/guardrails/changelog/aws-v5-31-0</link>
            <description>_What&apos;s new?_

- Users can now check if their account spend is `On Target` per Budget. To get started, set the `AWS &gt; Account &gt; Budget &gt; Enabled` policy to `Check: Budget &gt; State is On Target`.</description>
            <pubDate>Tue, 26 Nov 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-47-4</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.47.4 - Resolved an issue where reports pages could crash if certain information was null</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-47-4</link>
            <description>_Bug fixes_

- UI
  - Resolved an issue where reports pages could crash if certain information was null

_Requirements_

- TEF: 1.59.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Tue, 26 Nov 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-47-3</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.47.3 - Resolved issue with actor information handling</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-47-3</link>
            <description>_Bug fixes_

- Server
  - Resolved an issue where actor information was not being passed correctly during the process execution, ensuring accurate tracking and processing of actor-related data.


_Requirements_

- TEF: 1.59.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Mon, 25 Nov 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-vpc-core-v5-18-1</guid>
            <title>aws-vpc-core v5.18.1 - The VPC Route CMDB control would go into an error state due to an incorrect use of a function from an internal node package</title>
            <link>https://turbot.com/guardrails/changelog/aws-vpc-core-v5-18-1</link>
            <description>_Bug fixes_

- The `AWS &gt; VPC &gt; Route &gt; CMDB` control would go into an error state due to an incorrect use of a function from an internal node package. This is now fixed.</description>
            <pubDate>Mon, 25 Nov 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-storage-v5-20-3</guid>
            <title>azure-storage v5.20.3 - The `createdBy` and `createTimestamp` details will now be stored correctly and consistently for storage accounts</title>
            <link>https://turbot.com/guardrails/changelog/azure-storage-v5-20-3</link>
            <description>_Bug fixes_

- Guardrails would sometimes update the `createdBy` details for storage accounts due to mishandled real-time update events. This issue has been fixed, and `createdBy` details will now be stored more reliably and consistently than before.
- In a previous version, we inadvertently introduced a bug that prevented the `createTimestamp` details from being stored in the metadata of new storage accounts upserted in Guardrails CMDB. This issue has now been resolved, and `createTimestamp` details are now stored correctly and reliably.</description>
            <pubDate>Fri, 22 Nov 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-v5-22-0</guid>
            <title>azure v5.22.0 - Resource&apos;s metadata will now also include `createdBy` details in Guardrails CMDB</title>
            <link>https://turbot.com/guardrails/changelog/azure-v5-22-0</link>
            <description>_What&apos;s new?_

- Resource&apos;s metadata will now also include `createdBy` details in Guardrails CMDB.</description>
            <pubDate>Wed, 20 Nov 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-vpc-security-v5-11-1</guid>
            <title>aws-vpc-security v5.11.1 - Updated internal Terraform mapping for Flow Log resource type to update flow logs correctly corresponding to updates in stacks</title>
            <link>https://turbot.com/guardrails/changelog/aws-vpc-security-v5-11-1</link>
            <description>_Bug fixes_

- The `AWS &gt; VPC &gt; VPC &gt; Flow Logging` control would sometimes fail to update flow logs if the Max Aggregation Interval in the stack&apos;s source policy was updated. This is fixed and the stack control will now update such resources correctly, as expected.</description>
            <pubDate>Wed, 20 Nov 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-vpc-core-v5-18-0</guid>
            <title>aws-vpc-core v5.18.0 - Users can now configure the maximum aggregation interval in the Flow Logging control</title>
            <link>https://turbot.com/guardrails/changelog/aws-vpc-core-v5-18-0</link>
            <description>_What&apos;s new?_

- Users can now configure the maximum aggregation interval in the `AWS &gt; VPC &gt; VPC &gt; Flow Logging` control. To get started, set the `AWS &gt; VPC &gt; VPC &gt; Flow Logging &gt; Cloud Watch &gt; Maximum Aggregation Interval` policy and/or `AWS &gt; VPC &gt; VPC &gt; Flow Logging &gt; S3 &gt; Maximum Aggregation Interval` policy.

_Policy Types_

- AWS &gt; VPC &gt; VPC &gt; Flow Logging &gt; Cloud Watch &gt; Maximum Aggregation Interval
- AWS &gt; VPC &gt; VPC &gt; Flow Logging &gt; S3 &gt; Maximum Aggregation Interval</description>
            <pubDate>Wed, 20 Nov 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-sql-v5-16-0</guid>
            <title>azure-sql v5.16.0 - Track and manage Managed Instance resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-sql-v5-16-0</link>
            <description>_Resource Types_

- Azure &gt; SQL &gt; Managed Instance

_Control Types_

- Azure &gt; SQL &gt; Managed Instance &gt; Active
- Azure &gt; SQL &gt; Managed Instance &gt; Approved
- Azure &gt; SQL &gt; Managed Instance &gt; CMDB
- Azure &gt; SQL &gt; Managed Instance &gt; Discovery
- Azure &gt; SQL &gt; Managed Instance &gt; Tags

_Policy Types_

- Azure &gt; SQL &gt; Managed Instance &gt; Active
- Azure &gt; SQL &gt; Managed Instance &gt; Active &gt; Age
- Azure &gt; SQL &gt; Managed Instance &gt; Active &gt; Last Modified
- Azure &gt; SQL &gt; Managed Instance &gt; Approved
- Azure &gt; SQL &gt; Managed Instance &gt; Approved &gt; Custom
- Azure &gt; SQL &gt; Managed Instance &gt; Approved &gt; Regions
- Azure &gt; SQL &gt; Managed Instance &gt; Approved &gt; Usage
- Azure &gt; SQL &gt; Managed Instance &gt; CMDB
- Azure &gt; SQL &gt; Managed Instance &gt; Regions
- Azure &gt; SQL &gt; Managed Instance &gt; Tags
- Azure &gt; SQL &gt; Managed Instance &gt; Tags &gt; Template

_Action Types_

- Azure &gt; SQL &gt; Managed Instance &gt; Delete
- Azure &gt; SQL &gt; Managed Instance &gt; Router
- Azure &gt; SQL &gt; Managed Instance &gt; Set Tags</description>
            <pubDate>Thu, 31 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-cisv3-0-v5-0-2</guid>
            <title>aws-cisv3-0 v5.0.2 - Section 1 controls now correctly target a User/Root instead of Credentials Report</title>
            <link>https://turbot.com/guardrails/changelog/aws-cisv3-0-v5-0-2</link>
            <description>_Bug fixes_

- Controls previously targeting the `AWS &gt; IAM &gt; Credential Report` resource type have now been updated to target either the `AWS &gt; IAM &gt; Root` or `AWS &gt; IAM &gt; User` resource types, depending on the specific control requirements. This adjustment more accurately aligns each control with the relevant resources, enabling more precise and targeted checks.</description>
            <pubDate>Thu, 31 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-securitycenter-v5-5-2</guid>
            <title>azure-securitycenter v5.5.2 - Auto Provisioning control is now deprecated and will move to an Invalid state if enforcements are applied</title>
            <link>https://turbot.com/guardrails/changelog/azure-securitycenter-v5-5-2</link>
            <description>_Bug fixes_

- The `Azure &gt; Security Center &gt; Security Center &gt; Auto Provisioning` control is now deprecated and will now move to an Invalid state if enforcements are applied. This follows the [deprecation plan announcement](https://learn.microsoft.com/en-us/azure/defender-for-cloud/prepare-deprecation-log-analytics-mma-agent#log-analytics-agent-autoprovisioning-experience---deprecation-plan) from Azure. The control will be removed in a future mod version.

_Control Types_

_Renamed_

- Azure &gt; Security Center &gt; Security Center &gt; Auto Provisioning to Azure &gt; Security Center &gt; Security Center &gt; Auto Provisioning [Deprecated]

_Policy Types_

_Renamed_

- Azure &gt; Security Center &gt; Security Center &gt; Auto Provisioning to Azure &gt; Security Center &gt; Security Center &gt; Auto Provisioning [Deprecated]

_Action Types_

_Removed_

- Azure &gt; Security Center &gt; Security Center &gt; Update Auto Provisioning</description>
            <pubDate>Wed, 30 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-kubernetes-v5-5-0</guid>
            <title>servicenow-kubernetes v5.5.0 - Added support for Import Set controls for various Kubernetes resource types</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-kubernetes-v5-5-0</link>
            <description>_What&apos;s new?_

_Control Types_

- Kubernetes &gt; CronJob &gt; ServiceNow &gt; Import Set
- Kubernetes &gt; DaemonSet &gt; ServiceNow &gt; Import Set
- Kubernetes &gt; Ingress &gt; ServiceNow &gt; Import Set
- Kubernetes &gt; Job &gt; ServiceNow &gt; Import Set
- Kubernetes &gt; Persistent Volume &gt; ServiceNow &gt; Import Set
- Kubernetes &gt; ReplicationController &gt; ServiceNow &gt; Import Set
- Kubernetes &gt; StatefulSet &gt; ServiceNow &gt; Import Set

_Policy Types_

- Kubernetes &gt; CronJob &gt; ServiceNow &gt; Import Set
- Kubernetes &gt; CronJob &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- Kubernetes &gt; CronJob &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- Kubernetes &gt; CronJob &gt; ServiceNow &gt; Import Set &gt; Record
- Kubernetes &gt; CronJob &gt; ServiceNow &gt; Import Set &gt; Table Name
- Kubernetes &gt; DaemonSet &gt; ServiceNow &gt; Import Set
- Kubernetes &gt; DaemonSet &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- Kubernetes &gt; DaemonSet &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- Kubernetes &gt; DaemonSet &gt; ServiceNow &gt; Import Set &gt; Record
- Kubernetes &gt; DaemonSet &gt; ServiceNow &gt; Import Set &gt; Table Name
- Kubernetes &gt; Ingress &gt; ServiceNow &gt; Import Set
- Kubernetes &gt; Ingress &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- Kubernetes &gt; Ingress &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- Kubernetes &gt; Ingress &gt; ServiceNow &gt; Import Set &gt; Record
- Kubernetes &gt; Ingress &gt; ServiceNow &gt; Import Set &gt; Table Name
- Kubernetes &gt; Job &gt; ServiceNow &gt; Import Set
- Kubernetes &gt; Job &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- Kubernetes &gt; Job &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- Kubernetes &gt; Job &gt; ServiceNow &gt; Import Set &gt; Record
- Kubernetes &gt; Job &gt; ServiceNow &gt; Import Set &gt; Table Name
- Kubernetes &gt; Persistent Volume &gt; ServiceNow &gt; Import Set
- Kubernetes &gt; Persistent Volume &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- Kubernetes &gt; Persistent Volume &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- Kubernetes &gt; Persistent Volume &gt; ServiceNow &gt; Import Set &gt; Record
- Kubernetes &gt; Persistent Volume &gt; ServiceNow &gt; Import Set &gt; Table Name
- Kubernetes &gt; ReplicationController &gt; ServiceNow &gt; Import Set
- Kubernetes &gt; ReplicationController &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- Kubernetes &gt; ReplicationController &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- Kubernetes &gt; ReplicationController &gt; ServiceNow &gt; Import Set &gt; Record
- Kubernetes &gt; ReplicationController &gt; ServiceNow &gt; Import Set &gt; Table Name
- Kubernetes &gt; StatefulSet &gt; ServiceNow &gt; Import Set
- Kubernetes &gt; StatefulSet &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- Kubernetes &gt; StatefulSet &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- Kubernetes &gt; StatefulSet &gt; ServiceNow &gt; Import Set &gt; Record
- Kubernetes &gt; StatefulSet &gt; ServiceNow &gt; Import Set &gt; Table Name</description>
            <pubDate>Fri, 25 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-aws-s3-v5-2-1</guid>
            <title>servicenow-aws-s3 v5.2.1 - Import Set control will not transform JSON objects to strings while syncing data to ServiceNow</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-aws-s3-v5-2-1</link>
            <description>_Bug fixes_

- In a previous version, we updated the internal logic for the Import Set controls to convert JSON objects to strings to store them reliably in ServiceNow. However, applying transformation logic to this data proved to be difficult in such cases. We have reverted this behavior, and JSON objects will no longer be transformed via the Import Set control. They will now be synced to ServiceNow in their original format.</description>
            <pubDate>Fri, 25 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-v5-21-1</guid>
            <title>azure v5.21.1 - Removed unused Node package dependencies for Tenant lambda functions</title>
            <link>https://turbot.com/guardrails/changelog/azure-v5-21-1</link>
            <description>_Bug fixes_

- Removed unused node package dependencies for tenant lambda functions.</description>
            <pubDate>Fri, 25 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-vertexai-v5-0-1</guid>
            <title>servicenow-gcp-vertexai v5.0.1 - Import Set control will not transform JSON objects to strings while syncing data to ServiceNow</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-vertexai-v5-0-1</link>
            <description>_Bug fixes_

- In a previous version, we updated the internal logic for the Import Set controls to convert JSON objects to strings to store them reliably in ServiceNow. However, applying transformation logic to this data proved to be difficult in such cases. We have reverted this behavior, and JSON objects will no longer be transformed via the Import Set control. They will now be synced to ServiceNow in their original format.</description>
            <pubDate>Thu, 24 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-v5-7-1</guid>
            <title>servicenow-gcp v5.7.1 - Import Set control will not transform JSON objects to strings while syncing data to ServiceNow</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-v5-7-1</link>
            <description>_Bug fixes_

- In a previous version, we updated the internal logic for the Import Set controls to convert JSON objects to strings to store them reliably in ServiceNow. However, applying transformation logic to this data proved to be difficult in such cases. We have reverted this behavior, and JSON objects will no longer be transformed via the Import Set control. They will now be synced to ServiceNow in their original format.</description>
            <pubDate>Thu, 24 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-storage-v5-5-1</guid>
            <title>servicenow-gcp-storage v5.5.1 - Import Set control will not transform JSON objects to strings while syncing data to ServiceNow</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-storage-v5-5-1</link>
            <description>_Bug fixes_

- In a previous version, we updated the internal logic for the Import Set controls to convert JSON objects to strings to store them reliably in ServiceNow. However, applying transformation logic to this data proved to be difficult in such cases. We have reverted this behavior, and JSON objects will no longer be transformed via the Import Set control. They will now be synced to ServiceNow in their original format.</description>
            <pubDate>Thu, 24 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-kubernetesengine-v5-1-1</guid>
            <title>servicenow-gcp-kubernetesengine v5.1.1 - Import Set control will not transform JSON objects to strings while syncing data to ServiceNow</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-kubernetesengine-v5-1-1</link>
            <description>_Bug fixes_

- In a previous version, we updated the internal logic for the Import Set controls to convert JSON objects to strings to store them reliably in ServiceNow. However, applying transformation logic to this data proved to be difficult in such cases. We have reverted this behavior, and JSON objects will no longer be transformed via the Import Set control. They will now be synced to ServiceNow in their original format.</description>
            <pubDate>Thu, 24 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-dataplex-v5-0-1</guid>
            <title>servicenow-gcp-dataplex v5.0.1 - Import Set control will not transform JSON objects to strings while syncing data to ServiceNow</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-dataplex-v5-0-1</link>
            <description>_Bug fixes_

- In a previous version, we updated the internal logic for the Import Set controls to convert JSON objects to strings to store them reliably in ServiceNow. However, applying transformation logic to this data proved to be difficult in such cases. We have reverted this behavior, and JSON objects will no longer be transformed via the Import Set control. They will now be synced to ServiceNow in their original format.</description>
            <pubDate>Thu, 24 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-computeengine-v5-4-0</guid>
            <title>servicenow-gcp-computeengine v5.4.0 - Import Set control will not transform JSON objects to strings while syncing data to ServiceNow</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-computeengine-v5-4-0</link>
            <description>_What&apos;s new?_

_Policy Types_

- GCP &gt; Compute Engine &gt; Disk &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- GCP &gt; Compute Engine &gt; HTTP Health Check &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- GCP &gt; Compute Engine &gt; HTTPS Health Check &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- GCP &gt; Compute Engine &gt; Health Check &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- GCP &gt; Compute Engine &gt; Image &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- GCP &gt; Compute Engine &gt; Instance &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- GCP &gt; Compute Engine &gt; Instance Template &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- GCP &gt; Compute Engine &gt; Node Group &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- GCP &gt; Compute Engine &gt; Node template &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- GCP &gt; Compute Engine &gt; Project &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- GCP &gt; Compute Engine &gt; Region Disk &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- GCP &gt; Compute Engine &gt; Region Health Check &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- GCP &gt; Compute Engine &gt; Snapshot &gt; ServiceNow &gt; Import Set &gt; Insert Mode

_Bug fixes_

- In a previous version, we updated the internal logic for the Import Set controls to convert JSON objects to strings to store them reliably in ServiceNow. However, applying transformation logic to this data proved to be difficult in such cases. We have reverted this behavior, and JSON objects will no longer be transformed via the Import Set control. They will now be synced to ServiceNow in their original format.</description>
            <pubDate>Thu, 24 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-network-v5-4-1</guid>
            <title>servicenow-azure-network v5.4.1 - Import Set control will not transform JSON objects to strings while syncing data to ServiceNow</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-network-v5-4-1</link>
            <description>_Bug fixes_

- In a previous version, we updated the internal logic for the Import Set controls to convert JSON objects to strings to store them reliably in ServiceNow. However, applying transformation logic to this data proved to be difficult in such cases. We have reverted this behavior, and JSON objects will no longer be transformed via the Import Set control. They will now be synced to ServiceNow in their original format.</description>
            <pubDate>Thu, 24 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-compute-v5-2-1</guid>
            <title>servicenow-azure-compute v5.2.1 - Import Set control will not transform JSON objects to strings while syncing data to ServiceNow</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-compute-v5-2-1</link>
            <description>_Bug fixes_

- In a previous version, we updated the internal logic for the Import Set controls to convert JSON objects to strings to store them reliably in ServiceNow. However, applying transformation logic to this data proved to be difficult in such cases. We have reverted this behavior, and JSON objects will no longer be transformed via the Import Set control. They will now be synced to ServiceNow in their original format.</description>
            <pubDate>Thu, 24 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-aks-v5-1-1</guid>
            <title>servicenow-azure-aks v5.1.1 - Import Set control will not transform JSON objects to strings while syncing data to ServiceNow</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-aks-v5-1-1</link>
            <description>_Bug fixes_

- In a previous version, we updated the internal logic for the Import Set controls to convert JSON objects to strings to store them reliably in ServiceNow. However, applying transformation logic to this data proved to be difficult in such cases. We have reverted this behavior, and JSON objects will no longer be transformed via the Import Set control. They will now be synced to ServiceNow in their original format.</description>
            <pubDate>Thu, 24 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-securitycenter-v5-5-1</guid>
            <title>azure-securitycenter v5.5.1 - Fixed internal dependencies to allow Security Center controls to work for US Gov subscriptions</title>
            <link>https://turbot.com/guardrails/changelog/azure-securitycenter-v5-5-1</link>
            <description>_Bug fixes_

- In version 5.5.0, we updated internal dependencies to use the latest Azure SDK versions for discovering and managing Security Center resources in Guardrails. However, this caused controls to enter an error state for US Gov cloud subscriptions because the APIs did not work as expected. We have now updated dependencies that are compatible with both commercial and US Gov cloud subscriptions, ensuring that controls in both environments will work as expected.
- The `Azure &gt; Security Center &gt; Security Center &gt; CMDB` control would go into an error state if it was not able to fetch policy assignment details correctly. This issue has now been fixed.</description>
            <pubDate>Thu, 24 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-monitor-v5-8-1</guid>
            <title>azure-monitor v5.8.1 - Fixed internal dependencies to allow various Monitor controls to work for US Gov subscriptions</title>
            <link>https://turbot.com/guardrails/changelog/azure-monitor-v5-8-1</link>
            <description>_Bug fixes_

- In version 5.8.0, we updated internal dependencies to use the latest Azure SDK versions for discovering and managing Monitor resources in Guardrails. However, this caused controls to enter an error state for US Gov cloud subscriptions because the APIs did not work as expected. We have now updated dependencies that are compatible with both commercial and US Gov cloud subscriptions, ensuring that controls in both environments will work as expected.</description>
            <pubDate>Thu, 24 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-dns-v5-9-1</guid>
            <title>azure-dns v5.9.1 - Fixed incorrect endpoints used to make API calls for various DNS resources</title>
            <link>https://turbot.com/guardrails/changelog/azure-dns-v5-9-1</link>
            <description>_Bug fixes_

- In version 5.9.0, we updated internal dependencies to use the latest Azure SDK versions for discovering and managing DNS resources in Guardrails. However, this caused controls to enter an error state due to the inadvertent use of incorrect endpoints. This issue has been fixed, and the controls will now work as expected.</description>
            <pubDate>Thu, 24 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-compute-v5-18-1</guid>
            <title>azure-compute v5.18.1 - Fixed incorrect endpoints used to make API calls for various Compute resources</title>
            <link>https://turbot.com/guardrails/changelog/azure-compute-v5-18-1</link>
            <description>_Bug fixes_

- In version 5.18.0, we updated internal dependencies to use the latest Azure SDK versions for discovering and managing Compute resources in Guardrails. However, this caused controls to enter an error state due to the inadvertent use of incorrect endpoints. This issue has been fixed, and the controls will now work as expected.</description>
            <pubDate>Thu, 24 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-apimanagement-v5-4-1</guid>
            <title>azure-apimanagement v5.4.1 - Fixed incorrect endpoints used to make API calls for API Management resources</title>
            <link>https://turbot.com/guardrails/changelog/azure-apimanagement-v5-4-1</link>
            <description>_Bug fixes_

- In version 5.4.0, we updated internal dependencies to use the latest Azure SDK versions for discovering and managing API Management resources in Guardrails. However, this caused controls to enter an error state due to the inadvertent use of incorrect endpoints. This issue has been fixed, and the controls will now work as expected.</description>
            <pubDate>Thu, 24 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-automation-v5-1-0</guid>
            <title>azure-automation v5.1.0 - Controls and Actions now use latest Azure SDK versions to discover and manage Automation resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-automation-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated internal dependencies and now use the new authentication method to discover and manage Automation resources in Guardrails.

_Bug fixes_

- Improved descriptions for various resource types to ensure they are clearer and more helpful.</description>
            <pubDate>Wed, 23 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-storage-v5-4-1</guid>
            <title>servicenow-azure-storage v5.4.1 - Import Set control will not transform JSON objects to strings while syncing data to ServiceNow</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-storage-v5-4-1</link>
            <description>_Bug fixes_

- In a previous version, we updated the internal logic for the Import Set controls to convert JSON objects to strings to store them reliably in ServiceNow. However, applying transformation logic to this data proved to be difficult in such cases. We have reverted this behavior, and JSON objects will no longer be transformed via the Import Set control. They will now be synced to ServiceNow in their original format.</description>
            <pubDate>Tue, 22 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-v5-6-1</guid>
            <title>servicenow-azure v5.6.1 - Import Set control will not transform JSON objects to strings while syncing data to ServiceNow</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-v5-6-1</link>
            <description>_Bug fixes_

- In v5.3.1, we updated the internal logic for the Import Set controls to convert JSON objects to strings to store them reliably in ServiceNow. However, applying transformation logic to this data proved to be difficult in such cases. We have reverted this behavior, and JSON objects will no longer be transformed via the Import Set control. They will now be synced to ServiceNow in their original format.</description>
            <pubDate>Mon, 21 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-keyvault-v5-14-0</guid>
            <title>azure-keyvault v5.14.0 - Controls and Actions now use latest Azure SDK versions to discover and manage Key Vault resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-keyvault-v5-14-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated internal dependencies and now use the latest Azure SDK versions to discover and manage Key Vault resources in Guardrails. This release includes breaking changes in the CMDB data for key, and secret. We recommend updating your existing policy settings to refer to the updated attributes as mentioned below:

KeyVault &gt; Vault

Added :

- `enableSoftDelete`
- `publicNetworkAccess`
- `enableRbacAuthorization`

KeyVault &gt; Key

Added :

- `hsmPlatform`

Removed:

- `key.e`
- `key.n`

KeyVault &gt; Secret

Modified :

- `ID` property does not contain the secret version.

Removed:

- `expires`
- `updated`
- `created`

_Bug fixes_

- The `Azure &gt; Key Vault &gt; Key &gt; CMDB` control would go into an error state while fetching key rotation policy details for managed keys. The control will no longer attempt to fetch the key rotation policy details for such keys and will work as expected.
- Improved descriptions for various resource types to ensure they are clearer and more helpful.</description>
            <pubDate>Mon, 21 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/ted-v1-45-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.45.0 - Added support for PostgresSQL 16</title>
            <link>https://turbot.com/guardrails/changelog/ted-v1-45-0</link>
            <description>_What&apos;s new?_

- Added support for PostgresSQL 16.
- Added support for custom hive key.
- Default database engine version changed to 15.7.
- Default cache engine version set to 7.1.
- M4 and R4 instance types removed from the supported database instance list due to deprecation.</description>
            <pubDate>Fri, 18 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-47-2</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.47.2 - Feature enhancements and bug fixes</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-47-2</link>
            <description>_What&apos;s new?_

- Server
  - Introduced `Activity Retention` feature for Smart Retention control to enhance version and data management.

- UI
  - Support for downloading AWS CloudFormation templates directly from the AWS import page.

_Bug fixes_

- Server
  - Resolved controls getting stuck when `Notify` or `Ignore` keywords were missing in the notification rules.

- UI
  - The `+` button for adding permissions now correctly applies the appropriate attributes.


_Requirements_

- TEF: 1.59.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Fri, 18 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/turbot-v5-46-0</guid>
            <title>turbot v5.46.0 - Added policy to set Activity Retention</title>
            <link>https://turbot.com/guardrails/changelog/turbot-v5-46-0</link>
            <description>_What&apos;s new?_

- Policy Types:
  - Turbot &gt; Workspace &gt; Retention &gt; Activity Purge Limit.
  - Turbot &gt; Workspace &gt; Retention &gt; Activity Retention.

- Control Types:
  - Add support to `Turbot &gt; Smart Retention` control to enhance version and data management.

_Requirements_

- TE: 5.35.4</description>
            <pubDate>Fri, 18 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-mysql-v5-12-0</guid>
            <title>azure-mysql v5.12.0 - Check if flexible servers have TLS version set to 1.2 or higher</title>
            <link>https://turbot.com/guardrails/changelog/azure-mysql-v5-12-0</link>
            <description>_What&apos;s new?_

- You can now check if flexible servers have a TLS version setting of 1.2 or higher enabled. To get started, set the `Azure &gt; MySQL &gt; Flexible Server &gt; Set Minimum TLS Version` policy to `Check: TLS 1.2 or higher`.</description>
            <pubDate>Fri, 18 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-v5-21-0</guid>
            <title>azure v5.21.0 - Controls and Actions now use latest Azure SDK versions to discover and manage resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-v5-21-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated internal dependencies and now use the latest Azure SDK versions to discover and manage resources in Guardrails. This release includes breaking changes in the CMDB data for Azure. We recommend updating your existing policy settings to refer to the updated attributes as mentioned below.

Azure &gt; Management Group

Modified :

- The value of `type` property is updated as `type: Microsoft.Management/managementGroups`, earlier it was `/providers/Microsoft.Management/managementGroups`</description>
            <pubDate>Thu, 17 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-sqlvirtualmachine-v5-1-0</guid>
            <title>azure-sqlvirtualmachine v5.1.0 - Controls and Actions now use latest Azure SDK versions to discover and manage SQL Virtual Machine resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-sqlvirtualmachine-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated internal dependencies and now use the new authentication method to discover and manage SQL Virtual Machine resources in Guardrails.

_Bug fixes_

- Improved descriptions for various resource types to ensure they are clearer and more helpful.</description>
            <pubDate>Thu, 17 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-sql-v5-15-0</guid>
            <title>azure-sql v5.15.0 - Controls and Actions now use latest Azure SDK versions to discover and manage SQL resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-sql-v5-15-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated internal dependencies and now use the latest Azure SDK versions to discover and manage SQL resources in Guardrails. This release includes breaking changes in the CMDB data for server, database, and elasticpool. We recommend updating your existing policy settings to refer to the updated attributes as mentioned below:

Renamed:

- `transparentDataEncryption.status` to `transparentDataEncryption.state`
- `databaseThreatDetectionPolicy` to `databaseSecurityAlertPolicy`

Added:

Azure SQL &gt; Server

- Added `administrators` block
- `isManagedIdentityInUse `
- `autoRotationEnabled `
- `externalGovernanceStatus `
- `minimalTlsVersion`
- `privateEndpointConnections`
- `publicNetworkAccess`
- `restrictOutboundNetworkAccess`
- `serverAzureADAdministrator.azureADOnlyAuthentication`

Azure SQL &gt; Database

- `availabilityZone`
- `currentBackupStorageRedundancy`
- `databaseSecurityAlertPolicy. creationTime`
- `transparentDataEncryption.location`
- `isInfraEncryptionEnabled`
- `isLedgerOn`
- `maintenanceConfigurationId`
- `requestedBackupStorageRedundancy`
- `maintenanceConfigurationId`

Azure SQL &gt; ElasticPool

- `maintenanceConfigurationId`

Modified:

- The value of the attribute `serverAzureADAdministrator.name` has been changed from string (`activeDirectory`) to string (`ActiveDirectory`).
- The data type of the attribute `databaseThreatDetectionPolicy.disabledAlerts` has been changed from string (`&quot;&quot;`) to object (`[]`).
- The data type of the attribute `databaseThreatDetectionPolicy.emailAddresses` has been changed from string (`&quot;&quot;`) to object (`[]`).
- The data type of the attribute `databaseThreatDetectionPolicy.emailAccountAdmins` has been changed from string (`Disabled/Enabled`) to boolean (`false/true`).
- The data type of the attribute `disabledAlerts` has been changed from string (`&quot;&quot;`) to object (`[]`).

Removed:

- `databaseThreatDetectionPolicy.useServerDefault`

_Bug fixes_

- Improved descriptions for various resource types to ensure they are clearer and more helpful.</description>
            <pubDate>Thu, 17 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-provider-v5-13-0</guid>
            <title>azure-provider v5.13.0 - Controls and Actions now use latest Azure SDK versions to discover and manage Resource Providers in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-provider-v5-13-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated internal dependencies and now use the latest Azure SDK versions to discover and manage Resource Providers in Guardrails.</description>
            <pubDate>Thu, 17 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-network-v5-19-0</guid>
            <title>azure-network v5.19.0 - Controls and Actions now use latest Azure SDK versions to discover and manage Network resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-network-v5-19-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated internal dependencies and now use the latest Azure SDK versions to discover and manage Network resources in Guardrails.

Network &gt; NetworkInterface

Added :

- `auxiliaryMode`
- `auxiliarySku`
- `kind`
- `disableTcpStateTracking`

Network &gt; PrivateDNSZone

Added :

- `internalId`

Network &gt; VirtualNetworkGateway

Added :

- `allowVirtualWanTraffic`
- `allowRemoteVnetTraffic`

Modified :

- `activeActive` property updated as `active`</description>
            <pubDate>Thu, 17 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-monitor-v5-8-0</guid>
            <title>azure-monitor v5.8.0 - Controls and Actions now use latest Azure SDK versions to discover and manage Monitor resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-monitor-v5-8-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated internal dependencies and now use the latest Azure SDK versions to discover and manage Monitor resources in Guardrails. This release includes changes in the CMDB data for action groups.

Added:

- `tags`
- `kind`

_Resource Types_

- Azure &gt; Monitor &gt; Metric Alert

_Control Types_

- Azure &gt; Monitor &gt; Action Group &gt; Tags
- Azure &gt; Monitor &gt; Metric Alert &gt; Active
- Azure &gt; Monitor &gt; Metric Alert &gt; Approved
- Azure &gt; Monitor &gt; Metric Alert &gt; CMDB
- Azure &gt; Monitor &gt; Metric Alert &gt; Discovery
- Azure &gt; Monitor &gt; Metric Alert &gt; Tags

_Policy Types_

- Azure &gt; Monitor &gt; Action Group &gt; Tags
- Azure &gt; Monitor &gt; Action Group &gt; Tags &gt; Template
- Azure &gt; Monitor &gt; Metric Alert &gt; Active
- Azure &gt; Monitor &gt; Metric Alert &gt; Active &gt; Age
- Azure &gt; Monitor &gt; Metric Alert &gt; Active &gt; Last Modified
- Azure &gt; Monitor &gt; Metric Alert &gt; Approved
- Azure &gt; Monitor &gt; Metric Alert &gt; Approved &gt; Custom
- Azure &gt; Monitor &gt; Metric Alert &gt; Approved &gt; Usage
- Azure &gt; Monitor &gt; Metric Alert &gt; CMDB
- Azure &gt; Monitor &gt; Metric Alert &gt; Tags
- Azure &gt; Monitor &gt; Metric Alert &gt; Tags &gt; Template
- Azure &gt; Monitor &gt; Tags Template [Default]

_Action Types_

- Azure &gt; Monitor &gt; Action Group &gt; Set Tags
- Azure &gt; Monitor &gt; Metric Alert &gt; Delete
- Azure &gt; Monitor &gt; Metric Alert &gt; Router
- Azure &gt; Monitor &gt; Metric Alert &gt; Set Tags

_Bug fixes_

- Improved descriptions for various resource types to ensure they are clearer and more helpful.</description>
            <pubDate>Thu, 17 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-managedidentity-v5-1-0</guid>
            <title>azure-managedidentity v5.1.0 - Controls and Actions now use latest Azure SDK versions to discover and manage Managed Identity resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-managedidentity-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated internal dependencies and now use the latest Azure SDK versions to discover and manage Managed Identity resources in Guardrails. This release includes changes in the CMDB data as below.

Removed:

- `clientSecretUrl`</description>
            <pubDate>Thu, 17 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-loganalytics-v5-9-0</guid>
            <title>azure-loganalytics v5.9.0 - Controls and Actions now use latest Azure SDK versions to discover and manage Log Analytics resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-loganalytics-v5-9-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated internal dependencies and now use the latest Azure SDK versions to discover and manage Log Analytics resources in Guardrails.

_Bug fixes_

- Improved descriptions for various resource types to ensure they are clearer and more helpful.</description>
            <pubDate>Thu, 17 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-iam-v5-12-0</guid>
            <title>azure-iam v5.12.0 - Controls and Actions now use latest Azure SDK versions to discover and manage IAM resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-iam-v5-12-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated internal dependencies and now use the latest Azure SDK versions to discover and manage IAM resources in Guardrails.

_Bug fixes_

- Improved descriptions for various resource types to ensure they are clearer and more helpful.</description>
            <pubDate>Thu, 17 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-firewall-v5-7-0</guid>
            <title>azure-firewall v5.7.0 - Controls and Actions now use latest Azure SDK versions to discover and manage Firewall resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-firewall-v5-7-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated internal dependencies and now use the latest Azure SDK versions to discover and manage Firewall resources in Guardrails.

_Bug fixes_

- Improved descriptions for various resource types to ensure they are clearer and more helpful.</description>
            <pubDate>Wed, 16 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-cosmosdb-v5-7-0</guid>
            <title>azure-cosmosdb v5.7.0 - Controls and Actions now use latest Azure SDK versions to discover and manage CosmosDB resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-cosmosdb-v5-7-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated internal dependencies and now use the latest Azure SDK versions to discover and manage CosmosDB resources in Guardrails.

Added:

`createMode`

_Bug fixes_

- Improved descriptions for various resource types to ensure they are clearer and more helpful.</description>
            <pubDate>Wed, 16 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-v5-30-5</guid>
            <title>aws v5.30.5 - Budget control will now avoid making API calls for US Gov Cloud Accounts and rely on State policy being updated periodically</title>
            <link>https://turbot.com/guardrails/changelog/aws-v5-30-5</link>
            <description>_Bug fixes_

- The `AWS &gt; Account &gt; Budget &gt; Budget` control would enter an error state for US Gov cloud accounts because the budget APIs are not supported for these accounts. We have updated the control to avoid making these API calls and instead rely on the `AWS &gt; Account &gt; Budget &gt; State` policy being updated periodically, allowing the control to evaluate the outcome correctly.</description>
            <pubDate>Wed, 16 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-kubernetes-v5-4-0</guid>
            <title>servicenow-kubernetes v5.4.0 - Configure CI Relationships for Various Kubernetes Resources in ServiceNow</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-kubernetes-v5-4-0</link>
            <description>_What&apos;s new?_

- You can now configure and manage CI Relationships for various Kubernetes resources in ServiceNow. To get started, set their ServiceNow Relationships policies respectively.

_Control Types_

- Kubernetes &gt; Cluster &gt; ServiceNow &gt; Relationships
- Kubernetes &gt; ConfigMap &gt; ServiceNow &gt; Relationships
- Kubernetes &gt; CronJob &gt; ServiceNow &gt; Relationships
- Kubernetes &gt; DaemonSet &gt; ServiceNow &gt; Relationships
- Kubernetes &gt; Deployment &gt; ServiceNow &gt; Relationships
- Kubernetes &gt; Ingress &gt; ServiceNow &gt; Relationships
- Kubernetes &gt; Job &gt; ServiceNow &gt; Relationships
- Kubernetes &gt; Namespace &gt; ServiceNow &gt; Relationships
- Kubernetes &gt; Node &gt; ServiceNow &gt; Relationships
- Kubernetes &gt; Persistent Volume &gt; ServiceNow &gt; Relationships
- Kubernetes &gt; Pod &gt; ServiceNow &gt; Relationships
- Kubernetes &gt; ReplicaSet &gt; ServiceNow &gt; Relationships
- Kubernetes &gt; ReplicationController &gt; ServiceNow &gt; Relationships
- Kubernetes &gt; Service &gt; ServiceNow &gt; Relationships
- Kubernetes &gt; StatefulSet &gt; ServiceNow &gt; Relationships

_Policy Types_

- Kubernetes &gt; Cluster &gt; ServiceNow &gt; Relationships
- Kubernetes &gt; Cluster &gt; ServiceNow &gt; Relationships &gt; Template
- Kubernetes &gt; ConfigMap &gt; ServiceNow &gt; Relationships
- Kubernetes &gt; ConfigMap &gt; ServiceNow &gt; Relationships &gt; Template
- Kubernetes &gt; CronJob &gt; ServiceNow &gt; Relationships
- Kubernetes &gt; CronJob &gt; ServiceNow &gt; Relationships &gt; Template
- Kubernetes &gt; DaemonSet &gt; ServiceNow &gt; Relationships
- Kubernetes &gt; DaemonSet &gt; ServiceNow &gt; Relationships &gt; Template
- Kubernetes &gt; Deployment &gt; ServiceNow &gt; Relationships
- Kubernetes &gt; Deployment &gt; ServiceNow &gt; Relationships &gt; Template
- Kubernetes &gt; Ingress &gt; ServiceNow &gt; Relationships
- Kubernetes &gt; Ingress &gt; ServiceNow &gt; Relationships &gt; Template
- Kubernetes &gt; Job &gt; ServiceNow &gt; Relationships
- Kubernetes &gt; Job &gt; ServiceNow &gt; Relationships &gt; Template
- Kubernetes &gt; Namespace &gt; ServiceNow &gt; Relationships
- Kubernetes &gt; Namespace &gt; ServiceNow &gt; Relationships &gt; Template
- Kubernetes &gt; Node &gt; ServiceNow &gt; Relationships
- Kubernetes &gt; Node &gt; ServiceNow &gt; Relationships &gt; Template
- Kubernetes &gt; Persistent Volume &gt; ServiceNow &gt; Relationships
- Kubernetes &gt; Persistent Volume &gt; ServiceNow &gt; Relationships &gt; Template
- Kubernetes &gt; Pod &gt; ServiceNow &gt; Relationships
- Kubernetes &gt; Pod &gt; ServiceNow &gt; Relationships &gt; Template
- Kubernetes &gt; ReplicaSet &gt; ServiceNow &gt; Relationships
- Kubernetes &gt; ReplicaSet &gt; ServiceNow &gt; Relationships &gt; Template
- Kubernetes &gt; ReplicationController &gt; ServiceNow &gt; Relationships
- Kubernetes &gt; ReplicationController &gt; ServiceNow &gt; Relationships &gt; Template
- Kubernetes &gt; Service &gt; ServiceNow &gt; Relationships
- Kubernetes &gt; Service &gt; ServiceNow &gt; Relationships &gt; Template
- Kubernetes &gt; StatefulSet &gt; ServiceNow &gt; Relationships
- Kubernetes &gt; StatefulSet &gt; ServiceNow &gt; Relationships &gt; Template</description>
            <pubDate>Tue, 15 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-loadbalancer-v5-8-0</guid>
            <title>azure-loadbalancer v5.8.0 - Controls and Actions now use latest Azure SDK versions to discover and manage Load Balancer resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-loadbalancer-v5-8-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated internal dependencies and now use the latest Azure SDK versions to discover and manage Load Balancer resources in Guardrails.</description>
            <pubDate>Tue, 15 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-v5-7-0</guid>
            <title>servicenow-gcp v5.7.0 - Configure CI Relationships for Projects in ServiceNow</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-v5-7-0</link>
            <description>_What&apos;s new?_

- You can now configure and manage CI Relationships for projects in ServiceNow. To get started, set the `GCP &gt; Project &gt; ServiceNow &gt; Relationships &gt; *` policies.

_Control Types_

- GCP &gt; Project &gt; ServiceNow &gt; Relationships

_Policy Types_

- GCP &gt; Project &gt; ServiceNow &gt; Relationships
- GCP &gt; Project &gt; ServiceNow &gt; Relationships &gt; Template</description>
            <pubDate>Mon, 14 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-v5-6-0</guid>
            <title>servicenow-azure v5.6.0 - Configure CI Relationships for Subscriptions in ServiceNow</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-v5-6-0</link>
            <description>_What&apos;s new?_

- You can now configure and manage CI Relationships for subscriptions in ServiceNow. To get started, set the `Azure &gt; Subscription &gt; ServiceNow &gt; Relationships &gt; *` policies.

_Control Types_

- Azure &gt; Subscription &gt; ServiceNow &gt; Relationships

_Policy Types_

- Azure &gt; Subscription &gt; ServiceNow &gt; Relationships
- Azure &gt; Subscription &gt; ServiceNow &gt; Relationships &gt; Template</description>
            <pubDate>Mon, 14 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-aws-v5-3-0</guid>
            <title>servicenow-aws v5.3.0 - Configure CI Relationships for Accounts in ServiceNow</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-aws-v5-3-0</link>
            <description>_What&apos;s new?_

- You can now configure and manage CI Relationships for accounts in ServiceNow. To get started, set the `AWS &gt; Account &gt; ServiceNow &gt; Relationships &gt; *` policies.

_Control Types_

- AWS &gt; Account &gt; ServiceNow &gt; Relationships

_Policy Types_

- AWS &gt; Account &gt; ServiceNow &gt; Relationships
- AWS &gt; Account &gt; ServiceNow &gt; Relationships &gt; Template</description>
            <pubDate>Mon, 14 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-dns-v5-9-0</guid>
            <title>azure-dns v5.9.0 - Controls and Actions now use latest Azure SDK versions to discover and manage DNS resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-dns-v5-9-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated internal dependencies and now use the latest Azure SDK versions to discover and manage DNS resources in Guardrails. This release includes breaking changes in the CMDB data for security center. We recommend updating your existing policy settings to refer to the updated attributes as mentioned below.

Removed:

- `tTL`

_Bug fixes_

- Improved descriptions for various resource types to ensure they are clearer and more helpful.</description>
            <pubDate>Mon, 14 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-databricks-v5-4-0</guid>
            <title>azure-databricks v5.4.0 - Controls and Actions now use latest Azure SDK versions to discover and manage Databricks resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-databricks-v5-4-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated internal dependencies and now use the latest Azure SDK versions to discover and manage Databricks resources in Guardrails.

Added:

- `createdBy`
- `updatedBy`
- `systemData`
- `createdDateTime`

_Bug fixes_

- Improved descriptions for various resource types to ensure they are clearer and more helpful.</description>
            <pubDate>Mon, 14 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-containerregistry-v5-1-0</guid>
            <title>azure-containerregistry v5.1.0 - Controls and Actions now use latest Azure SDK versions to discover and manage Container Registry resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-containerregistry-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated internal dependencies and now use the latest Azure SDK versions to discover and manage Container Registry resources in Guardrails.

Added:

- `softDeletePolicy`
- `azureADAuthenticationAsArmPolicy`</description>
            <pubDate>Mon, 14 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-network-v5-2-0</guid>
            <title>servicenow-gcp-network v5.2.0 - Configure CI Relationships for Various Network Resources in ServiceNow</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-network-v5-2-0</link>
            <description>_What&apos;s new?_

- You can now configure and manage CI Relationships for various network resources in ServiceNow. To get started, set their ServiceNow Relationships policies respectively.

_Control Types_

- GCP &gt; Network &gt; Firewall &gt; ServiceNow &gt; Relationships
- GCP &gt; Network &gt; Forwarding Rule &gt; ServiceNow &gt; Relationships
- GCP &gt; Network &gt; Network &gt; ServiceNow &gt; Relationships
- GCP &gt; Network &gt; Route &gt; ServiceNow &gt; Relationships
- GCP &gt; Network &gt; Router &gt; ServiceNow &gt; Relationships
- GCP &gt; Network &gt; Subnetwork &gt; ServiceNow &gt; Relationships
- GCP &gt; Network &gt; Target Pool &gt; ServiceNow &gt; Relationships
- GCP &gt; Network &gt; Target VPN Gateway &gt; ServiceNow &gt; Relationships

_Policy Types_

- GCP &gt; Network &gt; Firewall &gt; ServiceNow &gt; Relationships
- GCP &gt; Network &gt; Firewall &gt; ServiceNow &gt; Relationships &gt; Template
- GCP &gt; Network &gt; Forwarding Rule &gt; ServiceNow &gt; Relationships
- GCP &gt; Network &gt; Forwarding Rule &gt; ServiceNow &gt; Relationships &gt; Template
- GCP &gt; Network &gt; Network &gt; ServiceNow &gt; Relationships
- GCP &gt; Network &gt; Network &gt; ServiceNow &gt; Relationships &gt; Template
- GCP &gt; Network &gt; Route &gt; ServiceNow &gt; Relationships
- GCP &gt; Network &gt; Route &gt; ServiceNow &gt; Relationships &gt; Template
- GCP &gt; Network &gt; Router &gt; ServiceNow &gt; Relationships
- GCP &gt; Network &gt; Router &gt; ServiceNow &gt; Relationships &gt; Template
- GCP &gt; Network &gt; Subnetwork &gt; ServiceNow &gt; Relationships
- GCP &gt; Network &gt; Subnetwork &gt; ServiceNow &gt; Relationships &gt; Template
- GCP &gt; Network &gt; Target Pool &gt; ServiceNow &gt; Relationships
- GCP &gt; Network &gt; Target Pool &gt; ServiceNow &gt; Relationships &gt; Template
- GCP &gt; Network &gt; Target VPN Gateway &gt; ServiceNow &gt; Relationships
- GCP &gt; Network &gt; Target VPN Gateway &gt; ServiceNow &gt; Relationships &gt; Template</description>
            <pubDate>Wed, 09 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-computeengine-v5-3-0</guid>
            <title>servicenow-gcp-computeengine v5.3.0 - Configure CI Relationships for Various Compute Engine Resources in ServiceNow</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-computeengine-v5-3-0</link>
            <description>_What&apos;s new?_

- You can now configure and manage CI Relationships for various compute engine resources in ServiceNow. To get started, set their ServiceNow Relationships policies respectively.

_Control Types_

- GCP &gt; Compute Engine &gt; Disk &gt; ServiceNow &gt; Relationships
- GCP &gt; Compute Engine &gt; Image &gt; ServiceNow &gt; Relationships
- GCP &gt; Compute Engine &gt; Instance &gt; ServiceNow &gt; Relationships
- GCP &gt; Compute Engine &gt; Node Group &gt; ServiceNow &gt; Relationships
- GCP &gt; Compute Engine &gt; Node template &gt; ServiceNow &gt; Relationships
- GCP &gt; Compute Engine &gt; Snapshot &gt; ServiceNow &gt; Relationships

_Policy Types_

- GCP &gt; Compute Engine &gt; Disk &gt; ServiceNow &gt; Relationships
- GCP &gt; Compute Engine &gt; Disk &gt; ServiceNow &gt; Relationships &gt; Template
- GCP &gt; Compute Engine &gt; Image &gt; ServiceNow &gt; Relationships
- GCP &gt; Compute Engine &gt; Image &gt; ServiceNow &gt; Relationships &gt; Template
- GCP &gt; Compute Engine &gt; Instance &gt; ServiceNow &gt; Relationships
- GCP &gt; Compute Engine &gt; Instance &gt; ServiceNow &gt; Relationships &gt; Template
- GCP &gt; Compute Engine &gt; Node Group &gt; ServiceNow &gt; Relationships
- GCP &gt; Compute Engine &gt; Node Group &gt; ServiceNow &gt; Relationships &gt; Template
- GCP &gt; Compute Engine &gt; Node template &gt; ServiceNow &gt; Relationships
- GCP &gt; Compute Engine &gt; Node template &gt; ServiceNow &gt; Relationships &gt; Template
- GCP &gt; Compute Engine &gt; Snapshot &gt; ServiceNow &gt; Relationships
- GCP &gt; Compute Engine &gt; Snapshot &gt; ServiceNow &gt; Relationships &gt; Template</description>
            <pubDate>Wed, 09 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-network-v5-4-0</guid>
            <title>servicenow-azure-network v5.4.0 - Configure CI Relationships for Various Network Resources in ServiceNow</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-network-v5-4-0</link>
            <description>_What&apos;s new?_

- You can now configure and manage CI Relationships for various network resources in ServiceNow. To get started, set their ServiceNow Relationships policies respectively.

_Control Types_

- Azure &gt; Network &gt; Application Security Group &gt; ServiceNow &gt; Import Set
- Azure &gt; Network &gt; Application Security Group &gt; ServiceNow &gt; Relationships
- Azure &gt; Network &gt; Express Route Circuits &gt; ServiceNow &gt; Import Set
- Azure &gt; Network &gt; Network Interface &gt; ServiceNow &gt; Import Set
- Azure &gt; Network &gt; Network Interface &gt; ServiceNow &gt; Relationships
- Azure &gt; Network &gt; Network Security Group &gt; ServiceNow &gt; Relationships
- Azure &gt; Network &gt; Private DNS Zones &gt; ServiceNow &gt; Import Set
- Azure &gt; Network &gt; Private Endpoints &gt; ServiceNow &gt; Import Set
- Azure &gt; Network &gt; Public IP Address &gt; ServiceNow &gt; Import Set
- Azure &gt; Network &gt; Public IP Address &gt; ServiceNow &gt; Relationships
- Azure &gt; Network &gt; Route Table &gt; ServiceNow &gt; Import Set
- Azure &gt; Network &gt; Route Table &gt; ServiceNow &gt; Relationships
- Azure &gt; Network &gt; Subnet &gt; ServiceNow &gt; Import Set
- Azure &gt; Network &gt; Subnet &gt; ServiceNow &gt; Relationships
- Azure &gt; Network &gt; Virtual Network &gt; ServiceNow &gt; Import Set
- Azure &gt; Network &gt; Virtual Network &gt; ServiceNow &gt; Relationships
- Azure &gt; Network &gt; Virtual Network Gateway &gt; ServiceNow &gt; Import Set
- Azure &gt; Network &gt; Virtual Network Gateway &gt; ServiceNow &gt; Relationships

_Policy Types_

- Azure &gt; Network &gt; Application Security Group &gt; ServiceNow &gt; Import Set
- Azure &gt; Network &gt; Application Security Group &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- Azure &gt; Network &gt; Application Security Group &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- Azure &gt; Network &gt; Application Security Group &gt; ServiceNow &gt; Import Set &gt; Record
- Azure &gt; Network &gt; Application Security Group &gt; ServiceNow &gt; Import Set &gt; Table Name
- Azure &gt; Network &gt; Application Security Group &gt; ServiceNow &gt; Relationships
- Azure &gt; Network &gt; Application Security Group &gt; ServiceNow &gt; Relationships &gt; Template
- Azure &gt; Network &gt; Express Route Circuits &gt; ServiceNow &gt; Import Set
- Azure &gt; Network &gt; Express Route Circuits &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- Azure &gt; Network &gt; Express Route Circuits &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- Azure &gt; Network &gt; Express Route Circuits &gt; ServiceNow &gt; Import Set &gt; Record
- Azure &gt; Network &gt; Express Route Circuits &gt; ServiceNow &gt; Import Set &gt; Table Name
- Azure &gt; Network &gt; Network Interface &gt; ServiceNow &gt; Import Set
- Azure &gt; Network &gt; Network Interface &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- Azure &gt; Network &gt; Network Interface &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- Azure &gt; Network &gt; Network Interface &gt; ServiceNow &gt; Import Set &gt; Record
- Azure &gt; Network &gt; Network Interface &gt; ServiceNow &gt; Import Set &gt; Table Name
- Azure &gt; Network &gt; Network Interface &gt; ServiceNow &gt; Relationships
- Azure &gt; Network &gt; Network Interface &gt; ServiceNow &gt; Relationships &gt; Template
- Azure &gt; Network &gt; Network Security Group &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- Azure &gt; Network &gt; Network Security Group &gt; ServiceNow &gt; Relationships
- Azure &gt; Network &gt; Network Security Group &gt; ServiceNow &gt; Relationships &gt; Template
- Azure &gt; Network &gt; Private DNS Zones &gt; ServiceNow &gt; Import Set
- Azure &gt; Network &gt; Private DNS Zones &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- Azure &gt; Network &gt; Private DNS Zones &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- Azure &gt; Network &gt; Private DNS Zones &gt; ServiceNow &gt; Import Set &gt; Record
- Azure &gt; Network &gt; Private DNS Zones &gt; ServiceNow &gt; Import Set &gt; Table Name
- Azure &gt; Network &gt; Private Endpoints &gt; ServiceNow &gt; Import Set
- Azure &gt; Network &gt; Private Endpoints &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- Azure &gt; Network &gt; Private Endpoints &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- Azure &gt; Network &gt; Private Endpoints &gt; ServiceNow &gt; Import Set &gt; Record
- Azure &gt; Network &gt; Private Endpoints &gt; ServiceNow &gt; Import Set &gt; Table Name
- Azure &gt; Network &gt; Public IP Address &gt; ServiceNow &gt; Import Set
- Azure &gt; Network &gt; Public IP Address &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- Azure &gt; Network &gt; Public IP Address &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- Azure &gt; Network &gt; Public IP Address &gt; ServiceNow &gt; Import Set &gt; Record
- Azure &gt; Network &gt; Public IP Address &gt; ServiceNow &gt; Import Set &gt; Table Name
- Azure &gt; Network &gt; Public IP Address &gt; ServiceNow &gt; Relationships
- Azure &gt; Network &gt; Public IP Address &gt; ServiceNow &gt; Relationships &gt; Template
- Azure &gt; Network &gt; Route Table &gt; ServiceNow &gt; Import Set
- Azure &gt; Network &gt; Route Table &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- Azure &gt; Network &gt; Route Table &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- Azure &gt; Network &gt; Route Table &gt; ServiceNow &gt; Import Set &gt; Record
- Azure &gt; Network &gt; Route Table &gt; ServiceNow &gt; Import Set &gt; Table Name
- Azure &gt; Network &gt; Route Table &gt; ServiceNow &gt; Relationships
- Azure &gt; Network &gt; Route Table &gt; ServiceNow &gt; Relationships &gt; Template
- Azure &gt; Network &gt; Subnet &gt; ServiceNow &gt; Import Set
- Azure &gt; Network &gt; Subnet &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- Azure &gt; Network &gt; Subnet &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- Azure &gt; Network &gt; Subnet &gt; ServiceNow &gt; Import Set &gt; Record
- Azure &gt; Network &gt; Subnet &gt; ServiceNow &gt; Import Set &gt; Table Name
- Azure &gt; Network &gt; Subnet &gt; ServiceNow &gt; Relationships
- Azure &gt; Network &gt; Subnet &gt; ServiceNow &gt; Relationships &gt; Template
- Azure &gt; Network &gt; Virtual Network &gt; ServiceNow &gt; Import Set
- Azure &gt; Network &gt; Virtual Network &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- Azure &gt; Network &gt; Virtual Network &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- Azure &gt; Network &gt; Virtual Network &gt; ServiceNow &gt; Import Set &gt; Record
- Azure &gt; Network &gt; Virtual Network &gt; ServiceNow &gt; Import Set &gt; Table Name
- Azure &gt; Network &gt; Virtual Network &gt; ServiceNow &gt; Relationships
- Azure &gt; Network &gt; Virtual Network &gt; ServiceNow &gt; Relationships &gt; Template
- Azure &gt; Network &gt; Virtual Network Gateway &gt; ServiceNow &gt; Import Set
- Azure &gt; Network &gt; Virtual Network Gateway &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- Azure &gt; Network &gt; Virtual Network Gateway &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- Azure &gt; Network &gt; Virtual Network Gateway &gt; ServiceNow &gt; Import Set &gt; Record
- Azure &gt; Network &gt; Virtual Network Gateway &gt; ServiceNow &gt; Import Set &gt; Table Name
- Azure &gt; Network &gt; Virtual Network Gateway &gt; ServiceNow &gt; Relationships
- Azure &gt; Network &gt; Virtual Network Gateway &gt; ServiceNow &gt; Relationships &gt; Template</description>
            <pubDate>Wed, 09 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-compute-v5-2-0</guid>
            <title>servicenow-azure-compute v5.2.0 - Configure CI Relationships for Various Compute Resources in ServiceNow</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-compute-v5-2-0</link>
            <description>_What&apos;s new?_

- You can now configure and manage CI Relationships for various compute resources in ServiceNow. To get started, set their ServiceNow Relationships policies respectively.

_Control Types_

- Azure &gt; Compute &gt; Availability Set &gt; ServiceNow &gt; Relationships
- Azure &gt; Compute &gt; Disk &gt; ServiceNow &gt; Relationships
- Azure &gt; Compute &gt; Image &gt; ServiceNow &gt; Relationships
- Azure &gt; Compute &gt; Snapshot &gt; ServiceNow &gt; Relationships
- Azure &gt; Compute &gt; Virtual Machine &gt; ServiceNow &gt; Relationships

_Policy Types_

- Azure &gt; Compute &gt; Availability Set &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- Azure &gt; Compute &gt; Availability Set &gt; ServiceNow &gt; Relationships
- Azure &gt; Compute &gt; Availability Set &gt; ServiceNow &gt; Relationships &gt; Template
- Azure &gt; Compute &gt; Disk &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- Azure &gt; Compute &gt; Disk &gt; ServiceNow &gt; Relationships
- Azure &gt; Compute &gt; Disk &gt; ServiceNow &gt; Relationships &gt; Template
- Azure &gt; Compute &gt; Disk Encryption Set &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- Azure &gt; Compute &gt; Image &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- Azure &gt; Compute &gt; Image &gt; ServiceNow &gt; Relationships
- Azure &gt; Compute &gt; Image &gt; ServiceNow &gt; Relationships &gt; Template
- Azure &gt; Compute &gt; Snapshot &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- Azure &gt; Compute &gt; Snapshot &gt; ServiceNow &gt; Relationships
- Azure &gt; Compute &gt; Snapshot &gt; ServiceNow &gt; Relationships &gt; Template
- Azure &gt; Compute &gt; Ssh Public Key &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- Azure &gt; Compute &gt; Virtual Machine &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- Azure &gt; Compute &gt; Virtual Machine &gt; ServiceNow &gt; Relationships
- Azure &gt; Compute &gt; Virtual Machine &gt; ServiceNow &gt; Relationships &gt; Template
- Azure &gt; Compute &gt; Virtual Machine Scale Set &gt; ServiceNow &gt; Import Set &gt; Insert Mode</description>
            <pubDate>Wed, 09 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-v5-6-0</guid>
            <title>servicenow-gcp v5.6.0 - Configure CI Relationships for Global Regions, Multi-Regions, Regions and Zones in ServiceNow</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-v5-6-0</link>
            <description>_What&apos;s new?_

- You can now configure and manage CI Relationships for global regions, multi-regions, regions and zones in ServiceNow. To get started, set the `GCP &gt; Global Region &gt; ServiceNow &gt; Relationships &gt; *`, `GCP &gt; Multi-Region &gt; ServiceNow &gt; Relationships &gt; *`, `GCP &gt; Region &gt; ServiceNow &gt; Relationships &gt; *` and `GCP &gt; Zone &gt; ServiceNow &gt; Relationships &gt; *` policies respectively.

_Control Types_

- GCP &gt; Global Region &gt; ServiceNow &gt; Relationships
- GCP &gt; Multi-Region &gt; ServiceNow &gt; Relationships
- GCP &gt; Region &gt; ServiceNow &gt; Relationships
- GCP &gt; Zone &gt; ServiceNow &gt; Relationships

_Policy Types_

- GCP &gt; Global Region &gt; ServiceNow &gt; Relationships
- GCP &gt; Global Region &gt; ServiceNow &gt; Relationships &gt; Template
- GCP &gt; Multi-Region &gt; ServiceNow &gt; Relationships
- GCP &gt; Multi-Region &gt; ServiceNow &gt; Relationships &gt; Template
- GCP &gt; Region &gt; ServiceNow &gt; Relationships
- GCP &gt; Region &gt; ServiceNow &gt; Relationships &gt; Template
- GCP &gt; Zone &gt; ServiceNow &gt; Relationships
- GCP &gt; Zone &gt; ServiceNow &gt; Relationships &gt; Template</description>
            <pubDate>Tue, 08 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-storage-v5-5-0</guid>
            <title>servicenow-gcp-storage v5.5.0 - Configure CI Relationships for Buckets and Objects in ServiceNow</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-storage-v5-5-0</link>
            <description>_What&apos;s new?_

- You can now configure and manage CI Relationships for buckets and objects in ServiceNow. To get started, set the `GCP &gt; Storage &gt; Bucket &gt; ServiceNow &gt; Relationships &gt; *` and `GCP &gt; Storage &gt; Object &gt; ServiceNow &gt; Relationships &gt; *` policies respectively.

_Control Types_

- GCP &gt; Storage &gt; Bucket &gt; ServiceNow &gt; Relationships
- GCP &gt; Storage &gt; Object &gt; ServiceNow &gt; Relationships

_Policy Types_

- GCP &gt; Storage &gt; Bucket &gt; ServiceNow &gt; Relationships
- GCP &gt; Storage &gt; Bucket &gt; ServiceNow &gt; Relationships &gt; Template
- GCP &gt; Storage &gt; Object &gt; ServiceNow &gt; Relationships
- GCP &gt; Storage &gt; Object &gt; ServiceNow &gt; Relationships &gt; Template</description>
            <pubDate>Tue, 08 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-v5-5-0</guid>
            <title>servicenow-azure v5.5.0 - Configure CI Relationships for Resource Groups in ServiceNow</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-v5-5-0</link>
            <description>_What&apos;s new?_

- You can now configure and manage CI Relationships for resource groups in ServiceNow. To get started, set the `Azure &gt; Resource Group &gt; ServiceNow &gt; Relationships &gt; *` policies.

_Control Types_

- Azure &gt; Resource Group &gt; ServiceNow &gt; Relationships

_Policy Types_

- Azure &gt; Resource Group &gt; ServiceNow &gt; Relationships
- Azure &gt; Resource Group &gt; ServiceNow &gt; Relationships &gt; Template</description>
            <pubDate>Tue, 08 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-storage-v5-4-0</guid>
            <title>servicenow-azure-storage v5.4.0 - Configure CI Relationships for Containers, File Shares, Queues and Storage Accounts in ServiceNow</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-storage-v5-4-0</link>
            <description>_What&apos;s new?_

- You can now configure and manage CI Relationships for containers, file shares, queues and storage accounts in ServiceNow. To get started, set the `Azure &gt; Storage &gt; Container &gt; ServiceNow &gt; Relationships &gt; *`, `Azure &gt; Storage &gt; File Share &gt; ServiceNow &gt; Relationships &gt; *`, `Azure &gt; Storage &gt; Queue &gt; ServiceNow &gt; Relationships &gt; *` and `Azure &gt; Storage &gt; Storage Account &gt; ServiceNow &gt; Relationships &gt; *` policies respectively.

_Control Types_

- Azure &gt; Storage &gt; Container &gt; ServiceNow &gt; Relationships
- Azure &gt; Storage &gt; FileShare &gt; ServiceNow &gt; Relationships
- Azure &gt; Storage &gt; Queue &gt; ServiceNow &gt; Relationships
- Azure &gt; Storage &gt; Storage Account &gt; ServiceNow &gt; Relationships

_Policy Types_

- Azure &gt; Storage &gt; Container &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- Azure &gt; Storage &gt; Container &gt; ServiceNow &gt; Relationships
- Azure &gt; Storage &gt; Container &gt; ServiceNow &gt; Relationships &gt; Template
- Azure &gt; Storage &gt; FileShare &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- Azure &gt; Storage &gt; FileShare &gt; ServiceNow &gt; Relationships
- Azure &gt; Storage &gt; FileShare &gt; ServiceNow &gt; Relationships &gt; Template
- Azure &gt; Storage &gt; Queue &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- Azure &gt; Storage &gt; Queue &gt; ServiceNow &gt; Relationships
- Azure &gt; Storage &gt; Queue &gt; ServiceNow &gt; Relationships &gt; Template
- Azure &gt; Storage &gt; Storage Account &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- Azure &gt; Storage &gt; Storage Account &gt; ServiceNow &gt; Relationships
- Azure &gt; Storage &gt; Storage Account &gt; ServiceNow &gt; Relationships &gt; Template</description>
            <pubDate>Tue, 08 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-aws-vpc-internet-v5-1-0</guid>
            <title>servicenow-aws-vpc-internet v5.1.0 - Configure CI Relationships for Elastic IPs, Internet Gateways and NAT Gateways in ServiceNow</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-aws-vpc-internet-v5-1-0</link>
            <description>_What&apos;s new?_

- You can now configure and manage CI Relationships for elastic IPs, internet gateways and NAT gateways in ServiceNow. To get started, set the `AWS &gt; VPC &gt; Elastic IP &gt; ServiceNow &gt; Relationships &gt; *`, `AWS &gt; VPC &gt; Internet Gateway &gt; ServiceNow &gt; Relationships &gt; *` and `AWS &gt; VPC &gt; NAT Gateway &gt; ServiceNow &gt; Relationships &gt; *` policies respectively.

_Control Types_

- AWS &gt; VPC &gt; Elastic IP &gt; ServiceNow &gt; Relationships
- AWS &gt; VPC &gt; Internet Gateway &gt; ServiceNow
- AWS &gt; VPC &gt; Internet Gateway &gt; ServiceNow &gt; Configuration Item
- AWS &gt; VPC &gt; Internet Gateway &gt; ServiceNow &gt; Relationships
- AWS &gt; VPC &gt; Internet Gateway &gt; ServiceNow &gt; Table
- AWS &gt; VPC &gt; NAT Gateway &gt; ServiceNow
- AWS &gt; VPC &gt; NAT Gateway &gt; ServiceNow &gt; Configuration Item
- AWS &gt; VPC &gt; NAT Gateway &gt; ServiceNow &gt; Relationships
- AWS &gt; VPC &gt; NAT Gateway &gt; ServiceNow &gt; Table

_Policy Types_

- AWS &gt; VPC &gt; Elastic IP &gt; ServiceNow &gt; Relationships
- AWS &gt; VPC &gt; Elastic IP &gt; ServiceNow &gt; Relationships &gt; Template
- AWS &gt; VPC &gt; Internet Gateway &gt; ServiceNow
- AWS &gt; VPC &gt; Internet Gateway &gt; ServiceNow &gt; Configuration Item
- AWS &gt; VPC &gt; Internet Gateway &gt; ServiceNow &gt; Configuration Item &gt; Record
- AWS &gt; VPC &gt; Internet Gateway &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
- AWS &gt; VPC &gt; Internet Gateway &gt; ServiceNow &gt; Relationships
- AWS &gt; VPC &gt; Internet Gateway &gt; ServiceNow &gt; Relationships &gt; Template
- AWS &gt; VPC &gt; Internet Gateway &gt; ServiceNow &gt; Table
- AWS &gt; VPC &gt; Internet Gateway &gt; ServiceNow &gt; Table &gt; Definition
- AWS &gt; VPC &gt; NAT Gateway &gt; ServiceNow
- AWS &gt; VPC &gt; NAT Gateway &gt; ServiceNow &gt; Configuration Item
- AWS &gt; VPC &gt; NAT Gateway &gt; ServiceNow &gt; Configuration Item &gt; Record
- AWS &gt; VPC &gt; NAT Gateway &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
- AWS &gt; VPC &gt; NAT Gateway &gt; ServiceNow &gt; Relationships
- AWS &gt; VPC &gt; NAT Gateway &gt; ServiceNow &gt; Relationships &gt; Template
- AWS &gt; VPC &gt; NAT Gateway &gt; ServiceNow &gt; Table
- AWS &gt; VPC &gt; NAT Gateway &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Tue, 08 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-aws-vpc-connect-v5-0-0</guid>
            <title>servicenow-aws-vpc-connect v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-aws-vpc-connect-v5-0-0</link>
            <description>_Control Types_

- AWS &gt; VPC &gt; Customer Gateway &gt; ServiceNow
- AWS &gt; VPC &gt; Customer Gateway &gt; ServiceNow &gt; Configuration Item
- AWS &gt; VPC &gt; Customer Gateway &gt; ServiceNow &gt; Relationships
- AWS &gt; VPC &gt; Customer Gateway &gt; ServiceNow &gt; Table
- AWS &gt; VPC &gt; Transit Gateway &gt; ServiceNow
- AWS &gt; VPC &gt; Transit Gateway &gt; ServiceNow &gt; Configuration Item
- AWS &gt; VPC &gt; Transit Gateway &gt; ServiceNow &gt; Relationships
- AWS &gt; VPC &gt; Transit Gateway &gt; ServiceNow &gt; Table
- AWS &gt; VPC &gt; VPN Gateway &gt; ServiceNow
- AWS &gt; VPC &gt; VPN Gateway &gt; ServiceNow &gt; Configuration Item
- AWS &gt; VPC &gt; VPN Gateway &gt; ServiceNow &gt; Relationships
- AWS &gt; VPC &gt; VPN Gateway &gt; ServiceNow &gt; Table

_Policy Types_

- AWS &gt; VPC &gt; Customer Gateway &gt; ServiceNow
- AWS &gt; VPC &gt; Customer Gateway &gt; ServiceNow &gt; Configuration Item
- AWS &gt; VPC &gt; Customer Gateway &gt; ServiceNow &gt; Configuration Item &gt; Record
- AWS &gt; VPC &gt; Customer Gateway &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
- AWS &gt; VPC &gt; Customer Gateway &gt; ServiceNow &gt; Relationships
- AWS &gt; VPC &gt; Customer Gateway &gt; ServiceNow &gt; Relationships &gt; Template
- AWS &gt; VPC &gt; Customer Gateway &gt; ServiceNow &gt; Table
- AWS &gt; VPC &gt; Customer Gateway &gt; ServiceNow &gt; Table &gt; Definition
- AWS &gt; VPC &gt; Transit Gateway &gt; ServiceNow
- AWS &gt; VPC &gt; Transit Gateway &gt; ServiceNow &gt; Configuration Item
- AWS &gt; VPC &gt; Transit Gateway &gt; ServiceNow &gt; Configuration Item &gt; Record
- AWS &gt; VPC &gt; Transit Gateway &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
- AWS &gt; VPC &gt; Transit Gateway &gt; ServiceNow &gt; Relationships
- AWS &gt; VPC &gt; Transit Gateway &gt; ServiceNow &gt; Relationships &gt; Template
- AWS &gt; VPC &gt; Transit Gateway &gt; ServiceNow &gt; Table
- AWS &gt; VPC &gt; Transit Gateway &gt; ServiceNow &gt; Table &gt; Definition
- AWS &gt; VPC &gt; VPN Gateway &gt; ServiceNow
- AWS &gt; VPC &gt; VPN Gateway &gt; ServiceNow &gt; Configuration Item
- AWS &gt; VPC &gt; VPN Gateway &gt; ServiceNow &gt; Configuration Item &gt; Record
- AWS &gt; VPC &gt; VPN Gateway &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
- AWS &gt; VPC &gt; VPN Gateway &gt; ServiceNow &gt; Relationships
- AWS &gt; VPC &gt; VPN Gateway &gt; ServiceNow &gt; Relationships &gt; Template
- AWS &gt; VPC &gt; VPN Gateway &gt; ServiceNow &gt; Table
- AWS &gt; VPC &gt; VPN Gateway &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Tue, 08 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-aws-ec2-v5-1-0</guid>
            <title>servicenow-aws-ec2 v5.1.0 - Configure CI Relationships for AMIs, Instances, Key Pairs, Network Interfaces, Snapshots and Volumes in ServiceNow</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-aws-ec2-v5-1-0</link>
            <description>_What&apos;s new?_

- You can now configure and manage CI Relationships for AMIs, instances, key pairs, network interfaces, snapshots and volumes in ServiceNow. To get started, set the `AWS &gt; EC2 &gt; AMI &gt; ServiceNow &gt; Relationships &gt; *`, `AWS &gt; EC2 &gt; Instance &gt; ServiceNow &gt; Relationships &gt; *`, `AWS &gt; EC2 &gt; Key Pair &gt; ServiceNow &gt; Relationships &gt; *`, `AWS &gt; EC2 &gt; Network Interface &gt; ServiceNow &gt; Relationships &gt; *`, `AWS &gt; EC2 &gt; Snapshot &gt; ServiceNow &gt; Relationships &gt; *` and `AWS &gt; EC2 &gt; Volume &gt; ServiceNow &gt; Relationships &gt; *` policies respectively.

_Control Types_

- AWS &gt; EC2 &gt; AMI &gt; ServiceNow
- AWS &gt; EC2 &gt; AMI &gt; ServiceNow &gt; Configuration Item
- AWS &gt; EC2 &gt; AMI &gt; ServiceNow &gt; Relationships
- AWS &gt; EC2 &gt; AMI &gt; ServiceNow &gt; Table
- AWS &gt; EC2 &gt; Instance &gt; ServiceNow &gt; Relationships
- AWS &gt; EC2 &gt; Key Pair &gt; ServiceNow
- AWS &gt; EC2 &gt; Key Pair &gt; ServiceNow &gt; Configuration Item
- AWS &gt; EC2 &gt; Key Pair &gt; ServiceNow &gt; Relationships
- AWS &gt; EC2 &gt; Key Pair &gt; ServiceNow &gt; Table
- AWS &gt; EC2 &gt; Network Interface &gt; ServiceNow
- AWS &gt; EC2 &gt; Network Interface &gt; ServiceNow &gt; Configuration Item
- AWS &gt; EC2 &gt; Network Interface &gt; ServiceNow &gt; Relationships
- AWS &gt; EC2 &gt; Network Interface &gt; ServiceNow &gt; Table
- AWS &gt; EC2 &gt; Snapshot &gt; ServiceNow &gt; Relationships
- AWS &gt; EC2 &gt; Volume &gt; ServiceNow &gt; Relationships

_Policy Types_

- AWS &gt; EC2 &gt; AMI &gt; ServiceNow
- AWS &gt; EC2 &gt; AMI &gt; ServiceNow &gt; Configuration Item
- AWS &gt; EC2 &gt; AMI &gt; ServiceNow &gt; Configuration Item &gt; Record
- AWS &gt; EC2 &gt; AMI &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
- AWS &gt; EC2 &gt; AMI &gt; ServiceNow &gt; Relationships
- AWS &gt; EC2 &gt; AMI &gt; ServiceNow &gt; Relationships &gt; Template
- AWS &gt; EC2 &gt; AMI &gt; ServiceNow &gt; Table
- AWS &gt; EC2 &gt; AMI &gt; ServiceNow &gt; Table &gt; Definition
- AWS &gt; EC2 &gt; Instance &gt; ServiceNow &gt; Relationships
- AWS &gt; EC2 &gt; Instance &gt; ServiceNow &gt; Relationships &gt; Template
- AWS &gt; EC2 &gt; Key Pair &gt; ServiceNow
- AWS &gt; EC2 &gt; Key Pair &gt; ServiceNow &gt; Configuration Item
- AWS &gt; EC2 &gt; Key Pair &gt; ServiceNow &gt; Configuration Item &gt; Record
- AWS &gt; EC2 &gt; Key Pair &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
- AWS &gt; EC2 &gt; Key Pair &gt; ServiceNow &gt; Relationships
- AWS &gt; EC2 &gt; Key Pair &gt; ServiceNow &gt; Relationships &gt; Template
- AWS &gt; EC2 &gt; Key Pair &gt; ServiceNow &gt; Table
- AWS &gt; EC2 &gt; Key Pair &gt; ServiceNow &gt; Table &gt; Definition
- AWS &gt; EC2 &gt; Network Interface &gt; ServiceNow
- AWS &gt; EC2 &gt; Network Interface &gt; ServiceNow &gt; Configuration Item
- AWS &gt; EC2 &gt; Network Interface &gt; ServiceNow &gt; Configuration Item &gt; Record
- AWS &gt; EC2 &gt; Network Interface &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
- AWS &gt; EC2 &gt; Network Interface &gt; ServiceNow &gt; Relationships
- AWS &gt; EC2 &gt; Network Interface &gt; ServiceNow &gt; Relationships &gt; Template
- AWS &gt; EC2 &gt; Network Interface &gt; ServiceNow &gt; Table
- AWS &gt; EC2 &gt; Network Interface &gt; ServiceNow &gt; Table &gt; Definition
- AWS &gt; EC2 &gt; Snapshot &gt; ServiceNow &gt; Relationships
- AWS &gt; EC2 &gt; Snapshot &gt; ServiceNow &gt; Relationships &gt; Template
- AWS &gt; EC2 &gt; Volume &gt; ServiceNow &gt; Relationships
- AWS &gt; EC2 &gt; Volume &gt; ServiceNow &gt; Relationships &gt; Template</description>
            <pubDate>Tue, 08 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-vertexai-v5-0-0</guid>
            <title>servicenow-gcp-vertexai v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-vertexai-v5-0-0</link>
            <description>_What&apos;s new?_

_Control Types_

- GCP &gt; Vertex AI &gt; Endpoint &gt; ServiceNow
- GCP &gt; Vertex AI &gt; Endpoint &gt; ServiceNow &gt; Configuration Item
- GCP &gt; Vertex AI &gt; Endpoint &gt; ServiceNow &gt; Import Set
- GCP &gt; Vertex AI &gt; Endpoint &gt; ServiceNow &gt; Table
- GCP &gt; Vertex AI &gt; Notebook Runtime Template &gt; ServiceNow
- GCP &gt; Vertex AI &gt; Notebook Runtime Template &gt; ServiceNow &gt; Configuration Item
- GCP &gt; Vertex AI &gt; Notebook Runtime Template &gt; ServiceNow &gt; Import Set
- GCP &gt; Vertex AI &gt; Notebook Runtime Template &gt; ServiceNow &gt; Table

_Policy Types_

- GCP &gt; Vertex AI &gt; Endpoint &gt; ServiceNow
- GCP &gt; Vertex AI &gt; Endpoint &gt; ServiceNow &gt; Configuration Item
- GCP &gt; Vertex AI &gt; Endpoint &gt; ServiceNow &gt; Configuration Item &gt; Record
- GCP &gt; Vertex AI &gt; Endpoint &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
- GCP &gt; Vertex AI &gt; Endpoint &gt; ServiceNow &gt; Import Set
- GCP &gt; Vertex AI &gt; Endpoint &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- GCP &gt; Vertex AI &gt; Endpoint &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- GCP &gt; Vertex AI &gt; Endpoint &gt; ServiceNow &gt; Import Set &gt; Record
- GCP &gt; Vertex AI &gt; Endpoint &gt; ServiceNow &gt; Import Set &gt; Table Name
- GCP &gt; Vertex AI &gt; Endpoint &gt; ServiceNow &gt; Table
- GCP &gt; Vertex AI &gt; Endpoint &gt; ServiceNow &gt; Table &gt; Definition
- GCP &gt; Vertex AI &gt; Notebook Runtime Template &gt; ServiceNow
- GCP &gt; Vertex AI &gt; Notebook Runtime Template &gt; ServiceNow &gt; Configuration Item
- GCP &gt; Vertex AI &gt; Notebook Runtime Template &gt; ServiceNow &gt; Configuration Item &gt; Record
- GCP &gt; Vertex AI &gt; Notebook Runtime Template &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
- GCP &gt; Vertex AI &gt; Notebook Runtime Template &gt; ServiceNow &gt; Import Set
- GCP &gt; Vertex AI &gt; Notebook Runtime Template &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- GCP &gt; Vertex AI &gt; Notebook Runtime Template &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- GCP &gt; Vertex AI &gt; Notebook Runtime Template &gt; ServiceNow &gt; Import Set &gt; Record
- GCP &gt; Vertex AI &gt; Notebook Runtime Template &gt; ServiceNow &gt; Import Set &gt; Table Name
- GCP &gt; Vertex AI &gt; Notebook Runtime Template &gt; ServiceNow &gt; Table
- GCP &gt; Vertex AI &gt; Notebook Runtime Template &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Mon, 07 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-dataplex-v5-0-0</guid>
            <title>servicenow-gcp-dataplex v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-dataplex-v5-0-0</link>
            <description>_What&apos;s new?_

_Control Types_

- GCP &gt; Dataplex &gt; Lake &gt; ServiceNow
- GCP &gt; Dataplex &gt; Lake &gt; ServiceNow &gt; Configuration Item
- GCP &gt; Dataplex &gt; Lake &gt; ServiceNow &gt; Import Set
- GCP &gt; Dataplex &gt; Lake &gt; ServiceNow &gt; Table
- GCP &gt; Dataplex &gt; Task &gt; ServiceNow
- GCP &gt; Dataplex &gt; Task &gt; ServiceNow &gt; Configuration Item
- GCP &gt; Dataplex &gt; Task &gt; ServiceNow &gt; Import Set
- GCP &gt; Dataplex &gt; Task &gt; ServiceNow &gt; Table
- GCP &gt; Dataplex &gt; Zone &gt; ServiceNow
- GCP &gt; Dataplex &gt; Zone &gt; ServiceNow &gt; Configuration Item
- GCP &gt; Dataplex &gt; Zone &gt; ServiceNow &gt; Import Set
- GCP &gt; Dataplex &gt; Zone &gt; ServiceNow &gt; Table

_Policy Types_

- GCP &gt; Dataplex &gt; Lake &gt; ServiceNow
- GCP &gt; Dataplex &gt; Lake &gt; ServiceNow &gt; Configuration Item
- GCP &gt; Dataplex &gt; Lake &gt; ServiceNow &gt; Configuration Item &gt; Record
- GCP &gt; Dataplex &gt; Lake &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
- GCP &gt; Dataplex &gt; Lake &gt; ServiceNow &gt; Import Set
- GCP &gt; Dataplex &gt; Lake &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- GCP &gt; Dataplex &gt; Lake &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- GCP &gt; Dataplex &gt; Lake &gt; ServiceNow &gt; Import Set &gt; Record
- GCP &gt; Dataplex &gt; Lake &gt; ServiceNow &gt; Import Set &gt; Table Name
- GCP &gt; Dataplex &gt; Lake &gt; ServiceNow &gt; Table
- GCP &gt; Dataplex &gt; Lake &gt; ServiceNow &gt; Table &gt; Definition
- GCP &gt; Dataplex &gt; Task &gt; ServiceNow
- GCP &gt; Dataplex &gt; Task &gt; ServiceNow &gt; Configuration Item
- GCP &gt; Dataplex &gt; Task &gt; ServiceNow &gt; Configuration Item &gt; Record
- GCP &gt; Dataplex &gt; Task &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
- GCP &gt; Dataplex &gt; Task &gt; ServiceNow &gt; Import Set
- GCP &gt; Dataplex &gt; Task &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- GCP &gt; Dataplex &gt; Task &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- GCP &gt; Dataplex &gt; Task &gt; ServiceNow &gt; Import Set &gt; Record
- GCP &gt; Dataplex &gt; Task &gt; ServiceNow &gt; Import Set &gt; Table Name
- GCP &gt; Dataplex &gt; Task &gt; ServiceNow &gt; Table
- GCP &gt; Dataplex &gt; Task &gt; ServiceNow &gt; Table &gt; Definition
- GCP &gt; Dataplex &gt; Zone &gt; ServiceNow
- GCP &gt; Dataplex &gt; Zone &gt; ServiceNow &gt; Configuration Item
- GCP &gt; Dataplex &gt; Zone &gt; ServiceNow &gt; Configuration Item &gt; Record
- GCP &gt; Dataplex &gt; Zone &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
- GCP &gt; Dataplex &gt; Zone &gt; ServiceNow &gt; Import Set
- GCP &gt; Dataplex &gt; Zone &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- GCP &gt; Dataplex &gt; Zone &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- GCP &gt; Dataplex &gt; Zone &gt; ServiceNow &gt; Import Set &gt; Record
- GCP &gt; Dataplex &gt; Zone &gt; ServiceNow &gt; Import Set &gt; Table Name
- GCP &gt; Dataplex &gt; Zone &gt; ServiceNow &gt; Table
- GCP &gt; Dataplex &gt; Zone &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Mon, 07 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-aws-vpc-security-v5-1-0</guid>
            <title>servicenow-aws-vpc-security v5.1.0 - Configure CI Relationships for Flow Logs, Network ACLs, Security Groups and Security Group Rules in ServiceNow</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-aws-vpc-security-v5-1-0</link>
            <description>_What&apos;s new?_

- You can now configure and manage CI Relationships for flow logs, network ACLs, security groups and security group rules in ServiceNow. To get started, set the `AWS &gt; VPC &gt; Flow Log &gt; ServiceNow &gt; Relationships &gt; *`, `AWS &gt; VPC &gt; Network ACL &gt; ServiceNow &gt; Relationships &gt; *`, `AWS &gt; VPC &gt; Security Group &gt; ServiceNow &gt; Relationships &gt; *` and `AWS &gt; VPC &gt; Security Group Rule &gt; ServiceNow &gt; Relationships &gt; *` policies respectively.

_Control Types_

- AWS &gt; VPC &gt; Flow Log &gt; ServiceNow
- AWS &gt; VPC &gt; Flow Log &gt; ServiceNow &gt; Configuration Item
- AWS &gt; VPC &gt; Flow Log &gt; ServiceNow &gt; Relationships
- AWS &gt; VPC &gt; Flow Log &gt; ServiceNow &gt; Table
- AWS &gt; VPC &gt; Network ACL &gt; ServiceNow &gt; Relationships
- AWS &gt; VPC &gt; Security Group &gt; ServiceNow &gt; Relationships
- AWS &gt; VPC &gt; Security Group Rule &gt; ServiceNow
- AWS &gt; VPC &gt; Security Group Rule &gt; ServiceNow &gt; Configuration Item
- AWS &gt; VPC &gt; Security Group Rule &gt; ServiceNow &gt; Relationships
- AWS &gt; VPC &gt; Security Group Rule &gt; ServiceNow &gt; Table

_Policy Types_

- AWS &gt; VPC &gt; Flow Log &gt; ServiceNow
- AWS &gt; VPC &gt; Flow Log &gt; ServiceNow &gt; Configuration Item
- AWS &gt; VPC &gt; Flow Log &gt; ServiceNow &gt; Configuration Item &gt; Record
- AWS &gt; VPC &gt; Flow Log &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
- AWS &gt; VPC &gt; Flow Log &gt; ServiceNow &gt; Relationships
- AWS &gt; VPC &gt; Flow Log &gt; ServiceNow &gt; Relationships &gt; Template
- AWS &gt; VPC &gt; Flow Log &gt; ServiceNow &gt; Table
- AWS &gt; VPC &gt; Flow Log &gt; ServiceNow &gt; Table &gt; Definition
- AWS &gt; VPC &gt; Network ACL &gt; ServiceNow &gt; Relationships
- AWS &gt; VPC &gt; Network ACL &gt; ServiceNow &gt; Relationships &gt; Template
- AWS &gt; VPC &gt; Security Group &gt; ServiceNow &gt; Relationships
- AWS &gt; VPC &gt; Security Group &gt; ServiceNow &gt; Relationships &gt; Template
- AWS &gt; VPC &gt; Security Group Rule &gt; ServiceNow
- AWS &gt; VPC &gt; Security Group Rule &gt; ServiceNow &gt; Configuration Item
- AWS &gt; VPC &gt; Security Group Rule &gt; ServiceNow &gt; Configuration Item &gt; Record
- AWS &gt; VPC &gt; Security Group Rule &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
- AWS &gt; VPC &gt; Security Group Rule &gt; ServiceNow &gt; Relationships
- AWS &gt; VPC &gt; Security Group Rule &gt; ServiceNow &gt; Relationships &gt; Template
- AWS &gt; VPC &gt; Security Group Rule &gt; ServiceNow &gt; Table
- AWS &gt; VPC &gt; Security Group Rule &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Mon, 07 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-aws-vpc-core-v5-1-0</guid>
            <title>servicenow-aws-vpc-core v5.1.0 - Configure CI Relationships for Route Tables, Subnets and VPCs in ServiceNow</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-aws-vpc-core-v5-1-0</link>
            <description>_What&apos;s new?_

- You can now configure and manage CI Relationships for route tables, subnets and VPCs in ServiceNow. To get started, set the `AWS &gt; VPC &gt; Route Table &gt; ServiceNow &gt; Relationships &gt; *`, `AWS &gt; VPC &gt; Subnet &gt; ServiceNow &gt; Relationships &gt; *` and `AWS &gt; VPC &gt; VPC &gt; ServiceNow &gt; Relationships &gt; *` policies respectively.

_Control Types_

- AWS &gt; VPC &gt; Route Table &gt; ServiceNow &gt; Relationships
- AWS &gt; VPC &gt; Subnet &gt; ServiceNow &gt; Relationships
- AWS &gt; VPC &gt; VPC &gt; ServiceNow &gt; Relationships

_Policy Types_

- AWS &gt; VPC &gt; Route Table &gt; ServiceNow &gt; Relationships
- AWS &gt; VPC &gt; Route Table &gt; ServiceNow &gt; Relationships &gt; Template
- AWS &gt; VPC &gt; Subnet &gt; ServiceNow &gt; Relationships
- AWS &gt; VPC &gt; Subnet &gt; ServiceNow &gt; Relationships &gt; Template
- AWS &gt; VPC &gt; VPC &gt; ServiceNow &gt; Relationships
- AWS &gt; VPC &gt; VPC &gt; ServiceNow &gt; Relationships &gt; Template</description>
            <pubDate>Mon, 07 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-aws-v5-2-0</guid>
            <title>servicenow-aws v5.2.0 - Configure Table, Configuration Item and Relationships for Accounts and Regions in ServiceNow</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-aws-v5-2-0</link>
            <description>_What&apos;s new?_

_Control Types_

- AWS &gt; Account &gt; ServiceNow
- AWS &gt; Account &gt; ServiceNow &gt; Configuration Item
- AWS &gt; Account &gt; ServiceNow &gt; Table
- AWS &gt; Region &gt; ServiceNow
- AWS &gt; Region &gt; ServiceNow &gt; Configuration Item
- AWS &gt; Region &gt; ServiceNow &gt; Relationships
- AWS &gt; Region &gt; ServiceNow &gt; Table

_Policy Types_

- AWS &gt; Account &gt; ServiceNow
- AWS &gt; Account &gt; ServiceNow &gt; Configuration Item
- AWS &gt; Account &gt; ServiceNow &gt; Configuration Item &gt; Record
- AWS &gt; Account &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
- AWS &gt; Account &gt; ServiceNow &gt; Table
- AWS &gt; Account &gt; ServiceNow &gt; Table &gt; Definition
- AWS &gt; Region &gt; ServiceNow
- AWS &gt; Region &gt; ServiceNow &gt; Configuration Item
- AWS &gt; Region &gt; ServiceNow &gt; Configuration Item &gt; Record
- AWS &gt; Region &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
- AWS &gt; Region &gt; ServiceNow &gt; Relationships
- AWS &gt; Region &gt; ServiceNow &gt; Relationships &gt; Template
- AWS &gt; Region &gt; ServiceNow &gt; Table
- AWS &gt; Region &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Mon, 07 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-aws-s3-v5-2-0</guid>
            <title>servicenow-aws-s3 v5.2.0 - Configure CI Relationships for Buckets in ServiceNow</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-aws-s3-v5-2-0</link>
            <description>_What&apos;s new?_

- You can now configure and manage CI Relationships for buckets in ServiceNow. To get started, set the `AWS &gt; S3 &gt; Bucket &gt; ServiceNow &gt; Relationships &gt; *` policies.

_Control Types_

- AWS &gt; S3 &gt; Bucket &gt; ServiceNow &gt; Relationships

_Policy Types_

- AWS &gt; S3 &gt; Bucket &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- AWS &gt; S3 &gt; Bucket &gt; ServiceNow &gt; Relationships
- AWS &gt; S3 &gt; Bucket &gt; ServiceNow &gt; Relationships &gt; Template</description>
            <pubDate>Mon, 07 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-billing-v5-4-0</guid>
            <title>aws-billing v5.4.0 - `AWS/Billing/Admin`, `AWS/Billing/Metadata` and `AWS/Billing/Operator` now also include purchase orders permissions</title>
            <link>https://turbot.com/guardrails/changelog/aws-billing-v5-4-0</link>
            <description>_What&apos;s new?_

- `AWS/Billing/Admin`, `AWS/Billing/Metadata` and `AWS/Billing/Operator` now also include purchase orders permissions.</description>
            <pubDate>Mon, 07 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-47-1</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.47.1 - Removed recursive loop detection logic, as this is now managed effectively by Lambda.</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-47-1</link>
            <description>_Bug fixes_

- Server
  - Removed recursive loop detection logic, as this is now managed effectively by Lambda.

_Requirements_

- TEF: 1.59.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Fri, 04 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-63-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.63.0 - Support for AWS Graviton instance with ARM64 architecture</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-63-0</link>
            <description>_What&apos;s new?_

  - Support for AWS Graviton instance with ARM64 architecture.</description>
            <pubDate>Tue, 01 Oct 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-v5-27-0</guid>
            <title>gcp v5.27.0 - Added support to process real-time enable and disable events for Dataplex API</title>
            <link>https://turbot.com/guardrails/changelog/gcp-v5-27-0</link>
            <description>_What&apos;s new?_

- Added support to process enable and disable real-time events for Dataplex.</description>
            <pubDate>Mon, 30 Sep 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-dataplex-v5-0-0</guid>
            <title>gcp-dataplex v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/gcp-dataplex-v5-0-0</link>
            <description>_Resource Types_

- GCP &gt; Dataplex
- GCP &gt; Dataplex &gt; Lake
- GCP &gt; Dataplex &gt; Task
- GCP &gt; Dataplex &gt; Zone

_Control Types_

- GCP &gt; Dataplex &gt; API Enabled
- GCP &gt; Dataplex &gt; CMDB
- GCP &gt; Dataplex &gt; Discovery
- GCP &gt; Dataplex &gt; Lake &gt; Active
- GCP &gt; Dataplex &gt; Lake &gt; Approved
- GCP &gt; Dataplex &gt; Lake &gt; CMDB
- GCP &gt; Dataplex &gt; Lake &gt; Discovery
- GCP &gt; Dataplex &gt; Lake &gt; Labels
- GCP &gt; Dataplex &gt; Lake &gt; Usage
- GCP &gt; Dataplex &gt; Task &gt; Active
- GCP &gt; Dataplex &gt; Task &gt; Approved
- GCP &gt; Dataplex &gt; Task &gt; CMDB
- GCP &gt; Dataplex &gt; Task &gt; Discovery
- GCP &gt; Dataplex &gt; Task &gt; Labels
- GCP &gt; Dataplex &gt; Task &gt; Usage
- GCP &gt; Dataplex &gt; Zone &gt; Active
- GCP &gt; Dataplex &gt; Zone &gt; Approved
- GCP &gt; Dataplex &gt; Zone &gt; CMDB
- GCP &gt; Dataplex &gt; Zone &gt; Discovery
- GCP &gt; Dataplex &gt; Zone &gt; Labels
- GCP &gt; Dataplex &gt; Zone &gt; Usage

_Policy Types_

- GCP &gt; Dataplex &gt; API Enabled
- GCP &gt; Dataplex &gt; Approved Regions [Default]
- GCP &gt; Dataplex &gt; CMDB
- GCP &gt; Dataplex &gt; Enabled
- GCP &gt; Dataplex &gt; Labels Template [Default]
- GCP &gt; Dataplex &gt; Lake &gt; Active
- GCP &gt; Dataplex &gt; Lake &gt; Active &gt; Age
- GCP &gt; Dataplex &gt; Lake &gt; Active &gt; Last Modified
- GCP &gt; Dataplex &gt; Lake &gt; Approved
- GCP &gt; Dataplex &gt; Lake &gt; Approved &gt; Custom
- GCP &gt; Dataplex &gt; Lake &gt; Approved &gt; Regions
- GCP &gt; Dataplex &gt; Lake &gt; Approved &gt; Usage
- GCP &gt; Dataplex &gt; Lake &gt; CMDB
- GCP &gt; Dataplex &gt; Lake &gt; Labels
- GCP &gt; Dataplex &gt; Lake &gt; Labels &gt; Template
- GCP &gt; Dataplex &gt; Lake &gt; Regions
- GCP &gt; Dataplex &gt; Lake &gt; Usage
- GCP &gt; Dataplex &gt; Lake &gt; Usage &gt; Limit
- GCP &gt; Dataplex &gt; Permissions
- GCP &gt; Dataplex &gt; Permissions &gt; Levels
- GCP &gt; Dataplex &gt; Permissions &gt; Levels &gt; Modifiers
- GCP &gt; Dataplex &gt; Regions
- GCP &gt; Dataplex &gt; Task &gt; Active
- GCP &gt; Dataplex &gt; Task &gt; Active &gt; Age
- GCP &gt; Dataplex &gt; Task &gt; Active &gt; Last Modified
- GCP &gt; Dataplex &gt; Task &gt; Approved
- GCP &gt; Dataplex &gt; Task &gt; Approved &gt; Custom
- GCP &gt; Dataplex &gt; Task &gt; Approved &gt; Regions
- GCP &gt; Dataplex &gt; Task &gt; Approved &gt; Usage
- GCP &gt; Dataplex &gt; Task &gt; CMDB
- GCP &gt; Dataplex &gt; Task &gt; Labels
- GCP &gt; Dataplex &gt; Task &gt; Labels &gt; Template
- GCP &gt; Dataplex &gt; Task &gt; Regions
- GCP &gt; Dataplex &gt; Task &gt; Usage
- GCP &gt; Dataplex &gt; Task &gt; Usage &gt; Limit
- GCP &gt; Dataplex &gt; Zone &gt; Active
- GCP &gt; Dataplex &gt; Zone &gt; Active &gt; Age
- GCP &gt; Dataplex &gt; Zone &gt; Active &gt; Last Modified
- GCP &gt; Dataplex &gt; Zone &gt; Approved
- GCP &gt; Dataplex &gt; Zone &gt; Approved &gt; Custom
- GCP &gt; Dataplex &gt; Zone &gt; Approved &gt; Regions
- GCP &gt; Dataplex &gt; Zone &gt; Approved &gt; Usage
- GCP &gt; Dataplex &gt; Zone &gt; CMDB
- GCP &gt; Dataplex &gt; Zone &gt; Labels
- GCP &gt; Dataplex &gt; Zone &gt; Labels &gt; Template
- GCP &gt; Dataplex &gt; Zone &gt; Regions
- GCP &gt; Dataplex &gt; Zone &gt; Usage
- GCP &gt; Dataplex &gt; Zone &gt; Usage &gt; Limit
- GCP &gt; Turbot &gt; Event Handlers &gt; Logging &gt; Sink &gt; Compiled Filter &gt; @turbot/gcp-dataplex
- GCP &gt; Turbot &gt; Permissions &gt; Compiled &gt; Levels &gt; @turbot/gcp-dataplex
- GCP &gt; Turbot &gt; Permissions &gt; Compiled &gt; Service Permissions &gt; @turbot/gcp-dataplex

_Action Types_

- GCP &gt; Dataplex &gt; Lake &gt; Delete
- GCP &gt; Dataplex &gt; Lake &gt; Router
- GCP &gt; Dataplex &gt; Lake &gt; Set Labels
- GCP &gt; Dataplex &gt; Set API Enabled
- GCP &gt; Dataplex &gt; Task &gt; Delete
- GCP &gt; Dataplex &gt; Task &gt; Router
- GCP &gt; Dataplex &gt; Task &gt; Set Labels
- GCP &gt; Dataplex &gt; Zone &gt; Delete
- GCP &gt; Dataplex &gt; Zone &gt; Router
- GCP &gt; Dataplex &gt; Zone &gt; Set Labels</description>
            <pubDate>Mon, 30 Sep 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-compute-v5-18-0</guid>
            <title>azure-compute v5.18.0 - Controls and Actions now use latest Azure SDK versions to discover and manage Compute resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-compute-v5-18-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated internal dependencies and now use the latest Azure SDK versions to discover and manage compute resources in Guardrails. This release includes breaking changes in the CMDB data for virtual machine. We recommend updating your existing policy settings to refer to the updated attributes as mentioned below

**Added:**

In Azure &gt; Compute &gt; Disk:

- `supportedCapabilities.diskControllerTypes`
- `diskIopsReadWrite`
- `lastOwnershipUpdateTime`

In Azure &gt; Compute &gt; Virtual Machine:

- `resources`
- `timeCreated`
- `etag`

In Azure &gt; Compute &gt; Virtual Machine Scale Set:

- `constrainedMaximumCapacity`
- `etag`
- `scaleInPolicy`
- `timeCreated`
- `upgradePolicy`
- `storageProfile. diskControllerType`

In Azure &gt; Compute &gt; Snapshot:

- `dataAccessAuthMode`
- `incrementalSnapshotFamilyId`

**Removed:**

In Azure &gt; Compute &gt; Virtual Machine:

- `statuses.time`

_Bug fixes_

- Improved descriptions for various resource types to ensure they are clearer and more helpful.</description>
            <pubDate>Mon, 30 Sep 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-appservice-v5-4-0</guid>
            <title>azure-appservice v5.4.0 - Controls and Actions now use latest Azure SDK versions to discover and manage App Service resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-appservice-v5-4-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated internal dependencies and now use the latest Azure SDK versions to discover and manage App Service resources in Guardrails.

**Added:**

Azure &gt; App Service &gt; App Service Plan

- `elasticScaleEnabled`
- `numberOfWorkers`
- `zoneRedundant`

Azure &gt; App Service &gt; Function App

- `configuration.acrUseManagedIdentityCreds`
- `configuration.acrUserManagedIdentityID`
- `configuration.elasticWebAppScaleLimit`
- `configuration.ipSecurityRestrictionsDefaultAction`
- `configuration.metadata`
- `configuration.minTlsCipherSuite`
- `configuration.scmIpSecurityRestrictionsDefaultAction`
- `dnsConfiguration`
- `publicNetworkAccess`
- `vnetBackupRestoreEnabled`
- `vnetContentShareEnabled`
- `vnetImagePullEnabled`
- `vnetRouteAllEnabled`

Azure &gt; App Service &gt; Web App

- `configuration.acrUseManagedIdentityCreds`
- `configuration.acrUserManagedIdentityID`
- `configuration.elasticWebAppScaleLimit`
- `configuration.ipSecurityRestrictionsDefaultAction`
- `configuration.metadata`
- `configuration.minTlsCipherSuite`
- `configuration.scmIpSecurityRestrictionsDefaultAction`
- `dnsConfiguration`
- `publicNetworkAccess`
- `vnetBackupRestoreEnabled`
- `vnetContentShareEnabled`
- `vnetImagePullEnabled`
- `vnetRouteAllEnabled`

_Bug fixes_

- Improved descriptions for various resource types to ensure they are clearer and more helpful.</description>
            <pubDate>Mon, 30 Sep 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-apimanagement-v5-4-0</guid>
            <title>azure-apimanagement v5.4.0 - Controls and Actions now use latest Azure SDK versions to discover and manage API Management resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-apimanagement-v5-4-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated internal dependencies and now use the latest Azure SDK versions to discover and manage API Management resources in Guardrails.</description>
            <pubDate>Mon, 30 Sep 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-securitycenter-v5-5-0</guid>
            <title>azure-securitycenter v5.5.0 - Controls and Actions now use latest Azure SDK versions to discover and manage Security Center resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-securitycenter-v5-5-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated internal dependencies and now use the latest Azure SDK versions to discover and manage Security Center resources in Guardrails. This release includes breaking changes in the CMDB data for security center. We recommend updating your existing policy settings to refer to the updated attributes as mentioned below

**Renamed:**

- `JitNetworkAccessPolicies` to `jitNetworkAccessPolicies`
- `Pricing` to `pricing`
- `Locations` to `locations`

_Bug fixes_

- Improved descriptions for various resource types to ensure they are clearer and more helpful.</description>
            <pubDate>Fri, 27 Sep 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-mysql-v5-11-0</guid>
            <title>azure-mysql v5.11.0 - Controls and Actions now use latest Azure SDK versions to discover and manage MySql resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-mysql-v5-11-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated internal dependencies and now use the latest Azure SDK versions to discover and manage MySQL resources in Guardrails.

_Bug fixes_

- Improved descriptions for various resource types to ensure they are clearer and more helpful.</description>
            <pubDate>Fri, 27 Sep 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-frontdoorservice-v5-8-0</guid>
            <title>azure-frontdoorservice v5.8.0 - Controls and Actions now use latest Azure SDK versions to discover and manage Front Door Service resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-frontdoorservice-v5-8-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated internal dependencies and now use the latest Azure SDK versions to discover and manage Front Door Service resources in Guardrails. This release includes breaking changes in the CMDB data for Front Door Service. We recommend updating your existing policy settings to refer to the updated attributes as mentioned below.

Added:

- `frontdoorId`
- `rulesEngines`
- `extendedProperties`
- `backendPoolsSettings`
- `backendPool.privateLinkAlias`
- `backendPool.privateLinkLocation`
- `backendPool.privateEndpointStatus`
- `backendPool.privateLinkResourceId`
- `backendPool.privateLinkApprovalMessage`
- `routingRule.rulesEngine`
- `routingRule.routeConfiguration.odataType`
- `routingRule.routeConfiguration.cacheConfiguration.cacheDuration`
- `routingRule.routeConfiguration.cacheConfiguration.queryParameters `
- `routingRule.webApplicationFirewallPolicyLink`

Modified:

- `routingRule.backendPool` to `routingRule.routeConfiguration.backendPool`
- `routingRule.forwardingProtocol ` to `routingRule.routeConfiguration.forwardingProtocol`
- `routingRule.customForwardingPath ` to `routingRule.routeConfiguration.customForwardingPath`
- `routingRule.cacheConfiguration.dynamicCompression ` to `routingRule.routeConfiguration.cacheConfiguration. dynamicCompression`
- `routingRule.cacheConfiguration.queryParameterStripDirective ` to `routingRule.routeConfiguration.cacheConfiguration. queryParameterStripDirective`

_Bug fixes_

- Improved descriptions for various resource types to ensure they are clearer and more helpful.</description>
            <pubDate>Fri, 27 Sep 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-datafactory-v5-7-0</guid>
            <title>azure-datafactory v5.7.0 - Controls and Actions now use latest Azure SDK versions to discover and manage Data Factory resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-datafactory-v5-7-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated internal dependencies and now use the latest Azure SDK versions to discover and manage Data Factory resources in Guardrails.

_Bug fixes_

- Improved descriptions for various resource types to ensure they are clearer and more helpful.</description>
            <pubDate>Fri, 27 Sep 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-aks-v5-7-0</guid>
            <title>azure-aks v5.7.0 - Controls and Actions now use latest Azure SDK versions to discover and manage AKS resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-aks-v5-7-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated internal dependencies and now use the latest Azure SDK versions to discover and manage AKS resources in Guardrails.

Added:

- `networkProfile.podCidrs`
- `networkProfile.ipFamilies`
- `networkProfile.outboundType`
- `networkProfile.serviceCidrs`
- `networkProfile.networkPolicy`
- `networkProfile.loadBalancerProfile.backendPoolType`
- `networkProfile.loadBalancerProfile.countIPv6`
- `networkProfile.loadBalancerProfile.idleTimeoutInMinutes`
- `networkProfile.loadBalancerProfile.allocatedOutboundPorts`
- `agentPoolProfiles.mode`
- `agentPoolProfiles.osSKU`
- `agentPoolProfiles.enableFips`
- `agentPoolProfiles.osDiskType`
- `agentPoolProfiles.spotMaxPrice`
- `agentPoolProfiles.scaleDownMode`
- `agentPoolProfiles.enableUltraSSD`
- `agentPoolProfiles.kubeletDiskType`
- `agentPoolProfiles.upgradeSettings.maxSurge`
- `agentPoolProfiles.nodeImageVersion`
- `agentPoolProfiles.enableEncryptionAtHost`
- `agentPoolProfiles.currentOrchestratorVersion`

_Bug fixes_

- Improved descriptions for various resource types to ensure they are clearer and more helpful.</description>
            <pubDate>Fri, 27 Sep 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-signalr-v5-2-0</guid>
            <title>azure-signalr v5.2.0 - Controls and Actions now use latest Azure SDK versions to discover and manage SignalR resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-signalr-v5-2-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated internal dependencies and now use the latest Azure SDK versions to discover and manage SignalR resources in Guardrails.

Added:

- `hostNamePrefix`
- `serverless. connectionTimeoutInSeconds`

_Bug fixes_

- Improved descriptions for various resource types to ensure they are clearer and more helpful.</description>
            <pubDate>Thu, 26 Sep 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-servicebus-v5-2-0</guid>
            <title>azure-servicebus v5.2.0 - Controls and Actions now use latest Azure SDK versions to discover and manage Service Bus resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-servicebus-v5-2-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated internal dependencies and now use the latest Azure SDK versions to discover and manage Service Bus resources in Guardrails.

Added:

Azure &gt; Service Bus &gt; Namespace

- `disableLocalAuth`
- `status`
- `zoneRedundant`

Azure &gt; Service Bus &gt; Queue

- `maxMessageSizeInKilobytes`

Azure &gt; Service Bus &gt; Topic

- `maxMessageSizeInKilobytes`

_Bug fixes_

- Improved descriptions for various resource types to ensure they are clearer and more helpful.</description>
            <pubDate>Thu, 26 Sep 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-relay-v5-2-0</guid>
            <title>azure-relay v5.2.0 - Controls and Actions now use latest Azure SDK versions to discover and manage Relay resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-relay-v5-2-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated internal dependencies and now use the latest Azure SDK versions to discover and manage Relay resources in Guardrails.

_Bug fixes_

- Improved descriptions for various resource types to ensure they are clearer and more helpful.</description>
            <pubDate>Thu, 26 Sep 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-recoveryservice-v5-6-0</guid>
            <title>azure-recoveryservice v5.6.0 - Controls and Actions now use latest Azure SDK versions to discover and manage Recovery Service resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-recoveryservice-v5-6-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated internal dependencies and now use the latest Azure SDK versions to discover and manage Recovery Service resources in Guardrails.

Added:
Azure &gt; Recovery Service &gt; Vault

- `properties.backupStorageVersion`
- `properties.bcdrSecurityLevel`
- `properties.publicNetworkAccess`
- `properties.restoreSettings`
- `properties.secureScore`
- `properties.securitySettings`

_Bug fixes_

- Improved descriptions for various resource types to ensure they are clearer and more helpful.</description>
            <pubDate>Thu, 26 Sep 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-robomaker-v5-4-1</guid>
            <title>aws-robomaker v5.4.1 - CMDB policies for various resource types will now default to Skip</title>
            <link>https://turbot.com/guardrails/changelog/aws-robomaker-v5-4-1</link>
            <description>_Bug fixes_

- The `AWS &gt; RoboMaker &gt; Robot Application &gt; CMDB`, `AWS &gt; RoboMaker &gt; Fleet &gt; CMDB` and `AWS &gt; RoboMaker &gt; Robot &gt; CMDB` policies will now be set to `Skip` by default because the resource types have been deprecated and will be removed in the next major version. Please check [end of support](https://docs.aws.amazon.com/robomaker/latest/dg/chapter-support-policy.html) for more information.</description>
            <pubDate>Thu, 26 Sep 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ecs-v5-7-0</guid>
            <title>aws-ecs v5.7.0 - Track and manage Fargate FIPS Mode for Gov cloud accounts via Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/aws-ecs-v5-7-0</link>
            <description>_What&apos;s new?_

- Track and manage Fargate FIPS Mode for Gov cloud accounts via Guardrails. To get started, set the `AWS &gt; ECS &gt; Account Settings &gt; Fargate FIPS Mode` policy.
- The `Approved &gt; Usage` policy for resource types will now default to `Approved` instead of `Approved if AWS &gt; {service} &gt; Enabled`.

_Resource Types_

- AWS &gt; ECS &gt; Account Settings

_Control Types_

- AWS &gt; ECS &gt; Account Settings &gt; CMDB
- AWS &gt; ECS &gt; Account Settings &gt; Discovery
- AWS &gt; ECS &gt; Account Settings &gt; Fargate FIPS Mode

_Policy Types_

- AWS &gt; ECS &gt; Account Settings &gt; CMDB
- AWS &gt; ECS &gt; Account Settings &gt; Fargate FIPS Mode
- AWS &gt; ECS &gt; Account Settings &gt; Regions

_Action Types_

- AWS &gt; ECS &gt; Account Settings &gt; Router
- AWS &gt; ECS &gt; Account Settings &gt; Update Fargate FIPS Mode</description>
            <pubDate>Thu, 26 Sep 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-47-0</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.47.0 - Introduced support for multi-architecture images, now compatible with both ARM64 and x86_64</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-47-0</link>
            <description>_What&apos;s new?_

- Server
  - Introduced support for multi-architecture images, now compatible with both ARM64 and x86_64.
  - Added a default resource query to the context of calculated policies.
  - Updated several node packages to newer versions for improved functionality and security.
  - Updated Lambda to support recursive loops.

- UI
  - Now you can use the `+` sign to grant permissions in the context of both the identity and resource.
  - Updated several node packages to newer versions for improved functionality and security.

_Bug fixes_

- Server
  - Azure Credential Resolver now respects proxy settings, adding full proxy support.

- UI
  - Updated policy pack Terraform to correctly reference turbot_policy_pack.
  - Adjusted the Admin page layout for improved usability.

_Requirements_

- TEF: 1.59.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Wed, 25 Sep 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/terraform-provider-v1-11-2</guid>
            <title>Terraform Provider v1.11.2 - `terraform apply` failed to detect existing Policy Pack attachments</title>
            <link>https://turbot.com/guardrails/changelog/terraform-provider-v1-11-2</link>
            <description>_Bug fixes_

* `resource/turbot_policy_pack_attachment`: `terraform apply` failed to detect existing Policy Pack attachments. ([#181](https://github.com/turbot/terraform-provider-turbot/issues/181))</description>
            <pubDate>Fri, 20 Sep 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-applicationinsights-v5-8-0</guid>
            <title>azure-applicationinsights v5.8.0 - Controls and Actions now use latest Azure SDK versions to discover and manage Application Insights resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-applicationinsights-v5-8-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated internal dependencies and now use the latest Azure SDK versions to discover and manage Application Insights resources in Guardrails. This release includes changes in the CMDB data as below.

Added:

- `flowType`
- `requestSource`

_Bug fixes_

- Improved descriptions for various resource types to ensure they are clearer and more helpful.</description>
            <pubDate>Fri, 20 Sep 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-applicationgateway-v5-8-0</guid>
            <title>azure-applicationgateway v5.8.0 - Controls and Actions now use latest Azure SDK versions to discover and manage Application Gateway resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-applicationgateway-v5-8-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated internal dependencies and now use the latest Azure SDK versions to discover and manage Application Gateway resources in Guardrails.

_Bug fixes_

- Improved descriptions for various resource types to ensure they are clearer and more helpful.</description>
            <pubDate>Fri, 20 Sep 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-support-v5-0-0</guid>
            <title>aws-support v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/aws-support-v5-0-0</link>
            <description>_Resource Types_

- AWS &gt; Support

_Policy Types_

- AWS &gt; Support &gt; API Enabled
- AWS &gt; Support &gt; Enabled
- AWS &gt; Support &gt; Permissions
- AWS &gt; Support &gt; Permissions &gt; Levels
- AWS &gt; Support &gt; Permissions &gt; Levels &gt; Modifiers
- AWS &gt; Support &gt; Permissions &gt; Lockdown
- AWS &gt; Support &gt; Permissions &gt; Lockdown &gt; API Boundary
- AWS &gt; Turbot &gt; Permissions &gt; Compiled &gt; API Boundary &gt; @turbot/aws-support
- AWS &gt; Turbot &gt; Permissions &gt; Compiled &gt; Levels &gt; @turbot/aws-support
- AWS &gt; Turbot &gt; Permissions &gt; Compiled &gt; Service Permissions &gt; @turbot/aws-support</description>
            <pubDate>Fri, 20 Sep 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-iam-v5-37-0</guid>
            <title>aws-iam v5.37.0 - Users can now manage whether `AWS/User` should grant include `support:*` permissions</title>
            <link>https://turbot.com/guardrails/changelog/aws-iam-v5-37-0</link>
            <description>_What&apos;s new?_

- Users can now manage whether `AWS/User` grant should include `support:*` permissions. To get started, set the `AWS &gt; Account &gt; Permissions &gt; Support Level` policy.

_Policy Types_

- AWS &gt; Account &gt; Permissions &gt; Support Level

_Bug fixes_

- The `AWS &gt; Turbot &gt; IAM` stack control did not correctly evaluate user memberships in custom IAM groups when the `AWS &gt; Turbot &gt; Permissions &gt; Custom Group Levels [Account]` policy was set, and users were granted permissions for those custom IAM groups. This issue has now been fixed.</description>
            <pubDate>Fri, 20 Sep 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ec2-v5-42-1</guid>
            <title>aws-ec2 v5.42.1 - Volume CMDB control sometimes ran unnecessarily due to a bad internal GraphQL dependency</title>
            <link>https://turbot.com/guardrails/changelog/aws-ec2-v5-42-1</link>
            <description>_Bug fixes_

- The `AWS &gt; EC2 &gt; Volume &gt; CMDB` control would sometimes run unnecessarily due to a bad internal GraphQL dependency. This is now fixed.</description>
            <pubDate>Fri, 20 Sep 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/kubernetes-v5-1-2</guid>
            <title>kubernetes v5.1.2 - Cluster CMDB control will now not depend on the CMDB &gt; Expiration policy</title>
            <link>https://turbot.com/guardrails/changelog/kubernetes-v5-1-2</link>
            <description>_Bug fixes_

- A precheck dependency on the `Kubernetes &gt; Cluster &gt; CMDB &gt; Expiration` policy was inadvertently added to the `Kubernetes &gt; Cluster &gt; CMDB` control. This precheck condition has now been removed.</description>
            <pubDate>Tue, 17 Sep 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-vertexai-v5-0-0</guid>
            <title>gcp-vertexai v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/gcp-vertexai-v5-0-0</link>
            <description>_Resource Types_

- GCP &gt; Vertex AI
- GCP &gt; Vertex AI &gt; Endpoint
- GCP &gt; Vertex AI &gt; Notebook Runtime Template

_Control Types_

- GCP &gt; Vertex AI &gt; API Enabled
- GCP &gt; Vertex AI &gt; CMDB
- GCP &gt; Vertex AI &gt; Discovery
- GCP &gt; Vertex AI &gt; Endpoint &gt; Active
- GCP &gt; Vertex AI &gt; Endpoint &gt; Approved
- GCP &gt; Vertex AI &gt; Endpoint &gt; CMDB
- GCP &gt; Vertex AI &gt; Endpoint &gt; Discovery
- GCP &gt; Vertex AI &gt; Endpoint &gt; Labels
- GCP &gt; Vertex AI &gt; Endpoint &gt; Usage
- GCP &gt; Vertex AI &gt; Notebook Runtime Template &gt; Active
- GCP &gt; Vertex AI &gt; Notebook Runtime Template &gt; Approved
- GCP &gt; Vertex AI &gt; Notebook Runtime Template &gt; CMDB
- GCP &gt; Vertex AI &gt; Notebook Runtime Template &gt; Discovery
- GCP &gt; Vertex AI &gt; Notebook Runtime Template &gt; Router
- GCP &gt; Vertex AI &gt; Notebook Runtime Template &gt; Usage

_Policy Types_

- GCP &gt; Turbot &gt; Event Handlers &gt; Logging &gt; Sink &gt; Compiled Filter &gt; @turbot/gcp-vertexai
- GCP &gt; Turbot &gt; Permissions &gt; Compiled &gt; Levels &gt; @turbot/gcp-vertexai
- GCP &gt; Turbot &gt; Permissions &gt; Compiled &gt; Service Permissions &gt; @turbot/gcp-vertexai
- GCP &gt; Vertex AI &gt; API Enabled
- GCP &gt; Vertex AI &gt; Approved Regions [Default]
- GCP &gt; Vertex AI &gt; CMDB
- GCP &gt; Vertex AI &gt; Enabled
- GCP &gt; Vertex AI &gt; Endpoint &gt; Active
- GCP &gt; Vertex AI &gt; Endpoint &gt; Active &gt; Age
- GCP &gt; Vertex AI &gt; Endpoint &gt; Active &gt; Last Modified
- GCP &gt; Vertex AI &gt; Endpoint &gt; Approved
- GCP &gt; Vertex AI &gt; Endpoint &gt; Approved &gt; Custom
- GCP &gt; Vertex AI &gt; Endpoint &gt; Approved &gt; Regions
- GCP &gt; Vertex AI &gt; Endpoint &gt; Approved &gt; Usage
- GCP &gt; Vertex AI &gt; Endpoint &gt; CMDB
- GCP &gt; Vertex AI &gt; Endpoint &gt; Labels
- GCP &gt; Vertex AI &gt; Endpoint &gt; Labels &gt; Template
- GCP &gt; Vertex AI &gt; Endpoint &gt; Regions
- GCP &gt; Vertex AI &gt; Endpoint &gt; Usage
- GCP &gt; Vertex AI &gt; Endpoint &gt; Usage &gt; Limit
- GCP &gt; Vertex AI &gt; Labels Template [Default]
- GCP &gt; Vertex AI &gt; Notebook Runtime Template &gt; Active
- GCP &gt; Vertex AI &gt; Notebook Runtime Template &gt; Active &gt; Age
- GCP &gt; Vertex AI &gt; Notebook Runtime Template &gt; Active &gt; Last Modified
- GCP &gt; Vertex AI &gt; Notebook Runtime Template &gt; Approved
- GCP &gt; Vertex AI &gt; Notebook Runtime Template &gt; Approved &gt; Custom
- GCP &gt; Vertex AI &gt; Notebook Runtime Template &gt; Approved &gt; Regions
- GCP &gt; Vertex AI &gt; Notebook Runtime Template &gt; Approved &gt; Usage
- GCP &gt; Vertex AI &gt; Notebook Runtime Template &gt; CMDB
- GCP &gt; Vertex AI &gt; Notebook Runtime Template &gt; Regions
- GCP &gt; Vertex AI &gt; Notebook Runtime Template &gt; Usage
- GCP &gt; Vertex AI &gt; Notebook Runtime Template &gt; Usage &gt; Limit
- GCP &gt; Vertex AI &gt; Permissions
- GCP &gt; Vertex AI &gt; Permissions &gt; Levels
- GCP &gt; Vertex AI &gt; Permissions &gt; Levels &gt; Modifiers
- GCP &gt; Vertex AI &gt; Regions

_Action Types_

- GCP &gt; Vertex AI &gt; Endpoint &gt; Delete
- GCP &gt; Vertex AI &gt; Endpoint &gt; Router
- GCP &gt; Vertex AI &gt; Endpoint &gt; Set Labels
- GCP &gt; Vertex AI &gt; Notebook Runtime Template &gt; Delete
- GCP &gt; Vertex AI &gt; Set API Enabled</description>
            <pubDate>Tue, 17 Sep 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-v5-26-0</guid>
            <title>gcp v5.26.0 - Added support to process real-time enable and disable events for Vertex AI API</title>
            <link>https://turbot.com/guardrails/changelog/gcp-v5-26-0</link>
            <description>_What&apos;s new?_

- Added support to process real-time enable and disable events for Vertex AI API via Service Usage APIs.</description>
            <pubDate>Tue, 17 Sep 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-kubernetesengine-v5-6-1</guid>
            <title>gcp-kubernetesengine v5.6.1 - CMDB control for the service resource type will no longer depend on the API Enabled policy being set to `Enforce: Enabled`</title>
            <link>https://turbot.com/guardrails/changelog/gcp-kubernetesengine-v5-6-1</link>
            <description>_Bug fixes_

- The CMDB control for the service resource type will no longer depend on the API Enabled policy being set to `Enforce: Enabled` for the service.</description>
            <pubDate>Mon, 16 Sep 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-searchmanagement-v5-8-0</guid>
            <title>azure-searchmanagement v5.8.0 - Controls and Actions now use latest Azure SDK versions to discover and manage Search Management resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-searchmanagement-v5-8-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated internal dependencies and now use the latest Azure SDK versions to discover and manage Search Management resources in Guardrails.

Added:

- `authOptions`
- `disableLocalAuth`
- `encryptionWithCmk`
- `networkRuleSet`
- `privateEndpointConnections`
- `publicNetworkAccess`
- `semanticSearch`
- `sharedPrivateLinkResources`

_Bug fixes_

- Improved descriptions for various resource types to ensure they are clearer and more helpful.</description>
            <pubDate>Mon, 16 Sep 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-storage-v5-11-3</guid>
            <title>gcp-storage v5.11.3 - Added Quick Actions for setting Fine-grained and Uniform access controls for buckets</title>
            <link>https://turbot.com/guardrails/changelog/gcp-storage-v5-11-3</link>
            <description>_What&apos;s new?_

_Action Types_

- GCP &gt; Storage &gt; Bucket &gt; Set Fine-grained Access Control
- GCP &gt; Storage &gt; Bucket &gt; Set Uniform Access Control</description>
            <pubDate>Fri, 13 Sep 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-sql-v5-10-1</guid>
            <title>gcp-sql v5.10.1 - CMDB control for the service resource type will no longer depend on the API Enabled policy being set to `Enforce: Enabled`</title>
            <link>https://turbot.com/guardrails/changelog/gcp-sql-v5-10-1</link>
            <description>_Bug fixes_

- The CMDB control for the service resource type will no longer depend on the API Enabled policy being set to `Enforce: Enabled` for the service.
- Improved descriptions for various resource types to ensure they are clearer and more helpful.</description>
            <pubDate>Fri, 13 Sep 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-secretmanager-v5-1-1</guid>
            <title>gcp-secretmanager v5.1.1 - CMDB control for the service resource type will no longer depend on the API Enabled policy being set to `Enforce: Enabled`</title>
            <link>https://turbot.com/guardrails/changelog/gcp-secretmanager-v5-1-1</link>
            <description>_Bug fixes_

- The CMDB control for the service resource type will no longer depend on the API Enabled policy being set to `Enforce: Enabled` for the service.
- Improved descriptions for various resource types to ensure they are clearer and more helpful.</description>
            <pubDate>Fri, 13 Sep 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-network-v5-14-1</guid>
            <title>gcp-network v5.14.1 - CMDB control for the service resource type will no longer depend on the API Enabled policy being set to `Enforce: Enabled`</title>
            <link>https://turbot.com/guardrails/changelog/gcp-network-v5-14-1</link>
            <description>_Bug fixes_

- The CMDB control for the service resource type will no longer depend on the API Enabled policy being set to `Enforce: Enabled` for the service.
- Improved descriptions for various resource types to ensure they are clearer and more helpful.</description>
            <pubDate>Fri, 13 Sep 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-monitoring-v5-7-1</guid>
            <title>gcp-monitoring v5.7.1 - CMDB control for the service resource type will no longer depend on the API Enabled policy being set to `Enforce: Enabled`</title>
            <link>https://turbot.com/guardrails/changelog/gcp-monitoring-v5-7-1</link>
            <description>_Bug fixes_

- The CMDB control for the service resource type will no longer depend on the API Enabled policy being set to `Enforce: Enabled` for the service.
- Improved descriptions for various resource types to ensure they are clearer and more helpful.</description>
            <pubDate>Fri, 13 Sep 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-logging-v5-5-1</guid>
            <title>gcp-logging v5.5.1 - CMDB control for the service resource type will no longer depend on the API Enabled policy being set to `Enforce: Enabled`</title>
            <link>https://turbot.com/guardrails/changelog/gcp-logging-v5-5-1</link>
            <description>_Bug fixes_

- The CMDB control for the service resource type will no longer depend on the API Enabled policy being set to `Enforce: Enabled` for the service.
- Improved descriptions for various resource types to ensure they are clearer and more helpful.</description>
            <pubDate>Fri, 13 Sep 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-kms-v5-8-1</guid>
            <title>gcp-kms v5.8.1 - CMDB control for the service resource type will no longer depend on the API Enabled policy being set to `Enforce: Enabled`</title>
            <link>https://turbot.com/guardrails/changelog/gcp-kms-v5-8-1</link>
            <description>_Bug fixes_

- The CMDB control for the service resource type will no longer depend on the API Enabled policy being set to `Enforce: Enabled` for the service.</description>
            <pubDate>Fri, 13 Sep 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-iam-v5-16-1</guid>
            <title>gcp-iam v5.16.1 - CMDB control for the service resource type will no longer depend on the API Enabled policy being set to `Enforce: Enabled`</title>
            <link>https://turbot.com/guardrails/changelog/gcp-iam-v5-16-1</link>
            <description>_Bug fixes_

- The CMDB control for the service resource type will no longer depend on the API Enabled policy being set to `Enforce: Enabled` for the service.</description>
            <pubDate>Fri, 13 Sep 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-functions-v5-8-1</guid>
            <title>gcp-functions v5.8.1 - CMDB control for the service resource type will no longer depend on the API Enabled policy being set to `Enforce: Enabled`</title>
            <link>https://turbot.com/guardrails/changelog/gcp-functions-v5-8-1</link>
            <description>_Bug fixes_

- The CMDB control for the service resource type will no longer depend on the API Enabled policy being set to `Enforce: Enabled` for the service.
- Improved descriptions for various resource types to ensure they are clearer and more helpful.</description>
            <pubDate>Fri, 13 Sep 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-dns-v5-8-1</guid>
            <title>gcp-dns v5.8.1 - CMDB control for the service resource type will no longer depend on the API Enabled policy being set to `Enforce: Enabled`</title>
            <link>https://turbot.com/guardrails/changelog/gcp-dns-v5-8-1</link>
            <description>_Bug fixes_

- The CMDB control for the service resource type will no longer depend on the API Enabled policy being set to `Enforce: Enabled` for the service.</description>
            <pubDate>Fri, 13 Sep 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-dataproc-v5-8-2</guid>
            <title>gcp-dataproc v5.8.2 - CMDB control for the service resource type will no longer depend on the API Enabled policy being set to `Enforce: Enabled`</title>
            <link>https://turbot.com/guardrails/changelog/gcp-dataproc-v5-8-2</link>
            <description>_Bug fixes_

- The CMDB control for the service resource type will no longer depend on the API Enabled policy being set to `Enforce: Enabled` for the service.
- Improved descriptions for various resource types to ensure they are clearer and more helpful.</description>
            <pubDate>Fri, 13 Sep 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-appengine-v5-3-1</guid>
            <title>gcp-appengine v5.3.1 - CMDB control for the service resource type will no longer depend on the API Enabled policy being set to `Enforce: Enabled`</title>
            <link>https://turbot.com/guardrails/changelog/gcp-appengine-v5-3-1</link>
            <description>_Bug fixes_

- The CMDB control for the service resource type will no longer depend on the API Enabled policy being set to `Enforce: Enabled` for the service.</description>
            <pubDate>Fri, 13 Sep 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-synapseanalytics-v5-8-0</guid>
            <title>azure-synapseanalytics v5.8.0 - Controls and Actions now use latest Azure SDK versions to discover and manage Synapse Analytics resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-synapseanalytics-v5-8-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated internal dependencies and now use the latest Azure SDK versions to discover and manage Synapse Analytics resources in Guardrails.

Added:
Azure &gt; Synapse Analytics &gt; Workspace

- `azureADOnlyAuthentication`
- `createManagedPrivateEndpoint `
- `encryption`
- `extraProperties`
- `publicNetworkAccess`
- `settings`
- `trustedServiceBypassEnabled`
- `workspaceUID`

Azure &gt; Synapse Analytics &gt; SQL Pool

- `storageAccountType`

_Bug fixes_

- Improved descriptions for various resource types to ensure they are clearer and more helpful.</description>
            <pubDate>Fri, 13 Sep 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-storage-v5-20-2</guid>
            <title>azure-storage v5.20.2 - Added Quick Action to set Minimum TLS Version for buckets</title>
            <link>https://turbot.com/guardrails/changelog/azure-storage-v5-20-2</link>
            <description>_What&apos;s new?_

_Action Types_

- Azure &gt; Storage &gt; Storage Account &gt; Set Minimum TLS Version</description>
            <pubDate>Fri, 13 Sep 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-postgresql-v5-16-0</guid>
            <title>azure-postgresql v5.16.0 - Controls and Actions now use latest Azure SDK versions to discover and manage PostgreSQL resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-postgresql-v5-16-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated internal dependencies and now use the latest Azure SDK versions to discover and manage PostgreSQL resources in Guardrails. This release includes breaking changes in the CMDB data for server and flexible server. We recommend updating your existing policy settings to refer to the updated attributes as mentioned below

Added:

- `authConfig`
- `dataEncryption`
- `standbyAvailabilityZone`
- `network. delegatedSubnetResourceId`
- `network. privateDnsZoneArmResourceId`
- `replicaCapacity`
- `replicationRole`
- `systemData`

- `configurations.documentationLink`
- `configurations.isConfigPendingRestart`
- `configurations.isDynamicConfig`
- `configurations.isReadOnly`
- `configurations.unit`

Modified:

- The data type of the attribute `firewallRules` has been changed from array (`[]`) to object (`{}`).

_Bug fixes_

- Improved descriptions for various resource types to ensure they are clearer and more helpful.</description>
            <pubDate>Fri, 13 Sep 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-networkwatcher-v5-10-0</guid>
            <title>azure-networkwatcher v5.10.0 - Controls and Actions now use latest Azure SDK versions to discover and manage Network Watcher resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-networkwatcher-v5-10-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated internal dependencies and now use the latest Azure SDK versions to discover and manage Network Watcher resources in Guardrails.

_Bug fixes_

- Improved descriptions for various resource types to ensure they are clearer and more helpful.</description>
            <pubDate>Fri, 13 Sep 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-storage-v5-20-1</guid>
            <title>azure-storage v5.20.1 - Updated few attributes to be `dynamic` for storage accounts to avoid unnecessary notifications in the activity tab</title>
            <link>https://turbot.com/guardrails/changelog/azure-storage-v5-20-1</link>
            <description>_Bug fixes_

- The `serviceProperties.table.clientRequestId` and `serviceProperties.table.requestId` properties for storage accounts have now been made `dynamic` to avoid unnecessary notifications in the activity tab.</description>
            <pubDate>Thu, 05 Sep 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ssm-v5-15-2</guid>
            <title>aws-ssm v5.15.2 - Fixed incorrect references to various Quick Actions</title>
            <link>https://turbot.com/guardrails/changelog/aws-ssm-v5-15-2</link>
            <description>_Bug fixes_

- Fixed incorrect references to various Quick Actions.</description>
            <pubDate>Thu, 05 Sep 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-kubernetes-v5-3-0</guid>
            <title>servicenow-kubernetes v5.3.0 - Added Import Set &gt; Insert Mode policy for various resource types</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-kubernetes-v5-3-0</link>
            <description>_What&apos;s new?_

_Policy Types_

- Kubernetes &gt; Cluster &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- Kubernetes &gt; ConfigMap &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- Kubernetes &gt; Deployment &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- Kubernetes &gt; Namespace &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- Kubernetes &gt; Node &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- Kubernetes &gt; Pod &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- Kubernetes &gt; ReplicaSet &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- Kubernetes &gt; Service &gt; ServiceNow &gt; Import Set &gt; Insert Mode</description>
            <pubDate>Tue, 03 Sep 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/osquery-v5-0-3</guid>
            <title>osquery v5.0.3 - Improved error handling for osquery error events</title>
            <link>https://turbot.com/guardrails/changelog/osquery-v5-0-3</link>
            <description>_Bug fixes_

- Improved error handling for `osquery` error events.</description>
            <pubDate>Tue, 03 Sep 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/kubernetes-v5-1-1</guid>
            <title>kubernetes v5.1.1 - Query controls will now go into an invalid state on encountering osquery agent errors</title>
            <link>https://turbot.com/guardrails/changelog/kubernetes-v5-1-1</link>
            <description>_Bug fixes_

- Query controls for various resource types will now go into an invalid state if we receive an error from the `osquery` agent.</description>
            <pubDate>Tue, 03 Sep 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-storage-v5-4-0</guid>
            <title>servicenow-gcp-storage v5.4.0 - Added Import Set &gt; Insert Mode policy for various resource types</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-storage-v5-4-0</link>
            <description>_What&apos;s new?_

_Policy Types_

- GCP &gt; Storage &gt; Bucket &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- GCP &gt; Storage &gt; Object &gt; ServiceNow &gt; Import Set &gt; Insert Mode</description>
            <pubDate>Fri, 30 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-kubernetesengine-v5-1-0</guid>
            <title>servicenow-gcp-kubernetesengine v5.1.0 - Added Import Set controls and policies for various resource types</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-kubernetesengine-v5-1-0</link>
            <description>_Control Types_

- GCP &gt; Kubernetes Engine &gt; Region Cluster &gt; ServiceNow &gt; Import Set
- GCP &gt; Kubernetes Engine &gt; Region Node Pool &gt; ServiceNow &gt; Import Set
- GCP &gt; Kubernetes Engine &gt; Zone Cluster &gt; ServiceNow &gt; Import Set
- GCP &gt; Kubernetes Engine &gt; Zone Node Pool &gt; ServiceNow &gt; Import Set

_Policy Types_

- GCP &gt; Kubernetes Engine &gt; Region Cluster &gt; ServiceNow &gt; Import Set
- GCP &gt; Kubernetes Engine &gt; Region Cluster &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- GCP &gt; Kubernetes Engine &gt; Region Cluster &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- GCP &gt; Kubernetes Engine &gt; Region Cluster &gt; ServiceNow &gt; Import Set &gt; Record
- GCP &gt; Kubernetes Engine &gt; Region Cluster &gt; ServiceNow &gt; Import Set &gt; Table Name
- GCP &gt; Kubernetes Engine &gt; Region Node Pool &gt; ServiceNow &gt; Import Set
- GCP &gt; Kubernetes Engine &gt; Region Node Pool &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- GCP &gt; Kubernetes Engine &gt; Region Node Pool &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- GCP &gt; Kubernetes Engine &gt; Region Node Pool &gt; ServiceNow &gt; Import Set &gt; Record
- GCP &gt; Kubernetes Engine &gt; Region Node Pool &gt; ServiceNow &gt; Import Set &gt; Table Name
- GCP &gt; Kubernetes Engine &gt; Zone Cluster &gt; ServiceNow &gt; Import Set
- GCP &gt; Kubernetes Engine &gt; Zone Cluster &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- GCP &gt; Kubernetes Engine &gt; Zone Cluster &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- GCP &gt; Kubernetes Engine &gt; Zone Cluster &gt; ServiceNow &gt; Import Set &gt; Record
- GCP &gt; Kubernetes Engine &gt; Zone Cluster &gt; ServiceNow &gt; Import Set &gt; Table Name
- GCP &gt; Kubernetes Engine &gt; Zone Node Pool &gt; ServiceNow &gt; Import Set
- GCP &gt; Kubernetes Engine &gt; Zone Node Pool &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- GCP &gt; Kubernetes Engine &gt; Zone Node Pool &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- GCP &gt; Kubernetes Engine &gt; Zone Node Pool &gt; ServiceNow &gt; Import Set &gt; Record
- GCP &gt; Kubernetes Engine &gt; Zone Node Pool &gt; ServiceNow &gt; Import Set &gt; Table Name</description>
            <pubDate>Fri, 30 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-v5-5-0</guid>
            <title>servicenow-gcp v5.5.0 - Added Import Set &gt; Insert Mode policy for various resource types</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-v5-5-0</link>
            <description>_What&apos;s new?_

_Policy Types_

- GCP &gt; Global Region &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- GCP &gt; Multi-Region &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- GCP &gt; Project &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- GCP &gt; Region &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- GCP &gt; Zone &gt; ServiceNow &gt; Import Set &gt; Insert Mode</description>
            <pubDate>Fri, 30 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-aks-v5-1-0</guid>
            <title>servicenow-azure-aks v5.1.0 - Added Import Set controls and policies for various resource types</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-aks-v5-1-0</link>
            <description>_Control Types_

- Azure &gt; AKS &gt; Managed Cluster &gt; ServiceNow &gt; Import Set

_Policy Types_

- Azure &gt; AKS &gt; Managed Cluster &gt; ServiceNow &gt; Import Set
- Azure &gt; AKS &gt; Managed Cluster &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- Azure &gt; AKS &gt; Managed Cluster &gt; ServiceNow &gt; Import Set &gt; Insert Mode
- Azure &gt; AKS &gt; Managed Cluster &gt; ServiceNow &gt; Import Set &gt; Record
- Azure &gt; AKS &gt; Managed Cluster &gt; ServiceNow &gt; Import Set &gt; Table Name</description>
            <pubDate>Fri, 30 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-v5-4-0</guid>
            <title>servicenow-azure v5.4.0 - Added Import Set &gt; Insert Mode policy for Subscription resource type</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-v5-4-0</link>
            <description>_What&apos;s new?_

_Policy Types_

- Azure &gt; Subscription &gt; ServiceNow &gt; Import Set &gt; Insert Mode</description>
            <pubDate>Fri, 30 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-v5-2-0</guid>
            <title>servicenow v5.2.0 - Added Import Set &gt; Insert Mode [Default] policy</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-v5-2-0</link>
            <description>_What&apos;s new?_

_Policy Types_

- ServiceNow &gt; Import Set &gt; Insert Mode [Default]</description>
            <pubDate>Fri, 30 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-v5-30-4</guid>
            <title>aws v5.30.4 - Real-time `modifyVolume` event will now be raised correctly for EBS Volume Notifications</title>
            <link>https://turbot.com/guardrails/changelog/aws-v5-30-4</link>
            <description>_Bug fixes_

- Guardrails did not correctly raise the real-time `modifyVolume` event for EBS Volume Notifications. This issue is now fixed.</description>
            <pubDate>Fri, 30 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-swf-v5-5-0</guid>
            <title>aws-swf v5.5.0 - Approved &gt; Usage policy will now default to Approved</title>
            <link>https://turbot.com/guardrails/changelog/aws-swf-v5-5-0</link>
            <description>_What&apos;s new?_

- The `Approved &gt; Usage` policy for resource types will now default to `Approved` instead of `Approved if AWS &gt; {service} &gt; Enabled`.

_Bug fixes_

- Improved descriptions for various resource types to ensure they are clearer and more helpful.
- Fixed incorrect references to various Quick Actions.

_Action Types_

- AWS &gt; SWF &gt; Domain &gt; Delete from AWS</description>
            <pubDate>Fri, 30 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-sns-v5-16-0</guid>
            <title>aws-sns v5.16.0 - Approved &gt; Usage policy will now default to Approved</title>
            <link>https://turbot.com/guardrails/changelog/aws-sns-v5-16-0</link>
            <description>_What&apos;s new?_

- The `Approved &gt; Usage` policy for resource types will now default to `Approved` instead of `Approved if AWS &gt; {service} &gt; Enabled`.

_Bug fixes_

- Improved descriptions for various resource types to ensure they are clearer and more helpful.
- Fixed incorrect references to various Quick Actions.</description>
            <pubDate>Fri, 30 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-sagemaker-v5-11-0</guid>
            <title>aws-sagemaker v5.11.0 - Approved &gt; Usage policy will now default to Approved</title>
            <link>https://turbot.com/guardrails/changelog/aws-sagemaker-v5-11-0</link>
            <description>_What&apos;s new?_

- The `Approved &gt; Usage` policy for resource types will now default to `Approved` instead of `Approved if AWS &gt; {service} &gt; Enabled`.

_Bug fixes_

- Improved descriptions for various resource types to ensure they are clearer and more helpful.
- Fixed incorrect references to various Quick Actions.</description>
            <pubDate>Fri, 30 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-redshift-v5-20-0</guid>
            <title>aws-redshift v5.20.0 - Approved &gt; Usage policy will now default to Approved</title>
            <link>https://turbot.com/guardrails/changelog/aws-redshift-v5-20-0</link>
            <description>_What&apos;s new?_

- The `Approved &gt; Usage` policy for resource types will now default to `Approved` instead of `Approved if AWS &gt; {service} &gt; Enabled`.

_Bug fixes_

- Improved descriptions for various resource types to ensure they are clearer and more helpful.
- Fixed incorrect references to various Quick Actions.</description>
            <pubDate>Fri, 30 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-outposts-v5-3-1</guid>
            <title>aws-outposts v5.3.1 - Fixed incorrect references to various Quick Actions</title>
            <link>https://turbot.com/guardrails/changelog/aws-outposts-v5-3-1</link>
            <description>_Bug fixes_

- Fixed incorrect references to various Quick Actions.
- Improved descriptions for various resource types to ensure they are clearer and more helpful.</description>
            <pubDate>Fri, 30 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-logs-v5-13-0</guid>
            <title>aws-logs v5.13.0 - Approved &gt; Usage policy will now default to Approved</title>
            <link>https://turbot.com/guardrails/changelog/aws-logs-v5-13-0</link>
            <description>_What&apos;s new?_

- The `Approved &gt; Usage` policy for resource types will now default to `Approved` instead of `Approved if AWS &gt; {service} &gt; Enabled`.

_Bug fixes_

- Improved descriptions for various resource types to ensure they are clearer and more helpful.
- Fixed incorrect references to various Quick Actions.</description>
            <pubDate>Fri, 30 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-guardduty-v5-8-0</guid>
            <title>aws-guardduty v5.8.0 - Approved &gt; Usage policy will now default to Approved</title>
            <link>https://turbot.com/guardrails/changelog/aws-guardduty-v5-8-0</link>
            <description>_What&apos;s new?_

- The `Approved &gt; Usage` policy for resource types will now default to `Approved` instead of `Approved if AWS &gt; {service} &gt; Enabled`.

_Bug fixes_

- Improved descriptions for various resource types to ensure they are clearer and more helpful.
- Fixed incorrect references to various Quick Actions.</description>
            <pubDate>Fri, 30 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ec2-v5-42-0</guid>
            <title>aws-ec2 v5.42.0 - Volume&apos;s metadata will now also include `createdBy` details in Guardrails CMDB</title>
            <link>https://turbot.com/guardrails/changelog/aws-ec2-v5-42-0</link>
            <description>_What&apos;s new?_

- Volume&apos;s metadata will now also include `createdBy` details in Guardrails CMDB.
- The `Approved &gt; Usage` policy for resource types will now default to `Approved` instead of `Approved if AWS &gt; {service} &gt; Enabled`.

_Bug fixes_

- The `AWS &gt; EC2 &gt; Volume &gt; Performance Configuration` control would sometimes fail to set the expected configuration per `AWS &gt; EC2 &gt; Volume &gt; Performance Configuration &gt; *` policies and move to an Invalid state if the required data was not available for new volumes in the CMDB. The control will now move to TBD instead and retry after 5 minutes to fetch the required data correctly and set the performance configuration as expected.</description>
            <pubDate>Fri, 30 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-dynamodb-v5-12-0</guid>
            <title>aws-dynamodb v5.12.0 - Approved &gt; Usage policy will now default to Approved</title>
            <link>https://turbot.com/guardrails/changelog/aws-dynamodb-v5-12-0</link>
            <description>_What&apos;s new?_

- The `Approved &gt; Usage` policy for resource types will now default to `Approved` instead of `Approved if AWS &gt; {service} &gt; Enabled`.

_Bug fixes_

- Improved descriptions for various resource types to ensure they are clearer and more helpful.
- Fixed incorrect references to various Quick Actions.</description>
            <pubDate>Fri, 30 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-backup-v5-11-0</guid>
            <title>aws-backup v5.11.0 - Approved &gt; Usage policy will now default to Approved</title>
            <link>https://turbot.com/guardrails/changelog/aws-backup-v5-11-0</link>
            <description>_What&apos;s new?_

- The `Approved &gt; Usage` policy for resource types will now default to `Approved` instead of `Approved if AWS &gt; {service} &gt; Enabled`.

_Bug fixes_

- Improved descriptions for various resource types to ensure they are clearer and more helpful.
- Fixed incorrect references to various Quick Actions.</description>
            <pubDate>Fri, 30 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-62-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.62.0 - Support for Node.js 20 in the Lambda runtime</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-62-0</link>
            <description>_What&apos;s new?_

  - Support for Node.js 20 in the Lambda runtime.</description>
            <pubDate>Thu, 29 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-storage-v5-11-2</guid>
            <title>gcp-storage v5.11.2 - CMDB control for the service resource type will no longer depend on the API Enabled policy being set to `Enforce: Enabled`</title>
            <link>https://turbot.com/guardrails/changelog/gcp-storage-v5-11-2</link>
            <description>_Bug fixes_

- The CMDB control for the service resource type will no longer depend on the API Enabled policy being set to `Enforce: Enabled` for the service.
- Improved descriptions for various resource types to ensure they are clearer and more helpful.</description>
            <pubDate>Wed, 28 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-pubsub-v5-9-1</guid>
            <title>gcp-pubsub v5.9.1 - CMDB control for the service resource type will no longer depend on the API Enabled policy being set to `Enforce: Enabled`</title>
            <link>https://turbot.com/guardrails/changelog/gcp-pubsub-v5-9-1</link>
            <description>_Bug fixes_

- The CMDB control for the service resource type will no longer depend on the API Enabled policy being set to `Enforce: Enabled` for the service.
- Improved descriptions for various resource types to ensure they are clearer and more helpful.</description>
            <pubDate>Wed, 28 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-bigquery-v5-7-1</guid>
            <title>gcp-bigquery v5.7.1 - CMDB control for the service resource type will no longer depend on the API Enabled policy being set to `Enforce: Enabled`</title>
            <link>https://turbot.com/guardrails/changelog/gcp-bigquery-v5-7-1</link>
            <description>_Bug fixes_

- The CMDB control for the service resource type will no longer depend on the API Enabled policy being set to `Enforce: Enabled` for the service.
- Improved descriptions for various resource types to ensure they are clearer and more helpful.</description>
            <pubDate>Wed, 28 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-storage-v5-20-0</guid>
            <title>azure-storage v5.20.0 - Diagnostic settings details will now be available in Storage Account CMDB</title>
            <link>https://turbot.com/guardrails/changelog/azure-storage-v5-20-0</link>
            <description>_What&apos;s new?_

- The `Azure &gt; Storage&gt; Storage Account &gt; CMDB` control will now also fetch diagnostic settings details and store them in CMDB.
- Track and manage storage account access keys in Guardrails CMDB.

_Resource Types_

- Azure &gt; Storage &gt; Access Key

_Control Types_

- Azure &gt; Storage &gt; Access Key &gt; CMDB
- Azure &gt; Storage &gt; Access Key &gt; Discovery

_Policy Types_

- Azure &gt; Storage &gt; Access Key &gt; CMDB

_Bug fixes_

- Improved descriptions for various resource types to ensure they are clearer and more helpful.</description>
            <pubDate>Mon, 26 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-waf-v5-8-0</guid>
            <title>aws-waf v5.8.0 - Approved &gt; Usage policy will now default to Approved</title>
            <link>https://turbot.com/guardrails/changelog/aws-waf-v5-8-0</link>
            <description>_What&apos;s new?_

- The `Approved &gt; Usage` policy for resource types will now default to `Approved` instead of `Approved if AWS &gt; {service} &gt; Enabled`.

_Bug fixes_

- Improved descriptions for various resource types to ensure they are clearer and more helpful.
- Fixed the AKA format for rule group v2 global and regional resource types.</description>
            <pubDate>Mon, 26 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-kubernetes-v5-2-2</guid>
            <title>servicenow-kubernetes v5.2.2 - Import Set controls will now not require permissions to read ServiceNow system tables</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-kubernetes-v5-2-2</link>
            <description>_Bug fixes_

- The `Import Set` controls will not require permissions to read the `sys_db_object` &amp; `sys_dictionary` tables in ServiceNow.</description>
            <pubDate>Fri, 23 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-storage-v5-3-2</guid>
            <title>servicenow-gcp-storage v5.3.2 - Import Set controls will now not require permissions to read ServiceNow system tables</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-storage-v5-3-2</link>
            <description>_Bug fixes_

- The `Import Set` controls will not require permissions to read the `sys_db_object` &amp; `sys_dictionary` tables in ServiceNow.</description>
            <pubDate>Fri, 23 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-computeengine-v5-2-2</guid>
            <title>servicenow-gcp-computeengine v5.2.2 - Import Set controls will now not require permissions to read ServiceNow system tables</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-computeengine-v5-2-2</link>
            <description>_Bug fixes_

- The `Import Set` controls will not require permissions to read the `sys_db_object` &amp; `sys_dictionary` tables in ServiceNow.</description>
            <pubDate>Fri, 23 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-v5-4-0</guid>
            <title>servicenow-gcp v5.4.0 - Added ServiceNow controls and policies for various resources</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-v5-4-0</link>
            <description>_Bug fixes_

- The `Import Set` controls will not require permissions to read the `sys_db_object` &amp; `sys_dictionary` tables in ServiceNow.

_Control Types_

- GCP &gt; Global Region &gt; ServiceNow
- GCP &gt; Global Region &gt; ServiceNow &gt; Configuration Item
- GCP &gt; Global Region &gt; ServiceNow &gt; Import Set
- GCP &gt; Global Region &gt; ServiceNow &gt; Table
- GCP &gt; Multi-Region &gt; ServiceNow
- GCP &gt; Multi-Region &gt; ServiceNow &gt; Configuration Item
- GCP &gt; Multi-Region &gt; ServiceNow &gt; Import Set
- GCP &gt; Multi-Region &gt; ServiceNow &gt; Table
- GCP &gt; Region &gt; ServiceNow
- GCP &gt; Region &gt; ServiceNow &gt; Configuration Item
- GCP &gt; Region &gt; ServiceNow &gt; Import Set
- GCP &gt; Region &gt; ServiceNow &gt; Table
- GCP &gt; Zone &gt; ServiceNow
- GCP &gt; Zone &gt; ServiceNow &gt; Configuration Item
- GCP &gt; Zone &gt; ServiceNow &gt; Import Set
- GCP &gt; Zone &gt; ServiceNow &gt; Table

_Policy Types_

- GCP &gt; Global Region &gt; ServiceNow
- GCP &gt; Global Region &gt; ServiceNow &gt; Configuration Item
- GCP &gt; Global Region &gt; ServiceNow &gt; Configuration Item &gt; Record
- GCP &gt; Global Region &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
- GCP &gt; Global Region &gt; ServiceNow &gt; Import Set
- GCP &gt; Global Region &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- GCP &gt; Global Region &gt; ServiceNow &gt; Import Set &gt; Record
- GCP &gt; Global Region &gt; ServiceNow &gt; Import Set &gt; Table Name
- GCP &gt; Global Region &gt; ServiceNow &gt; Table
- GCP &gt; Global Region &gt; ServiceNow &gt; Table &gt; Definition
- GCP &gt; Multi-Region &gt; ServiceNow
- GCP &gt; Multi-Region &gt; ServiceNow &gt; Configuration Item
- GCP &gt; Multi-Region &gt; ServiceNow &gt; Configuration Item &gt; Record
- GCP &gt; Multi-Region &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
- GCP &gt; Multi-Region &gt; ServiceNow &gt; Import Set
- GCP &gt; Multi-Region &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- GCP &gt; Multi-Region &gt; ServiceNow &gt; Import Set &gt; Record
- GCP &gt; Multi-Region &gt; ServiceNow &gt; Import Set &gt; Table Name
- GCP &gt; Multi-Region &gt; ServiceNow &gt; Table
- GCP &gt; Multi-Region &gt; ServiceNow &gt; Table &gt; Definition
- GCP &gt; Region &gt; ServiceNow
- GCP &gt; Region &gt; ServiceNow &gt; Configuration Item
- GCP &gt; Region &gt; ServiceNow &gt; Configuration Item &gt; Record
- GCP &gt; Region &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
- GCP &gt; Region &gt; ServiceNow &gt; Import Set
- GCP &gt; Region &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- GCP &gt; Region &gt; ServiceNow &gt; Import Set &gt; Record
- GCP &gt; Region &gt; ServiceNow &gt; Import Set &gt; Table Name
- GCP &gt; Region &gt; ServiceNow &gt; Table
- GCP &gt; Region &gt; ServiceNow &gt; Table &gt; Definition
- GCP &gt; Zone &gt; ServiceNow
- GCP &gt; Zone &gt; ServiceNow &gt; Configuration Item
- GCP &gt; Zone &gt; ServiceNow &gt; Configuration Item &gt; Record
- GCP &gt; Zone &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
- GCP &gt; Zone &gt; ServiceNow &gt; Import Set
- GCP &gt; Zone &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- GCP &gt; Zone &gt; ServiceNow &gt; Import Set &gt; Record
- GCP &gt; Zone &gt; ServiceNow &gt; Import Set &gt; Table Name
- GCP &gt; Zone &gt; ServiceNow &gt; Table
- GCP &gt; Zone &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Fri, 23 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-storage-v5-3-2</guid>
            <title>servicenow-azure-storage v5.3.2 - Import Set controls will now not require permissions to read ServiceNow system tables</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-storage-v5-3-2</link>
            <description>_Bug fixes_

- The `Import Set` controls will not require permissions to read the `sys_db_object` &amp; `sys_dictionary` tables in ServiceNow.</description>
            <pubDate>Fri, 23 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-network-v5-3-2</guid>
            <title>servicenow-azure-network v5.3.2 - Import Set controls will now not require permissions to read ServiceNow system tables</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-network-v5-3-2</link>
            <description>_Bug fixes_

- The `Import Set` controls will not require permissions to read the `sys_db_object` &amp; `sys_dictionary` tables in ServiceNow.</description>
            <pubDate>Fri, 23 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-compute-v5-1-2</guid>
            <title>servicenow-azure-compute v5.1.2 - Import Set controls will now not require permissions to read ServiceNow system tables</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-compute-v5-1-2</link>
            <description>_Bug fixes_

- The `Import Set` controls will not require permissions to read the `sys_db_object` &amp; `sys_dictionary` tables in ServiceNow.</description>
            <pubDate>Fri, 23 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-v5-3-3</guid>
            <title>servicenow-azure v5.3.3 - Import Set controls will now not require permissions to read ServiceNow system tables</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-v5-3-3</link>
            <description>_Bug fixes_

- The `Import Set` controls will not require permissions to read the `sys_db_object` &amp; `sys_dictionary` tables in ServiceNow.</description>
            <pubDate>Fri, 23 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-aws-s3-v5-1-2</guid>
            <title>servicenow-aws-s3 v5.1.2 - Import Set controls will now not require permissions to read ServiceNow system tables</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-aws-s3-v5-1-2</link>
            <description>_Bug fixes_

- The `Import Set` controls will not require permissions to read the `sys_db_object` &amp; `sys_dictionary` tables in ServiceNow.</description>
            <pubDate>Fri, 23 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-rds-v5-27-0</guid>
            <title>aws-rds v5.27.0 - Track and manage parameter groups for DB clusters</title>
            <link>https://turbot.com/guardrails/changelog/aws-rds-v5-27-0</link>
            <description>_What&apos;s new?_

- You can now configure parameter groups for DB clusters. To get started, set the `AWS &gt; RDS &gt; DB Cluster &gt; Parameter Group &gt; *` policies.

_Control Types_

- AWS &gt; RDS &gt; DB Cluster &gt; Parameter Group

_Policy Types_

- AWS &gt; RDS &gt; DB Cluster &gt; Parameter Group
- AWS &gt; RDS &gt; DB Cluster &gt; Parameter Group &gt; Name

_Action Types_

- AWS &gt; RDS &gt; DB Cluster &gt; Update Parameter Group

_Bug fixes_

- Improved descriptions for various resource types to ensure they are clearer and more helpful.</description>
            <pubDate>Fri, 23 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-computeengine-v5-19-1</guid>
            <title>gcp-computeengine v5.19.1 - CMDB control for the service resource type will no longer depend on the API Enabled policy being set to `Enforce: Enabled`</title>
            <link>https://turbot.com/guardrails/changelog/gcp-computeengine-v5-19-1</link>
            <description>_Bug fixes_

- The CMDB control for the service resource type will no longer depend on the API Enabled policy being set to `Enforce: Enabled` for the service.
- Improved descriptions for various resource types to ensure they are clearer and more helpful.</description>
            <pubDate>Thu, 22 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-45-5</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.45.5 - General improvements and bug fixes</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-45-5</link>
            <description>_Bug fixes_

- Server
  - Resolved an issue where policy values were not being terminated due to a race condition.
  - The ServiceNow credentials resolver will now display a clear message when the instance is hibernate or unavailable state.

- UI
  - Fixed an issue where filters on the Resource Explorer page were not functioning correctly.
  - The `Import` button on the Connect page has been updated to `Connect`.

_Requirements_

- TEF: 1.59.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Tue, 20 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-v5-25-1</guid>
            <title>gcp v5.25.1 - Updated various policies set during project imports to allow for a smoother import experience</title>
            <link>https://turbot.com/guardrails/changelog/gcp-v5-25-1</link>
            <description>_What&apos;s new?_

- We have updated various policies set during project imports to allow for a smoother import experience. We recommend upgrading your TE to v5.42.21 or higher to enable these changes to take effect.
- Improved descriptions for various resource types to ensure they are clearer and more helpful.</description>
            <pubDate>Mon, 19 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-kubernetesengine-v5-6-0</guid>
            <title>gcp-kubernetesengine v5.6.0 - Configure Master Authorized Networks for region and zone clusters</title>
            <link>https://turbot.com/guardrails/changelog/gcp-kubernetesengine-v5-6-0</link>
            <description>_What&apos;s new?_

- You can now configure Master Authorized Networks for region and zone clusters via Guardrails. To get started, set the `GCP &gt; Kubernetes Engine &gt; Region Cluster &gt; Master Authorized Networks Config` and `GCP &gt; Kubernetes Engine &gt; Zone Cluster &gt; Master Authorized Networks Config` policies respectively.

- Improved descriptions for various resource types to ensure they are clearer and more helpful.

_Control Types_

- GCP &gt; Kubernetes Engine &gt; Zone Cluster &gt; Master Authorized Networks Config

_Policy Types_

- GCP &gt; Kubernetes Engine &gt; Zone Cluster &gt; Master Authorized Networks Config

_Action Types_

- GCP &gt; Kubernetes Engine &gt; Region Cluster &gt; Set Desired Master Authorized Network Config
- GCP &gt; Kubernetes Engine &gt; Zone Cluster &gt; Set Desired Master Authorized Network Config</description>
            <pubDate>Mon, 19 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-v5-20-1</guid>
            <title>azure v5.20.1 - Updated various policies set during subscription imports to allow for a smoother import experience</title>
            <link>https://turbot.com/guardrails/changelog/azure-v5-20-1</link>
            <description>_What&apos;s new?_

- We have updated various policies set during subscription imports to allow for a smoother import experience. We recommend upgrading your TE to v5.42.21 or higher to enable these changes to take effect.
- Improved descriptions for various resource types to ensure they are clearer and more helpful.</description>
            <pubDate>Mon, 19 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-network-v5-18-0</guid>
            <title>azure-network v5.18.0 - Track and manage Private Link Service resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-network-v5-18-0</link>
            <description>_Bug fixes_

- Improved descriptions for various resource types to ensure they are clearer and more helpful.

_Resource Types_

- Azure &gt; Network &gt; Private Link Service

_Control Types_

- Azure &gt; Network &gt; Private Link Service &gt; Active
- Azure &gt; Network &gt; Private Link Service &gt; Approved
- Azure &gt; Network &gt; Private Link Service &gt; CMDB
- Azure &gt; Network &gt; Private Link Service &gt; Discovery
- Azure &gt; Network &gt; Private Link Service &gt; Tags

_Policy Types_

- Azure &gt; Network &gt; Private Link Service &gt; Active
- Azure &gt; Network &gt; Private Link Service &gt; Active &gt; Age
- Azure &gt; Network &gt; Private Link Service &gt; Active &gt; Last Modified
- Azure &gt; Network &gt; Private Link Service &gt; Approved
- Azure &gt; Network &gt; Private Link Service &gt; Approved &gt; Custom
- Azure &gt; Network &gt; Private Link Service &gt; Approved &gt; Regions
- Azure &gt; Network &gt; Private Link Service &gt; Approved &gt; Usage
- Azure &gt; Network &gt; Private Link Service &gt; CMDB
- Azure &gt; Network &gt; Private Link Service &gt; Regions
- Azure &gt; Network &gt; Private Link Service &gt; Tags
- Azure &gt; Network &gt; Private Link Service &gt; Tags &gt; Template

_Action Types_

- Azure &gt; Network &gt; Private Link Service &gt; Delete
- Azure &gt; Network &gt; Private Link Service &gt; Router
- Azure &gt; Network &gt; Private Link Service &gt; Set Tags</description>
            <pubDate>Fri, 16 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-s3-v5-27-0</guid>
            <title>aws-s3 v5.27.0 - Approved &gt; Usage policy will now default to Approved</title>
            <link>https://turbot.com/guardrails/changelog/aws-s3-v5-27-0</link>
            <description>_What&apos;s new?_

- The `Approved &gt; Usage` policy for resource types will now default to `Approved` instead of `Approved if AWS &gt; {service} &gt; Enabled`.

_Bug fixes_

- In version 5.25.0, we added support to ignore permission errors on a bucket via the CMDB policy `Enforce: Enabled but ignore permission errors`. However, the CMDB control previously ignored permission errors only on the `HeadBucket` operation and still entered an error state for permission errors on sub-API calls. The CMDB control will now ignore all sub-API calls if the `HeadBucket` operation is denied access. If the HeadBucket operation is successful, the control will attempt to make all sub-API calls and ignore access denied errors if encountered.</description>
            <pubDate>Fri, 16 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-provider-v5-12-0</guid>
            <title>azure-provider v5.12.0 - Track and manage Container Registry resource provider in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-provider-v5-12-0</link>
            <description>_What&apos;s new?_

- Improved descriptions for various resource types to ensure they are clearer and more helpful.

_Resource Types_

- Azure &gt; Provider &gt; Container Registry

_Control Types_

- Azure &gt; Provider &gt; Container Registry &gt; CMDB
- Azure &gt; Provider &gt; Container Registry &gt; Discovery
- Azure &gt; Provider &gt; Container Registry &gt; Registered

_Policy Types_

- Azure &gt; Provider &gt; Container Registry &gt; CMDB
- Azure &gt; Provider &gt; Container Registry &gt; Registered

_Action Types_

- Azure &gt; Provider &gt; Container Registry &gt; Set Registered</description>
            <pubDate>Wed, 14 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-containerregistry-v5-0-0</guid>
            <title>azure-containerregistry v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/azure-containerregistry-v5-0-0</link>
            <description>_Resource Types_

- Azure &gt; Container Registry
- Azure &gt; Container Registry &gt; Registry

_Control Types_

- Azure &gt; Container Registry &gt; Registry &gt; Active
- Azure &gt; Container Registry &gt; Registry &gt; Approved
- Azure &gt; Container Registry &gt; Registry &gt; CMDB
- Azure &gt; Container Registry &gt; Registry &gt; Discovery
- Azure &gt; Container Registry &gt; Registry &gt; Tags

_Policy Types_

- Azure &gt; Container Registry &gt; Approved Regions [Default]
- Azure &gt; Container Registry &gt; Enabled
- Azure &gt; Container Registry &gt; Permissions
- Azure &gt; Container Registry &gt; Permissions &gt; Levels
- Azure &gt; Container Registry &gt; Permissions &gt; Levels &gt; Modifiers
- Azure &gt; Container Registry &gt; Regions
- Azure &gt; Container Registry &gt; Registry &gt; Active
- Azure &gt; Container Registry &gt; Registry &gt; Active &gt; Age
- Azure &gt; Container Registry &gt; Registry &gt; Active &gt; Last Modified
- Azure &gt; Container Registry &gt; Registry &gt; Approved
- Azure &gt; Container Registry &gt; Registry &gt; Approved &gt; Custom
- Azure &gt; Container Registry &gt; Registry &gt; Approved &gt; Regions
- Azure &gt; Container Registry &gt; Registry &gt; Approved &gt; Usage
- Azure &gt; Container Registry &gt; Registry &gt; CMDB
- Azure &gt; Container Registry &gt; Registry &gt; Regions
- Azure &gt; Container Registry &gt; Registry &gt; Tags
- Azure &gt; Container Registry &gt; Registry &gt; Tags &gt; Template
- Azure &gt; Container Registry &gt; Tags Template [Default]
- Azure &gt; Turbot &gt; Permissions &gt; Compiled &gt; Levels &gt; @turbot/azure-containerregistry
- Azure &gt; Turbot &gt; Permissions &gt; Compiled &gt; Service Permissions &gt; @turbot/azure-containerregistry

_Action Types_

- Azure &gt; Container Registry &gt; Registry &gt; Delete
- Azure &gt; Container Registry &gt; Registry &gt; Router
- Azure &gt; Container Registry &gt; Registry &gt; Set Tags</description>
            <pubDate>Wed, 14 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-vpc-security-v5-11-0</guid>
            <title>aws-vpc-security v5.11.0 - Approved &gt; Usage policy will now default to Approved</title>
            <link>https://turbot.com/guardrails/changelog/aws-vpc-security-v5-11-0</link>
            <description>_What&apos;s new?_

- The `Approved &gt; Usage` policy for resource types will now default to `Approved` instead of `Approved if AWS &gt; {service} &gt; Enabled`.
- Improved descriptions for various resource types to ensure they are clearer and more helpful.

_Bug fixes_

- The `AWS &gt; VPC &gt; VPC &gt; Stack` control would sometimes go into an error state while upserting newly created flow logs in Guardrails due to incorrect mapping of its parent resource. This issue has now been fixed, and the control will upsert flow logs more consistently and reliably than before.</description>
            <pubDate>Wed, 14 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-bigquerydatatransfer-v5-0-2</guid>
            <title>gcp-bigquerydatatransfer v5.0.2 - CMDB control for the service resource type will no longer depend on the API Enabled policy being set to `Enforce: Enabled`</title>
            <link>https://turbot.com/guardrails/changelog/gcp-bigquerydatatransfer-v5-0-2</link>
            <description>_Bug fixes_

- The CMDB control for the service resource type will no longer depend on the API Enabled policy being set to `Enforce: Enabled` for the service.</description>
            <pubDate>Tue, 13 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/ted-v1-44-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.44.0 - Added support for Postgres versions 13.14, 13.15, 13.16, 14.11, 14.12, 14.13 and 15.8.</title>
            <link>https://turbot.com/guardrails/changelog/ted-v1-44-0</link>
            <description>_What&apos;s new?_

- Added support for Postgres versions 13.14, 13.15, 13.16, 14.11, 14.12, 14.13 and 15.8.
- Updated Default value for the RDS certificate to `rds-ca-rsa4096-g1`.</description>
            <pubDate>Tue, 13 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-managedidentity-v5-0-0</guid>
            <title>azure-managedidentity v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/azure-managedidentity-v5-0-0</link>
            <description>## 5.0.0 (2024-08-13)

_Resource Types_

- Azure &gt; Managed Identity
- Azure &gt; Managed Identity &gt; User Assigned Identity

_Control Types_

- Azure &gt; Managed Identity &gt; User Assigned Identity &gt; Active
- Azure &gt; Managed Identity &gt; User Assigned Identity &gt; Approved
- Azure &gt; Managed Identity &gt; User Assigned Identity &gt; CMDB
- Azure &gt; Managed Identity &gt; User Assigned Identity &gt; Discovery
- Azure &gt; Managed Identity &gt; User Assigned Identity &gt; Tags

_Policy Types_

- Azure &gt; Managed Identity &gt; Approved Regions [Default]
- Azure &gt; Managed Identity &gt; Enabled
- Azure &gt; Managed Identity &gt; Permissions
- Azure &gt; Managed Identity &gt; Permissions &gt; Levels
- Azure &gt; Managed Identity &gt; Permissions &gt; Levels &gt; Modifiers
- Azure &gt; Managed Identity &gt; Regions
- Azure &gt; Managed Identity &gt; Tags Template [Default]
- Azure &gt; Managed Identity &gt; User Assigned Identity &gt; Active
- Azure &gt; Managed Identity &gt; User Assigned Identity &gt; Active &gt; Age
- Azure &gt; Managed Identity &gt; User Assigned Identity &gt; Active &gt; Last Modified
- Azure &gt; Managed Identity &gt; User Assigned Identity &gt; Approved
- Azure &gt; Managed Identity &gt; User Assigned Identity &gt; Approved &gt; Custom
- Azure &gt; Managed Identity &gt; User Assigned Identity &gt; Approved &gt; Regions
- Azure &gt; Managed Identity &gt; User Assigned Identity &gt; Approved &gt; Usage
- Azure &gt; Managed Identity &gt; User Assigned Identity &gt; CMDB
- Azure &gt; Managed Identity &gt; User Assigned Identity &gt; Regions
- Azure &gt; Managed Identity &gt; User Assigned Identity &gt; Tags
- Azure &gt; Managed Identity &gt; User Assigned Identity &gt; Tags &gt; Template
- Azure &gt; Turbot &gt; Permissions &gt; Compiled &gt; Levels &gt; @turbot/azure-managedidentity
- Azure &gt; Turbot &gt; Permissions &gt; Compiled &gt; Service Permissions &gt; @turbot/azure-managedidentity

_Action Types_

- Azure &gt; Managed Identity &gt; User Assigned Identity &gt; Delete
- Azure &gt; Managed Identity &gt; User Assigned Identity &gt; Router
- Azure &gt; Managed Identity &gt; User Assigned Identity &gt; Set Tags</description>
            <pubDate>Tue, 13 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-v5-30-3</guid>
            <title>aws v5.30.3 - AWS &gt; Turbot &gt; Logging &gt; Bucket control will now set AWS SSE encryption by default for buckets</title>
            <link>https://turbot.com/guardrails/changelog/aws-v5-30-3</link>
            <description>_What&apos;s new?_

- The `AWS &gt; Turbot &gt; Logging &gt; Bucket &gt; Default Encryption` policy is now deprecated because all buckets are now encrypted by default in AWS. As a result, all buckets created and managed via the `AWS &gt; Turbot &gt; Logging &gt; Bucket` stack control will now be encrypted by `AWS SSE` by default. We&apos;ve also removed ACL settings for buckets and now apply bucket ownership controls instead via the stack control to align with the latest AWS recommendations. Please upgrade the `@turbot/aws-s3` mod to v5.26.0 for the stack control to work reliably as before.
- Improved descriptions for various resource types to ensure they are clearer and more helpful.

_Policy Types_

_Renamed_

- AWS &gt; Turbot &gt; Logging &gt; Bucket &gt; Default Encryption to AWS &gt; Turbot &gt; Logging &gt; Bucket &gt; Default Encryption [Deprecated]</description>
            <pubDate>Mon, 12 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-s3-v5-26-0</guid>
            <title>aws-s3 v5.26.0 - Added support for aws_s3_bucket_ownership_controls Terraform resource for buckets</title>
            <link>https://turbot.com/guardrails/changelog/aws-s3-v5-26-0</link>
            <description>_What&apos;s new?_

- Added support for `aws_s3_bucket_ownership_controls` Terraform resource for buckets.
- Improved descriptions for various resource types to ensure they are clearer and more helpful.</description>
            <pubDate>Mon, 12 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-robomaker-v5-4-0</guid>
            <title>aws-robomaker v5.4.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-robomaker-v5-4-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.</description>
            <pubDate>Fri, 09 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-config-v5-9-0</guid>
            <title>aws-config v5.9.0 - Configure Terraform version for the Configuration Recording stack control</title>
            <link>https://turbot.com/guardrails/changelog/aws-config-v5-9-0</link>
            <description>_What&apos;s new?_

- Users can now configure the Terraform version for the `AWS &gt; Config &gt; Configuration Recording` stack control. To get started, set the `AWS &gt; Config &gt; Configuration Recording &gt; Terraform Version` policy. We recommend using versions 0.11, 0.12, or 0.15 for this control to create and manage resources effectively and reliably.

_Policy Types_

- AWS &gt; Config &gt; Configuration Recording &gt; Terraform Version</description>
            <pubDate>Fri, 09 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-v5-25-0</guid>
            <title>gcp v5.25.0 - Create and manage labels for topics created via the GCP &gt; Turbot &gt; Event Handlers &gt; Pub/Sub control</title>
            <link>https://turbot.com/guardrails/changelog/gcp-v5-25-0</link>
            <description>_What&apos;s new?_

- Users can now create and manage labels on Pub/Sub topics created via the `GCP &gt; Turbot &gt; Event Handlers &gt; Pub/Sub` control. To get started, set the `GCP &gt; Turbot &gt; Event Handlers &gt; Pub/Sub &gt; Topic &gt; Labels` policy.

_Policy Types_

- GCP &gt; Turbot &gt; Event Handlers &gt; Pub/Sub &gt; Subscription &gt; Labels &gt; Ignore Changes
- GCP &gt; Turbot &gt; Event Handlers &gt; Pub/Sub &gt; Topic &gt; Labels
- GCP &gt; Turbot &gt; Event Handlers &gt; Pub/Sub &gt; Topic &gt; Labels &gt; Ignore Changes</description>
            <pubDate>Thu, 08 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-vpc-security-v5-10-1</guid>
            <title>aws-vpc-security v5.10.1 - Guardrails failed to cleanup deleted security group rules via the real-time `ec2:RevokeSecurityGroupEgress` and `ec2:RevokeSecurityGroupIngress` events</title>
            <link>https://turbot.com/guardrails/changelog/aws-vpc-security-v5-10-1</link>
            <description>_Bug fixes_

- Guardrails failed to cleanup deleted security group rules via the real-time `ec2:RevokeSecurityGroupEgress` and `ec2:RevokeSecurityGroupIngress` events. This issue is now fixed.</description>
            <pubDate>Wed, 07 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-v5-30-2</guid>
            <title>aws v5.30.2 - The Event Handlers control did not correctly raise the real-time `CreateTags` and `DeleteTags` events for VPC security group rules</title>
            <link>https://turbot.com/guardrails/changelog/aws-v5-30-2</link>
            <description>_Bug fixes_

- The `AWS &gt; Turbot &gt; Event Handlers` control did not correctly raise the real-time `CreateTags` and `DeleteTags` events for VPC security group rules. This issue is now fixed.</description>
            <pubDate>Wed, 07 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-network-v5-14-0</guid>
            <title>gcp-network v5.14.0 - Configure Flow Logging for Subnetworks</title>
            <link>https://turbot.com/guardrails/changelog/gcp-network-v5-14-0</link>
            <description>_What&apos;s new?_

- Users can now configure flow logging for subnetworks. To get started, set the `GCP &gt; Network &gt; Subnetwork &gt; Flow Log` policy.

_Control Types_

- GCP &gt; Network &gt; Subnetwork &gt; Flow Log

_Policy Types_

- GCP &gt; Network &gt; Subnetwork &gt; Flow Log

_Action Types_

- GCP &gt; Network &gt; Subnetwork &gt; Set Flow Log</description>
            <pubDate>Tue, 06 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-memorystore-v5-3-0</guid>
            <title>gcp-memorystore v5.3.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/gcp-memorystore-v5-3-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.</description>
            <pubDate>Tue, 06 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-provider-v5-11-0</guid>
            <title>azure-provider v5.11.0 - Track and manage Elastic and Managed Identity resource providers in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-provider-v5-11-0</link>
            <description>_Resource Types_

- Azure &gt; Provider &gt; Elastic
- Azure &gt; Provider &gt; Managed Identity

_Control Types_

- Azure &gt; Provider &gt; Elastic &gt; CMDB
- Azure &gt; Provider &gt; Elastic &gt; Discovery
- Azure &gt; Provider &gt; Elastic &gt; Registered
- Azure &gt; Provider &gt; Managed Identity &gt; CMDB
- Azure &gt; Provider &gt; Managed Identity &gt; Discovery
- Azure &gt; Provider &gt; Managed Identity &gt; Registered

_Policy Types_

- Azure &gt; Provider &gt; Elastic &gt; CMDB
- Azure &gt; Provider &gt; Elastic &gt; Registered
- Azure &gt; Provider &gt; Managed Identity &gt; CMDB
- Azure &gt; Provider &gt; Managed Identity &gt; Registered

_Action Types_

- Azure &gt; Provider &gt; Elastic &gt; Set Registered
- Azure &gt; Provider &gt; Managed Identity &gt; Set Registered</description>
            <pubDate>Tue, 06 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-run-v5-1-0</guid>
            <title>gcp-run v5.1.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/gcp-run-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.</description>
            <pubDate>Mon, 05 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-iam-v5-16-0</guid>
            <title>gcp-iam v5.16.0 - Disable inactive or unapproved service accounts via Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/gcp-iam-v5-16-0</link>
            <description>_What&apos;s new?_

- You can now disable inactive or unapproved service accounts via Guardrails. To get started, set the `GCP &gt; IAM &gt; Service Account &gt; Active` or `GCP &gt; IAM &gt; Service Account &gt; Approved` policy to `Enforce: Disable inactive with &lt;x&gt; days warning` or `Enforce: Disable unapproved` respectively.

_Action Types_

- GCP &gt; IAM &gt; Service Account &gt; Disable</description>
            <pubDate>Mon, 05 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-servicebus-v5-1-0</guid>
            <title>azure-servicebus v5.1.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/azure-servicebus-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.</description>
            <pubDate>Mon, 05 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-applicationinsights-v5-7-0</guid>
            <title>azure-applicationinsights v5.7.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/azure-applicationinsights-v5-7-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.</description>
            <pubDate>Mon, 05 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-secretmanager-v5-1-0</guid>
            <title>aws-secretmanager v5.1.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-secretmanager-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.</description>
            <pubDate>Mon, 05 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ram-v5-3-0</guid>
            <title>aws-ram v5.3.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-ram-v5-3-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.</description>
            <pubDate>Mon, 05 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ecr-v5-13-1</guid>
            <title>aws-ecr v5.13.1 - The Repository CMDB control went into an error state for shared repositories upserted incorrectly in Guardrails CMDB</title>
            <link>https://turbot.com/guardrails/changelog/aws-ecr-v5-13-1</link>
            <description>_Bug fixes_

- The `AWS &gt; ECR &gt; Repository &gt; CMDB` control went into an error state for shared repositories upserted incorrectly in Guardrails CMDB. Shared repositories will now not be upserted under shared accounts or regions, but will only be upserted under their owner accounts and regions.</description>
            <pubDate>Mon, 05 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ec2-v5-41-3</guid>
            <title>aws-ec2 v5.41.3 - Guardrails will now process `ec2:CreateReplaceRootVolumeTask` real-time event for instances</title>
            <link>https://turbot.com/guardrails/changelog/aws-ec2-v5-41-3</link>
            <description>_Bug fixes_

- Guardrails failed to process the real-time event `ec2:CreateReplaceRootVolumeTask` for instances. This is now fixed.</description>
            <pubDate>Mon, 05 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-45-4</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.45.4 - Performance enhancements and UI improvements</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-45-4</link>
            <description>_What&apos;s new?_

- Server
  - Made notifications faster by improving the query, which enhances the performance of the resource activity tab.

- UI
  - Fixed a bug where policy pack creation would fail if the AKA was not provided from the user interface.

_Requirements_

- TEF: 1.59.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Fri, 02 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-v5-3-2</guid>
            <title>servicenow-azure v5.3.2 - Bug fixed - Configuration Item control for resource group will now process data correctly in ServiceNow</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-v5-3-2</link>
            <description>_Bug fixes_

- The `Azure &gt; Resource Group &gt; ServiceNow &gt; Configuration Item` control would fail to fetch instance credentials internally and did not process the data correctly in ServiceNow. This issue has now been fixed.</description>
            <pubDate>Fri, 02 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-kubernetes-v5-2-1</guid>
            <title>servicenow-kubernetes v5.2.1 - Bug fixed - Import Set control will now convert JSON objects to correct format so that they are stored reliably and consistently in ServiceNow</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-kubernetes-v5-2-1</link>
            <description>_Bug fixes_

- The Import Set control for various resources would push JSON objects to ServiceNow without converting them to strings. This would result in ServiceNow reading those JSON objects in an incorrect format. The Import Set control will now convert such JSON objects to strings so that they are stored reliably and consistently in ServiceNow.</description>
            <pubDate>Thu, 01 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-storage-v5-3-1</guid>
            <title>servicenow-gcp-storage v5.3.1 - Bug fixed - Import Set control will now convert JSON objects to correct format so that they are stored reliably and consistently in ServiceNow</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-storage-v5-3-1</link>
            <description>_Bug fixes_

- The Import Set control for various resources would push JSON objects to ServiceNow without converting them to strings. This would result in ServiceNow reading those JSON objects in an incorrect format. The Import Set control will now convert such JSON objects to strings so that they are stored reliably and consistently in ServiceNow.</description>
            <pubDate>Thu, 01 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-computeengine-v5-2-1</guid>
            <title>servicenow-gcp-computeengine v5.2.1 - Bug fixed - Import Set control will now convert JSON objects to correct format so that they are stored reliably and consistently in ServiceNow</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-computeengine-v5-2-1</link>
            <description>_Bug fixes_

- The Import Set control for various resources would push JSON objects to ServiceNow without converting them to strings. This would result in ServiceNow reading those JSON objects in an incorrect format. The Import Set control will now convert such JSON objects to strings so that they are stored reliably and consistently in ServiceNow.</description>
            <pubDate>Thu, 01 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-v5-3-0</guid>
            <title>servicenow-gcp v5.3.0 - Added Project &gt; ServiceNow &gt; Import Set control and policies</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-v5-3-0</link>
            <description>_Control Types_

- GCP &gt; Project &gt; ServiceNow &gt; Import Set

_Policy Types_

- GCP &gt; Project &gt; ServiceNow &gt; Import Set
- GCP &gt; Project &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- GCP &gt; Project &gt; ServiceNow &gt; Import Set &gt; Record
- GCP &gt; Project &gt; ServiceNow &gt; Import Set &gt; Table Name</description>
            <pubDate>Thu, 01 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-storage-v5-3-1</guid>
            <title>servicenow-azure-storage v5.3.1 - Bug fixed - Import Set control will now convert JSON objects to correct format so that they are stored reliably and consistently in ServiceNow</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-storage-v5-3-1</link>
            <description>_Bug fixes_

- The Import Set control for various resources would push JSON objects to ServiceNow without converting them to strings. This would result in ServiceNow reading those JSON objects in an incorrect format. The Import Set control will now convert such JSON objects to strings so that they are stored reliably and consistently in ServiceNow.</description>
            <pubDate>Thu, 01 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-network-v5-3-1</guid>
            <title>servicenow-azure-network v5.3.1 - Bug fixed - Import Set control will now convert JSON objects to correct format so that they are stored reliably and consistently in ServiceNow</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-network-v5-3-1</link>
            <description>_Bug fixes_

- The Import Set control for various resources would push JSON objects to ServiceNow without converting them to strings. This would result in ServiceNow reading those JSON objects in an incorrect format. The Import Set control will now convert such JSON objects to strings so that they are stored reliably and consistently in ServiceNow.</description>
            <pubDate>Thu, 01 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-compute-v5-1-1</guid>
            <title>servicenow-azure-compute v5.1.1 - Bug fixed - Import Set control will now convert JSON objects to correct format so that they are stored reliably and consistently in ServiceNow</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-compute-v5-1-1</link>
            <description>_Bug fixes_

- The Import Set control for various resources would push JSON objects to ServiceNow without converting them to strings. This would result in ServiceNow reading those JSON objects in an incorrect format. The Import Set control will now convert such JSON objects to strings so that they are stored reliably and consistently in ServiceNow.</description>
            <pubDate>Thu, 01 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-v5-3-1</guid>
            <title>servicenow-azure v5.3.1 - Bug fixed - Import Set control will now convert JSON objects to correct format so that they are stored reliably and consistently in ServiceNow</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-v5-3-1</link>
            <description>_Bug fixes_

- The Import Set control for various resources would push JSON objects to ServiceNow without converting them to strings. This would result in ServiceNow reading those JSON objects in an incorrect format. The Import Set control will now convert such JSON objects to strings so that they are stored reliably and consistently in ServiceNow.</description>
            <pubDate>Thu, 01 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-aws-s3-v5-1-1</guid>
            <title>servicenow-aws-s3 v5.1.1 - Bug fixed - Import Set control will now convert JSON objects to correct format so that they are stored reliably and consistently in ServiceNow</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-aws-s3-v5-1-1</link>
            <description>_Bug fixes_

- The Import Set control for various resources would push JSON objects to ServiceNow without converting them to strings. This would result in ServiceNow reading those JSON objects in an incorrect format. The Import Set control will now convert such JSON objects to strings so that they are stored reliably and consistently in ServiceNow.</description>
            <pubDate>Thu, 01 Aug 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/ted-v1-43-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.43.0 - Added support for Postgres versions 15.6 and 15.7</title>
            <link>https://turbot.com/guardrails/changelog/ted-v1-43-0</link>
            <description>_What&apos;s new?_

- Added support for Postgres versions 15.6 and 15.7.</description>
            <pubDate>Wed, 31 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-v5-20-0</guid>
            <title>azure v5.20.0 - Updated internal dependencies to use the latest Azure SDK versions to poll events from Azure Monitor and process them in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-v5-20-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated internal dependencies and now use the latest Azure SDK versions to poll events from Azure Monitor and process them in Guardrails. You won&apos;t notice any difference, and things will continue to work smoothly as before.</description>
            <pubDate>Wed, 31 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-dynamodb-v5-11-0</guid>
            <title>aws-dynamodb v5.11.0 - `AWS/DynamoDB/Admin`, `AWS/DynamoDB/Metadata` and `AWS/DynamoDB/Operator` now include permissions for Resource Policy, Imports, Time to Live and Global Table Version</title>
            <link>https://turbot.com/guardrails/changelog/aws-dynamodb-v5-11-0</link>
            <description>_What&apos;s new?_

- `AWS/DynamoDB/Admin`, `AWS/DynamoDB/Metadata` and `AWS/DynamoDB/Operator` now include permissions for Resource Policy, Imports, Time to Live and Global Table Version.</description>
            <pubDate>Wed, 31 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-network-v5-3-0</guid>
            <title>servicenow-azure-network v5.3.0 - Added Network Security Group &gt; ServiceNow &gt; Import Set control and policies</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-network-v5-3-0</link>
            <description>_What&apos;s new?_

_Control Types_

- Azure &gt; Network &gt; Network Security Group &gt; ServiceNow &gt; Import Set

_Policy Types_

- Azure &gt; Network &gt; Network Security Group &gt; ServiceNow &gt; Import Set
- Azure &gt; Network &gt; Network Security Group &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- Azure &gt; Network &gt; Network Security Group &gt; ServiceNow &gt; Import Set &gt; Record
- Azure &gt; Network &gt; Network Security Group &gt; ServiceNow &gt; Import Set &gt; Table Name</description>
            <pubDate>Tue, 30 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-v5-3-0</guid>
            <title>servicenow-azure v5.3.0 - Added Subscription &gt; ServiceNow &gt; Import Set control and policies</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-v5-3-0</link>
            <description>_What&apos;s new?_

_Control Types_

- Azure &gt; Subscription &gt; ServiceNow &gt; Import Set

_Policy Types_

- Azure &gt; Subscription &gt; ServiceNow &gt; Import Set
- Azure &gt; Subscription &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- Azure &gt; Subscription &gt; ServiceNow &gt; Import Set &gt; Record
- Azure &gt; Subscription &gt; ServiceNow &gt; Import Set &gt; Table Name</description>
            <pubDate>Tue, 30 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-storage-v5-19-0</guid>
            <title>azure-storage v5.19.0 - Enable Encryption at Rest and table logging for storage accounts</title>
            <link>https://turbot.com/guardrails/changelog/azure-storage-v5-19-0</link>
            <description>_What&apos;s new?_

- Users can now enable/disable `Table logging` for `Storage Accounts` via `Azure &gt; Storage &gt; Storage Account &gt; Table &gt; Logging` control. To get started, set the `Azure &gt; Storage &gt; Storage Account &gt; Table &gt; Logging` policy.

_Control Types_

- Azure &gt; Storage &gt; Storage Account &gt; Encryption at Rest
- Azure &gt; Storage &gt; Storage Account &gt; Table
- Azure &gt; Storage &gt; Storage Account &gt; Table &gt; Logging

_Policy Types_

- Azure &gt; Storage &gt; Storage Account &gt; Encryption at Rest
- Azure &gt; Storage &gt; Storage Account &gt; Encryption at Rest &gt; Customer Managed Key
- Azure &gt; Storage &gt; Storage Account &gt; Table
- Azure &gt; Storage &gt; Storage Account &gt; Table &gt; Logging
- Azure &gt; Storage &gt; Storage Account &gt; Table &gt; Logging &gt; Properties
- Azure &gt; Storage &gt; Storage Account &gt; Table &gt; Logging &gt; Retention Days

_Action Types_

- Azure &gt; Storage &gt; Storage Account &gt; Update Encryption at Rest
- Azure &gt; Storage &gt; Storage Account &gt; Update Storage Account Table Logging

- The Storage Account CMDB data will now also include information about the account&apos;s table service properties.

- We&apos;ve removed the dependency on `listKeys` permission for `Azure &gt; Storage Account &gt; Container &gt; Discovery` to run its course to completion. This release includes breaking changes in the CMDB data for containers. We recommend updating your existing policy settings to refer to the updated attributes as mentioned below.

Renamed:
`isImmutableStorageWithVersioningEnabled` to `isImmutableStorageWithVersioning.enabled`

Removed:
`preventEncryptionScopeOverride`

_Bug fixes_

- The `Azure &gt; Storage &gt; Storage Account &gt; CMDB` control would go into an error state while trying to fetch default Queue and Blob properties if Guardrails did not have permission to list the storage account keys. The control will now not attempt to fetch default Queue and Blob properties if Guardrails does not have the required access for `listKeys`, and will run its course to completion without going into an error state.</description>
            <pubDate>Tue, 30 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-s3-v5-25-1</guid>
            <title>aws-s3 v5.25.1 - Bug fixed - Improved error message for the bucket CMDB control when it would go to error state due to insufficient permissions for the `headBucket` operation</title>
            <link>https://turbot.com/guardrails/changelog/aws-s3-v5-25-1</link>
            <description>_Bug fixes_

- Improved error message for the `AWS &gt; S3 &gt; Bucket &gt; CMDB` control if it would go into an error state due to insufficient permissions for the `headBucket` operation.</description>
            <pubDate>Tue, 30 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-46-0</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.46.0 - Upgraded from Node.js 18 to Node.js 20</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-46-0</link>
            <description>_What&apos;s new?_

- Server
  - Migrated from Node.js 18 to Node.js 20 for improved performance and security.
  - Updated the Mod Lambda architecture to ARM64 for better efficiency.
  - Added support for Node.js 20 in the Lambda runtime.

_Bug fixes_

- Server
  - Resolved an issue where the next tick timestamp was not being set for large commands

_Requirements_

- TEF: 1.59.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Mon, 29 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-45-3</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.45.3 - Resolved UI deletion issue for Policy Packs with latest Turbot Mod and TE 5.45.0</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-45-3</link>
            <description>_Bug fixes_

- UI
  - Resolved deletion issue from UI for Policy Packs with latest Turbot Mod(5.45.0) and TE 5.45.0.

_Requirements_

- TEF: 1.59.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Mon, 29 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-45-2</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.45.2 - Minor internal improvements</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-45-2</link>
            <description>_Bug fixes_

- Server
  - Minor internal improvements.

_Requirements_

- TEF: 1.59.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Mon, 29 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-kubernetes-v5-2-0</guid>
            <title>servicenow-kubernetes v5.2.0 - Added support for new Kubernetes resource types</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-kubernetes-v5-2-0</link>
            <description>_What&apos;s new?_

_Control Types_

- Kubernetes &gt; CronJob &gt; ServiceNow
- Kubernetes &gt; CronJob &gt; ServiceNow &gt; Configuration Item
- Kubernetes &gt; CronJob &gt; ServiceNow &gt; Table
- Kubernetes &gt; DaemonSet &gt; ServiceNow
- Kubernetes &gt; DaemonSet &gt; ServiceNow &gt; Configuration Item
- Kubernetes &gt; DaemonSet &gt; ServiceNow &gt; Table
- Kubernetes &gt; Ingress &gt; ServiceNow
- Kubernetes &gt; Ingress &gt; ServiceNow &gt; Configuration Item
- Kubernetes &gt; Ingress &gt; ServiceNow &gt; Table
- Kubernetes &gt; Job &gt; ServiceNow
- Kubernetes &gt; Job &gt; ServiceNow &gt; Configuration Item
- Kubernetes &gt; Job &gt; ServiceNow &gt; Table
- Kubernetes &gt; Persistent Volume &gt; ServiceNow
- Kubernetes &gt; Persistent Volume &gt; ServiceNow &gt; Configuration Item
- Kubernetes &gt; Persistent Volume &gt; ServiceNow &gt; Table
- Kubernetes &gt; ReplicationController &gt; ServiceNow
- Kubernetes &gt; ReplicationController &gt; ServiceNow &gt; Configuration Item
- Kubernetes &gt; ReplicationController &gt; ServiceNow &gt; Table
- Kubernetes &gt; StatefulSet &gt; ServiceNow
- Kubernetes &gt; StatefulSet &gt; ServiceNow &gt; Configuration Item
- Kubernetes &gt; StatefulSet &gt; ServiceNow &gt; Table

_Policy Types_

- Kubernetes &gt; CronJob &gt; ServiceNow
- Kubernetes &gt; CronJob &gt; ServiceNow &gt; Configuration Item
- Kubernetes &gt; CronJob &gt; ServiceNow &gt; Configuration Item &gt; Record
- Kubernetes &gt; CronJob &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
- Kubernetes &gt; CronJob &gt; ServiceNow &gt; Table
- Kubernetes &gt; CronJob &gt; ServiceNow &gt; Table &gt; Definition
- Kubernetes &gt; DaemonSet &gt; ServiceNow
- Kubernetes &gt; DaemonSet &gt; ServiceNow &gt; Configuration Item
- Kubernetes &gt; DaemonSet &gt; ServiceNow &gt; Configuration Item &gt; Record
- Kubernetes &gt; DaemonSet &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
- Kubernetes &gt; DaemonSet &gt; ServiceNow &gt; Table
- Kubernetes &gt; DaemonSet &gt; ServiceNow &gt; Table &gt; Definition
- Kubernetes &gt; Ingress &gt; ServiceNow
- Kubernetes &gt; Ingress &gt; ServiceNow &gt; Configuration Item
- Kubernetes &gt; Ingress &gt; ServiceNow &gt; Configuration Item &gt; Record
- Kubernetes &gt; Ingress &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
- Kubernetes &gt; Ingress &gt; ServiceNow &gt; Table
- Kubernetes &gt; Ingress &gt; ServiceNow &gt; Table &gt; Definition
- Kubernetes &gt; Job &gt; ServiceNow
- Kubernetes &gt; Job &gt; ServiceNow &gt; Configuration Item
- Kubernetes &gt; Job &gt; ServiceNow &gt; Configuration Item &gt; Record
- Kubernetes &gt; Job &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
- Kubernetes &gt; Job &gt; ServiceNow &gt; Table
- Kubernetes &gt; Job &gt; ServiceNow &gt; Table &gt; Definition
- Kubernetes &gt; Persistent Volume &gt; ServiceNow
- Kubernetes &gt; Persistent Volume &gt; ServiceNow &gt; Configuration Item
- Kubernetes &gt; Persistent Volume &gt; ServiceNow &gt; Configuration Item &gt; Record
- Kubernetes &gt; Persistent Volume &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
- Kubernetes &gt; Persistent Volume &gt; ServiceNow &gt; Table
- Kubernetes &gt; Persistent Volume &gt; ServiceNow &gt; Table &gt; Definition
- Kubernetes &gt; ReplicationController &gt; ServiceNow
- Kubernetes &gt; ReplicationController &gt; ServiceNow &gt; Configuration Item
- Kubernetes &gt; ReplicationController &gt; ServiceNow &gt; Configuration Item &gt; Record
- Kubernetes &gt; ReplicationController &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
- Kubernetes &gt; ReplicationController &gt; ServiceNow &gt; Table
- Kubernetes &gt; ReplicationController &gt; ServiceNow &gt; Table &gt; Definition
- Kubernetes &gt; StatefulSet &gt; ServiceNow
- Kubernetes &gt; StatefulSet &gt; ServiceNow &gt; Configuration Item
- Kubernetes &gt; StatefulSet &gt; ServiceNow &gt; Configuration Item &gt; Record
- Kubernetes &gt; StatefulSet &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
- Kubernetes &gt; StatefulSet &gt; ServiceNow &gt; Table
- Kubernetes &gt; StatefulSet &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Fri, 26 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/kubernetes-v5-1-0</guid>
            <title>kubernetes v5.1.0 - Added support for new Kubernetes resource types</title>
            <link>https://turbot.com/guardrails/changelog/kubernetes-v5-1-0</link>
            <description>_What&apos;s new?_

_Resource Types_

- Kubernetes &gt; CronJob
- Kubernetes &gt; DaemonSet
- Kubernetes &gt; Ingress
- Kubernetes &gt; Job
- Kubernetes &gt; Persistent Volume
- Kubernetes &gt; ReplicationController
- Kubernetes &gt; StatefulSet

_Control Types_

- Kubernetes &gt; ConfigMap &gt; Active
- Kubernetes &gt; CronJob &gt; Active
- Kubernetes &gt; CronJob &gt; Annotations
- Kubernetes &gt; CronJob &gt; Approved
- Kubernetes &gt; CronJob &gt; CMDB
- Kubernetes &gt; CronJob &gt; Labels
- Kubernetes &gt; CronJob &gt; Query
- Kubernetes &gt; DaemonSet &gt; Active
- Kubernetes &gt; DaemonSet &gt; Annotations
- Kubernetes &gt; DaemonSet &gt; Approved
- Kubernetes &gt; DaemonSet &gt; CMDB
- Kubernetes &gt; DaemonSet &gt; Labels
- Kubernetes &gt; DaemonSet &gt; Query
- Kubernetes &gt; Deployment &gt; Active
- Kubernetes &gt; Ingress &gt; Active
- Kubernetes &gt; Ingress &gt; Annotations
- Kubernetes &gt; Ingress &gt; Approved
- Kubernetes &gt; Ingress &gt; CMDB
- Kubernetes &gt; Ingress &gt; Labels
- Kubernetes &gt; Ingress &gt; Query
- Kubernetes &gt; Job &gt; Active
- Kubernetes &gt; Job &gt; Annotations
- Kubernetes &gt; Job &gt; Approved
- Kubernetes &gt; Job &gt; CMDB
- Kubernetes &gt; Job &gt; Labels
- Kubernetes &gt; Job &gt; Query
- Kubernetes &gt; Namespace &gt; Active
- Kubernetes &gt; Node &gt; Active
- Kubernetes &gt; Persistent Volume &gt; Active
- Kubernetes &gt; Persistent Volume &gt; Annotations
- Kubernetes &gt; Persistent Volume &gt; Approved
- Kubernetes &gt; Persistent Volume &gt; CMDB
- Kubernetes &gt; Persistent Volume &gt; Labels
- Kubernetes &gt; Persistent Volume &gt; Query
- Kubernetes &gt; Pod &gt; Active
- Kubernetes &gt; ReplicaSet &gt; Active
- Kubernetes &gt; ReplicationController &gt; Active
- Kubernetes &gt; ReplicationController &gt; Annotations
- Kubernetes &gt; ReplicationController &gt; Approved
- Kubernetes &gt; ReplicationController &gt; CMDB
- Kubernetes &gt; ReplicationController &gt; Labels
- Kubernetes &gt; ReplicationController &gt; Query
- Kubernetes &gt; Service &gt; Active
- Kubernetes &gt; StatefulSet &gt; Active
- Kubernetes &gt; StatefulSet &gt; Annotations
- Kubernetes &gt; StatefulSet &gt; Approved
- Kubernetes &gt; StatefulSet &gt; CMDB
- Kubernetes &gt; StatefulSet &gt; Labels
- Kubernetes &gt; StatefulSet &gt; Query

_Policy Types_

- Kubernetes &gt; Cluster &gt; CMDB &gt; Expiration
- Kubernetes &gt; Cluster &gt; CMDB &gt; Expiration &gt; Expiration Days
- Kubernetes &gt; Cluster &gt; osquery
- Kubernetes &gt; Cluster &gt; osquery &gt; Configuration
- Kubernetes &gt; ConfigMap &gt; Active
- Kubernetes &gt; ConfigMap &gt; Active &gt; Age
- Kubernetes &gt; ConfigMap &gt; Active &gt; Last Modified
- Kubernetes &gt; CronJob &gt; Active
- Kubernetes &gt; CronJob &gt; Active &gt; Age
- Kubernetes &gt; CronJob &gt; Active &gt; Last Modified
- Kubernetes &gt; CronJob &gt; Annotations
- Kubernetes &gt; CronJob &gt; Annotations &gt; Template
- Kubernetes &gt; CronJob &gt; Approved
- Kubernetes &gt; CronJob &gt; Approved &gt; Custom
- Kubernetes &gt; CronJob &gt; CMDB
- Kubernetes &gt; CronJob &gt; Labels
- Kubernetes &gt; CronJob &gt; Labels &gt; Template
- Kubernetes &gt; CronJob &gt; osquery
- Kubernetes &gt; CronJob &gt; osquery &gt; Configuration
- Kubernetes &gt; CronJob &gt; osquery &gt; Configuration &gt; Columns
- Kubernetes &gt; CronJob &gt; osquery &gt; Configuration &gt; Interval
- Kubernetes &gt; CronJob &gt; osquery &gt; Configuration &gt; Name
- Kubernetes &gt; DaemonSet &gt; Active
- Kubernetes &gt; DaemonSet &gt; Active &gt; Age
- Kubernetes &gt; DaemonSet &gt; Active &gt; Last Modified
- Kubernetes &gt; DaemonSet &gt; Annotations
- Kubernetes &gt; DaemonSet &gt; Annotations &gt; Template
- Kubernetes &gt; DaemonSet &gt; Approved
- Kubernetes &gt; DaemonSet &gt; Approved &gt; Custom
- Kubernetes &gt; DaemonSet &gt; CMDB
- Kubernetes &gt; DaemonSet &gt; Labels
- Kubernetes &gt; DaemonSet &gt; Labels &gt; Template
- Kubernetes &gt; DaemonSet &gt; osquery
- Kubernetes &gt; DaemonSet &gt; osquery &gt; Configuration
- Kubernetes &gt; DaemonSet &gt; osquery &gt; Configuration &gt; Columns
- Kubernetes &gt; DaemonSet &gt; osquery &gt; Configuration &gt; Interval
- Kubernetes &gt; DaemonSet &gt; osquery &gt; Configuration &gt; Name
- Kubernetes &gt; Deployment &gt; Active
- Kubernetes &gt; Deployment &gt; Active &gt; Age
- Kubernetes &gt; Deployment &gt; Active &gt; Last Modified
- Kubernetes &gt; Ingress &gt; Active
- Kubernetes &gt; Ingress &gt; Active &gt; Age
- Kubernetes &gt; Ingress &gt; Active &gt; Last Modified
- Kubernetes &gt; Ingress &gt; Annotations
- Kubernetes &gt; Ingress &gt; Annotations &gt; Template
- Kubernetes &gt; Ingress &gt; Approved
- Kubernetes &gt; Ingress &gt; Approved &gt; Custom
- Kubernetes &gt; Ingress &gt; CMDB
- Kubernetes &gt; Ingress &gt; Labels
- Kubernetes &gt; Ingress &gt; Labels &gt; Template
- Kubernetes &gt; Ingress &gt; osquery
- Kubernetes &gt; Ingress &gt; osquery &gt; Configuration
- Kubernetes &gt; Ingress &gt; osquery &gt; Configuration &gt; Columns
- Kubernetes &gt; Ingress &gt; osquery &gt; Configuration &gt; Interval
- Kubernetes &gt; Ingress &gt; osquery &gt; Configuration &gt; Name
- Kubernetes &gt; Job &gt; Active
- Kubernetes &gt; Job &gt; Active &gt; Age
- Kubernetes &gt; Job &gt; Active &gt; Last Modified
- Kubernetes &gt; Job &gt; Annotations
- Kubernetes &gt; Job &gt; Annotations &gt; Template
- Kubernetes &gt; Job &gt; Approved
- Kubernetes &gt; Job &gt; Approved &gt; Custom
- Kubernetes &gt; Job &gt; CMDB
- Kubernetes &gt; Job &gt; Labels
- Kubernetes &gt; Job &gt; Labels &gt; Template
- Kubernetes &gt; Job &gt; osquery
- Kubernetes &gt; Job &gt; osquery &gt; Configuration
- Kubernetes &gt; Job &gt; osquery &gt; Configuration &gt; Columns
- Kubernetes &gt; Job &gt; osquery &gt; Configuration &gt; Interval
- Kubernetes &gt; Job &gt; osquery &gt; Configuration &gt; Name
- Kubernetes &gt; Namespace &gt; Active
- Kubernetes &gt; Namespace &gt; Active &gt; Age
- Kubernetes &gt; Namespace &gt; Active &gt; Last Modified
- Kubernetes &gt; Node &gt; Active
- Kubernetes &gt; Node &gt; Active &gt; Age
- Kubernetes &gt; Node &gt; Active &gt; Last Modified
- Kubernetes &gt; Persistent Volume &gt; Active
- Kubernetes &gt; Persistent Volume &gt; Active &gt; Age
- Kubernetes &gt; Persistent Volume &gt; Active &gt; Last Modified
- Kubernetes &gt; Persistent Volume &gt; Annotations
- Kubernetes &gt; Persistent Volume &gt; Annotations &gt; Template
- Kubernetes &gt; Persistent Volume &gt; Approved
- Kubernetes &gt; Persistent Volume &gt; Approved &gt; Custom
- Kubernetes &gt; Persistent Volume &gt; CMDB
- Kubernetes &gt; Persistent Volume &gt; Labels
- Kubernetes &gt; Persistent Volume &gt; Labels &gt; Template
- Kubernetes &gt; Persistent Volume &gt; osquery
- Kubernetes &gt; Persistent Volume &gt; osquery &gt; Configuration
- Kubernetes &gt; Persistent Volume &gt; osquery &gt; Configuration &gt; Columns
- Kubernetes &gt; Persistent Volume &gt; osquery &gt; Configuration &gt; Interval
- Kubernetes &gt; Persistent Volume &gt; osquery &gt; Configuration &gt; Name
- Kubernetes &gt; Pod &gt; Active
- Kubernetes &gt; Pod &gt; Active &gt; Age
- Kubernetes &gt; Pod &gt; Active &gt; Last Modified
- Kubernetes &gt; ReplicaSet &gt; Active
- Kubernetes &gt; ReplicaSet &gt; Active &gt; Age
- Kubernetes &gt; ReplicaSet &gt; Active &gt; Last Modified
- Kubernetes &gt; ReplicationController &gt; Active
- Kubernetes &gt; ReplicationController &gt; Active &gt; Age
- Kubernetes &gt; ReplicationController &gt; Active &gt; Last Modified
- Kubernetes &gt; ReplicationController &gt; Annotations
- Kubernetes &gt; ReplicationController &gt; Annotations &gt; Template
- Kubernetes &gt; ReplicationController &gt; Approved
- Kubernetes &gt; ReplicationController &gt; Approved &gt; Custom
- Kubernetes &gt; ReplicationController &gt; CMDB
- Kubernetes &gt; ReplicationController &gt; Labels
- Kubernetes &gt; ReplicationController &gt; Labels &gt; Template
- Kubernetes &gt; ReplicationController &gt; osquery
- Kubernetes &gt; ReplicationController &gt; osquery &gt; Configuration
- Kubernetes &gt; ReplicationController &gt; osquery &gt; Configuration &gt; Columns
- Kubernetes &gt; ReplicationController &gt; osquery &gt; Configuration &gt; Interval
- Kubernetes &gt; ReplicationController &gt; osquery &gt; Configuration &gt; Name
- Kubernetes &gt; Service &gt; Active
- Kubernetes &gt; Service &gt; Active &gt; Age
- Kubernetes &gt; Service &gt; Active &gt; Last Modified
- Kubernetes &gt; StatefulSet &gt; Active
- Kubernetes &gt; StatefulSet &gt; Active &gt; Age
- Kubernetes &gt; StatefulSet &gt; Active &gt; Last Modified
- Kubernetes &gt; StatefulSet &gt; Annotations
- Kubernetes &gt; StatefulSet &gt; Annotations &gt; Template
- Kubernetes &gt; StatefulSet &gt; Approved
- Kubernetes &gt; StatefulSet &gt; Approved &gt; Custom
- Kubernetes &gt; StatefulSet &gt; CMDB
- Kubernetes &gt; StatefulSet &gt; Labels
- Kubernetes &gt; StatefulSet &gt; Labels &gt; Template
- Kubernetes &gt; StatefulSet &gt; osquery
- Kubernetes &gt; StatefulSet &gt; osquery &gt; Configuration
- Kubernetes &gt; StatefulSet &gt; osquery &gt; Configuration &gt; Columns
- Kubernetes &gt; StatefulSet &gt; osquery &gt; Configuration &gt; Interval
- Kubernetes &gt; StatefulSet &gt; osquery &gt; Configuration &gt; Name

_Action Types_

- Kubernetes &gt; Cluster &gt; Router
- Kubernetes &gt; CronJob &gt; Router
- Kubernetes &gt; DaemonSet &gt; Router
- Kubernetes &gt; Ingress &gt; Router
- Kubernetes &gt; Job &gt; Router
- Kubernetes &gt; Persistent Volume &gt; Router
- Kubernetes &gt; ReplicationController &gt; Router
- Kubernetes &gt; StatefulSet &gt; Router

_Bug fixes_

- CMDB controls for various resources sometimes failed to process a large number of updates that occurred in quick succession via Cluster events. We’ve improved our GraphQL queries to handle such a load, and the controls will now be able to process such events more smoothly and reliably than before.</description>
            <pubDate>Fri, 26 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-s3-v5-25-0</guid>
            <title>aws-s3 v5.25.0 - Ignore `headBucket` permission errors and allow the CMDB control to run its course to completion</title>
            <link>https://turbot.com/guardrails/changelog/aws-s3-v5-25-0</link>
            <description>_What&apos;s new?_

- The `AWS &gt; S3 &gt; Bucket &gt; CMDB` control would go into an error state if Guardrails did not have permissions to call the `headBucket` operation on a bucket. Users can now ignore such permission errors and allow the CMDB control to run its course to completion. To get started, set the `AWS &gt; S3 &gt; Bucket &gt; CMDB` policy to `Enforce: Enabled but ignore permission errors`.</description>
            <pubDate>Fri, 26 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-45-1</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.45.1 - Minor internal improvements</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-45-1</link>
            <description>_Bug fixes_

- Server
  - Minor internal improvements.

_Requirements_

- TEF: 1.59.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Thu, 25 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-appservice-v5-11-2</guid>
            <title>azure-appservice v5.11.2 - Bug fixed - Client Certificate Mode control for Web Apps did not handle the default `Ignore` setting correctly</title>
            <link>https://turbot.com/guardrails/changelog/azure-appservice-v5-11-2</link>
            <description>_Bug fixes_

- In the previous version, we fixed an issue with the `Azure &gt; App Service &gt; Web App &gt; Client Certificate Mode` control, ensuring that the Client Certificate Mode is set to `Require` correctly. However, we missed an edge case where the control wouldn’t enforce any mode other than the default setting of `Ignore`. We have now addressed all cases, and the control will work more reliably and consistently than before.</description>
            <pubDate>Thu, 25 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-61-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.61.0 - Updated AWS Lambda function architecture to ARM64 for improved performance and cost efficiency</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-61-0</link>
            <description>_What&apos;s new?_

  - Updated AWS Lambda function architecture to ARM64 for improved performance and cost efficiency.</description>
            <pubDate>Mon, 22 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-45-0</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.45.0 - Cost optimizations with ARM64 Lambda functions and enhanced Redis memory management</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-45-0</link>
            <description>_What&apos;s new?_

- Server
  - Improved memory optimization for Redis.
  - Updated all AWS Lambda functions in the TE environment to use ARM64 architecture for improved performance and cost efficiency.
  - Allow notifications rules to accept nunjucks for Email address.
  - Updated several node packages to newer versions for improved functionality and security.

- UI
  - `Smart Folders` are now called `Policy Packs`.
  - Now you can add AKA while creating `Policy Packs` from UI.

_Bug fixes_

- Server
  - Fixed an issue where controls remained in TBD state for accounts imported without an External ID.

- UI
  - Removed the unsupported feature for rearranging `Policy Packs` from the UI.

_Requirements_

- TEF: 1.59.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Mon, 22 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-kubernetes-v5-1-1</guid>
            <title>servicenow-kubernetes v5.1.1 - Import Set policies for various Kubernetes resources will no longer include the `Enforce: Sync` policy value</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-kubernetes-v5-1-1</link>
            <description>_Bug fixes_

- The Import Set policies for various Kubernetes resources will no longer include the `Enforce: Sync` policy value for integrating Import Sets in ServiceNow.</description>
            <pubDate>Mon, 22 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-storage-v5-3-0</guid>
            <title>servicenow-gcp-storage v5.3.0 - Added Object &gt; ServiceNow &gt; Import Set controls and policies</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-storage-v5-3-0</link>
            <description>_Control Types_

- GCP &gt; Storage &gt; Object &gt; ServiceNow &gt; Import Set

_Policy Types_

- GCP &gt; Storage &gt; Object &gt; ServiceNow &gt; Import Set
- GCP &gt; Storage &gt; Object &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- GCP &gt; Storage &gt; Object &gt; ServiceNow &gt; Import Set &gt; Record
- GCP &gt; Storage &gt; Object &gt; ServiceNow &gt; Import Set &gt; Table Name</description>
            <pubDate>Mon, 22 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-computeengine-v5-2-0</guid>
            <title>servicenow-gcp-computeengine v5.2.0 - Added Import Set controls and policies for various Compute Engine resource types</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-computeengine-v5-2-0</link>
            <description>_Control Types_

- GCP &gt; Compute Engine &gt; Disk &gt; ServiceNow &gt; Import Set
- GCP &gt; Compute Engine &gt; HTTP Health Check &gt; ServiceNow &gt; Import Set
- GCP &gt; Compute Engine &gt; HTTPS Health Check &gt; ServiceNow &gt; Import Set
- GCP &gt; Compute Engine &gt; Health Check &gt; ServiceNow &gt; Import Set
- GCP &gt; Compute Engine &gt; Image &gt; ServiceNow &gt; Import Set
- GCP &gt; Compute Engine &gt; Instance &gt; ServiceNow &gt; Import Set
- GCP &gt; Compute Engine &gt; Instance Template &gt; ServiceNow &gt; Import Set
- GCP &gt; Compute Engine &gt; Node Group &gt; ServiceNow &gt; Import Set
- GCP &gt; Compute Engine &gt; Node template &gt; ServiceNow &gt; Import Set
- GCP &gt; Compute Engine &gt; Project &gt; ServiceNow &gt; Import Set
- GCP &gt; Compute Engine &gt; Region Disk &gt; ServiceNow &gt; Import Set
- GCP &gt; Compute Engine &gt; Region Health Check &gt; ServiceNow &gt; Import Set
- GCP &gt; Compute Engine &gt; Snapshot &gt; ServiceNow &gt; Import Set

_Policy Types_

- GCP &gt; Compute Engine &gt; Disk &gt; ServiceNow &gt; Import Set
- GCP &gt; Compute Engine &gt; Disk &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- GCP &gt; Compute Engine &gt; Disk &gt; ServiceNow &gt; Import Set &gt; Record
- GCP &gt; Compute Engine &gt; Disk &gt; ServiceNow &gt; Import Set &gt; Table Name
- GCP &gt; Compute Engine &gt; HTTP Health Check &gt; ServiceNow &gt; Import Set
- GCP &gt; Compute Engine &gt; HTTP Health Check &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- GCP &gt; Compute Engine &gt; HTTP Health Check &gt; ServiceNow &gt; Import Set &gt; Record
- GCP &gt; Compute Engine &gt; HTTP Health Check &gt; ServiceNow &gt; Import Set &gt; Table Name
- GCP &gt; Compute Engine &gt; HTTPS Health Check &gt; ServiceNow &gt; Import Set
- GCP &gt; Compute Engine &gt; HTTPS Health Check &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- GCP &gt; Compute Engine &gt; HTTPS Health Check &gt; ServiceNow &gt; Import Set &gt; Record
- GCP &gt; Compute Engine &gt; HTTPS Health Check &gt; ServiceNow &gt; Import Set &gt; Table Name
- GCP &gt; Compute Engine &gt; Health Check &gt; ServiceNow &gt; Import Set
- GCP &gt; Compute Engine &gt; Health Check &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- GCP &gt; Compute Engine &gt; Health Check &gt; ServiceNow &gt; Import Set &gt; Record
- GCP &gt; Compute Engine &gt; Health Check &gt; ServiceNow &gt; Import Set &gt; Table Name
- GCP &gt; Compute Engine &gt; Image &gt; ServiceNow &gt; Import Set
- GCP &gt; Compute Engine &gt; Image &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- GCP &gt; Compute Engine &gt; Image &gt; ServiceNow &gt; Import Set &gt; Record
- GCP &gt; Compute Engine &gt; Image &gt; ServiceNow &gt; Import Set &gt; Table Name
- GCP &gt; Compute Engine &gt; Instance &gt; ServiceNow &gt; Import Set
- GCP &gt; Compute Engine &gt; Instance &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- GCP &gt; Compute Engine &gt; Instance &gt; ServiceNow &gt; Import Set &gt; Record
- GCP &gt; Compute Engine &gt; Instance &gt; ServiceNow &gt; Import Set &gt; Table Name
- GCP &gt; Compute Engine &gt; Instance Template &gt; ServiceNow &gt; Import Set
- GCP &gt; Compute Engine &gt; Instance Template &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- GCP &gt; Compute Engine &gt; Instance Template &gt; ServiceNow &gt; Import Set &gt; Record
- GCP &gt; Compute Engine &gt; Instance Template &gt; ServiceNow &gt; Import Set &gt; Table Name
- GCP &gt; Compute Engine &gt; Node Group &gt; ServiceNow &gt; Import Set
- GCP &gt; Compute Engine &gt; Node Group &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- GCP &gt; Compute Engine &gt; Node Group &gt; ServiceNow &gt; Import Set &gt; Record
- GCP &gt; Compute Engine &gt; Node Group &gt; ServiceNow &gt; Import Set &gt; Table Name
- GCP &gt; Compute Engine &gt; Node template &gt; ServiceNow &gt; Import Set
- GCP &gt; Compute Engine &gt; Node template &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- GCP &gt; Compute Engine &gt; Node template &gt; ServiceNow &gt; Import Set &gt; Record
- GCP &gt; Compute Engine &gt; Node template &gt; ServiceNow &gt; Import Set &gt; Table Name
- GCP &gt; Compute Engine &gt; Project &gt; ServiceNow &gt; Import Set
- GCP &gt; Compute Engine &gt; Project &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- GCP &gt; Compute Engine &gt; Project &gt; ServiceNow &gt; Import Set &gt; Record
- GCP &gt; Compute Engine &gt; Project &gt; ServiceNow &gt; Import Set &gt; Table Name
- GCP &gt; Compute Engine &gt; Region Disk &gt; ServiceNow &gt; Import Set
- GCP &gt; Compute Engine &gt; Region Disk &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- GCP &gt; Compute Engine &gt; Region Disk &gt; ServiceNow &gt; Import Set &gt; Record
- GCP &gt; Compute Engine &gt; Region Disk &gt; ServiceNow &gt; Import Set &gt; Table Name
- GCP &gt; Compute Engine &gt; Region Health Check &gt; ServiceNow &gt; Import Set
- GCP &gt; Compute Engine &gt; Region Health Check &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- GCP &gt; Compute Engine &gt; Region Health Check &gt; ServiceNow &gt; Import Set &gt; Record
- GCP &gt; Compute Engine &gt; Region Health Check &gt; ServiceNow &gt; Import Set &gt; Table Name
- GCP &gt; Compute Engine &gt; Snapshot &gt; ServiceNow &gt; Import Set
- GCP &gt; Compute Engine &gt; Snapshot &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- GCP &gt; Compute Engine &gt; Snapshot &gt; ServiceNow &gt; Import Set &gt; Record
- GCP &gt; Compute Engine &gt; Snapshot &gt; ServiceNow &gt; Import Set &gt; Table Name</description>
            <pubDate>Mon, 22 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-storage-v5-3-0</guid>
            <title>servicenow-azure-storage v5.3.0 - Added Import Set controls and policies for various Storage resource types</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-storage-v5-3-0</link>
            <description>_Control Types_

- Azure &gt; Storage &gt; Container &gt; ServiceNow &gt; Import Set
- Azure &gt; Storage &gt; FileShare &gt; ServiceNow &gt; Import Set
- Azure &gt; Storage &gt; Queue &gt; ServiceNow &gt; Import Set

_Policy Types_

- Azure &gt; Storage &gt; Container &gt; ServiceNow &gt; Import Set
- Azure &gt; Storage &gt; Container &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- Azure &gt; Storage &gt; Container &gt; ServiceNow &gt; Import Set &gt; Record
- Azure &gt; Storage &gt; Container &gt; ServiceNow &gt; Import Set &gt; Table Name
- Azure &gt; Storage &gt; FileShare &gt; ServiceNow &gt; Import Set
- Azure &gt; Storage &gt; FileShare &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- Azure &gt; Storage &gt; FileShare &gt; ServiceNow &gt; Import Set &gt; Record
- Azure &gt; Storage &gt; FileShare &gt; ServiceNow &gt; Import Set &gt; Table Name
- Azure &gt; Storage &gt; Queue &gt; ServiceNow &gt; Import Set
- Azure &gt; Storage &gt; Queue &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- Azure &gt; Storage &gt; Queue &gt; ServiceNow &gt; Import Set &gt; Record
- Azure &gt; Storage &gt; Queue &gt; ServiceNow &gt; Import Set &gt; Table Name</description>
            <pubDate>Mon, 22 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-compute-v5-1-0</guid>
            <title>servicenow-azure-compute v5.1.0 - Added Import Set controls and policies for various Compute resource types</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-compute-v5-1-0</link>
            <description>_Control Types_

- Azure &gt; Compute &gt; Availability Set &gt; ServiceNow &gt; Import Set
- Azure &gt; Compute &gt; Disk &gt; ServiceNow &gt; Import Set
- Azure &gt; Compute &gt; Disk Encryption Set &gt; ServiceNow &gt; Import Set
- Azure &gt; Compute &gt; Image &gt; ServiceNow &gt; Import Set
- Azure &gt; Compute &gt; Snapshot &gt; ServiceNow &gt; Import Set
- Azure &gt; Compute &gt; Ssh Public Key &gt; ServiceNow &gt; Import Set
- Azure &gt; Compute &gt; Virtual Machine &gt; ServiceNow &gt; Import Set
- Azure &gt; Compute &gt; Virtual Machine Scale Set &gt; ServiceNow &gt; Import Set

_Policy Types_

- Azure &gt; Compute &gt; Availability Set &gt; ServiceNow &gt; Import Set
- Azure &gt; Compute &gt; Availability Set &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- Azure &gt; Compute &gt; Availability Set &gt; ServiceNow &gt; Import Set &gt; Record
- Azure &gt; Compute &gt; Availability Set &gt; ServiceNow &gt; Import Set &gt; Table Name
- Azure &gt; Compute &gt; Disk &gt; ServiceNow &gt; Import Set
- Azure &gt; Compute &gt; Disk &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- Azure &gt; Compute &gt; Disk &gt; ServiceNow &gt; Import Set &gt; Record
- Azure &gt; Compute &gt; Disk &gt; ServiceNow &gt; Import Set &gt; Table Name
- Azure &gt; Compute &gt; Disk Encryption Set &gt; ServiceNow &gt; Import Set
- Azure &gt; Compute &gt; Disk Encryption Set &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- Azure &gt; Compute &gt; Disk Encryption Set &gt; ServiceNow &gt; Import Set &gt; Record
- Azure &gt; Compute &gt; Disk Encryption Set &gt; ServiceNow &gt; Import Set &gt; Table Name
- Azure &gt; Compute &gt; Image &gt; ServiceNow &gt; Import Set
- Azure &gt; Compute &gt; Image &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- Azure &gt; Compute &gt; Image &gt; ServiceNow &gt; Import Set &gt; Record
- Azure &gt; Compute &gt; Image &gt; ServiceNow &gt; Import Set &gt; Table Name
- Azure &gt; Compute &gt; Snapshot &gt; ServiceNow &gt; Import Set
- Azure &gt; Compute &gt; Snapshot &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- Azure &gt; Compute &gt; Snapshot &gt; ServiceNow &gt; Import Set &gt; Record
- Azure &gt; Compute &gt; Snapshot &gt; ServiceNow &gt; Import Set &gt; Table Name
- Azure &gt; Compute &gt; Ssh Public Key &gt; ServiceNow &gt; Import Set
- Azure &gt; Compute &gt; Ssh Public Key &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- Azure &gt; Compute &gt; Ssh Public Key &gt; ServiceNow &gt; Import Set &gt; Record
- Azure &gt; Compute &gt; Ssh Public Key &gt; ServiceNow &gt; Import Set &gt; Table Name
- Azure &gt; Compute &gt; Virtual Machine &gt; ServiceNow &gt; Import Set
- Azure &gt; Compute &gt; Virtual Machine &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- Azure &gt; Compute &gt; Virtual Machine &gt; ServiceNow &gt; Import Set &gt; Record
- Azure &gt; Compute &gt; Virtual Machine &gt; ServiceNow &gt; Import Set &gt; Table Name
- Azure &gt; Compute &gt; Virtual Machine Scale Set &gt; ServiceNow &gt; Import Set
- Azure &gt; Compute &gt; Virtual Machine Scale Set &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- Azure &gt; Compute &gt; Virtual Machine Scale Set &gt; ServiceNow &gt; Import Set &gt; Record
- Azure &gt; Compute &gt; Virtual Machine Scale Set &gt; ServiceNow &gt; Import Set &gt; Table Name</description>
            <pubDate>Mon, 22 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-aws-s3-v5-1-0</guid>
            <title>servicenow-aws-s3 v5.1.0 - Added Bucket &gt; ServiceNow &gt; Import Set controls and policies</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-aws-s3-v5-1-0</link>
            <description>_Control Types_

- AWS &gt; S3 &gt; Bucket &gt; ServiceNow &gt; Import Set

_Policy Types_

- AWS &gt; S3 &gt; Bucket &gt; ServiceNow &gt; Import Set
- AWS &gt; S3 &gt; Bucket &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- AWS &gt; S3 &gt; Bucket &gt; ServiceNow &gt; Import Set &gt; Record
- AWS &gt; S3 &gt; Bucket &gt; ServiceNow &gt; Import Set &gt; Table Name</description>
            <pubDate>Mon, 22 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-aws-v5-1-0</guid>
            <title>servicenow-aws v5.1.0 - Added support for archiving Import Sets in ServiceNow</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-aws-v5-1-0</link>
            <description>_What&apos;s new?_

- Added support to archive Import Sets in ServiceNow.</description>
            <pubDate>Mon, 22 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-appservice-v5-11-1</guid>
            <title>azure-appservice v5.11.1 - Bug fixed - Client Certificate Mode control for Web Apps did not apply `Enforce: Require` settings correctly</title>
            <link>https://turbot.com/guardrails/changelog/azure-appservice-v5-11-1</link>
            <description>_Bug fixes_

- The `Azure &gt; App Service &gt; Web App &gt; Client Certificate Mode` control did not apply `Enforce: Require` settings correctly. This is now fixed.</description>
            <pubDate>Fri, 19 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-monitoring-v5-7-0</guid>
            <title>gcp-monitoring v5.7.0 - Added support for `google_monitoring_alert_policy` and `google_monitoring_notification_channel` Terraform resources</title>
            <link>https://turbot.com/guardrails/changelog/gcp-monitoring-v5-7-0</link>
            <description>_What&apos;s new?_

- Added support for `google_monitoring_alert_policy` and `google_monitoring_notification_channel` Terraform resources.

_Control Types_

- GCP &gt; Monitoring &gt; Alert Policy &gt; Configured
- GCP &gt; Monitoring &gt; Notification Channel &gt; Configured

_Policy Types_

- GCP &gt; Monitoring &gt; Alert Policy &gt; Configured
- GCP &gt; Monitoring &gt; Alert Policy &gt; Configured &gt; Claim Precedence
- GCP &gt; Monitoring &gt; Alert Policy &gt; Configured &gt; Source
- GCP &gt; Monitoring &gt; Notification Channel &gt; Configured
- GCP &gt; Monitoring &gt; Notification Channel &gt; Configured &gt; Claim Precedence
- GCP &gt; Monitoring &gt; Notification Channel &gt; Configured &gt; Source</description>
            <pubDate>Thu, 18 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-logging-v5-5-0</guid>
            <title>gcp-logging v5.5.0 - Added support for `google_logging_metric` Terraform resource</title>
            <link>https://turbot.com/guardrails/changelog/gcp-logging-v5-5-0</link>
            <description>_What&apos;s new?_

- Added support for `google_logging_metric` Terraform resource.

_Control Types_

- GCP &gt; Logging &gt; Metric &gt; Configured

_Policy Types_

- GCP &gt; Logging &gt; Metric &gt; Configured
- GCP &gt; Logging &gt; Metric &gt; Configured &gt; Claim Precedence
- GCP &gt; Logging &gt; Metric &gt; Configured &gt; Source</description>
            <pubDate>Thu, 18 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-storage-v5-18-1</guid>
            <title>azure-storage v5.18.1 - Bug fixed - Queue logging control failed to set logging properties correctly</title>
            <link>https://turbot.com/guardrails/changelog/azure-storage-v5-18-1</link>
            <description>_Bug fixes_

- The `Azure &gt; Storage &gt; Storage Account &gt; Queue &gt; Logging` control failed to set queue logging properties correctly. This issue has been fixed, and the control will now function correctly as intended.</description>
            <pubDate>Thu, 18 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-iam-v5-36-2</guid>
            <title>aws-iam v5.36.2 - Improved descriptions for various IAM Resource Types to ensure they are clearer and more helpful</title>
            <link>https://turbot.com/guardrails/changelog/aws-iam-v5-36-2</link>
            <description>_Bug fixes_

- Improved descriptions for various resource types to ensure they are clearer and more helpful.</description>
            <pubDate>Thu, 18 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ec2-v5-41-2</guid>
            <title>aws-ec2 v5.41.2 - Improved descriptions for various EC2 Resource Types to ensure they are clearer and more helpful</title>
            <link>https://turbot.com/guardrails/changelog/aws-ec2-v5-41-2</link>
            <description>_Bug fixes_

- Improved descriptions for various resource types to ensure they are clearer and more helpful.</description>
            <pubDate>Thu, 18 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-computeengine-v5-9-0</guid>
            <title>gcp-computeengine v5.9.0 - Configure Shielded Instance Configuration for instances</title>
            <link>https://turbot.com/guardrails/changelog/gcp-computeengine-v5-9-0</link>
            <description>_What&apos;s new?_

- Users can now configure Shielded Instance Configuration for instances. To get started, set `GCP &gt; Compute &gt; Instance &gt; Shielded Instance Configuration &gt; *` policies.

_Control Types_

- GCP &gt; Compute Engine &gt; Instance &gt; Shielded Instance Configuration

_Policy Types_

- GCP &gt; Compute Engine &gt; Instance &gt; Shielded Instance Configuration
- GCP &gt; Compute Engine &gt; Instance &gt; Shielded Instance Configuration &gt; Integrity Monitoring
- GCP &gt; Compute Engine &gt; Instance &gt; Shielded Instance Configuration &gt; Secure Boot
- GCP &gt; Compute Engine &gt; Instance &gt; Shielded Instance Configuration &gt; vTPM

_Action Types_

- GCP &gt; Compute Engine &gt; Instance &gt; Set Shielded Instance Configuration</description>
            <pubDate>Tue, 16 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-cisv2-0-v5-1-0</guid>
            <title>azure-cisv2-0 v5.1.0 - Added support for control 5.01.06 - Ensure that Network Security Group Flow logs are captured and sent to Log Analytics</title>
            <link>https://turbot.com/guardrails/changelog/azure-cisv2-0-v5-1-0</link>
            <description>_What&apos;s new?_

- The `Azure &gt; CIS v2.0 &gt; 5.05 - Ensure that SKU Basic/Consumption is not used on artifacts that need to be monitored (Particularly for Production Workloads)` control will also evaluate SQL databases for SKU Basic/Consumption.

_Control Types_

- Azure &gt; CIS v2.0 &gt; 05 - Logging and Monitoring &gt; 5.01 - Configuring Diagnostic Settings &gt; 5.01.06 - Ensure that Network Security Group Flow logs are captured and sent to Log Analytics

_Policy Types_

- Azure &gt; CIS v2.0 &gt; 05 - Logging and Monitoring &gt; 5.01 - Configuring Diagnostic Settings &gt; 5.01.06 - Ensure that Network Security Group flow logs are captured and sent to Log Analytics

_Bug fixes_

- The `Azure &gt; CIS v2.0 &gt; 4 - Database Services &gt; 01.03 - Ensure SQL server&apos;s Transparent Data Encryption (TDE) protector is encrypted with Customer-managed key` control did not evaluate the result correctly, as expected. This is now fixed.</description>
            <pubDate>Tue, 16 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/terraform-provider-v1-11-1</guid>
            <title>Terraform Provider v1.11.1 - Added documentation for `akas` attribute for `turbot_policy_pack` resource</title>
            <link>https://turbot.com/guardrails/changelog/terraform-provider-v1-11-1</link>
            <description>_What&apos;s new?_

DOCUMENTATION:

* `resource/turbot_policy_pack`: Added documentation for `akas` attribute for the resource. ([#179](https://github.com/turbot/terraform-provider-turbot/issues/179))</description>
            <pubDate>Mon, 15 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-sql-v5-10-0</guid>
            <title>gcp-sql v5.10.0 - Configure Encryption In Transit for Instances</title>
            <link>https://turbot.com/guardrails/changelog/gcp-sql-v5-10-0</link>
            <description>_What&apos;s new?_

- Users can now configure Encryption In Transit for instances. To get started, set the `GCP &gt; SQL &gt; Instance &gt; Encryption In Transit` policy.

_Control Types_

- GCP &gt; SQL &gt; Instance &gt; Encryption In Transit

_Policy Types_

- GCP &gt; SQL &gt; Instance &gt; Encryption In Transit

_Action Types_

- GCP &gt; SQL &gt; Instance &gt; Update Encryption in Transit</description>
            <pubDate>Mon, 15 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-cisv2-0-v5-1-0</guid>
            <title>gcp-cisv2-0 v5.1.0 - Added controls related to IAM API Keys in section 1 - Identity and Access Management</title>
            <link>https://turbot.com/guardrails/changelog/gcp-cisv2-0-v5-1-0</link>
            <description>_What&apos;s new?_

_Control Types_

- GCP &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.12 - Ensure API Keys Only Exist for Active Services
- GCP &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.13 - Ensure API Keys Are Restricted To Use by Only Specified Hosts and Apps
- GCP &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.14 - Ensure API Keys Are Restricted to Only APIs That Application Needs Access
- GCP &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.15 - Ensure API Keys Are Rotated Every 90 Days

_Policy Types_

- GCP &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.12 - Ensure API Keys Only Exist for Active Services
- GCP &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.13 - Ensure API Keys Are Restricted To Use by Only Specified Hosts and Apps
- GCP &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.14 - Ensure API Keys Are Restricted to Only APIs That Application Needs Access
- GCP &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.15 - Ensure API Keys Are Rotated Every 90 Days</description>
            <pubDate>Mon, 15 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-network-v5-17-0</guid>
            <title>azure-network v5.17.0 - Upgrade SKU from Basic to Standard for Public IP Addresses</title>
            <link>https://turbot.com/guardrails/changelog/azure-network-v5-17-0</link>
            <description>_What&apos;s new?_

- Users can now upgrade the SKU from `Basic` to `Standard` for Public IP Addresss via `Azure &gt; Network &gt; Public IP Address &gt; Standard SKU` control. To get started, set the `Azure &gt; Network &gt; Public IP Address &gt; Standard SKU` policy.

_Control Types_

- Azure &gt; Network &gt; Public IP Address &gt; Standard SKU

_Policy Types_

- Azure &gt; Network &gt; Public IP Address &gt; Standard SKU
- Azure &gt; Network &gt; Public IP Address &gt; Standard SKU &gt; SKU Tier

_Action Types_

- Azure &gt; Network &gt; Public IP Address &gt; Update SKU to Standard</description>
            <pubDate>Mon, 15 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-cosmosdb-v5-6-0</guid>
            <title>azure-cosmosdb v5.6.0 - Configure Firewall and Virtual Network settings for Database Accounts</title>
            <link>https://turbot.com/guardrails/changelog/azure-cosmosdb-v5-6-0</link>
            <description>_What&apos;s new?_

- We&apos;ve added guardrails to help secure access to your database accounts&apos; public endpoints. All database accounts have public endpoints that are accessible through the internet by default. This access can be limited to specific IP ranges, virtual network subnets, and trusted Microsoft services by defining [firewall and virtual network rules](https://learn.microsoft.com/en-us/azure/cosmos-db/how-to-configure-vnet-service-endpoint).

To get started configuring these rules through Guardrails, the following policies should set according to your desired firewall rules configuration:

`Azure &gt; Cosmos DB &gt; Database Account &gt; Firewall` - Configure default access rules for the public endpoint
`Azure &gt; Cosmos DB &gt; Database Account &gt; Firewall &gt; IP Ranges &gt; Approved` - Remove unapproved IP ranges
`Azure &gt; Cosmos DB &gt; Database Account &gt; Firewall &gt; IP Ranges &gt; Required` - Grant access to specific IP ranges
`Azure &gt; Cosmos DB &gt; Database Account &gt; Firewall &gt; Virtual Networks &gt; Approved` - Remove unapproved virtual network subnets
`Azure &gt; Cosmos DB &gt; Database Account &gt; Firewall &gt; Virtual Networks &gt; Required` - Grant access to specific virtual network subnets
Please note that if the `Azure &gt; Cosmos DB &gt; Database Account &gt; Firewall` policy is set to `Enforce: Allow only approved virtual networks and IP ranges`, only applications in the configured IP ranges, virtual network subnets, and trusted Microsoft services will be allowed to access the database accounts. If these boundaries are not properly configured beforehand or an application is outside of these boundaries, it will lose access to the database accounts.

_Control Types_

- Azure &gt; Cosmos DB &gt; Database Account &gt; Firewall
- Azure &gt; Cosmos DB &gt; Database Account &gt; Firewall &gt; IP Ranges
- Azure &gt; Cosmos DB &gt; Database Account &gt; Firewall &gt; IP Ranges &gt; Approved
- Azure &gt; Cosmos DB &gt; Database Account &gt; Firewall &gt; IP Ranges &gt; Required
- Azure &gt; Cosmos DB &gt; Database Account &gt; Firewall &gt; Virtual Networks
- Azure &gt; Cosmos DB &gt; Database Account &gt; Firewall &gt; Virtual Networks &gt; Approved
- Azure &gt; Cosmos DB &gt; Database Account &gt; Firewall &gt; Virtual Networks &gt; Required

_Policy Types_

- Azure &gt; Cosmos DB &gt; Database Account &gt; Firewall
- Azure &gt; Cosmos DB &gt; Database Account &gt; Firewall &gt; IP Ranges
- Azure &gt; Cosmos DB &gt; Database Account &gt; Firewall &gt; IP Ranges &gt; Approved
- Azure &gt; Cosmos DB &gt; Database Account &gt; Firewall &gt; IP Ranges &gt; Approved &gt; CIDR Ranges
- Azure &gt; Cosmos DB &gt; Database Account &gt; Firewall &gt; IP Ranges &gt; Approved &gt; Compiled Rules
- Azure &gt; Cosmos DB &gt; Database Account &gt; Firewall &gt; IP Ranges &gt; Approved &gt; Rules
- Azure &gt; Cosmos DB &gt; Database Account &gt; Firewall &gt; IP Ranges &gt; Required
- Azure &gt; Cosmos DB &gt; Database Account &gt; Firewall &gt; IP Ranges &gt; Required &gt; Compiled Items
- Azure &gt; Cosmos DB &gt; Database Account &gt; Firewall &gt; IP Ranges &gt; Required &gt; Exceptions
- Azure &gt; Cosmos DB &gt; Database Account &gt; Firewall &gt; IP Ranges &gt; Required &gt; Items
- Azure &gt; Cosmos DB &gt; Database Account &gt; Firewall &gt; Virtual Networks
- Azure &gt; Cosmos DB &gt; Database Account &gt; Firewall &gt; Virtual Networks &gt; Approved
- Azure &gt; Cosmos DB &gt; Database Account &gt; Firewall &gt; Virtual Networks &gt; Approved &gt; Compiled Rules
- Azure &gt; Cosmos DB &gt; Database Account &gt; Firewall &gt; Virtual Networks &gt; Approved &gt; Rules
- Azure &gt; Cosmos DB &gt; Database Account &gt; Firewall &gt; Virtual Networks &gt; Approved &gt; Subnets
- Azure &gt; Cosmos DB &gt; Database Account &gt; Firewall &gt; Virtual Networks &gt; Required
- Azure &gt; Cosmos DB &gt; Database Account &gt; Firewall &gt; Virtual Networks &gt; Required &gt; Items

_Action Types_

- Azure &gt; Cosmos DB &gt; Database Account &gt; Update Firewall Default Access Rule
- Azure &gt; Cosmos DB &gt; Database Account &gt; Update Firewall IP Ranges
- Azure &gt; Cosmos DB &gt; Database Account &gt; Update Firewall Virtual Networks

_Bug fixes_

- Various Discovery and CMDB controls entered an error state because they used outdated APIs that no longer functioned as expected. We have updated internal package dependencies, and those controls now operate smoothly as intended.</description>
            <pubDate>Mon, 15 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-60-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.60.0 -  Resolved an issue where an empty outbound_cidr_ranges SSM parameter caused a validation error</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-60-0</link>
            <description>_Bug fixes_

  - Resolved an issue where an empty outbound_cidr_ranges SSM parameter caused a validation error. Now, if the outbound_cidr_ranges parameter is empty, it will be set to None.

_What&apos;s new?_

  - Added M7i and M7i-flex instance type.
  - Updated the HealthCheckProxy lambda function to use python 3.10.</description>
            <pubDate>Fri, 12 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-v5-24-4</guid>
            <title>gcp v5.24.4 - Bug fixed - Project CMDB control would go into error if Access Transparency was disabled</title>
            <link>https://turbot.com/guardrails/changelog/gcp-v5-24-4</link>
            <description>_Bug fixes_

- The `GCP &gt; Project &gt; CMDB` control went into an error state while fetching Access Approval settings for the project if Access Transparency was disabled at the organization level. We have now handled such cases gracefully, and the control will fetch all available details without going into an error state.</description>
            <pubDate>Fri, 12 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-sql-v5-9-0</guid>
            <title>gcp-sql v5.9.0 - Configure Authorized Networks and Database Flags for Instances</title>
            <link>https://turbot.com/guardrails/changelog/gcp-sql-v5-9-0</link>
            <description>_What&apos;s new?_

- Users can now configure authorized networks for instances in Guardrails. To get started, set the `GCP &gt; SQL &gt; Instance &gt; Authorized Network &gt; *` policies.
- Users can now configure Database Flags for instances in Guardrails. To get started, set the `GCP &gt; SQL &gt; Instance &gt; Database Flags` policy.
- Users can now clean up and stop tracking SQL resources in Guardrails. To get started, set the `GCP &gt; SQL &gt; CMDB` policy to `Enforce: Disabled`.

_Control Types_

- GCP &gt; SQL &gt; Instance &gt; Authorized Network
- GCP &gt; SQL &gt; Instance &gt; Authorized Network &gt; Approved
- GCP &gt; SQL &gt; Instance &gt; Database Flags

_Policy Types_

- GCP &gt; SQL &gt; Instance &gt; Authorized Network
- GCP &gt; SQL &gt; Instance &gt; Authorized Network &gt; Approved
- GCP &gt; SQL &gt; Instance &gt; Authorized Network &gt; Approved &gt; CIDR Ranges
- GCP &gt; SQL &gt; Instance &gt; Database Flags
- GCP &gt; SQL &gt; Instance &gt; Database Flags &gt; MySQL
- GCP &gt; SQL &gt; Instance &gt; Database Flags &gt; MySQL &gt; Template
- GCP &gt; SQL &gt; Instance &gt; Database Flags &gt; PostgreSQL
- GCP &gt; SQL &gt; Instance &gt; Database Flags &gt; PostgreSQL &gt; Template
- GCP &gt; SQL &gt; Instance &gt; Database Flags &gt; SQL Server
- GCP &gt; SQL &gt; Instance &gt; Database Flags &gt; SQL Server &gt; Template

_Action Types_

- GCP &gt; SQL &gt; Instance &gt; Update Authorized Network
- GCP &gt; SQL &gt; Instance &gt; Update Database Flags</description>
            <pubDate>Fri, 12 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-storage-v5-18-0</guid>
            <title>azure-storage v5.18.0 - Controls and Actions now use latest Azure SDK versions to discover and manage Storage resources in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-storage-v5-18-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated internal dependencies and now use the latest Azure SDK versions to discover and manage Storage resources in Guardrails. This release includes **breaking changes** in the CMDB data for storage accounts. We recommend updating your existing policy settings to refer to the updated attributes as mentioned below.

  Renamed:

  - `serviceProperties.blob.DeleteRetentionPolicy` to `serviceProperties.blob.deleteRetentionPolicy`
  - `serviceProperties.blob.DeleteRetentionPolicy.Days` to `serviceProperties.blob.deleteRetentionPolicy.days`
  - `serviceProperties.blob.DeleteRetentionPolicy.Enabled` to `serviceProperties.blob.deleteRetentionPolicy.enabled`
  - `serviceProperties.blob.StaticWebsite` to `serviceProperties.blob.staticWebsite`
  - `serviceProperties.blob.StaticWebsite.Enabled` to `serviceProperties.blob.staticWebsite.enabled`
  - `serviceProperties.blob.logging` to `serviceProperties.blob.blobAnalyticsLogging`
  - `serviceProperties.queue.logging` to `serviceProperties.queue.queueAnalyticsLogging`

  Added:
  
  - `serviceProperties.blob.deleteRetentionPolicy.AllowPermanentDelete`
  
  Modified:
  
  - The data type of the attribute `serviceProperties.blob.cors` has been changed from string (`&quot;&quot;`) to array (`[]`).
  - The data type of the attribute `serviceProperties.queue.cors` has been changed from string (`&quot;&quot;`) to array (`[]`).

- Users can now enable/disable `Blob logging` for storage accounts. To get started, set the `Azure &gt; Storage &gt; Storage Account &gt; Blob &gt; Logging &gt; *` policies.
- Users can now check if storage accounts are approved for use based on Infrastructure Encryption settings. To get started, set the `Azure &gt; Storage &gt; Storage Account &gt; Approved &gt; Infrastructure Encryption` policy.

_Control Types_

- Azure &gt; Storage &gt; Storage Account &gt; Blob
- Azure &gt; Storage &gt; Storage Account &gt; Blob &gt; Logging

_Renamed_

- Azure &gt; Storage &gt; Storage Account &gt; Public Access to Azure &gt; Storage &gt; Storage Account &gt; Blob Public Access

_Policy Types_

- Azure &gt; Storage &gt; Storage Account &gt; Approved &gt; Infrastructure Encryption
- Azure &gt; Storage &gt; Storage Account &gt; Blob
- Azure &gt; Storage &gt; Storage Account &gt; Blob &gt; Logging
- Azure &gt; Storage &gt; Storage Account &gt; Blob &gt; Logging &gt; Properties
- Azure &gt; Storage &gt; Storage Account &gt; Blob &gt; Logging &gt; Retention Days

_Renamed_

- Azure &gt; Storage &gt; Storage Account &gt; Public Access to Azure &gt; Storage &gt; Storage Account &gt; Blob Public Access

_Action Types_

- Azure &gt; Storage &gt; Storage Account &gt; Update Storage Account Blob Logging

_Renamed_

- Azure &gt; Storage &gt; Storage Account &gt; Set Public Access to Azure &gt; Storage &gt; Storage Account &gt; Set Blob Public Access</description>
            <pubDate>Fri, 12 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-appservice-v5-11-0</guid>
            <title>azure-appservice v5.11.0 - Configure Client Certificate Mode for Web Apps</title>
            <link>https://turbot.com/guardrails/changelog/azure-appservice-v5-11-0</link>
            <description>_What&apos;s new?_

- Users can now configure Client Certificate Mode for web apps. To get started, set the `Azure &gt; App Service &gt; Web App &gt; Client Certificate Mode` policy.

_Control Types_

- Azure &gt; App Service &gt; Web App &gt; Client Certificate Mode

_Policy Types_

- Azure &gt; App Service &gt; Web App &gt; Client Certificate Mode

_Action Types_

- Azure &gt; App Service &gt; Web App &gt; Set Client Certificate Mode</description>
            <pubDate>Fri, 12 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/terraform-provider-v1-11-0</guid>
            <title>Terraform Provider v1.11.0 - Added `turbot_policy_pack` and `turbot_policy_pack_attachment` resources</title>
            <link>https://turbot.com/guardrails/changelog/terraform-provider-v1-11-0</link>
            <description>_What&apos;s new?_

FEATURES:

* **New Resource:** `turbot_policy_pack` ([#171](https://github.com/turbot/terraform-provider-turbot/issues/171))
* **New Resource:** `turbot_policy_pack_attachment` ([#173](https://github.com/turbot/terraform-provider-turbot/issues/173))

ENHANCEMENTS:

* `resource/turbot_smart_folder`: The `parent` argument is now optional and defaults to `tmod:@turbot/turbot#/`. ([#177](https://github.com/turbot/terraform-provider-turbot/issues/177))</description>
            <pubDate>Thu, 11 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-iam-v5-15-0</guid>
            <title>gcp-iam v5.15.0 - Track and manage IAM API Keys in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/gcp-iam-v5-15-0</link>
            <description>_What&apos;s new?_

_Resource Types_

- GCP &gt; IAM &gt; API Key

_Control Types_

- GCP &gt; IAM &gt; API Key &gt; Active
- GCP &gt; IAM &gt; API Key &gt; Approved
- GCP &gt; IAM &gt; API Key &gt; CMDB
- GCP &gt; IAM &gt; API Key &gt; Discovery
- GCP &gt; IAM &gt; API Key &gt; Usage

_Policy Types_

- GCP &gt; IAM &gt; API Key &gt; Active
- GCP &gt; IAM &gt; API Key &gt; Active &gt; Age
- GCP &gt; IAM &gt; API Key &gt; Active &gt; Last Modified
- GCP &gt; IAM &gt; API Key &gt; Approved
- GCP &gt; IAM &gt; API Key &gt; Approved &gt; Custom
- GCP &gt; IAM &gt; API Key &gt; Approved &gt; Usage
- GCP &gt; IAM &gt; API Key &gt; CMDB
- GCP &gt; IAM &gt; API Key &gt; Usage
- GCP &gt; IAM &gt; API Key &gt; Usage &gt; Limit

_Action Types_

- GCP &gt; IAM &gt; API Key &gt; Delete
- GCP &gt; IAM &gt; API Key &gt; Router</description>
            <pubDate>Thu, 11 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-bigquery-v5-7-0</guid>
            <title>gcp-bigquery v5.7.0 - Configure Encryption at Rest for Datasets</title>
            <link>https://turbot.com/guardrails/changelog/gcp-bigquery-v5-7-0</link>
            <description>_What&apos;s new?_

- You can now configure Encryption at Rest for datasets. To get started, set the `GCP &gt; BigQuery &gt; Dataset &gt; Encryption at Rest &gt; *` policies.

_Control Types_

- GCP &gt; BigQuery &gt; Dataset &gt; Encryption at Rest

_Policy Types_

- GCP &gt; BigQuery &gt; Dataset &gt; Encryption at Rest
- GCP &gt; BigQuery &gt; Dataset &gt; Encryption at Rest &gt; Customer Managed Key

_Action Types_

- GCP &gt; BigQuery &gt; Dataset &gt; Update Encryption At Rest</description>
            <pubDate>Thu, 11 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-kubernetes-v5-1-0</guid>
            <title>servicenow-kubernetes v5.1.0 - Added ServiceNow &gt; Import Set controls and policies for various resource types</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-kubernetes-v5-1-0</link>
            <description>_What&apos;s new?_

_Control Types_

- Kubernetes &gt; Cluster &gt; ServiceNow &gt; Import Set
- Kubernetes &gt; ConfigMap &gt; ServiceNow &gt; Import Set
- Kubernetes &gt; Deployment &gt; ServiceNow &gt; Import Set
- Kubernetes &gt; Namespace &gt; ServiceNow &gt; Import Set
- Kubernetes &gt; Node &gt; ServiceNow &gt; Import Set
- Kubernetes &gt; Pod &gt; ServiceNow &gt; Import Set
- Kubernetes &gt; ReplicaSet &gt; ServiceNow &gt; Import Set
- Kubernetes &gt; Service &gt; ServiceNow &gt; Import Set

_Policy Types_

- Kubernetes &gt; Cluster &gt; ServiceNow &gt; Import Set
- Kubernetes &gt; Cluster &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- Kubernetes &gt; Cluster &gt; ServiceNow &gt; Import Set &gt; Record
- Kubernetes &gt; Cluster &gt; ServiceNow &gt; Import Set &gt; Table Name
- Kubernetes &gt; ConfigMap &gt; ServiceNow &gt; Import Set
- Kubernetes &gt; ConfigMap &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- Kubernetes &gt; ConfigMap &gt; ServiceNow &gt; Import Set &gt; Record
- Kubernetes &gt; ConfigMap &gt; ServiceNow &gt; Import Set &gt; Table Name
- Kubernetes &gt; Deployment &gt; ServiceNow &gt; Import Set
- Kubernetes &gt; Deployment &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- Kubernetes &gt; Deployment &gt; ServiceNow &gt; Import Set &gt; Record
- Kubernetes &gt; Deployment &gt; ServiceNow &gt; Import Set &gt; Table Name
- Kubernetes &gt; Namespace &gt; ServiceNow &gt; Import Set
- Kubernetes &gt; Namespace &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- Kubernetes &gt; Namespace &gt; ServiceNow &gt; Import Set &gt; Record
- Kubernetes &gt; Namespace &gt; ServiceNow &gt; Import Set &gt; Table Name
- Kubernetes &gt; Node &gt; ServiceNow &gt; Import Set
- Kubernetes &gt; Node &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- Kubernetes &gt; Node &gt; ServiceNow &gt; Import Set &gt; Record
- Kubernetes &gt; Node &gt; ServiceNow &gt; Import Set &gt; Table Name
- Kubernetes &gt; Pod &gt; ServiceNow &gt; Import Set
- Kubernetes &gt; Pod &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- Kubernetes &gt; Pod &gt; ServiceNow &gt; Import Set &gt; Record
- Kubernetes &gt; Pod &gt; ServiceNow &gt; Import Set &gt; Table Name
- Kubernetes &gt; ReplicaSet &gt; ServiceNow &gt; Import Set
- Kubernetes &gt; ReplicaSet &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- Kubernetes &gt; ReplicaSet &gt; ServiceNow &gt; Import Set &gt; Record
- Kubernetes &gt; ReplicaSet &gt; ServiceNow &gt; Import Set &gt; Table Name
- Kubernetes &gt; Service &gt; ServiceNow &gt; Import Set
- Kubernetes &gt; Service &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- Kubernetes &gt; Service &gt; ServiceNow &gt; Import Set &gt; Record
- Kubernetes &gt; Service &gt; ServiceNow &gt; Import Set &gt; Table Name</description>
            <pubDate>Tue, 09 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ec2-v5-41-1</guid>
            <title>aws-ec2 v5.41.1 - Bug fixed - Guardrails failed to process real-time snapshot events if the Snapshot CMDB policy was set to `Enforce: Enabled for Snapshots not created with AWS Backup`</title>
            <link>https://turbot.com/guardrails/changelog/aws-ec2-v5-41-1</link>
            <description>_Bug fixes_

- Guardrails failed to process real-time snapshot events if the `AWS &gt; EC2 &gt; Snapshot &gt; CMDB` policy was set to `Enforce: Enabled for Snapshots not created with AWS Backup`. This issue has now been fixed.</description>
            <pubDate>Tue, 09 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-dns-v5-8-0</guid>
            <title>gcp-dns v5.8.0 - Configure DNSSEC for managed zones and logging for DNS policies</title>
            <link>https://turbot.com/guardrails/changelog/gcp-dns-v5-8-0</link>
            <description>_What&apos;s new?_

- Users can now configure DNSSEC for managed zones via Guardrails. To get started, set the`GCP &gt; DNS &gt; Managed Zone &gt; DNSSEC Configuration` policy.
- Users can now configure logging for DNS policies. To get started, set the `GCP &gt; DNS &gt; Policy &gt; Logging` policy.

_Control Types_

- GCP &gt; DNS &gt; Managed Zone &gt; DNSSEC Configuration
- GCP &gt; DNS &gt; Policy &gt; Logging

_Policy Types_

- GCP &gt; DNS &gt; Managed Zone &gt; DNSSEC Configuration
- GCP &gt; DNS &gt; Policy &gt; Logging

_Action Types_

- GCP &gt; DNS &gt; Managed Zone &gt; Update DNSSEC Configuration
- GCP &gt; DNS &gt; Policy &gt; Update Logging</description>
            <pubDate>Mon, 08 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-network-v5-16-4</guid>
            <title>azure-network v5.16.4 - Bug fixed - Discovery controls for various resource types would go into an error state without discovering resources and upserting them in Guardrails CMDB</title>
            <link>https://turbot.com/guardrails/changelog/azure-network-v5-16-4</link>
            <description>_Bug fixes_

- Discovery controls for various resource types would go into an error state without discovering resources and upserting them in Guardrails CMDB due to a bad internal build. This issue has been fixed, and those controls will now work correctly as expected.</description>
            <pubDate>Mon, 08 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-compute-v5-17-0</guid>
            <title>azure-compute v5.17.0 - Configure Trusted Launch for second generation virtual machines</title>
            <link>https://turbot.com/guardrails/changelog/azure-compute-v5-17-0</link>
            <description>_What&apos;s new?_

- Users can now enable/disable Trusted Launch for all second generation virtual machines. To get started, set the `Azure &gt; Compute &gt; Virtual Machine &gt; Trusted launch` policy.
- You can now configure Encryption at Rest for Disks. To get started, set the `Azure &gt; Compute &gt; Disk &gt; Encryption at Rest &gt; *` policies.

_Control Types_

- Azure &gt; Compute &gt; Disk &gt; Encryption at Rest
- Azure &gt; Compute &gt; Virtual Machine &gt; Trusted Launch

_Policy Types_

- Azure &gt; Compute &gt; Disk &gt; Encryption at Rest
- Azure &gt; Compute &gt; Disk &gt; Encryption at Rest &gt; Disk Encryption Set
- Azure &gt; Compute &gt; Virtual Machine &gt; Trusted launch

_Action Types_

- Azure &gt; Compute &gt; Disk &gt; Update Encryption at Rest
- Azure &gt; Compute &gt; Virtual Machine &gt; Update Trusted Luanch</description>
            <pubDate>Mon, 08 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-appservice-v5-10-0</guid>
            <title>azure-appservice v5.10.0 - Register web apps with Entra ID to connect to other Azure services securely</title>
            <link>https://turbot.com/guardrails/changelog/azure-appservice-v5-10-0</link>
            <description>_What&apos;s new?_

- User can now register web apps with Entra ID to connect to other Azure services securely without the need for usernames and passwords. To get started, set the `Azure &gt; App Service &gt; Web App &gt; System Assigned Identity` policy.
- Diagnostic Settings details will now also be available for Web Apps in Guardrails CMDB.

_Control Types_

- Azure &gt; App Service &gt; Web App &gt; System Assigned Identity

_Policy Types_

- Azure &gt; App Service &gt; Web App &gt; System Assigned Identity

_Action Types_

- Azure &gt; App Service &gt; Web App &gt; Set System Assigned Identity

_Bug fixes_

- The `Azure &gt; App Service &gt; Web App &gt; FTPS State` control failed to set the FTPS State correctly for web apps. This issue is now fixed.</description>
            <pubDate>Mon, 08 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-bigquery-v5-6-0</guid>
            <title>gcp-bigquery v5.6.0 - Added support for Approved &gt; Custom policy for Datasets</title>
            <link>https://turbot.com/guardrails/changelog/gcp-bigquery-v5-6-0</link>
            <description>_What&apos;s new?_

_Policy Types_

- GCP &gt; BigQuery &gt; Dataset &gt; Approved &gt; Custom</description>
            <pubDate>Fri, 05 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-networkwatcher-v5-9-0</guid>
            <title>azure-networkwatcher v5.9.0 - Configure retention policy for flow logs</title>
            <link>https://turbot.com/guardrails/changelog/azure-networkwatcher-v5-9-0</link>
            <description>_What&apos;s new?_

- Users can now configure retention policy for flow logs. To get started, set the `Azure &gt; Network Watcher &gt; Flow Log &gt; Retention Policy &gt; *` policies.

_Control Types_

- Azure &gt; Network Watcher &gt; Flow Log &gt; Retention Policy

_Policy Types_

- Azure &gt; Network Watcher &gt; Flow Log &gt; Retention Policy
- Azure &gt; Network Watcher &gt; Flow Log &gt; Retention Policy &gt; Days

_Action Types_

- Azure &gt; Network Watcher &gt; Flow Log &gt; Update Retention Policy</description>
            <pubDate>Fri, 05 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-activedirectory-v5-6-0</guid>
            <title>azure-activedirectory v5.6.0 - Directory CMDB data will now also include named locations and authorization policy details</title>
            <link>https://turbot.com/guardrails/changelog/azure-activedirectory-v5-6-0</link>
            <description>_What&apos;s new?_

- The `Azure &gt; Active Directory &gt; Directory &gt; CMDB` control will now also fetch named locations and authorization policy details and store them in CMDB.</description>
            <pubDate>Fri, 05 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-iam-v5-36-1</guid>
            <title>aws-iam v5.36.1 - Bug fixed - Account Password Policy details did not refresh correctly in Guardrails CMDB</title>
            <link>https://turbot.com/guardrails/changelog/aws-iam-v5-36-1</link>
            <description>_Bug fixes_

- Account Password Policy details did not refresh correctly in Guardrails CMDB if those settings were reset to defaults in AWS. This resulted in the `AWS &gt; IAM &gt; Account Password Policy &gt; Settings` control not applying custom settings correctly. This issue is fixed, and the CMDB details will now refresh correctly, allowing the corresponding Settings control to work as expected.</description>
            <pubDate>Fri, 05 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-securitycenter-v5-4-1</guid>
            <title>azure-securitycenter v5.4.1 - Security Center CMDB data will now also include security settings details</title>
            <link>https://turbot.com/guardrails/changelog/azure-securitycenter-v5-4-1</link>
            <description>_What&apos;s new?_

- The `Azure &gt; Security Center &gt; Security Center  &gt; CMDB` control will now also fetch security settings details and store them in CMDB.</description>
            <pubDate>Thu, 04 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-rds-v5-26-3</guid>
            <title>aws-rds v5.26.3 - Bug fixed - Discovery controls for various resource types would go into an error state without discovering resources and upserting them in Guardrails CMDB</title>
            <link>https://turbot.com/guardrails/changelog/aws-rds-v5-26-3</link>
            <description>_Bug fixes_

- Discovery controls for various resource types would go into an error state without discovering resources and upserting them in Guardrails CMDB due to a bad internal build. This issue has been fixed, and those controls will now work correctly as expected.</description>
            <pubDate>Thu, 04 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-44-7</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.44.7 - Resolved an issue that caused control targeting to accounts fail when AWS Gov accounts were imported in commercial environment</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-44-7</link>
            <description>_Bug fixes_

- Server
  - Resolved an issue that caused control targeting to accounts fail when AWS Gov accounts were imported in commercial environment.

_Requirements_

- TEF: 1.59.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Wed, 03 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-storage-v5-2-1</guid>
            <title>servicenow-gcp-storage v5.2.1 - Fixed GCP &gt; Storage &gt; Bucket &gt; ServiceNow &gt; Import Set &gt; Record default value</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-storage-v5-2-1</link>
            <description>_Bug fixes_

The default value for `GCP &gt; Storage &gt; Bucket &gt; ServiceNow &gt; Import Set` now shows the `resource_type_uri` correctly.</description>
            <pubDate>Wed, 03 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-storage-v5-2-0</guid>
            <title>servicenow-gcp-storage v5.2.0 - Added Bucket &gt; ServiceNow &gt; Import Set controls and policies</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-storage-v5-2-0</link>
            <description>_Control Types_

**Added**

- GCP &gt; Storage &gt; Bucket &gt; ServiceNow &gt; Import Set

_Policy Types_

**Added**

- GCP &gt; Storage &gt; Bucket &gt; ServiceNow &gt; Import Set
- GCP &gt; Storage &gt; Bucket &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- GCP &gt; Storage &gt; Bucket &gt; ServiceNow &gt; Import Set &gt; Record
- GCP &gt; Storage &gt; Bucket &gt; ServiceNow &gt; Import Set &gt; Table Name</description>
            <pubDate>Wed, 03 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-v5-2-0</guid>
            <title>servicenow-gcp v5.2.0 - Records can now be archived when using import sets</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-v5-2-0</link>
            <description>_What&apos;s new?_

- `ServiceNow &gt; Turbot &gt; Watches &gt; GCP Archive and Delete Record` action now supports archiving `Import Set` records.</description>
            <pubDate>Wed, 03 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-storage-v5-2-0</guid>
            <title>servicenow-azure-storage v5.2.0 - Added Storage Account &gt; ServiceNow &gt; Import Set controls and policies</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-storage-v5-2-0</link>
            <description>_Control Types_

**Added**

- Azure &gt; Storage &gt; Storage Account &gt; ServiceNow &gt; Import Set

_Policy Types_

**Added**

- Azure &gt; Storage &gt; Storage Account &gt; ServiceNow &gt; Import Set
- Azure &gt; Storage &gt; Storage Account &gt; ServiceNow &gt; Import Set &gt; Archive Columns
- Azure &gt; Storage &gt; Storage Account &gt; ServiceNow &gt; Import Set &gt; Record
- Azure &gt; Storage &gt; Storage Account &gt; ServiceNow &gt; Import Set &gt; Table Name</description>
            <pubDate>Wed, 03 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-v5-2-0</guid>
            <title>servicenow-azure v5.2.0 - Records can now be archived when using import sets</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-v5-2-0</link>
            <description>_What&apos;s new?_

- `ServiceNow &gt; Turbot &gt; Watches &gt; Azure Archive and Delete Record` action now supports archiving `Import Set` records.</description>
            <pubDate>Wed, 03 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-v5-1-0</guid>
            <title>servicenow v5.1.0 - Fixed default values for various CMDB policies and add Import Set default table name policy</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-v5-1-0</link>
            <description>_Bug fixes_

- Default policy values for `ServiceNow &gt; Application &gt; CMDB`, `ServiceNow &gt; Cost Center &gt; CMDB` &amp; `ServiceNow &gt; User &gt; CMDB` have been updated from `Enforce: Enabled` to `Skip`.

_Policy Types_

**Added**

- ServiceNow &gt; Import Set
- ServiceNow &gt; Import Set &gt; Table Name [Default]</description>
            <pubDate>Wed, 03 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-44-6</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.44.6 - Minor internal improvements</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-44-6</link>
            <description>_Bug fixes_

- Server
  - Minor internal improvements.

_Requirements_

- TEF: 1.59.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Tue, 02 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-44-5</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.44.5 - The OUTBOUND_SECURITY_GROUP_ID environment variable in Lambda functions now defaults to using the TEF outbound security group when there is no override specified in TEF and TE</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-44-5</link>
            <description>_Bug fixes_

- Server
  - The `OUTBOUND_SECURITY_GROUP_ID` environment variable in Lambda functions now defaults to using the TEF outbound security group when there is no override specified in TEF and TE.

_Requirements_

- TEF: 1.59.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Mon, 01 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-network-v5-16-3</guid>
            <title>azure-network v5.16.3 - The Security Group Ingress and Egress Approved controls would now revoke only the rejected port prefixes instead of deleting the entire rule</title>
            <link>https://turbot.com/guardrails/changelog/azure-network-v5-16-3</link>
            <description>_Bug fixes_

- The `Azure &gt; Network &gt; Network Security Group &gt; Ingress Rules &gt; Approved` and `Azure &gt; Network &gt; Network Security Group &gt; Egress Rules &gt; Approved` controls previously deleted an entire rule if at least one of the corresponding port prefixes was rejected, even if the others were approved. These controls will now revoke only the rejected port prefixes instead of deleting the entire rule in such cases.</description>
            <pubDate>Mon, 01 Jul 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-rds-v5-26-2</guid>
            <title>aws-rds v5.26.2 - Bug fixed - The RDS DB Instance Approved control did not stop an unapproved instance if the corresponding policy was set to `Enforce: Stop unapproved` or `Enforce: Stop unapproved if new`, and deletion protection for the instance was enabled</title>
            <link>https://turbot.com/guardrails/changelog/aws-rds-v5-26-2</link>
            <description>_Bug fixes_

- The `AWS &gt; RDS &gt; DB Instance &gt; Approved` control will now be skipped for instances that belong to a cluster. To check if a cluster is approved for use, please set the `AWS &gt; RDS &gt; DB Cluster &gt; Approved &gt; *` policies.
- The `AWS &gt; RDS &gt; DB Instance &gt; Approved` control did not stop an unapproved instance if the corresponding policy was set to `Enforce: Stop unapproved` or `Enforce: Stop unapproved if new`, and deletion protection for the instance was enabled. The control will now stop instances correctly in such cases.</description>
            <pubDate>Fri, 28 Jun 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-44-4</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.44.4 - Enhanced management of EncryptionInTransit topic policy</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-44-4</link>
            <description>_What&apos;s new?_

- Server
  - The creation of the `EncryptionInTransit` TopicPolicy has shifted from a custom resource to AWS CloudFormation’s `AWS::SNS::TopicPolicy`.

_Bug fixes_

- Server
  - Changes to notifications introduced in version 5.44.2 have been rolled back due to issues with specific queries. This action restores previous functionality and ensures stability across the platform.

_Requirements_

- TEF: 1.59.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Thu, 27 Jun 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-44-2</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.44.2 - Performance enhancements and UI improvements</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-44-2</link>
            <description>_What&apos;s new?_

- Server
  - Made notifications faster by improving the query, which enhances the performance of the activity tab.

- UI
  - The `Depends-on` tab on the controls page has been renamed to `Related`. It now includes the information from the Depends-on tab along with additional related controls information.

_Bug fixes_

- Server
  - Fixed an issue where sometimes an older mod version was used instead of the latest one after a mod upgrade. Now, the cache is properly updated to always use the latest version.

_Requirements_

- TEF: 1.59.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Mon, 24 Jun 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-network-v5-16-2</guid>
            <title>azure-network v5.16.2 - Bug fixed - The Network Security Group Ingress Rules Approved control would sometimes fail to revoke rejected rules from a network security group</title>
            <link>https://turbot.com/guardrails/changelog/azure-network-v5-16-2</link>
            <description>_Bug fixes_

- The `Azure &gt; Network &gt; Network Security Group &gt; Ingress Rules &gt; Approved` control would sometimes fail to revoke rejected rules when the corresponding policy was set to `Enforce: Delete unapproved`. This has been fixed, and the control will now work more reliably and consistently than before.</description>
            <pubDate>Mon, 24 Jun 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/osquery-v5-0-2</guid>
            <title>osquery v5.0.2 - The osquery Event Handler action would not handle events for large payloads</title>
            <link>https://turbot.com/guardrails/changelog/osquery-v5-0-2</link>
            <description>_Bug fixes_

- `Turbot &gt; osquery &gt; Event Handler` action was not able to handle events for large payloads. This issue is now fixed.</description>
            <pubDate>Tue, 18 Jun 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-v5-24-3</guid>
            <title>gcp v5.24.3 - Bug fixed - The Project CMDB control would incorrectly delete a project from Guardrails CMDB if it was unable to fetch Access Approval settings for the project</title>
            <link>https://turbot.com/guardrails/changelog/gcp-v5-24-3</link>
            <description>_Bug fixes_

- The `GCP &gt; Project &gt; CMDB` control would incorrectly delete a project from Guardrails CMDB if it was unable to fetch Access Approval settings for the project. This issue has been fixed and the control will now attempt to fetch all available details and will not delete the project from CMDB.</description>
            <pubDate>Tue, 18 Jun 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-securitycenter-v5-4-0</guid>
            <title>azure-securitycenter v5.4.0 - Auto Provisioning for Security Center is now available</title>
            <link>https://turbot.com/guardrails/changelog/azure-securitycenter-v5-4-0</link>
            <description>_Bug fixes_

- Users can now configure Auto Provisioning for Azure Security Center in Guardrails. To get started, set the `Azure &gt; Security Center &gt; Security Center &gt; Auto Provisioning` policy.

_Control Types_
- Azure &gt; Security Center &gt; Security Center &gt; Auto Provisioning

_Policy Types_
- Azure &gt; Security Center &gt; Security Center &gt; Auto Provisioning

_Action Types_
- Azure &gt; Security Center &gt; Security Center &gt; Update Auto Provisioning</description>
            <pubDate>Mon, 17 Jun 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-v5-19-0</guid>
            <title>azure v5.19.0 - Subscription CMDB data will now also include tagging details for the subscription</title>
            <link>https://turbot.com/guardrails/changelog/azure-v5-19-0</link>
            <description>_What&apos;s new?_

- Subscription CMDB data will now also include tagging details for the subscription.</description>
            <pubDate>Fri, 14 Jun 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-securitycenter-v5-3-0</guid>
            <title>azure-securitycenter v5.3.0 - The Security Center Defender Plan control now also supports services like Cloud Posture, Containers and Cosmos DB</title>
            <link>https://turbot.com/guardrails/changelog/azure-securitycenter-v5-3-0</link>
            <description>_What&apos;s new?_

- The `Azure &gt; Security Center &gt; Security Center &gt; Defender Plan` control now also supports services like Cloud Posture, Containers and Cosmos DB.</description>
            <pubDate>Fri, 14 Jun 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-44-1</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.44.1 - Added support for newer auth mechanism to fetch temporary Azure credentials</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-44-1</link>
            <description>_What&apos;s new?_

- Server

  - Added support for newer auth mechanism to fetch temporary Azure credentials via the `@azure/msal-node` package.

_Requirements_

- TEF: 1.59.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Thu, 13 Jun 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ec2-v5-41-0</guid>
            <title>aws-ec2 v5.41.0 - Skip upserting snapshots in Guardrails CMDB if they are created via the AWS Backup service</title>
            <link>https://turbot.com/guardrails/changelog/aws-ec2-v5-41-0</link>
            <description>_What&apos;s new?_

- Users can now skip upserting snapshots in Guardrails CMDB if they are created via the AWS Backup service. To get started, set the `AWS &gt; EC2 &gt; Snapshot &gt; CMDB` policy to `Enforce: Enabled for Snapshots not created with AWS Backup`.</description>
            <pubDate>Thu, 13 Jun 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-v5-30-1</guid>
            <title>aws v5.30.1 - Bug fixed - The Turbot Service Roles stack control did not work as expected when all policies except the Event Handlers [Global] policy were enabled</title>
            <link>https://turbot.com/guardrails/changelog/aws-v5-30-1</link>
            <description>_Bug fixes_

- The `AWS &gt; Turbot &gt; Service Roles &gt; Source` policy went to an invalid state if all but the `AWS &gt; Turbot &gt; Service Roles &gt; Event Handlers [Global]` policy was enabled. This issue impacted the `AWS &gt; Turbot &gt; Service Roles` stack control, preventing the role from being created correctly. This has been fixed, and the `AWS &gt; Turbot &gt; Service Roles &gt; Source` policy will now work as expected.</description>
            <pubDate>Tue, 11 Jun 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-cisv3-0-v5-0-1</guid>
            <title>aws-cisv3-0 v5.0.1 - `1.02 Ensure security contact information is registered` control will now evaluate the outcome correctly</title>
            <link>https://turbot.com/guardrails/changelog/aws-cisv3-0-v5-0-1</link>
            <description>_Bug fixes_

- The `AWS &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.02 - Ensure security contact information is registered` control did not evaluate the result correctly, as expected. This is now fixed.</description>
            <pubDate>Tue, 11 Jun 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-59-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.59.0 - Added support for new flags in the Flags attribute</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-59-0</link>
            <description>_What&apos;s new?_

  - Updated the existing *Flags* attribute to include new specific flags that control the operation of Mod Lambda functions within a Virtual Private Cloud (VPC). This update allows Lambdas to use static IP addresses, improving network stability and predictability across different cloud environments.
  New flags Added to *Flags* Attribute:
    - LAMBDA_IN_VPC_AWS
    - LAMBDA_IN_VPC_AZURE
    - LAMBDA_IN_VPC_GCP
    - LAMBDA_IN_VPC_SERVICENOW

  - Introduced a new SSM parameter outbound_cidr_ranges to retrieve the Elastic IPs associated with the NAT gateways.</description>
            <pubDate>Mon, 10 Jun 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-44-0</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.44.0 - Lambda functions now support static IPs with VPC integration.</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-44-0</link>
            <description>_What&apos;s new?_

- Server

  - You can now configure Mod Lambda functions to run within a VPC across various providers including AWS, Azure, ServiceNow, and GCP. This update ensures Lambdas operate with static CIDR ranges.
  - Enhanced `osquery/logger` API to support payloads up to 10MB.

_Requirements_

- TEF: 1.59.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Mon, 10 Jun 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-cisv2-0-v5-0-1</guid>
            <title>azure-cisv2-0 v5.0.1 - Minor fixes and improvements</title>
            <link>https://turbot.com/guardrails/changelog/azure-cisv2-0-v5-0-1</link>
            <description>_Bug fixes_

- Minor fixes and improvements.</description>
            <pubDate>Mon, 10 Jun 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-cisv2-0-v5-0-2</guid>
            <title>aws-cisv2-0 v5.0.2 - `1.02 Ensure security contact information is registered` control will now evaluate the outcome correctly</title>
            <link>https://turbot.com/guardrails/changelog/aws-cisv2-0-v5-0-2</link>
            <description>_Bug fixes_

- The `AWS &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.02 - Ensure security contact information is registered` control did not evaluate the result correctly, as expected. This is now fixed.</description>
            <pubDate>Mon, 10 Jun 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-network-v5-16-1</guid>
            <title>azure-network v5.16.1 - The Ingress/Egress Rules Approved controls for Network Security Group Rules will now revoke rejected address prefixes individually instead of deleting an entire rule</title>
            <link>https://turbot.com/guardrails/changelog/azure-network-v5-16-1</link>
            <description>_Bug fixes_

- The `Azure &gt; Network &gt; Network Security Group &gt; Ingress Rules &gt; Approved` and `Azure &gt; Network &gt; Network Security Group &gt; Egress Rules &gt; Approved` controls previously deleted an entire rule if at least one of the corresponding address prefixes was rejected, even if the others were approved. These controls will now revoke only the rejected address prefix instead of deleting the entire rule in such cases.</description>
            <pubDate>Mon, 03 Jun 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-bigquerydatatransfer-v5-0-1</guid>
            <title>gcp-bigquerydatatransfer v5.0.1 - Fixed incorrect filter patterns in the Compiled Filter policy to allow Event Handlers to work as expected</title>
            <link>https://turbot.com/guardrails/changelog/gcp-bigquerydatatransfer-v5-0-1</link>
            <description>_Bug fixes_

- The `GCP &gt; Turbot &gt; Event Handlers &gt; Logging` would go into an Invalid state because of incorrect filter patterns defined in the `GCP &gt; Turbot &gt; Event Handlers &gt; Logging &gt; Sink &gt; Compiled Filter &gt; @turbot/gcp-bigquerydatatransfer` policy. This is fixed and the control will now work as expected.</description>
            <pubDate>Wed, 29 May 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-network-v5-13-1</guid>
            <title>gcp-network v5.13.1 - Guardrails would sometimes process the real-time event `compute.networks.delete` for default networks incorrectly, resulting in the inadvertent deletion of those networks from CMDB</title>
            <link>https://turbot.com/guardrails/changelog/gcp-network-v5-13-1</link>
            <description>_Bug fixes_

- Guardrails would sometimes process the real-time event `compute.networks.delete` for default networks incorrectly, resulting in the inadvertent deletion of those networks from CMDB. This is now fixed.</description>
            <pubDate>Tue, 28 May 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-appfabric-v5-0-0</guid>
            <title>aws-appfabric v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/aws-appfabric-v5-0-0</link>
            <description>_What&apos;s new?_

_Resource Types_
  - AWS &gt; AppFabric

_Policy Types_
  - AWS &gt; AppFabric &gt; API Enabled
  - AWS &gt; AppFabric &gt; Approved Regions [Default]
  - AWS &gt; AppFabric &gt; Enabled
  - AWS &gt; AppFabric &gt; Permissions
  - AWS &gt; AppFabric &gt; Permissions &gt; Levels
  - AWS &gt; AppFabric &gt; Permissions &gt; Levels &gt; Modifiers
  - AWS &gt; AppFabric &gt; Permissions &gt; Lockdown
  - AWS &gt; AppFabric &gt; Permissions &gt; Lockdown &gt; API Boundary
  - AWS &gt; AppFabric &gt; Regions
  - AWS &gt; AppFabric &gt; Tags Template [Default]
  - AWS &gt; Turbot &gt; Permissions &gt; Compiled &gt; API Boundary &gt; @turbot/aws-appfabric
  - AWS &gt; Turbot &gt; Permissions &gt; Compiled &gt; Levels &gt; @turbot/aws-appfabric
  - AWS &gt; Turbot &gt; Permissions &gt; Compiled &gt; Service Permissions &gt; @turbot/aws-appfabric</description>
            <pubDate>Tue, 28 May 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-iam-v5-14-0</guid>
            <title>gcp-iam v5.14.0 - Approved control and its associated policies are now available for Project User resource type</title>
            <link>https://turbot.com/guardrails/changelog/gcp-iam-v5-14-0</link>
            <description>_What&apos;s new?_

_Control Types_
  - GCP &gt; IAM &gt; Project User &gt; Approved

_Policy Types_
  - GCP &gt; IAM &gt; Project User &gt; Approved
  - GCP &gt; IAM &gt; Project User &gt; Approved &gt; Custom
  - GCP &gt; IAM &gt; Project User &gt; Approved &gt; Usage</description>
            <pubDate>Mon, 27 May 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-s3-v5-24-1</guid>
            <title>aws-s3 v5.24.1 - Guardrails failed to process the real-time event `s3:PutBucketReplication` for buckets</title>
            <link>https://turbot.com/guardrails/changelog/aws-s3-v5-24-1</link>
            <description>_Bug fixes_

- Guardrails failed to process the real-time event `s3:PutBucketReplication` for buckets. This is now fixed.
- The `AWS &gt; S3 &gt; Bucket &gt; Access Logging` control would sometimes go into an error state if the target bucket name started with a number. This is fixed and the control will now work more smoothly and consistently than before.</description>
            <pubDate>Fri, 24 May 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-storage-v5-17-2</guid>
            <title>azure-storage v5.17.2 - System storage containers will now be discovered correctly in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/azure-storage-v5-17-2</link>
            <description>_Bug fixes_

- Guardrails failed to discover system storage containers (e.g. `$logs`) for storage accounts. This is now fixed.</description>
            <pubDate>Thu, 16 May 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-v5-24-2</guid>
            <title>gcp v5.24.2 - Added support to process enable and disable real-time events for BigQuery Data Transfer API via Service Usage APIs</title>
            <link>https://turbot.com/guardrails/changelog/gcp-v5-24-2</link>
            <description>_Bug fixes_

- Added support to process enable and disable real-time events for BigQuery Data Transfer API via Service Usage APIs.</description>
            <pubDate>Wed, 15 May 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-bigquerydatatransfer-v5-0-0</guid>
            <title>gcp-bigquerydatatransfer v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/gcp-bigquerydatatransfer-v5-0-0</link>
            <description>## 5.0.0 (2024-05-15)

_What&apos;s new?_

_Resource Types_
  - GCP &gt; BigQuery Data Transfer
  - GCP &gt; BigQuery Data Transfer &gt; Transfer Config

_Control Types_
  - GCP &gt; BigQuery Data Transfer &gt; API Enabled
  - GCP &gt; BigQuery Data Transfer &gt; CMDB
  - GCP &gt; BigQuery Data Transfer &gt; Discovery
  - GCP &gt; BigQuery Data Transfer &gt; Transfer Config &gt; Active
  - GCP &gt; BigQuery Data Transfer &gt; Transfer Config &gt; Approved
  - GCP &gt; BigQuery Data Transfer &gt; Transfer Config &gt; CMDB
  - GCP &gt; BigQuery Data Transfer &gt; Transfer Config &gt; Discovery
  - GCP &gt; BigQuery Data Transfer &gt; Transfer Config &gt; Usage

_Policy Types_
  - GCP &gt; BigQuery Data Transfer &gt; API Enabled
  - GCP &gt; BigQuery Data Transfer &gt; Approved Regions [Default]
  - GCP &gt; BigQuery Data Transfer &gt; CMDB
  - GCP &gt; BigQuery Data Transfer &gt; Enabled
  - GCP &gt; BigQuery Data Transfer &gt; Permissions
  - GCP &gt; BigQuery Data Transfer &gt; Permissions &gt; Levels
  - GCP &gt; BigQuery Data Transfer &gt; Permissions &gt; Levels &gt; Modifiers
  - GCP &gt; BigQuery Data Transfer &gt; Regions
  - GCP &gt; BigQuery Data Transfer &gt; Transfer Config &gt; Active
  - GCP &gt; BigQuery Data Transfer &gt; Transfer Config &gt; Active &gt; Age
  - GCP &gt; BigQuery Data Transfer &gt; Transfer Config &gt; Active &gt; Last Modified
  - GCP &gt; BigQuery Data Transfer &gt; Transfer Config &gt; Approved
  - GCP &gt; BigQuery Data Transfer &gt; Transfer Config &gt; Approved &gt; Custom
  - GCP &gt; BigQuery Data Transfer &gt; Transfer Config &gt; Approved &gt; Usage
  - GCP &gt; BigQuery Data Transfer &gt; Transfer Config &gt; CMDB
  - GCP &gt; BigQuery Data Transfer &gt; Transfer Config &gt; Regions
  - GCP &gt; BigQuery Data Transfer &gt; Transfer Config &gt; Usage
  - GCP &gt; BigQuery Data Transfer &gt; Transfer Config &gt; Usage &gt; Limit
  - GCP &gt; Turbot &gt; Event Handlers &gt; Logging &gt; Sink &gt; Compiled Filter &gt; @turbot/gcp-bigquerydatatransfer
  - GCP &gt; Turbot &gt; Permissions &gt; Compiled &gt; Levels &gt; @turbot/gcp-bigquerydatatransfer
  - GCP &gt; Turbot &gt; Permissions &gt; Compiled &gt; Service Permissions &gt; @turbot/gcp-bigquerydatatransfer

_Action Types_
  - GCP &gt; BigQuery Data Transfer &gt; Set API Enabled
  - GCP &gt; BigQuery Data Transfer &gt; Transfer Config &gt; Delete
  - GCP &gt; BigQuery Data Transfer &gt; Transfer Config &gt; Router</description>
            <pubDate>Wed, 15 May 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/osquery-v5-0-1</guid>
            <title>osquery v5.0.1 - Fixed control category titles</title>
            <link>https://turbot.com/guardrails/changelog/osquery-v5-0-1</link>
            <description>_Bug fixes_

- Fixed control category titles to use `osquery` instead of `Osquery`.</description>
            <pubDate>Tue, 14 May 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/kubernetes-v5-0-1</guid>
            <title>kubernetes v5.0.1 is now available</title>
            <link>https://turbot.com/guardrails/changelog/kubernetes-v5-0-1</link>
            <description>_Bug fixes_

- `Kubernetes &gt; Node` resources will no longer include the `conditions.lastHeartbeatTime` or `resource_version` properties to avoid unnecessary notifications in the activity tab.</description>
            <pubDate>Tue, 14 May 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-eventbridgescheduler-v5-0-0</guid>
            <title>aws-eventbridgescheduler v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/aws-eventbridgescheduler-v5-0-0</link>
            <description>_What&apos;s new?_

_Resource Types_
  - AWS &gt; EventBridge Scheduler

_Policy Types_
  - AWS &gt; EventBridge Scheduler &gt; API Enabled
  - AWS &gt; EventBridge Scheduler &gt; Approved Regions [Default]
  - AWS &gt; EventBridge Scheduler &gt; Enabled
  - AWS &gt; EventBridge Scheduler &gt; Permissions
  - AWS &gt; EventBridge Scheduler &gt; Permissions &gt; Levels
  - AWS &gt; EventBridge Scheduler &gt; Permissions &gt; Levels &gt; Modifiers
  - AWS &gt; EventBridge Scheduler &gt; Permissions &gt; Lockdown
  - AWS &gt; EventBridge Scheduler &gt; Permissions &gt; Lockdown &gt; API Boundary
  - AWS &gt; EventBridge Scheduler &gt; Regions
  - AWS &gt; EventBridge Scheduler &gt; Tags Template [Default]
  - AWS &gt; Turbot &gt; Permissions &gt; Compiled &gt; API Boundary &gt; @turbot/aws-eventbridgescheduler
  - AWS &gt; Turbot &gt; Permissions &gt; Compiled &gt; Levels &gt; @turbot/aws-eventbridgescheduler
  - AWS &gt; Turbot &gt; Permissions &gt; Compiled &gt; Service Permissions &gt; @turbot/aws-eventbridgescheduler</description>
            <pubDate>Tue, 14 May 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-eventbridgepipes-v5-0-0</guid>
            <title>aws-eventbridgepipes v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/aws-eventbridgepipes-v5-0-0</link>
            <description>_What&apos;s new?_

_Resource Types_
  - AWS &gt; EventBridge Pipes

_Policy Types_
  - AWS &gt; EventBridge Pipes &gt; API Enabled
  - AWS &gt; EventBridge Pipes &gt; Approved Regions [Default]
  - AWS &gt; EventBridge Pipes &gt; Enabled
  - AWS &gt; EventBridge Pipes &gt; Permissions
  - AWS &gt; EventBridge Pipes &gt; Permissions &gt; Levels
  - AWS &gt; EventBridge Pipes &gt; Permissions &gt; Levels &gt; Modifiers
  - AWS &gt; EventBridge Pipes &gt; Permissions &gt; Lockdown
  - AWS &gt; EventBridge Pipes &gt; Permissions &gt; Lockdown &gt; API Boundary
  - AWS &gt; EventBridge Pipes &gt; Regions
  - AWS &gt; EventBridge Pipes &gt; Tags Template [Default]
  - AWS &gt; Turbot &gt; Permissions &gt; Compiled &gt; API Boundary &gt; @turbot/aws-eventbridgepipes
  - AWS &gt; Turbot &gt; Permissions &gt; Compiled &gt; Levels &gt; @turbot/aws-eventbridgepipes
  - AWS &gt; Turbot &gt; Permissions &gt; Compiled &gt; Service Permissions &gt; @turbot/aws-eventbridgepipes</description>
            <pubDate>Tue, 14 May 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-43-0</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.43.0 - Added support for osquery management and operations.</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-43-0</link>
            <description>_What&apos;s new?_

- Server

  - Added a new GraphQL resolver for osquery to generate an enrollSecret.
  - Added new REST APIs for osquery management, which includes:
    - `api/latest/osquery/enroll`
    - `api/latest/osquery/config`
    - `api/latest/osquery/logger`
  - Introduced a dedicated worker, along with SQS FIFO queue and SNS topic FIFO, to run osquery operations.
  - Implemented a new `serviceNowCredential` resolver specifically for Kubernetes clusters.
  - Upgraded our SDK (`@turbot/sdk`) to version 5.15.0 and our fn toolkit (`@turbot/fn`) to version 5.22.0, to support FIFO queues.

- UI
  - Added support for connecting to Kubernetes, facilitating easier integration and management.
  - Added report for AWS CIS v2.0.
  - Added report for AWS CIS v3.0.
  - Added report for Azure CIS v2.0.
  - Added report for GCP CIS v2.0.

_Requirements_

- TEF: 1.58.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Mon, 13 May 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-kubernetes-v5-0-0</guid>
            <title>servicenow-kubernetes v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-kubernetes-v5-0-0</link>
            <description>_What&apos;s new?_

_Control Types_

- Kubernetes &gt; Cluster &gt; ServiceNow
- Kubernetes &gt; Cluster &gt; ServiceNow &gt; Configuration Item
- Kubernetes &gt; Cluster &gt; ServiceNow &gt; Table
- Kubernetes &gt; ConfigMap &gt; ServiceNow
- Kubernetes &gt; ConfigMap &gt; ServiceNow &gt; Configuration Item
- Kubernetes &gt; ConfigMap &gt; ServiceNow &gt; Table
- Kubernetes &gt; Deployment &gt; ServiceNow
- Kubernetes &gt; Deployment &gt; ServiceNow &gt; Configuration Item
- Kubernetes &gt; Deployment &gt; ServiceNow &gt; Table
- Kubernetes &gt; Namespace &gt; ServiceNow
- Kubernetes &gt; Namespace &gt; ServiceNow &gt; Configuration Item
- Kubernetes &gt; Namespace &gt; ServiceNow &gt; Table
- Kubernetes &gt; Node &gt; ServiceNow
- Kubernetes &gt; Node &gt; ServiceNow &gt; Configuration Item
- Kubernetes &gt; Node &gt; ServiceNow &gt; Table
- Kubernetes &gt; Pod &gt; ServiceNow
- Kubernetes &gt; Pod &gt; ServiceNow &gt; Configuration Item
- Kubernetes &gt; Pod &gt; ServiceNow &gt; Table
- Kubernetes &gt; ReplicaSet &gt; ServiceNow
- Kubernetes &gt; ReplicaSet &gt; ServiceNow &gt; Configuration Item
- Kubernetes &gt; ReplicaSet &gt; ServiceNow &gt; Table
- Kubernetes &gt; Service &gt; ServiceNow
- Kubernetes &gt; Service &gt; ServiceNow &gt; Configuration Item
- Kubernetes &gt; Service &gt; ServiceNow &gt; Table
- ServiceNow &gt; Turbot &gt; Watches &gt; Kubernetes

_Policy Types_

- Kubernetes &gt; Cluster &gt; ServiceNow
- Kubernetes &gt; Cluster &gt; ServiceNow &gt; Configuration Item
- Kubernetes &gt; Cluster &gt; ServiceNow &gt; Configuration Item &gt; Record
- Kubernetes &gt; Cluster &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
- Kubernetes &gt; Cluster &gt; ServiceNow &gt; Table
- Kubernetes &gt; Cluster &gt; ServiceNow &gt; Table &gt; Definition
- Kubernetes &gt; ConfigMap &gt; ServiceNow
- Kubernetes &gt; ConfigMap &gt; ServiceNow &gt; Configuration Item
- Kubernetes &gt; ConfigMap &gt; ServiceNow &gt; Configuration Item &gt; Record
- Kubernetes &gt; ConfigMap &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
- Kubernetes &gt; ConfigMap &gt; ServiceNow &gt; Table
- Kubernetes &gt; ConfigMap &gt; ServiceNow &gt; Table &gt; Definition
- Kubernetes &gt; Deployment &gt; ServiceNow
- Kubernetes &gt; Deployment &gt; ServiceNow &gt; Configuration Item
- Kubernetes &gt; Deployment &gt; ServiceNow &gt; Configuration Item &gt; Record
- Kubernetes &gt; Deployment &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
- Kubernetes &gt; Deployment &gt; ServiceNow &gt; Table
- Kubernetes &gt; Deployment &gt; ServiceNow &gt; Table &gt; Definition
- Kubernetes &gt; Namespace &gt; ServiceNow
- Kubernetes &gt; Namespace &gt; ServiceNow &gt; Configuration Item
- Kubernetes &gt; Namespace &gt; ServiceNow &gt; Configuration Item &gt; Record
- Kubernetes &gt; Namespace &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
- Kubernetes &gt; Namespace &gt; ServiceNow &gt; Table
- Kubernetes &gt; Namespace &gt; ServiceNow &gt; Table &gt; Definition
- Kubernetes &gt; Node &gt; ServiceNow
- Kubernetes &gt; Node &gt; ServiceNow &gt; Configuration Item
- Kubernetes &gt; Node &gt; ServiceNow &gt; Configuration Item &gt; Record
- Kubernetes &gt; Node &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
- Kubernetes &gt; Node &gt; ServiceNow &gt; Table
- Kubernetes &gt; Node &gt; ServiceNow &gt; Table &gt; Definition
- Kubernetes &gt; Pod &gt; ServiceNow
- Kubernetes &gt; Pod &gt; ServiceNow &gt; Configuration Item
- Kubernetes &gt; Pod &gt; ServiceNow &gt; Configuration Item &gt; Record
- Kubernetes &gt; Pod &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
- Kubernetes &gt; Pod &gt; ServiceNow &gt; Table
- Kubernetes &gt; Pod &gt; ServiceNow &gt; Table &gt; Definition
- Kubernetes &gt; ReplicaSet &gt; ServiceNow
- Kubernetes &gt; ReplicaSet &gt; ServiceNow &gt; Configuration Item
- Kubernetes &gt; ReplicaSet &gt; ServiceNow &gt; Configuration Item &gt; Record
- Kubernetes &gt; ReplicaSet &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
- Kubernetes &gt; ReplicaSet &gt; ServiceNow &gt; Table
- Kubernetes &gt; ReplicaSet &gt; ServiceNow &gt; Table &gt; Definition
- Kubernetes &gt; Service &gt; ServiceNow
- Kubernetes &gt; Service &gt; ServiceNow &gt; Configuration Item
- Kubernetes &gt; Service &gt; ServiceNow &gt; Configuration Item &gt; Record
- Kubernetes &gt; Service &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
- Kubernetes &gt; Service &gt; ServiceNow &gt; Table
- Kubernetes &gt; Service &gt; ServiceNow &gt; Table &gt; Definition
- ServiceNow &gt; Turbot &gt; Watches &gt; Kubernetes

_Action Types_

- ServiceNow &gt; Turbot &gt; Watches &gt; Kubernetes Archive And Delete Record</description>
            <pubDate>Mon, 13 May 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/osquery-v5-0-0</guid>
            <title>osquery v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/osquery-v5-0-0</link>
            <description>_What&apos;s new?_

_Resource Types_

- osquery

_Control Types_

- Turbot &gt; Workspace &gt; osquery
- Turbot &gt; Workspace &gt; osquery &gt; Secret Rotation

_Policy Types_

- Turbot &gt; Workspace &gt; osquery
- Turbot &gt; Workspace &gt; osquery &gt; Enroll Secret Expiration
- Turbot &gt; Workspace &gt; osquery &gt; Secrets
- Turbot &gt; Workspace &gt; osquery &gt; Secrets &gt; Expiration Period
- Turbot &gt; Workspace &gt; osquery &gt; Secrets &gt; Rotation
- osquery &gt; Configuration

_Action Types_

- Turbot &gt; Rotate osquery Secret
- osquery &gt; Event Handler</description>
            <pubDate>Mon, 13 May 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/kubernetes-v5-0-0</guid>
            <title>kubernetes v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/kubernetes-v5-0-0</link>
            <description>_What&apos;s new?_

_Resource Types_

- Kubernetes
- Kubernetes &gt; Cluster
- Kubernetes &gt; ConfigMap
- Kubernetes &gt; Deployment
- Kubernetes &gt; Namespace
- Kubernetes &gt; Node
- Kubernetes &gt; Pod
- Kubernetes &gt; ReplicaSet
- Kubernetes &gt; Service

_Control Types_

- Kubernetes &gt; Cluster &gt; CMDB
- Kubernetes &gt; ConfigMap &gt; Annotations
- Kubernetes &gt; ConfigMap &gt; Approved
- Kubernetes &gt; ConfigMap &gt; CMDB
- Kubernetes &gt; ConfigMap &gt; Labels
- Kubernetes &gt; ConfigMap &gt; Query
- Kubernetes &gt; Deployment &gt; Annotations
- Kubernetes &gt; Deployment &gt; Approved
- Kubernetes &gt; Deployment &gt; CMDB
- Kubernetes &gt; Deployment &gt; Labels
- Kubernetes &gt; Deployment &gt; Query
- Kubernetes &gt; Namespace &gt; Annotations
- Kubernetes &gt; Namespace &gt; Approved
- Kubernetes &gt; Namespace &gt; CMDB
- Kubernetes &gt; Namespace &gt; Labels
- Kubernetes &gt; Namespace &gt; Query
- Kubernetes &gt; Node &gt; Annotations
- Kubernetes &gt; Node &gt; Approved
- Kubernetes &gt; Node &gt; CMDB
- Kubernetes &gt; Node &gt; Labels
- Kubernetes &gt; Node &gt; Query
- Kubernetes &gt; Pod &gt; Annotations
- Kubernetes &gt; Pod &gt; Approved
- Kubernetes &gt; Pod &gt; CMDB
- Kubernetes &gt; Pod &gt; Labels
- Kubernetes &gt; Pod &gt; Query
- Kubernetes &gt; ReplicaSet &gt; Annotations
- Kubernetes &gt; ReplicaSet &gt; Approved
- Kubernetes &gt; ReplicaSet &gt; CMDB
- Kubernetes &gt; ReplicaSet &gt; Labels
- Kubernetes &gt; ReplicaSet &gt; Query
- Kubernetes &gt; Service &gt; Annotations
- Kubernetes &gt; Service &gt; Approved
- Kubernetes &gt; Service &gt; CMDB
- Kubernetes &gt; Service &gt; Labels
- Kubernetes &gt; Service &gt; Query

_Policy Types_

- Kubernetes &gt; Cluster &gt; CMDB
- Kubernetes &gt; ConfigMap &gt; Annotations
- Kubernetes &gt; ConfigMap &gt; Annotations &gt; Template
- Kubernetes &gt; ConfigMap &gt; Approved
- Kubernetes &gt; ConfigMap &gt; Approved &gt; Custom
- Kubernetes &gt; ConfigMap &gt; CMDB
- Kubernetes &gt; ConfigMap &gt; Labels
- Kubernetes &gt; ConfigMap &gt; Labels &gt; Template
- Kubernetes &gt; ConfigMap &gt; osquery
- Kubernetes &gt; ConfigMap &gt; osquery &gt; Configuration
- Kubernetes &gt; ConfigMap &gt; osquery &gt; Configuration &gt; Columns
- Kubernetes &gt; ConfigMap &gt; osquery &gt; Configuration &gt; Interval
- Kubernetes &gt; ConfigMap &gt; osquery &gt; Configuration &gt; Name
- Kubernetes &gt; Deployment &gt; Annotations
- Kubernetes &gt; Deployment &gt; Annotations &gt; Template
- Kubernetes &gt; Deployment &gt; Approved
- Kubernetes &gt; Deployment &gt; Approved &gt; Custom
- Kubernetes &gt; Deployment &gt; CMDB
- Kubernetes &gt; Deployment &gt; Labels
- Kubernetes &gt; Deployment &gt; Labels &gt; Template
- Kubernetes &gt; Deployment &gt; osquery
- Kubernetes &gt; Deployment &gt; osquery &gt; Configuration
- Kubernetes &gt; Deployment &gt; osquery &gt; Configuration &gt; Columns
- Kubernetes &gt; Deployment &gt; osquery &gt; Configuration &gt; Interval
- Kubernetes &gt; Deployment &gt; osquery &gt; Configuration &gt; Name
- Kubernetes &gt; Namespace &gt; Annotations
- Kubernetes &gt; Namespace &gt; Annotations &gt; Template
- Kubernetes &gt; Namespace &gt; Approved
- Kubernetes &gt; Namespace &gt; Approved &gt; Custom
- Kubernetes &gt; Namespace &gt; CMDB
- Kubernetes &gt; Namespace &gt; Labels
- Kubernetes &gt; Namespace &gt; Labels &gt; Template
- Kubernetes &gt; Namespace &gt; osquery
- Kubernetes &gt; Namespace &gt; osquery &gt; Configuration
- Kubernetes &gt; Namespace &gt; osquery &gt; Configuration &gt; Columns
- Kubernetes &gt; Namespace &gt; osquery &gt; Configuration &gt; Interval
- Kubernetes &gt; Namespace &gt; osquery &gt; Configuration &gt; Name
- Kubernetes &gt; Node &gt; Annotations
- Kubernetes &gt; Node &gt; Annotations &gt; Template
- Kubernetes &gt; Node &gt; Approved
- Kubernetes &gt; Node &gt; Approved &gt; Custom
- Kubernetes &gt; Node &gt; CMDB
- Kubernetes &gt; Node &gt; Labels
- Kubernetes &gt; Node &gt; Labels &gt; Template
- Kubernetes &gt; Node &gt; osquery
- Kubernetes &gt; Node &gt; osquery &gt; Configuration
- Kubernetes &gt; Node &gt; osquery &gt; Configuration &gt; Columns
- Kubernetes &gt; Node &gt; osquery &gt; Configuration &gt; Interval
- Kubernetes &gt; Node &gt; osquery &gt; Configuration &gt; Name
- Kubernetes &gt; Pod &gt; Annotations
- Kubernetes &gt; Pod &gt; Annotations &gt; Template
- Kubernetes &gt; Pod &gt; Approved
- Kubernetes &gt; Pod &gt; Approved &gt; Custom
- Kubernetes &gt; Pod &gt; CMDB
- Kubernetes &gt; Pod &gt; Labels
- Kubernetes &gt; Pod &gt; Labels &gt; Template
- Kubernetes &gt; Pod &gt; osquery
- Kubernetes &gt; Pod &gt; osquery &gt; Configuration
- Kubernetes &gt; Pod &gt; osquery &gt; Configuration &gt; Columns
- Kubernetes &gt; Pod &gt; osquery &gt; Configuration &gt; Interval
- Kubernetes &gt; Pod &gt; osquery &gt; Configuration &gt; Name
- Kubernetes &gt; ReplicaSet &gt; Annotations
- Kubernetes &gt; ReplicaSet &gt; Annotations &gt; Template
- Kubernetes &gt; ReplicaSet &gt; Approved
- Kubernetes &gt; ReplicaSet &gt; Approved &gt; Custom
- Kubernetes &gt; ReplicaSet &gt; CMDB
- Kubernetes &gt; ReplicaSet &gt; Labels
- Kubernetes &gt; ReplicaSet &gt; Labels &gt; Template
- Kubernetes &gt; ReplicaSet &gt; osquery
- Kubernetes &gt; ReplicaSet &gt; osquery &gt; Configuration
- Kubernetes &gt; ReplicaSet &gt; osquery &gt; Configuration &gt; Columns
- Kubernetes &gt; ReplicaSet &gt; osquery &gt; Configuration &gt; Interval
- Kubernetes &gt; ReplicaSet &gt; osquery &gt; Configuration &gt; Name
- Kubernetes &gt; Service &gt; Annotations
- Kubernetes &gt; Service &gt; Annotations &gt; Template
- Kubernetes &gt; Service &gt; Approved
- Kubernetes &gt; Service &gt; Approved &gt; Custom
- Kubernetes &gt; Service &gt; CMDB
- Kubernetes &gt; Service &gt; Labels
- Kubernetes &gt; Service &gt; Labels &gt; Template
- Kubernetes &gt; Service &gt; osquery
- Kubernetes &gt; Service &gt; osquery &gt; Configuration
- Kubernetes &gt; Service &gt; osquery &gt; Configuration &gt; Columns
- Kubernetes &gt; Service &gt; osquery &gt; Configuration &gt; Interval
- Kubernetes &gt; Service &gt; osquery &gt; Configuration &gt; Name
- Kubernetes &gt; osquery
- Kubernetes &gt; osquery &gt; Decorators

_Action Types_

- Kubernetes &gt; ConfigMap &gt; Router
- Kubernetes &gt; Deployment &gt; Router
- Kubernetes &gt; Namespace &gt; Router
- Kubernetes &gt; Node &gt; Router
- Kubernetes &gt; Pod &gt; Router
- Kubernetes &gt; ReplicaSet &gt; Router
- Kubernetes &gt; Service &gt; Router</description>
            <pubDate>Mon, 13 May 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-iam-v5-13-1</guid>
            <title>gcp-iam v5.13.1 - Service Account Key Active control will no longer attempt to delete system-managed service account keys deemed inactive by the control</title>
            <link>https://turbot.com/guardrails/changelog/gcp-iam-v5-13-1</link>
            <description>_Bug fixes_

- The `GCP &gt; IAM &gt; Service Account Key &gt; Active` control will no longer attempt to delete a system-managed service account key deemed inactive by the control.</description>
            <pubDate>Mon, 13 May 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-iam-v5-36-0</guid>
            <title>aws-iam v5.36.0 - Determine if an IAM access key for a user is latest and take appropriate actions</title>
            <link>https://turbot.com/guardrails/changelog/aws-iam-v5-36-0</link>
            <description>_What&apos;s new?_

- You can now determine if an IAM access key for a user is latest and deactivate or delete any keys that are not, using Guardrails. To get started, set the `AWS &gt; IAM &gt; Access Key &gt; Active &gt; Latest` policy.
- You can now determine if an IAM server certificate is active based on its expiration. To get started, set the `AWS &gt; IAM &gt; Server Certificate &gt; Active &gt; Expired` policy.

_Policy Types_

  - AWS &gt; IAM &gt; Access Key &gt; Active &gt; Latest
  - AWS &gt; IAM &gt; Server Certificate &gt; Active &gt; Expired</description>
            <pubDate>Mon, 13 May 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-v5-24-1</guid>
            <title>gcp v5.24.1 - The Project CMDB control would go into an error state if Access Approval API was disabled in GCP</title>
            <link>https://turbot.com/guardrails/changelog/gcp-v5-24-1</link>
            <description>_Bug fixes_

- The `GCP &gt; Project &gt; CMDB` control would go into an error state if Access Approval API was disabled in GCP. This is now fixed.</description>
            <pubDate>Fri, 10 May 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-58-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.58.0 - Enhanced Monitoring, Tagging, and Resource Management</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-58-0</link>
            <description>_What&apos;s new?_

- Implemented SNS topic to handle critical alarms notifications.
- Added Product, Vendor Tags to the IAM Role resources created by the TEF stack.
- Introduced a new SSM parameter to manage the reserved concurrency settings for the osquery worker lambda function.
- Updated Log Bucket Lifecycle Policies:
  - **Increased Retention Period:** Extended the retention period of the lifecycle policy for logs in the log bucket with the `/processes` prefix from 1 day to 2 days.
  - **New Policy Addition:** Implemented a new lifecycle policy for managing log retention in the log bucket for logs with the `/osquery` prefix.</description>
            <pubDate>Wed, 08 May 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/ted-v1-42-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.42.0 - Implementation of Critical Alarms for RDS and Redis ElastiCache Utilization Metrics</title>
            <link>https://turbot.com/guardrails/changelog/ted-v1-42-0</link>
            <description>_What&apos;s new?_

- Implemented critical alarms for RDS DB CPU utilization, DB Max Connections and Redis ElastiCache Memory utilization.
- Added Product, Vendor Tags to the IAM Role resources created by the TED stack.</description>
            <pubDate>Wed, 08 May 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-compute-v5-16-1</guid>
            <title>azure-compute v5.16.1 - Virtual Machine Scale Set Tags control would sometimes fail to update tags correctly for Scale Sets launched via Azure marketplace</title>
            <link>https://turbot.com/guardrails/changelog/azure-compute-v5-16-1</link>
            <description>_Bug fixes_

- The `Azure &gt; Compute &gt; Virtual Machine Scale Set &gt; Tags` control would sometimes fail to update tags correctly for Scale Sets launched via Azure marketplace. This is fixed and the control will now update tags correctly, as expected.</description>
            <pubDate>Wed, 08 May 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-vpc-security-v5-10-0</guid>
            <title>aws-vpc-security v5.10.0 - Revoke ingress rules that are unapproved for use in Network ACLs</title>
            <link>https://turbot.com/guardrails/changelog/aws-vpc-security-v5-10-0</link>
            <description>_What&apos;s new?_

- Revoke ingress rules that are unapproved for use in Network ACLs. To get started, set the `AWS &gt; VPC &gt; Network ACL &gt; Ingress Rules &gt; Approved &gt; *` policies.</description>
            <pubDate>Wed, 08 May 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-logs-v5-12-2</guid>
            <title>aws-logs v5.12.2 - Minor fixes and improvements</title>
            <link>https://turbot.com/guardrails/changelog/aws-logs-v5-12-2</link>
            <description>_Bug fixes_

- Minor fixes and improvements.</description>
            <pubDate>Wed, 08 May 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-efs-v5-8-0</guid>
            <title>aws-efs v5.8.0 - Delete existing Mount Targets which are unapproved for use in the account</title>
            <link>https://turbot.com/guardrails/changelog/aws-efs-v5-8-0</link>
            <description>_What&apos;s new?_

- You can now delete existing Mount Targets which are unapproved for use in the account. To get started, set the `AWS &gt; EFS &gt; Mount Target &gt; Approved` policy to `Enforce: Delete unapproved`.</description>
            <pubDate>Wed, 08 May 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-cloudwatch-v5-8-0</guid>
            <title>aws-cloudwatch v5.8.0 - Create and manage `aws_cloudwatch_metric_alarm` resources via Guardrails stacks</title>
            <link>https://turbot.com/guardrails/changelog/aws-cloudwatch-v5-8-0</link>
            <description>_What&apos;s new?_

- Create and manage `aws_cloudwatch_metric_alarm` resources via Guardrails stacks.

_Control Types_
  - AWS &gt; CloudWatch &gt; Alarm &gt; Configured

_Policy Types_
  - AWS &gt; CloudWatch &gt; Alarm &gt; Configured
  - AWS &gt; CloudWatch &gt; Alarm &gt; Configured &gt; Claim Precedence
  - AWS &gt; CloudWatch &gt; Alarm &gt; Configured &gt; Source</description>
            <pubDate>Wed, 08 May 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-securityhub-v5-3-1</guid>
            <title>aws-securityhub v5.3.1 - Added support for `aws_securityhub_account` Terraform resource</title>
            <link>https://turbot.com/guardrails/changelog/aws-securityhub-v5-3-1</link>
            <description>_Bug fixes_

- Added support for `aws_securityhub_account` Terraform resource.</description>
            <pubDate>Tue, 07 May 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-eks-v5-7-0</guid>
            <title>aws-eks v5.7.0 - Metadata for EKS resources will now also include `createdBy` details in Turbot CMDB</title>
            <link>https://turbot.com/guardrails/changelog/aws-eks-v5-7-0</link>
            <description>_What&apos;s new?_

- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.</description>
            <pubDate>Tue, 07 May 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-cisv3-0-v5-0-0</guid>
            <title>aws-cisv3-0 v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/aws-cisv3-0-v5-0-0</link>
            <description>_What&apos;s new?_

_Control Types_

- AWS &gt; CIS v3.0
- AWS &gt; CIS v3.0 &gt; 1 - Identity and Access Management
- AWS &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.01 - Maintain current contact details
- AWS &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.02 - Ensure security contact information is registered
- AWS &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.03 - Ensure security questions are registered in the AWS account
- AWS &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.04 - Ensure no &apos;root&apos; user account access key exists
- AWS &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.05 - Ensure MFA is enabled for the &apos;root&apos; user account
- AWS &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.06 - Ensure hardware MFA is enabled for the &apos;root&apos; user account
- AWS &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.07 - Eliminate use of the &apos;root&apos; user for administrative and daily tasks
- AWS &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.08 - Ensure IAM password policy requires minimum length of 14 or greater
- AWS &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.09 - Ensure IAM password policy prevents password reuse
- AWS &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.10 - Ensure multi-factor authentication (MFA) is enabled for all IAM users that have a console password
- AWS &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.11 - Do not setup access keys during initial user setup for all IAM users that have a console password
- AWS &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.12 - Ensure credentials unused for 45 days or greater are disabled
- AWS &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.13 - Ensure there is only one active access key available for any single IAM user
- AWS &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.14 - Ensure access keys are rotated every 90 days or less
- AWS &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.15 - Ensure IAM Users Receive Permissions Only Through Groups
- AWS &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.16 - Ensure IAM policies that allow full &quot;*:*&quot; administrative privileges are not attached
- AWS &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.17 - Ensure a support role has been created to manage incidents with AWS Support
- AWS &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.18 - Ensure IAM instance roles are used for AWS resource access from instances
- AWS &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.19 - Ensure that all the expired SSL/TLS certificates stored in AWS IAM are removed
- AWS &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.20 - Ensure that IAM Access analyzer is enabled for all regions
- AWS &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.21 - Ensure IAM users are managed centrally via identity federation or AWS Organizations for multi-account environments
- AWS &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.22 - Ensure access to AWSCloudShellFullAccess is restricted
- AWS &gt; CIS v3.0 &gt; 2 - Storage
- AWS &gt; CIS v3.0 &gt; 2 - Storage &gt; 2.01 - Simple Storage Service (S3)
- AWS &gt; CIS v3.0 &gt; 2 - Storage &gt; 2.01 - Simple Storage Service (S3) &gt; 2.01.01 - Ensure S3 Bucket Policy is set to deny HTTP requests
- AWS &gt; CIS v3.0 &gt; 2 - Storage &gt; 2.01 - Simple Storage Service (S3) &gt; 2.01.02 - Ensure MFA Delete is enabled on S3 buckets
- AWS &gt; CIS v3.0 &gt; 2 - Storage &gt; 2.01 - Simple Storage Service (S3) &gt; 2.01.03 - Ensure all data in Amazon S3 has been discovered, classified and secured when required
- AWS &gt; CIS v3.0 &gt; 2 - Storage &gt; 2.01 - Simple Storage Service (S3) &gt; 2.01.04 - Ensure that S3 Buckets are configured with &apos;Block public access (bucket settings)&apos;
- AWS &gt; CIS v3.0 &gt; 2 - Storage &gt; 2.02 - Elastic Compute Cloud (EC2)
- AWS &gt; CIS v3.0 &gt; 2 - Storage &gt; 2.02 - Elastic Compute Cloud (EC2) &gt; 2.02.01 - Ensure EBS Volume Encryption is Enabled in all Regions
- AWS &gt; CIS v3.0 &gt; 2 - Storage &gt; 2.03 - Relational Database Service (RDS)
- AWS &gt; CIS v3.0 &gt; 2 - Storage &gt; 2.03 - Relational Database Service (RDS) &gt; 2.03.01 - Ensure that encryption-at-rest is enabled for RDS Instances
- AWS &gt; CIS v3.0 &gt; 2 - Storage &gt; 2.03 - Relational Database Service (RDS) &gt; 2.03.02 - Ensure Auto Minor Version Upgrade feature is Enabled for RDS Instances
- AWS &gt; CIS v3.0 &gt; 2 - Storage &gt; 2.03 - Relational Database Service (RDS) &gt; 2.03.03 - Ensure that public access is not given to RDS Instance
- AWS &gt; CIS v3.0 &gt; 2 - Storage &gt; 2.04 - Elastic File System (EFS)
- AWS &gt; CIS v3.0 &gt; 2 - Storage &gt; 2.04 - Elastic File System (EFS) &gt; 2.04.01 - Ensure that encryption is enabled for EFS file systems
- AWS &gt; CIS v3.0 &gt; 3 - Logging
- AWS &gt; CIS v3.0 &gt; 3 - Logging &gt; 3.01 - Ensure CloudTrail is enabled in all regions
- AWS &gt; CIS v3.0 &gt; 3 - Logging &gt; 3.02 - Ensure CloudTrail log file validation is enabled
- AWS &gt; CIS v3.0 &gt; 3 - Logging &gt; 3.03 - Ensure AWS Config is enabled in all regions
- AWS &gt; CIS v3.0 &gt; 3 - Logging &gt; 3.04 - Ensure S3 bucket access logging is enabled on the CloudTrail S3 bucket
- AWS &gt; CIS v3.0 &gt; 3 - Logging &gt; 3.05 - Ensure CloudTrail logs are encrypted at rest using KMS CMKs
- AWS &gt; CIS v3.0 &gt; 3 - Logging &gt; 3.06 - Ensure rotation for customer created symmetric CMKs is enabled
- AWS &gt; CIS v3.0 &gt; 3 - Logging &gt; 3.07 - Ensure VPC flow logging is enabled in all VPCs
- AWS &gt; CIS v3.0 &gt; 3 - Logging &gt; 3.08 - Ensure that Object-level logging for write events is enabled for S3 bucket
- AWS &gt; CIS v3.0 &gt; 3 - Logging &gt; 3.09 - Ensure that Object-level logging for read events is enabled for S3 bucket
- AWS &gt; CIS v3.0 &gt; 4 - Monitoring
- AWS &gt; CIS v3.0 &gt; 4 - Monitoring &gt; 4.01 - Ensure unauthorized API calls are monitored
- AWS &gt; CIS v3.0 &gt; 4 - Monitoring &gt; 4.02 - Ensure management console sign-in without MFA is monitored
- AWS &gt; CIS v3.0 &gt; 4 - Monitoring &gt; 4.03 - Ensure usage of &apos;root&apos; account is monitored
- AWS &gt; CIS v3.0 &gt; 4 - Monitoring &gt; 4.04 - Ensure IAM policy changes are monitored
- AWS &gt; CIS v3.0 &gt; 4 - Monitoring &gt; 4.05 - Ensure CloudTrail configuration changes are monitored
- AWS &gt; CIS v3.0 &gt; 4 - Monitoring &gt; 4.06 - Ensure AWS Management Console authentication failures are monitored
- AWS &gt; CIS v3.0 &gt; 4 - Monitoring &gt; 4.07 - Ensure disabling or scheduled deletion of customer created CMKs is monitored
- AWS &gt; CIS v3.0 &gt; 4 - Monitoring &gt; 4.08 - Ensure S3 bucket policy changes are monitored
- AWS &gt; CIS v3.0 &gt; 4 - Monitoring &gt; 4.09 - Ensure AWS Config configuration changes are monitored
- AWS &gt; CIS v3.0 &gt; 4 - Monitoring &gt; 4.10 - Ensure security group changes are monitored
- AWS &gt; CIS v3.0 &gt; 4 - Monitoring &gt; 4.11 - Ensure Network Access Control Lists (NACL) changes are monitored
- AWS &gt; CIS v3.0 &gt; 4 - Monitoring &gt; 4.12 - Ensure changes to network gateways are monitored
- AWS &gt; CIS v3.0 &gt; 4 - Monitoring &gt; 4.13 - Ensure route table changes are monitored
- AWS &gt; CIS v3.0 &gt; 4 - Monitoring &gt; 4.14 - Ensure VPC changes are monitored
- AWS &gt; CIS v3.0 &gt; 4 - Monitoring &gt; 4.15 - Ensure AWS Organizations changes are monitored
- AWS &gt; CIS v3.0 &gt; 4 - Monitoring &gt; 4.16 - Ensure AWS Security Hub is enabled
- AWS &gt; CIS v3.0 &gt; 5 - Networking
- AWS &gt; CIS v3.0 &gt; 5 - Networking &gt; 5.01 - Ensure no Network ACLs allow ingress from 0.0.0.0/0 to remote server administration ports
- AWS &gt; CIS v3.0 &gt; 5 - Networking &gt; 5.02 - Ensure no security groups allow ingress from 0.0.0.0/0 to remote server administration ports
- AWS &gt; CIS v3.0 &gt; 5 - Networking &gt; 5.03 - Ensure no security groups allow ingress from ::/0 to remote server administration ports
- AWS &gt; CIS v3.0 &gt; 5 - Networking &gt; 5.04 - Ensure the default security group of every VPC restricts all traffic
- AWS &gt; CIS v3.0 &gt; 5 - Networking &gt; 5.05 - Ensure routing tables for VPC peering are &apos;least access&apos;
- AWS &gt; CIS v3.0 &gt; 5 - Networking &gt; 5.06 - Ensure that EC2 Metadata Service only allows IMDSv2

_Policy Types_

- AWS &gt; CIS v3.0
- AWS &gt; CIS v3.0 &gt; 1 - Identity and Access Management
- AWS &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.01 - Maintain current contact details
- AWS &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.01 - Maintain current contact details &gt; Attestation
- AWS &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.02 - Ensure security contact information is registered
- AWS &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.03 - Ensure security questions are registered in the AWS account
- AWS &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.03 - Ensure security questions are registered in the AWS account &gt; Attestation
- AWS &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.04 - Ensure no &apos;root&apos; user account access key exists
- AWS &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.05 - Ensure MFA is enabled for the &apos;root&apos; user account
- AWS &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.06 - Ensure hardware MFA is enabled for the &apos;root&apos; user account
- AWS &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.07 - Eliminate use of the &apos;root&apos; user for administrative and daily tasks
- AWS &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.08 - Ensure IAM password policy requires minimum length of 14 or greater
- AWS &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.09 - Ensure IAM password policy prevents password reuse
- AWS &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.10 - Ensure multi-factor authentication (MFA) is enabled for all IAM users that have a console password
- AWS &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.11 - Do not setup access keys during initial user setup for all IAM users that have a console password
- AWS &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.12 - Ensure credentials unused for 45 days or greater are disabled
- AWS &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.13 - Ensure there is only one active access key available for any single IAM user
- AWS &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.14 - Ensure access keys are rotated every 90 days or less
- AWS &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.15 - Ensure IAM Users Receive Permissions Only Through Groups
- AWS &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.16 - Ensure IAM policies that allow full &quot;*:*&quot; administrative privileges are not attached
- AWS &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.17 - Ensure a support role has been created to manage incidents with AWS Support
- AWS &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.18 - Ensure IAM instance roles are used for AWS resource access from instances
- AWS &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.19 - Ensure that all the expired SSL/TLS certificates stored in AWS IAM are removed
- AWS &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.20 - Ensure that IAM Access analyzer is enabled for all regions
- AWS &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.21 - Ensure IAM users are managed centrally via identity federation or AWS Organizations for multi-account environments
- AWS &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.21 - Ensure IAM users are managed centrally via identity federation or AWS Organizations for multi-account environments &gt; Attestation
- AWS &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.22 - Ensure access to AWSCloudShellFullAccess is restricted
- AWS &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; 1.22 - Ensure access to AWSCloudShellFullAccess is restricted &gt; Attestation
- AWS &gt; CIS v3.0 &gt; 1 - Identity and Access Management &gt; Maximum Attestation Duration
- AWS &gt; CIS v3.0 &gt; 2 - Storage
- AWS &gt; CIS v3.0 &gt; 2 - Storage &gt; 2.01 - Simple Storage Service (S3)
- AWS &gt; CIS v3.0 &gt; 2 - Storage &gt; 2.01 - Simple Storage Service (S3) &gt; 2.01.01 - Ensure S3 Bucket Policy is set to deny HTTP requests
- AWS &gt; CIS v3.0 &gt; 2 - Storage &gt; 2.01 - Simple Storage Service (S3) &gt; 2.01.02 - Ensure MFA Delete is enable on S3 buckets
- AWS &gt; CIS v3.0 &gt; 2 - Storage &gt; 2.01 - Simple Storage Service (S3) &gt; 2.01.03 - Ensure all data in Amazon S3 has been discovered, classified and secured when required
- AWS &gt; CIS v3.0 &gt; 2 - Storage &gt; 2.01 - Simple Storage Service (S3) &gt; 2.01.03 - Ensure all data in Amazon S3 has been discovered, classified and secured when required &gt; Attestation
- AWS &gt; CIS v3.0 &gt; 2 - Storage &gt; 2.01 - Simple Storage Service (S3) &gt; 2.01.04 - Ensure that S3 Buckets are configured with &apos;Block public access (bucket settings)&apos;
- AWS &gt; CIS v3.0 &gt; 2 - Storage &gt; 2.02 - Elastic Compute Cloud (EC2)
- AWS &gt; CIS v3.0 &gt; 2 - Storage &gt; 2.02 - Elastic Compute Cloud (EC2) &gt; 2.02.01 - Ensure EBS Volume Encryption is Enabled in all Regions
- AWS &gt; CIS v3.0 &gt; 2 - Storage &gt; 2.03 - Relational Database Service (RDS)
- AWS &gt; CIS v3.0 &gt; 2 - Storage &gt; 2.03 - Relational Database Service (RDS) &gt; 2.03.01 - Ensure that encryption-at-rest is enabled for RDS Instances
- AWS &gt; CIS v3.0 &gt; 2 - Storage &gt; 2.03 - Relational Database Service (RDS) &gt; 2.03.02 - Ensure Auto Minor Version Upgrade feature is Enabled for RDS Instances
- AWS &gt; CIS v3.0 &gt; 2 - Storage &gt; 2.03 - Relational Database Service (RDS) &gt; 2.03.03 - Ensure that public access is not given to RDS Instance
- AWS &gt; CIS v3.0 &gt; 2 - Storage &gt; 2.04 - Elastic File System (EFS)
- AWS &gt; CIS v3.0 &gt; 2 - Storage &gt; 2.04 - Elastic File System (EFS) &gt; 2.04.01 - Ensure that encryption is enabled for EFS file systems
- AWS &gt; CIS v3.0 &gt; 2 - Storage &gt; Maximum Attestation Duration
- AWS &gt; CIS v3.0 &gt; 3 - Logging
- AWS &gt; CIS v3.0 &gt; 3 - Logging &gt; 3.01 - Ensure CloudTrail is enabled in all regions
- AWS &gt; CIS v3.0 &gt; 3 - Logging &gt; 3.02 - Ensure CloudTrail log file validation is enabled
- AWS &gt; CIS v3.0 &gt; 3 - Logging &gt; 3.03 - Ensure AWS Config is enabled in all regions
- AWS &gt; CIS v3.0 &gt; 3 - Logging &gt; 3.04 - Ensure S3 bucket access logging is enabled on the CloudTrail S3 bucket
- AWS &gt; CIS v3.0 &gt; 3 - Logging &gt; 3.05 - Ensure CloudTrail logs are encrypted at rest using KMS CMKs
- AWS &gt; CIS v3.0 &gt; 3 - Logging &gt; 3.06 - Ensure rotation for customer created symmetric CMKs is enabled
- AWS &gt; CIS v3.0 &gt; 3 - Logging &gt; 3.07 - Ensure VPC flow logging is enabled in all VPCs
- AWS &gt; CIS v3.0 &gt; 3 - Logging &gt; 3.08 - Ensure that Object-level logging for write events is enabled for S3 bucket
- AWS &gt; CIS v3.0 &gt; 3 - Logging &gt; 3.09 - Ensure that Object-level logging for read events is enabled for S3 bucket
- AWS &gt; CIS v3.0 &gt; 3 - Logging &gt; Maximum Attestation Duration
- AWS &gt; CIS v3.0 &gt; 4 - Monitoring
- AWS &gt; CIS v3.0 &gt; 4 - Monitoring &gt; 4.01 - Ensure unauthorized API calls are monitored
- AWS &gt; CIS v3.0 &gt; 4 - Monitoring &gt; 4.02 - Ensure management console sign-in without MFA is monitored
- AWS &gt; CIS v3.0 &gt; 4 - Monitoring &gt; 4.03 - Ensure usage of &apos;root&apos; account is monitored
- AWS &gt; CIS v3.0 &gt; 4 - Monitoring &gt; 4.04 - Ensure IAM policy changes are monitored
- AWS &gt; CIS v3.0 &gt; 4 - Monitoring &gt; 4.05 - Ensure CloudTrail configuration changes are monitored
- AWS &gt; CIS v3.0 &gt; 4 - Monitoring &gt; 4.06 - Ensure AWS Management Console authentication failures are monitored
- AWS &gt; CIS v3.0 &gt; 4 - Monitoring &gt; 4.07 - Ensure disabling or scheduled deletion of customer created CMKs is monitored
- AWS &gt; CIS v3.0 &gt; 4 - Monitoring &gt; 4.08 - Ensure S3 bucket policy changes are monitored
- AWS &gt; CIS v3.0 &gt; 4 - Monitoring &gt; 4.09 - Ensure AWS Config configuration changes are monitored
- AWS &gt; CIS v3.0 &gt; 4 - Monitoring &gt; 4.10 - Ensure security group changes are monitored
- AWS &gt; CIS v3.0 &gt; 4 - Monitoring &gt; 4.11 - Ensure Network Access Control Lists (NACL) changes are monitored
- AWS &gt; CIS v3.0 &gt; 4 - Monitoring &gt; 4.12 - Ensure changes to network gateways are monitored
- AWS &gt; CIS v3.0 &gt; 4 - Monitoring &gt; 4.13 - Ensure route table changes are monitored
- AWS &gt; CIS v3.0 &gt; 4 - Monitoring &gt; 4.14 - Ensure VPC changes are monitored
- AWS &gt; CIS v3.0 &gt; 4 - Monitoring &gt; 4.15 - Ensure AWS Organizations changes are monitored
- AWS &gt; CIS v3.0 &gt; 4 - Monitoring &gt; 4.16 - Ensure AWS Security Hub is enabled
- AWS &gt; CIS v3.0 &gt; 4 - Monitoring &gt; Maximum Attestation Duration
- AWS &gt; CIS v3.0 &gt; 5 - Networking
- AWS &gt; CIS v3.0 &gt; 5 - Networking &gt; 5.01 - Ensure no Network ACLs allow ingress from 0.0.0.0/0 to remote server administration ports
- AWS &gt; CIS v3.0 &gt; 5 - Networking &gt; 5.02 - Ensure no security groups allow ingress from 0.0.0.0/0 to remote server administration ports
- AWS &gt; CIS v3.0 &gt; 5 - Networking &gt; 5.03 - Ensure no security groups allow ingress from ::/0 to remote server administration ports
- AWS &gt; CIS v3.0 &gt; 5 - Networking &gt; 5.04 - Ensure the default security group of every VPC restricts all traffic
- AWS &gt; CIS v3.0 &gt; 5 - Networking &gt; 5.05 - Ensure routing tables for VPC peering are &apos;least access&apos;
- AWS &gt; CIS v3.0 &gt; 5 - Networking &gt; 5.05 - Ensure routing tables for VPC peering are &apos;least access&apos; &gt; Attestation
- AWS &gt; CIS v3.0 &gt; 5 - Networking &gt; 5.06 - Ensure that EC2 Metadata Service only allows IMDSv2
- AWS &gt; CIS v3.0 &gt; 5 - Networking &gt; Maximum Attestation Duration
- AWS &gt; CIS v3.0 &gt; Maximum Attestation Duration</description>
            <pubDate>Mon, 06 May 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-42-26</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.42.26 - Minor internal improvements</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-42-26</link>
            <description>_Bug fixes_

- Server
  - Minor internal improvements.

_Requirements_

- TEF: 1.57.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Fri, 03 May 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-dns-v5-7-0</guid>
            <title>gcp-dns v5.7.0 - Track and manage DNS Policies in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/gcp-dns-v5-7-0</link>
            <description>_What&apos;s new?_

- Resource Types:
  - GCP &gt; DNS &gt; Policy

- Control Types:
  - GCP &gt; DNS &gt; Policy &gt; Active
  - GCP &gt; DNS &gt; Policy &gt; Approved
  - GCP &gt; DNS &gt; Policy &gt; CMDB
  - GCP &gt; DNS &gt; Policy &gt; Discovery
  - GCP &gt; DNS &gt; Policy &gt; Usage

- Policy Types:
  - GCP &gt; DNS &gt; Policy &gt; Active
  - GCP &gt; DNS &gt; Policy &gt; Active &gt; Age
  - GCP &gt; DNS &gt; Policy &gt; Active &gt; Last Modified
  - GCP &gt; DNS &gt; Policy &gt; Approved
  - GCP &gt; DNS &gt; Policy &gt; Approved &gt; Custom
  - GCP &gt; DNS &gt; Policy &gt; Approved &gt; Usage
  - GCP &gt; DNS &gt; Policy &gt; CMDB
  - GCP &gt; DNS &gt; Policy &gt; Usage
  - GCP &gt; DNS &gt; Policy &gt; Usage &gt; Limit

- Action Types:
  - GCP &gt; DNS &gt; Policy &gt; Delete
  - GCP &gt; DNS &gt; Policy &gt; Router</description>
            <pubDate>Fri, 03 May 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-cisv2-0-v5-0-0</guid>
            <title>gcp-cisv2-0 v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/gcp-cisv2-0-v5-0-0</link>
            <description>_What&apos;s new?_

_Control Types_

- GCP &gt; CIS v2.0
- GCP &gt; CIS v2.0 &gt; 1 - Identity and Access Management
- GCP &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.01 - Ensure that Corporate Login Credentials are Used
- GCP &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.02 - Ensure that Multi-Factor Authentication is &apos;Enabled&apos; for All Non-Service Accounts
- GCP &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.03 - Ensure that Security Key Enforcement is Enabled for All Admin Accounts
- GCP &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.04 - Ensure That There Are Only GCP-Managed Service Account Keys for Each Service Account
- GCP &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.05 - Ensure That Service Account Has No Admin Privileges
- GCP &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.06 - Ensure That IAM Users Are Not Assigned the Service Account User or Service Account Token Creator Roles at Project Level
- GCP &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.07 - Ensure User-Managed/External Keys for Service Accounts Are Rotated Every 90 Days or Fewer
- GCP &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.08 - Ensure That Separation of Duties Is Enforced While Assigning Service Account Related Roles to Users
- GCP &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.09 - Ensure That Cloud KMS Cryptokeys Are Not Anonymously or Publicly Accessible
- GCP &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.10 - Ensure KMS Encryption Keys Are Rotated Within a Period of 90 Days
- GCP &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.11 - Ensure That Separation of Duties Is Enforced While Assigning KMS Related Roles to Users
- GCP &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.16 - Ensure Essential Contacts is Configured for Organization
- GCP &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.17 - Ensure that Dataproc Cluster is encrypted using Customer-Managed Encryption Key
- GCP &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.18 - Ensure Secrets are Not Stored in Cloud Functions Environment Variables by Using Secret Manager
- GCP &gt; CIS v2.0 &gt; 2 - Logging and Monitoring
- GCP &gt; CIS v2.0 &gt; 2 - Logging and Monitoring &gt; 2.01 - Ensure That Cloud Audit Logging Is Configured Properly
- GCP &gt; CIS v2.0 &gt; 2 - Logging and Monitoring &gt; 2.02 - Ensure That Sinks Are Configured for All Log Entries
- GCP &gt; CIS v2.0 &gt; 2 - Logging and Monitoring &gt; 2.03 - Ensure That Retention Policies on Cloud Storage Buckets Used for Exporting Logs Are Configured Using Bucket Lock
- GCP &gt; CIS v2.0 &gt; 2 - Logging and Monitoring &gt; 2.04 - Ensure Log Metric Filter and Alerts Exist for Project Ownership Assignments/Changes
- GCP &gt; CIS v2.0 &gt; 2 - Logging and Monitoring &gt; 2.05 - Ensure That the Log Metric Filter and Alerts Exist for Audit Configuration Changes
- GCP &gt; CIS v2.0 &gt; 2 - Logging and Monitoring &gt; 2.06 - Ensure That the Log Metric Filter and Alerts Exist for Custom Role Changes
- GCP &gt; CIS v2.0 &gt; 2 - Logging and Monitoring &gt; 2.07 - Ensure That the Log Metric Filter and Alerts Exist for VPC Network Firewall Rule Changes
- GCP &gt; CIS v2.0 &gt; 2 - Logging and Monitoring &gt; 2.08 - Ensure That the Log Metric Filter and Alerts Exist for VPC Network Route Changes
- GCP &gt; CIS v2.0 &gt; 2 - Logging and Monitoring &gt; 2.09 - Ensure That the Log Metric Filter and Alerts Exist for VPC Network Changes
- GCP &gt; CIS v2.0 &gt; 2 - Logging and Monitoring &gt; 2.10 - Ensure That the Log Metric Filter and Alerts Exist for Cloud Storage IAM Permission Changes
- GCP &gt; CIS v2.0 &gt; 2 - Logging and Monitoring &gt; 2.11 - Ensure That the Log Metric Filter and Alerts Exist for SQL Instance Configuration Changes
- GCP &gt; CIS v2.0 &gt; 2 - Logging and Monitoring &gt; 2.12 - Ensure That Cloud DNS Logging Is Enabled for All VPC Networks
- GCP &gt; CIS v2.0 &gt; 2 - Logging and Monitoring &gt; 2.13 - Ensure Cloud Asset Inventory Is Enabled
- GCP &gt; CIS v2.0 &gt; 2 - Logging and Monitoring &gt; 2.14 - Ensure &apos;Access Transparency&apos; is &apos;Enabled&apos;
- GCP &gt; CIS v2.0 &gt; 2 - Logging and Monitoring &gt; 2.15 - Ensure &apos;Access Approval&apos; is &apos;Enabled&apos;
- GCP &gt; CIS v2.0 &gt; 2 - Logging and Monitoring &gt; 2.16 - Ensure Logging is enabled for HTTP(S) Load Balancer
- GCP &gt; CIS v2.0 &gt; 3 - Networking
- GCP &gt; CIS v2.0 &gt; 3 - Networking &gt; 3.01 - Ensure That the Default Network Does Not Exist in a Project
- GCP &gt; CIS v2.0 &gt; 3 - Networking &gt; 3.02 - Ensure Legacy Networks Do Not Exist for Older Projects
- GCP &gt; CIS v2.0 &gt; 3 - Networking &gt; 3.03 - Ensure That DNSSEC Is Enabled for Cloud DNS
- GCP &gt; CIS v2.0 &gt; 3 - Networking &gt; 3.04 - Ensure That RSASHA1 Is Not Used for the Key-Signing Key in Cloud DNS DNSSEC
- GCP &gt; CIS v2.0 &gt; 3 - Networking &gt; 3.05 - Ensure That RSASHA1 Is Not Used for the Zone-Signing Key in Cloud DNS DNSSEC
- GCP &gt; CIS v2.0 &gt; 3 - Networking &gt; 3.06 - Ensure That SSH Access Is Restricted From the Internet
- GCP &gt; CIS v2.0 &gt; 3 - Networking &gt; 3.07 - Ensure That RDP Access Is Restricted From the Internet
- GCP &gt; CIS v2.0 &gt; 3 - Networking &gt; 3.08 - Ensure that VPC Flow Logs is Enabled for Every Subnet in a VPC Network
- GCP &gt; CIS v2.0 &gt; 3 - Networking &gt; 3.09 - Ensure No HTTPS or SSL Proxy Load Balancers Permit SSL Policies With Weak Cipher Suites
- GCP &gt; CIS v2.0 &gt; 3 - Networking &gt; 3.10 - Use Identity Aware Proxy (IAP) to Ensure Only Traffic From Google IP Addresses are &apos;Allowed&apos;
- GCP &gt; CIS v2.0 &gt; 4 - Virtual Machines
- GCP &gt; CIS v2.0 &gt; 4 - Virtual Machines &gt; 4.01 - Ensure That Instances Are Not Configured To Use the Default Service Account
- GCP &gt; CIS v2.0 &gt; 4 - Virtual Machines &gt; 4.02 - Ensure That Instances Are Not Configured To Use the Default Service Account With Full Access to All Cloud APIs
- GCP &gt; CIS v2.0 &gt; 4 - Virtual Machines &gt; 4.03 - Ensure &quot;Block Project-Wide SSH Keys&quot; Is Enabled for VM Instances
- GCP &gt; CIS v2.0 &gt; 4 - Virtual Machines &gt; 4.04 - Ensure Oslogin Is Enabled for a Project
- GCP &gt; CIS v2.0 &gt; 4 - Virtual Machines &gt; 4.05 - Ensure &apos;Enable Connecting to Serial Ports&apos; Is Not Enabled for VM Instance
- GCP &gt; CIS v2.0 &gt; 4 - Virtual Machines &gt; 4.06 - Ensure That IP Forwarding Is Not Enabled on Instances
- GCP &gt; CIS v2.0 &gt; 4 - Virtual Machines &gt; 4.07 - Ensure VM Disks for Critical VMs Are Encrypted With Customer-Supplied Encryption Keys (CSEK)
- GCP &gt; CIS v2.0 &gt; 4 - Virtual Machines &gt; 4.08 - Ensure Compute Instances Are Launched With Shielded VM Enabled
- GCP &gt; CIS v2.0 &gt; 4 - Virtual Machines &gt; 4.09 - Ensure That Compute Instances Do Not Have Public IP Addresses
- GCP &gt; CIS v2.0 &gt; 4 - Virtual Machines &gt; 4.10 - Ensure That App Engine Applications Enforce HTTPS Connections
- GCP &gt; CIS v2.0 &gt; 4 - Virtual Machines &gt; 4.11 - Ensure That Compute Instances Have Confidential Computing Enabled
- GCP &gt; CIS v2.0 &gt; 4 - Virtual Machines &gt; 4.12 - Ensure the Latest Operating System Updates Are Installed On Your Virtual Machines in All Projects
- GCP &gt; CIS v2.0 &gt; 5 - Storage
- GCP &gt; CIS v2.0 &gt; 5 - Storage &gt; 5.01 - Ensure That Cloud Storage Bucket Is Not Anonymously or Publicly Accessible
- GCP &gt; CIS v2.0 &gt; 5 - Storage &gt; 5.02 - Ensure That Cloud Storage Buckets Have Uniform Bucket-Level Access Enabled
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; 6.01 - MySQL Database
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; 6.01 - MySQL Database &gt; 6.01.01 - Ensure That a MySQL Database Instance Does Not Allow Anyone To Connect With Administrative Privileges
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; 6.01 - MySQL Database &gt; 6.01.02 - Ensure &apos;Skip_show_database&apos; Database Flag for Cloud SQL MySQL Instance Is Set to &apos;On&apos;
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; 6.01 - MySQL Database &gt; 6.01.03 - Ensure That the &apos;Local_infile&apos; Database Flag for a Cloud SQL MySQL Instance Is Set to &apos;Off&apos;
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database &gt; 6.02.01 - Ensure &apos;Log_error_verbosity&apos; Database Flag for Cloud SQL PostgreSQL Instance Is Set to &apos;DEFAULT&apos; or Stricter
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database &gt; 6.02.02 - Ensure &apos;Log_connections&apos; Database Flag for Cloud SQL PostgreSQL Instance Is Set to &apos;On&apos;
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database &gt; 6.02.03 - Ensure &apos;Log_disconnections&apos; Database Flag for Cloud SQL PostgreSQL Instance Is Set to &apos;On&apos;
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database &gt; 6.02.04 - Ensure &apos;Log_statement&apos; Database Flag for Cloud SQL PostgreSQL Instance Is Set Appropriately
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database &gt; 6.02.05 - Ensure &apos;Log_min_messages&apos; Database Flag for Cloud SQL PostgreSQL Instance is set at minimum to &apos;Warning&apos;
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database &gt; 6.02.06 - Ensure &apos;Log_min_error_statement&apos; Database Flag for Cloud SQL PostgreSQL Instance Is Set to &apos;Error&apos; or Stricter
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database &gt; 6.02.07 - Ensure That the &apos;Log_min_duration_statement&apos; Database Flag for Cloud SQL PostgreSQL Instance Is Set to &apos;-1&apos;
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database &gt; 6.02.08 - Ensure That &apos;cloudsql.enable_pgaudit&apos; Database Flag for each Cloud Sql Postgresql Instance Is Set to &apos;on&apos; For Centralized Logging
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database &gt; 6.02.09 - Ensure Instance IP assignment is set to private
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; 6.03 - SQL Server
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; 6.03 - SQL Server &gt; 6.03.01 - Ensure &apos;external scripts enabled&apos; database flag for Cloud SQL SQL Server instance is set to &apos;off&apos;
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; 6.03 - SQL Server &gt; 6.03.02 - Ensure that the &apos;cross db ownership chaining&apos; database flag for Cloud SQL SQL Server instance is set to &apos;off&apos;
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; 6.03 - SQL Server &gt; 6.03.03 - Ensure &apos;user Connections&apos; Database Flag for Cloud Sql Sql Server Instance Is Set to a Non-limiting Value
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; 6.03 - SQL Server &gt; 6.03.04 - Ensure &apos;user options&apos; database flag for Cloud SQL SQL Server instance is not configured
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; 6.03 - SQL Server &gt; 6.03.05 - Ensure &apos;remote access&apos; database flag for Cloud SQL SQL Server instance is set to &apos;off&apos;
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; 6.03 - SQL Server &gt; 6.03.06 - Ensure &apos;3625 (trace flag)&apos; database flag for all Cloud SQL Server instances is set to &apos;on&apos;
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; 6.03 - SQL Server &gt; 6.03.07 - Ensure that the &apos;contained database authentication&apos; database flag for Cloud SQL on the SQL Server instance is set to &apos;off&apos;
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; 6.04 - Ensure That the Cloud SQL Database Instance Requires All Incoming Connections To Use SSL
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; 6.05 - Ensure That Cloud SQL Database Instances Do Not Implicitly Whitelist All Public IP Addresses
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; 6.06 - Ensure That Cloud SQL Database Instances Do Not Have Public IPs
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; 6.07 - Ensure That Cloud SQL Database Instances Are Configured With Automated Backups
- GCP &gt; CIS v2.0 &gt; 7 - BigQuery
- GCP &gt; CIS v2.0 &gt; 7 - BigQuery &gt; 7.01 - Ensure That BigQuery Datasets Are Not Anonymously or Publicly Accessible
- GCP &gt; CIS v2.0 &gt; 7 - BigQuery &gt; 7.02 - Ensure That All BigQuery Tables Are Encrypted With Customer-Managed Encryption Key (CMEK)
- GCP &gt; CIS v2.0 &gt; 7 - BigQuery &gt; 7.03 - Ensure That a Default Customer-Managed Encryption Key (CMEK) Is Specified for All BigQuery Data Sets

_Policy Types_

- GCP &gt; CIS v2.0
- GCP &gt; CIS v2.0 &gt; 1 - Identity and Access Management
- GCP &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.01 - Ensure that Corporate Login Credentials are Used
- GCP &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.01 - Ensure that Corporate Login Credentials are Used &gt; Attestation
- GCP &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.02 - Ensure that Multi-Factor Authentication is &apos;Enabled&apos; for All Non-Service Accounts
- GCP &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.02 - Ensure that Multi-Factor Authentication is &apos;Enabled&apos; for All Non-Service Accounts &gt; Attestation
- GCP &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.03 - Ensure that Security Key Enforcement is Enabled for All Admin Accounts
- GCP &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.03 - Ensure that Security Key Enforcement is Enabled for All Admin Accounts &gt; Attestation
- GCP &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.04 - Ensure That There Are Only GCP-Managed Service Account Keys for Each Service Account
- GCP &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.05 - Ensure That Service Account Has No Admin Privileges
- GCP &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.06 - Ensure That IAM Users Are Not Assigned the Service Account User or Service Account Token Creator Roles at Project Level
- GCP &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.07 - Ensure User-Managed/External Keys for Service Accounts Are Rotated Every 90 Days or Fewer
- GCP &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.08 - Ensure That Separation of Duties Is Enforced While Assigning Service Account Related Roles to Users
- GCP &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.09 - Ensure That Cloud KMS Cryptokeys Are Not Anonymously or Publicly Accessible
- GCP &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.10 - Ensure KMS Encryption Keys Are Rotated Within a Period of 90 Days
- GCP &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.11 - Ensure That Separation of Duties Is Enforced While Assigning KMS Related Roles to Users
- GCP &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.16 - Ensure Essential Contacts is Configured for Organization
- GCP &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.16 - Ensure Essential Contacts is Configured for Organization &gt; Attestation
- GCP &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.17 - Ensure that Dataproc Cluster is encrypted using Customer-Managed Encryption Key
- GCP &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.18 - Ensure Secrets are Not Stored in Cloud Functions Environment Variables by Using Secret Manager
- GCP &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.18 - Ensure Secrets are Not Stored in Cloud Functions Environment Variables by Using Secret Manager &gt; Attestation
- GCP &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; Maximum Attestation Duration
- GCP &gt; CIS v2.0 &gt; 2 - Logging and Monitoring
- GCP &gt; CIS v2.0 &gt; 2 - Logging and Monitoring &gt; 2.01 - Ensure That Cloud Audit Logging Is Configured Properly
- GCP &gt; CIS v2.0 &gt; 2 - Logging and Monitoring &gt; 2.02 - Ensure That Sinks Are Configured for All Log Entries
- GCP &gt; CIS v2.0 &gt; 2 - Logging and Monitoring &gt; 2.03 - Ensure That Retention Policies on Cloud Storage Buckets Used for Exporting Logs Are Configured Using Bucket Lock
- GCP &gt; CIS v2.0 &gt; 2 - Logging and Monitoring &gt; 2.04 - Ensure Log Metric Filter and Alerts Exist for Project Ownership Assignments/Changes
- GCP &gt; CIS v2.0 &gt; 2 - Logging and Monitoring &gt; 2.05 - Ensure That the Log Metric Filter and Alerts Exist for Audit Configuration Changes
- GCP &gt; CIS v2.0 &gt; 2 - Logging and Monitoring &gt; 2.06 - Ensure That the Log Metric Filter and Alerts Exist for Custom Role Changes
- GCP &gt; CIS v2.0 &gt; 2 - Logging and Monitoring &gt; 2.07 - Ensure That the Log Metric Filter and Alerts Exist for VPC Network Firewall Rule Changes
- GCP &gt; CIS v2.0 &gt; 2 - Logging and Monitoring &gt; 2.08 - Ensure That the Log Metric Filter and Alerts Exist for VPC Network Route Changes
- GCP &gt; CIS v2.0 &gt; 2 - Logging and Monitoring &gt; 2.09 - Ensure That the Log Metric Filter and Alerts Exist for VPC Network Changes
- GCP &gt; CIS v2.0 &gt; 2 - Logging and Monitoring &gt; 2.10 - Ensure That the Log Metric Filter and Alerts Exist for Cloud Storage IAM Permission Changes
- GCP &gt; CIS v2.0 &gt; 2 - Logging and Monitoring &gt; 2.11 - Ensure That the Log Metric Filter and Alerts Exist for SQL Instance Configuration Changes
- GCP &gt; CIS v2.0 &gt; 2 - Logging and Monitoring &gt; 2.12 - Ensure That Cloud DNS Logging Is Enabled for All VPC Networks
- GCP &gt; CIS v2.0 &gt; 2 - Logging and Monitoring &gt; 2.13 - Ensure Cloud Asset Inventory Is Enabled
- GCP &gt; CIS v2.0 &gt; 2 - Logging and Monitoring &gt; 2.14 - Ensure &apos;Access Transparency&apos; is &apos;Enabled&apos;
- GCP &gt; CIS v2.0 &gt; 2 - Logging and Monitoring &gt; 2.14 - Ensure &apos;Access Transparency&apos; is &apos;Enabled&apos; &gt; Attestation
- GCP &gt; CIS v2.0 &gt; 2 - Logging and Monitoring &gt; 2.15 - Ensure &apos;Access Approval&apos; is &apos;Enabled&apos;
- GCP &gt; CIS v2.0 &gt; 2 - Logging and Monitoring &gt; 2.16 - Ensure Logging is enabled for HTTP(S) Load Balancer
- GCP &gt; CIS v2.0 &gt; 2 - Logging and Monitoring &gt; Maximum Attestation Duration
- GCP &gt; CIS v2.0 &gt; 3 - Networking
- GCP &gt; CIS v2.0 &gt; 3 - Networking &gt; 3.01 - Ensure That the Default Network Does Not Exist in a Project
- GCP &gt; CIS v2.0 &gt; 3 - Networking &gt; 3.02 - Ensure Legacy Networks Do Not Exist for Older Projects
- GCP &gt; CIS v2.0 &gt; 3 - Networking &gt; 3.03 - Ensure That DNSSEC Is Enabled for Cloud DNS
- GCP &gt; CIS v2.0 &gt; 3 - Networking &gt; 3.04 - Ensure That RSASHA1 Is Not Used for the Key-Signing Key in Cloud DNS DNSSEC
- GCP &gt; CIS v2.0 &gt; 3 - Networking &gt; 3.05 - Ensure That RSASHA1 Is Not Used for the Zone-Signing Key in Cloud DNS DNSSEC
- GCP &gt; CIS v2.0 &gt; 3 - Networking &gt; 3.06 - Ensure That SSH Access Is Restricted From the Internet
- GCP &gt; CIS v2.0 &gt; 3 - Networking &gt; 3.07 - Ensure That RDP Access Is Restricted From the Internet
- GCP &gt; CIS v2.0 &gt; 3 - Networking &gt; 3.08 - Ensure that VPC Flow Logs is Enabled for Every Subnet in a VPC Network
- GCP &gt; CIS v2.0 &gt; 3 - Networking &gt; 3.09 - Ensure No HTTPS or SSL Proxy Load Balancers Permit SSL Policies With Weak Cipher Suites
- GCP &gt; CIS v2.0 &gt; 3 - Networking &gt; 3.10 - Use Identity Aware Proxy (IAP) to Ensure Only Traffic From Google IP Addresses are &apos;Allowed&apos;
- GCP &gt; CIS v2.0 &gt; 4 - Virtual Machines
- GCP &gt; CIS v2.0 &gt; 4 - Virtual Machines &gt; 4.01 - Ensure That Instances Are Not Configured To Use the Default Service Account
- GCP &gt; CIS v2.0 &gt; 4 - Virtual Machines &gt; 4.02 - Ensure That Instances Are Not Configured To Use the Default Service Account With Full Access to All Cloud APIs
- GCP &gt; CIS v2.0 &gt; 4 - Virtual Machines &gt; 4.03 - Ensure &quot;Block Project-Wide SSH Keys&quot; Is Enabled for VM Instances
- GCP &gt; CIS v2.0 &gt; 4 - Virtual Machines &gt; 4.04 - Ensure Oslogin Is Enabled for a Project
- GCP &gt; CIS v2.0 &gt; 4 - Virtual Machines &gt; 4.05 - Ensure &apos;Enable Connecting to Serial Ports&apos; Is Not Enabled for VM Instance
- GCP &gt; CIS v2.0 &gt; 4 - Virtual Machines &gt; 4.06 - Ensure That IP Forwarding Is Not Enabled on Instances
- GCP &gt; CIS v2.0 &gt; 4 - Virtual Machines &gt; 4.07 - Ensure VM Disks for Critical VMs Are Encrypted With Customer-Supplied Encryption Keys (CSEK)
- GCP &gt; CIS v2.0 &gt; 4 - Virtual Machines &gt; 4.08 - Ensure Compute Instances Are Launched With Shielded VM Enabled
- GCP &gt; CIS v2.0 &gt; 4 - Virtual Machines &gt; 4.09 - Ensure That Compute Instances Do Not Have Public IP Addresses
- GCP &gt; CIS v2.0 &gt; 4 - Virtual Machines &gt; 4.10 - Ensure That App Engine Applications Enforce HTTPS Connections
- GCP &gt; CIS v2.0 &gt; 4 - Virtual Machines &gt; 4.10 - Ensure That App Engine Applications Enforce HTTPS Connections &gt; Attestation
- GCP &gt; CIS v2.0 &gt; 4 - Virtual Machines &gt; 4.11 - Ensure That Compute Instances Have Confidential Computing Enabled
- GCP &gt; CIS v2.0 &gt; 4 - Virtual Machines &gt; 4.12 - Ensure the Latest Operating System Updates Are Installed On Your Virtual Machines in All Projects
- GCP &gt; CIS v2.0 &gt; 4 - Virtual Machines &gt; 4.12 - Ensure the Latest Operating System Updates Are Installed On Your Virtual Machines in All Projects &gt; Attestation
- GCP &gt; CIS v2.0 &gt; 4 - Virtual Machines &gt; Maximum Attestation Duration
- GCP &gt; CIS v2.0 &gt; 5 - Storage
- GCP &gt; CIS v2.0 &gt; 5 - Storage &gt; 5.01 - Ensure That Cloud Storage Bucket Is Not Anonymously or Publicly Accessible
- GCP &gt; CIS v2.0 &gt; 5 - Storage &gt; 5.02 - Ensure That Cloud Storage Buckets Have Uniform Bucket-Level Access Enabled
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; 6.01 - MySQL Database
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; 6.01 - MySQL Database &gt; 6.01.01 - Ensure That a MySQL Database Instance Does Not Allow Anyone To Connect With Administrative Privileges
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; 6.01 - MySQL Database &gt; 6.01.01 - Ensure That a MySQL Database Instance Does Not Allow Anyone To Connect With Administrative Privileges &gt; Attestation
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; 6.01 - MySQL Database &gt; 6.01.02 - Ensure &apos;Skip_show_database&apos; Database Flag for Cloud SQL MySQL Instance Is Set to &apos;On&apos;
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; 6.01 - MySQL Database &gt; 6.01.03 - Ensure That the &apos;Local_infile&apos; Database Flag for a Cloud SQL MySQL Instance Is Set to &apos;Off&apos;
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database &gt; 6.02.01 - Ensure &apos;Log_error_verbosity&apos; Database Flag for Cloud SQL PostgreSQL Instance Is Set to &apos;DEFAULT&apos; or Stricter
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database &gt; 6.02.02 - Ensure &apos;Log_connections&apos; Database Flag for Cloud SQL PostgreSQL Instance Is Set to &apos;On&apos;
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database &gt; 6.02.03 - Ensure &apos;Log_disconnections&apos; Database Flag for Cloud SQL PostgreSQL Instance Is Set to &apos;On&apos;
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database &gt; 6.02.04 - Ensure &apos;Log_statement&apos; Database Flag for Cloud SQL PostgreSQL Instance Is Set Appropriately
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database &gt; 6.02.05 - Ensure &apos;Log_min_messages&apos; Database Flag for Cloud SQL PostgreSQL Instance is set at minimum to &apos;Warning&apos;
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database &gt; 6.02.06 - Ensure &apos;Log_min_error_statement&apos; Database Flag for Cloud SQL PostgreSQL Instance Is Set to &apos;Error&apos; or Stricter
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database &gt; 6.02.07 - Ensure That the &apos;Log_min_duration_statement&apos; Database Flag for Cloud SQL PostgreSQL Instance Is Set to &apos;-1&apos;
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database &gt; 6.02.08 - Ensure That &apos;cloudsql.enable_pgaudit&apos; Database Flag for each Cloud Sql Postgresql Instance Is Set to &apos;on&apos; For Centralized Logging
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; 6.02 - PostgreSQL Database &gt; 6.02.09 - Ensure Instance IP assignment is set to private
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; 6.03 - SQL Server
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; 6.03 - SQL Server &gt; 6.03.01 - Ensure &apos;external scripts enabled&apos; database flag for Cloud SQL SQL Server instance is set to &apos;off&apos;
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; 6.03 - SQL Server &gt; 6.03.02 - Ensure that the &apos;cross db ownership chaining&apos; database flag for Cloud SQL SQL Server instance is set to &apos;off&apos;
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; 6.03 - SQL Server &gt; 6.03.03 - Ensure &apos;user Connections&apos; Database Flag for Cloud Sql Sql Server Instance Is Set to a Non-limiting Value
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; 6.03 - SQL Server &gt; 6.03.04 - Ensure &apos;user options&apos; database flag for Cloud SQL SQL Server instance is not configured
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; 6.03 - SQL Server &gt; 6.03.05 - Ensure &apos;remote access&apos; database flag for Cloud SQL SQL Server instance is set to &apos;off&apos;
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; 6.03 - SQL Server &gt; 6.03.06 - Ensure &apos;3625 (trace flag)&apos; database flag for all Cloud SQL Server instances is set to &apos;on&apos;
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; 6.03 - SQL Server &gt; 6.03.07 - Ensure that the &apos;contained database authentication&apos; database flag for Cloud SQL on the SQL Server instance is set to &apos;off&apos;
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; 6.04 - Ensure That the Cloud SQL Database Instance Requires All Incoming Connections To Use SSL
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; 6.05 - Ensure That Cloud SQL Database Instances Do Not Implicitly Whitelist All Public IP Addresses
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; 6.06 - Ensure That Cloud SQL Database Instances Do Not Have Public IPs
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; 6.07 - Ensure That Cloud SQL Database Instances Are Configured With Automated Backups
- GCP &gt; CIS v2.0 &gt; 6 - Cloud SQL Database Services &gt; Maximum Attestation Duration
- GCP &gt; CIS v2.0 &gt; 7 - BigQuery
- GCP &gt; CIS v2.0 &gt; 7 - BigQuery &gt; 7.01 - Ensure That BigQuery Datasets Are Not Anonymously or Publicly Accessible
- GCP &gt; CIS v2.0 &gt; 7 - BigQuery &gt; 7.02 - Ensure That All BigQuery Tables Are Encrypted With Customer-Managed Encryption Key (CMEK)
- GCP &gt; CIS v2.0 &gt; 7 - BigQuery &gt; 7.03 - Ensure That a Default Customer-Managed Encryption Key (CMEK) Is Specified for All BigQuery Data Sets
- GCP &gt; CIS v2.0 &gt; Maximum Attestation Duration</description>
            <pubDate>Fri, 03 May 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-cisv2-0-v5-0-1</guid>
            <title>aws-cisv2-0 v5.0.1 - Minor fixes and improvements</title>
            <link>https://turbot.com/guardrails/changelog/aws-cisv2-0-v5-0-1</link>
            <description>_Bug fixes_

- Minor fixes and improvements.</description>
            <pubDate>Fri, 03 May 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-v5-24-0</guid>
            <title>gcp v5.24.0 - Access approval setting details for projects is now be available in Project CMDB</title>
            <link>https://turbot.com/guardrails/changelog/gcp-v5-24-0</link>
            <description>_What&apos;s new?_

- Access approval setting details for projects is now be available in Project CMDB.</description>
            <pubDate>Thu, 02 May 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-42-25</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.42.25 - Minor internal improvements</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-42-25</link>
            <description>_Bug fixes_

- Server
  - Minor internal improvements.

_Requirements_

- TEF: 1.57.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Tue, 30 Apr 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-postgresql-v5-15-1</guid>
            <title>azure-postgresql v5.15.1 - Action Type for Firewall &gt; IP Ranges &gt; Approved control did not render correctly for Flexi Servers on mod inspect</title>
            <link>https://turbot.com/guardrails/changelog/azure-postgresql-v5-15-1</link>
            <description>_Bug fixes_
- Action Type for `Azure &gt; PostgreSQL &gt; Flexible Server &gt; Firewall &gt; IP Ranges &gt; Approved` control did not render correctly on mod inspect. This is now fixed.</description>
            <pubDate>Mon, 29 Apr 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-42-24</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.42.24 - Minor internal improvements</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-42-24</link>
            <description>_Bug fixes_

- Server
  - Minor internal improvements.

_Requirements_

- TEF: 1.57.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Fri, 26 Apr 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-storage-v5-17-1</guid>
            <title>azure-storage v5.17.1 - Storage Account Data Protection control would go into an error state when container delete retention policy data was not available in CMDB</title>
            <link>https://turbot.com/guardrails/changelog/azure-storage-v5-17-1</link>
            <description>_Bug fixes_

- The `Azure &gt; Storage &gt; Storage Account &gt; Data Protection` control would go into an error state when container delete retention policy data was not available in CMDB. This issue is fixed and the control will now work as expected.</description>
            <pubDate>Fri, 26 Apr 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-postgresql-v5-15-0</guid>
            <title>azure-postgresql v5.15.0 - Remove unapproved firewall IP Ranges on PostgreSQL servers and flexi servers</title>
            <link>https://turbot.com/guardrails/changelog/azure-postgresql-v5-15-0</link>
            <description>_What&apos;s new?_
- You can now removed unapproved Firewall IP Ranges on PostgreSQL servers and flexi servers. To get started, set the `Azure &gt; PostgreSQL &gt; Server &gt; Firewall &gt; IP Ranges &gt; Approved &gt; *` and `Azure &gt; PostgreSQL &gt; Flexible Server &gt; Firewall &gt; IP Ranges &gt; Approved &gt; *` policies respectively.
- You can now stop unapproved flexi servers. To get started, set the `Azure &gt; PostgreSQL &gt; Flexible Server &gt; Approved` policy to `Enforce: Stop unapproved` or `Enforce: Stop unapproved if new`.

_Control Types_

- Azure &gt; PostgreSQL &gt; Flexible Server &gt; Firewall
- Azure &gt; PostgreSQL &gt; Flexible Server &gt; Firewall &gt; IP Ranges
- Azure &gt; PostgreSQL &gt; Flexible Server &gt; Firewall &gt; IP Ranges &gt; Approved
- Azure &gt; PostgreSQL &gt; Server &gt; Firewall
- Azure &gt; PostgreSQL &gt; Server &gt; Firewall &gt; IP Ranges
- Azure &gt; PostgreSQL &gt; Server &gt; Firewall &gt; IP Ranges &gt; Approved

_Policy Types_

- Azure &gt; PostgreSQL &gt; Flexible Server &gt; Firewall
- Azure &gt; PostgreSQL &gt; Flexible Server &gt; Firewall &gt; IP Ranges
- Azure &gt; PostgreSQL &gt; Flexible Server &gt; Firewall &gt; IP Ranges &gt; Approved
- Azure &gt; PostgreSQL &gt; Flexible Server &gt; Firewall &gt; IP Ranges &gt; Approved &gt; Compiled Rules
- Azure &gt; PostgreSQL &gt; Flexible Server &gt; Firewall &gt; IP Ranges &gt; Approved &gt; IP Addresses
- Azure &gt; PostgreSQL &gt; Flexible Server &gt; Firewall &gt; IP Ranges &gt; Approved &gt; Rules
- Azure &gt; PostgreSQL &gt; Server &gt; Firewall
- Azure &gt; PostgreSQL &gt; Server &gt; Firewall &gt; IP Ranges
- Azure &gt; PostgreSQL &gt; Server &gt; Firewall &gt; IP Ranges &gt; Approved
- Azure &gt; PostgreSQL &gt; Server &gt; Firewall &gt; IP Ranges &gt; Approved &gt; Compiled Rules
- Azure &gt; PostgreSQL &gt; Server &gt; Firewall &gt; IP Ranges &gt; Approved &gt; IP Addresses
- Azure &gt; PostgreSQL &gt; Server &gt; Firewall &gt; IP Ranges &gt; Approved &gt; Rules

_Action Types_

- Azure &gt; PostgreSQL &gt; Flexible Server &gt; Stop
- Azure &gt; PostgreSQL &gt; Server &gt; Update Firewall IP Ranges</description>
            <pubDate>Fri, 26 Apr 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cis-v5-0-1</guid>
            <title>cis v5.0.1 - Fixed control category names for v7.2.10, v7.7.10 and v7.14.1</title>
            <link>https://turbot.com/guardrails/changelog/cis-v5-0-1</link>
            <description>_Bug fixes_

- Fixed control category names for v7.2.10, v7.7.10 and v7.14.1.</description>
            <pubDate>Wed, 24 Apr 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-cisv2-0-v5-0-0</guid>
            <title>azure-cisv2-0 v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/azure-cisv2-0-v5-0-0</link>
            <description>_What&apos;s new?_

_Control Types_

- Azure &gt; CIS v2.0
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.01 - Security Defaults
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.01 - Security Defaults &gt; 1.01.01 - Ensure Security Defaults is enabled on Azure Active Directory
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.01 - Security Defaults &gt; 1.01.02 Ensure that &apos;Multi-Factor Auth Status&apos; is &apos;Enabled&apos; for all Privileged Users
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.01 - Security Defaults &gt; 1.01.03 Ensure that &apos;Multi-Factor Auth Status&apos; is &apos;Enabled&apos; for all Non-Privileged Users
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.01 - Security Defaults &gt; 1.01.04 Ensure that &apos;Allow users to remember multi-factor authentication on devices they trust&apos; is Disabled
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.02 - Conditional Access
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.02 - Conditional Access &gt; 1.02.01 - Ensure Trusted Locations Are Defined
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.02 - Conditional Access &gt; 1.02.02 - Ensure that an exclusionary Geographic Access Policy is considered
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.02 - Conditional Access &gt; 1.02.03 - Ensure that A Multi-factor Authentication Policy Exists for Administrative Groups
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.02 - Conditional Access &gt; 1.02.04 - Ensure that A Multi-factor Authentication Policy Exists for All Users
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.02 - Conditional Access &gt; 1.02.05 - Ensure Multi-factor Authentication is Required for Risky Sign-ins
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.02 - Conditional Access &gt; 1.02.06 - Ensure Multi-factor Authentication is Required for Azure Management
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.03 - Ensure that &apos;Users can create Azure AD Tenants&apos; is set to &apos;No&apos;
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.04 - Ensure Access Review is Set Up for External Users in Azure AD Privileged Identity Management
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.05 - Ensure Guest Users Are Reviewed on a Regular Basis
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.06 Ensure That &apos;Number of methods required to reset&apos; is set to &apos;2&apos;
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.07 - Ensure that a Custom Bad Password List is set to &apos;Enforce&apos; for your Organization
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.08 Ensure that &apos;Number of days before users are asked to re-confirm their authentication information&apos; is not set to &apos;0&apos;
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.09 Ensure that &apos;Notify users on password resets?&apos; is set to &apos;Yes&apos;
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.10 Ensure That &apos;Notify all admins when other admins reset their password?&apos; is set to &apos;Yes&apos;
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.11 - Ensure `User consent for applications` is set to `Do not allow user consent`
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.12 Ensure &apos;User consent for applications&apos; Is Set To &apos;Allow for Verified Publishers&apos;
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.13 Ensure that &apos;Users can add gallery apps to My Apps&apos; is set to &apos;No&apos;
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.14 - Ensure That &apos;Users Can Register Applications&apos; Is Set to &apos;No&apos;
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.15 Ensure That &apos;Guest users access restrictions&apos; is set to &apos;Guest user access is restricted to properties and memberships of their own directory objects&apos;
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.16 Ensure that &apos;Guest invite restrictions&apos; is set to &quot;Only users assigned to specific admin roles can invite guest users&quot;
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.17 Ensure That &apos;Restrict access to Azure AD administration portal&apos; is Set to &apos;Yes&apos;
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.18 Ensure that &apos;Restrict user ability to access groups features in the Access Pane&apos; is Set to &apos;Yes&apos;
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.19 - Ensure that &apos;Users can create security groups in Azure portals, API or PowerShell&apos; is set to &apos;No&apos;
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.20 Ensure that &apos;Owners can manage group membership requests in the Access Panel&apos; is set to &apos;No&apos;
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.21 Ensure that &apos;Users can create Microsoft 365 groups in Azure portals, API or PowerShell&apos; is set to &apos;No&apos;
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.22 Ensure that &apos;Require Multi-Factor Authentication to register or join devices with Azure AD&apos; is set to &apos;Yes&apos;
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.23 - Ensure That No Custom Subscription Administrator Roles Exist
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.24  Ensure a Custom Role is Assigned Permissions for Administering Resource Locks
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.25 Ensure That &apos;Subscription Entering AAD Directory&apos; and &apos;Subscription Leaving AAD Directory&apos; Is Set To &apos;Permit No One&apos;
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.01 - Microsoft Defender for Cloud
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.01 - Microsoft Defender for Cloud &gt; 2.01.01 - Ensure That Microsoft Defender for Servers Is Set to &apos;On&apos;
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.01 - Microsoft Defender for Cloud &gt; 2.01.02 - Ensure That Microsoft Defender for App Services Is Set To &apos;On&apos;
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.01 - Microsoft Defender for Cloud &gt; 2.01.03 -  Ensure That Microsoft Defender for Databases Is Set To &apos;On&apos;
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.01 - Microsoft Defender for Cloud &gt; 2.01.04 - Ensure That Microsoft Defender for Azure SQL Databases Is Set To &apos;On&apos;
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.01 - Microsoft Defender for Cloud &gt; 2.01.05 - Ensure That Microsoft Defender for SQL Servers on Machines Is Set To &apos;On&apos;
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.01 - Microsoft Defender for Cloud &gt; 2.01.06 - Ensure That Microsoft Defender for Open-Source Relational Databases Is Set To &apos;On&apos;
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.01 - Microsoft Defender for Cloud &gt; 2.01.07 - Ensure That Microsoft Defender for Storage Is Set To &apos;On&apos;
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.01 - Microsoft Defender for Cloud &gt; 2.01.08 - Ensure That Microsoft Defender for Containers Is Set To &apos;On&apos;
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.01 - Microsoft Defender for Cloud &gt; 2.01.09 - Ensure That Microsoft Defender for Azure Cosmos DB Is Set To &apos;On&apos;
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.01 - Microsoft Defender for Cloud &gt; 2.01.10 - Ensure That Microsoft Defender for Key Vault Is Set To &apos;On&apos;
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.01 - Microsoft Defender for Cloud &gt; 2.01.11 - Ensure That Microsoft Defender for DNS Is Set To &apos;On&apos;
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.01 - Microsoft Defender for Cloud &gt; 2.01.12 - Ensure That Microsoft Defender for Resource Manager Is Set To &apos;On&apos;
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.01 - Microsoft Defender for Cloud &gt; 2.01.13 - Ensure that Microsoft Defender Recommendation for &apos;Apply system updates&apos; status is &apos;Completed&apos;
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.01 - Microsoft Defender for Cloud &gt; 2.01.14 - Ensure Any of the ASC Default Policy Settings are Not Set to &apos;Disabled&apos;
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.01 - Microsoft Defender for Cloud &gt; 2.01.15 - Ensure that Auto provisioning of &apos;Log Analytics agent for Azure VMs&apos; is Set to &apos;On&apos;
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.01 - Microsoft Defender for Cloud &gt; 2.01.16 - Ensure that Auto provisioning of &apos;Vulnerability assessment for machines&apos; is Set to &apos;On&apos;
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.01 - Microsoft Defender for Cloud &gt; 2.01.17 - Ensure that Auto provisioning of &apos;Microsoft Defender for Containers components&apos; is Set to &apos;On&apos;
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.01 - Microsoft Defender for Cloud &gt; 2.01.18 - Ensure That &apos;All users with the following roles&apos; is set to &apos;Owner&apos;
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.01 - Microsoft Defender for Cloud &gt; 2.01.19 - Ensure &apos;Additional email addresses&apos; is Configured with a Security Contact Email
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.01 - Microsoft Defender for Cloud &gt; 2.01.20 - Ensure That &apos;Notify about alerts with the following severity&apos; is Set to &apos;High&apos;
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.01 - Microsoft Defender for Cloud &gt; 2.01.21 - Ensure that Microsoft Defender for Cloud Apps integration with Microsoft Defender for Cloud is Selected
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.01 - Microsoft Defender for Cloud &gt; 2.01.22 - Ensure that Microsoft Defender for Endpoint integration with Microsoft Defender for Cloud is selected
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.02 - Microsoft Defender for IoT
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.02 - Microsoft Defender for IoT &gt; 2.02.01 - Ensure That Microsoft Defender for IoT Hub Is Set To &apos;On&apos;
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.03 - Microsoft Defender for External Attack Surface Monitoring
- Azure &gt; CIS v2.0 &gt; 03 - Storage Accounts
- Azure &gt; CIS v2.0 &gt; 03 - Storage Accounts &gt; 3.01 - Ensure that &apos;Secure transfer required&apos; is set to &apos;Enabled&apos;
- Azure &gt; CIS v2.0 &gt; 03 - Storage Accounts &gt; 3.02 - Ensure that `Enable Infrastructure Encryption` for Each Storage Account in Azure Storage is Set to `enabled`
- Azure &gt; CIS v2.0 &gt; 03 - Storage Accounts &gt; 3.03 - Ensure that &apos;Enable key rotation reminders&apos; is enabled for each Storage Account
- Azure &gt; CIS v2.0 &gt; 03 - Storage Accounts &gt; 3.04 - Ensure that Storage Account Access Keys are Periodically Regenerated
- Azure &gt; CIS v2.0 &gt; 03 - Storage Accounts &gt; 3.05 - Ensure Storage Logging is Enabled for Queue Service for &apos;Read&apos;, &apos;Write&apos;, and &apos;Delete&apos; requests
- Azure &gt; CIS v2.0 &gt; 03 - Storage Accounts &gt; 3.06 - Ensure that Shared Access Signature Tokens Expire Within an Hour
- Azure &gt; CIS v2.0 &gt; 03 - Storage Accounts &gt; 3.08 - Ensure Default Network Access Rule for Storage Accounts is Set to Deny
- Azure &gt; CIS v2.0 &gt; 03 - Storage Accounts &gt; 3.09 - Ensure &apos;Allow Azure services on the trusted services list to access this storage account&apos; is Enabled for Storage Account Access
- Azure &gt; CIS v2.0 &gt; 03 - Storage Accounts &gt; 3.10 - Ensure Private Endpoints are used to access Storage Accounts
- Azure &gt; CIS v2.0 &gt; 03 - Storage Accounts &gt; 3.11 - Ensure Soft Delete is Enabled for Azure Containers and Blob Storage
- Azure &gt; CIS v2.0 &gt; 03 - Storage Accounts &gt; 3.12 - Ensure Storage for Critical Data are Encrypted with Customer Managed Keys
- Azure &gt; CIS v2.0 &gt; 03 - Storage Accounts &gt; 3.13 - Ensure Storage logging is Enabled for Blob Service for &apos;Read&apos;, &apos;Write&apos;, and &apos;Delete&apos; requests
- Azure &gt; CIS v2.0 &gt; 03 - Storage Accounts &gt; 3.15 - Ensure the &quot;Minimum TLS version&quot; for storage accounts is set to &quot;Version 1.2&quot;
- Azure &gt; CIS v2.0 &gt; 04 - Database Services
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.01 SQL Server - Auditing
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.01 SQL Server - Auditing &gt; 4.01.01 - Ensure that &apos;Auditing&apos; is set to &apos;On&apos;
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.01 SQL Server - Auditing &gt; 4.01.02 - Ensure no Azure SQL Databases allow ingress from 0.0.0.0/0 (ANY IP)
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.01 SQL Server - Auditing &gt; 4.01.03 - Ensure SQL server&apos;s Transparent Data Encryption (TDE) protector is encrypted with Customer-managed key
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.01 SQL Server - Auditing &gt; 4.01.04 - Ensure that Azure Active Directory Admin is Configured for SQL Servers
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.01 SQL Server - Auditing &gt; 4.01.05 - Ensure that &apos;Data encryption&apos; is set to &apos;On&apos; on a SQL Database
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.01 SQL Server - Auditing &gt; 4.01.06 - Ensure that &apos;Auditing&apos; Retention is &apos;greater than 90 days&apos;
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.02 SQL Server - Microsoft Defender for SQL
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.02 SQL Server - Microsoft Defender for SQL &gt; 4.02.01 - Ensure that Microsoft Defender for SQL is set to &apos;On&apos; for critical SQL Servers
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.02 SQL Server - Microsoft Defender for SQL &gt; 4.02.02 - Ensure that Vulnerability Assessment (VA) is enabled on a SQL server by setting a Storage Account
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.02 SQL Server - Microsoft Defender for SQL &gt; 4.02.03 - Ensure that Vulnerability Assessment (VA) setting &apos;Periodic recurring scans&apos; is set to &apos;on&apos; for each SQL server
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.02 SQL Server - Microsoft Defender for SQL &gt; 4.02.04 - Ensure that Vulnerability Assessment (VA) setting &apos;Send scan reports to&apos; is configured for a SQL server
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.02 SQL Server - Microsoft Defender for SQL &gt; 4.02.05 - Ensure that Vulnerability Assessment (VA) setting &apos;Also send email notifications to admins and subscription owners&apos; is set for each SQL Server
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.03 PostgreSQL Database Server
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.03 PostgreSQL Database Server &gt; 4.03.01 - Ensure &apos;Enforce SSL connection&apos; is set to &apos;ENABLED&apos; for PostgreSQL Database Server
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.03 PostgreSQL Database Server &gt; 4.03.02 - Ensure Server Parameter &apos;log_checkpoints&apos; is set to &apos;ON&apos; for PostgreSQL Database Server
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.03 PostgreSQL Database Server &gt; 4.03.03 - Ensure server parameter &apos;log_connections&apos; is set to &apos;ON&apos; for PostgreSQL Database Server
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.03 PostgreSQL Database Server &gt; 4.03.04 - Ensure Server Parameter &apos;log_disconnections&apos; is set to &apos;ON&apos; for PostgreSQL Database Server
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.03 PostgreSQL Database Server &gt; 4.03.05 - Ensure Server Parameter &apos;connection_throttling&apos; is set to &apos;ON&apos; for PostgreSQL Database Server
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.03 PostgreSQL Database Server &gt; 4.03.06 - Ensure Server Parameter &apos;log_retention_days&apos; is greater than 3 days for PostgreSQL Database Server
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.03 PostgreSQL Database Server &gt; 4.03.07 - Ensure &apos;Allow access to Azure services&apos; for PostgreSQL Database Server is disabled
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.03 PostgreSQL Database Server &gt; 4.03.08 - Ensure &apos;Infrastructure double encryption&apos; for PostgreSQL Database Server is &apos;Enabled&apos;
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.04 - MySQL Database
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.04 - MySQL Database &gt; 4.04.01 - Ensure &apos;Enforce SSL connection&apos; is set to &apos;Enabled&apos; for Standard MySQL Database Server
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.04 - MySQL Database &gt; 4.04.02 - Ensure &apos;TLS Version&apos; is set to &apos;TLSV1.2&apos; for MySQL flexible Database Server
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.04 - MySQL Database &gt; 4.04.03 - Ensure server parameter &apos;audit_log_enabled&apos; is set to &apos;ON&apos; for MySQL Database Server
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.04 - MySQL Database &gt; 4.04.04 - Ensure server parameter &apos;audit_log_events&apos; has &apos;CONNECTION&apos; set for MySQL Database Server
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.05 - Cosmos DB
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.05 - Cosmos DB &gt; 4.05.01 - Ensure That &apos;Firewalls &amp; Networks&apos; Is Limited to Use Selected Networks Instead of All Networks
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.05 - Cosmos DB &gt; 4.05.02 - Ensure That Private Endpoints Are Used Where Possible
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.05 - Cosmos DB &gt; 4.05.03 - Use Azure Active Directory (AAD) Client Authentication and Azure RBAC where possible
- Azure &gt; CIS v2.0 &gt; 05 - Logging and Monitoring
- Azure &gt; CIS v2.0 &gt; 05 - Logging and Monitoring &gt; 5.01 - Configuring Diagnostic Settings
- Azure &gt; CIS v2.0 &gt; 05 - Logging and Monitoring &gt; 5.01 - Configuring Diagnostic Settings &gt; 5.01.03 - Ensure the Storage Container Storing the Activity Logs is not Publicly Accessible
- Azure &gt; CIS v2.0 &gt; 05 - Logging and Monitoring &gt; 5.01 - Configuring Diagnostic Settings &gt; 5.01.04 - Ensure the storage account containing the container with activity logs is encrypted with Customer Managed Key
- Azure &gt; CIS v2.0 &gt; 05 - Logging and Monitoring &gt; 5.01 - Configuring Diagnostic Settings &gt; 5.01.05 - Ensure that logging for Azure Key Vault is &apos;Enabled&apos;
- Azure &gt; CIS v2.0 &gt; 05 - Logging and Monitoring &gt; 5.01 - Configuring Diagnostic Settings &gt; 5.01.07 - Ensure that logging for Azure AppService &apos;HTTP logs&apos; is enabled
- Azure &gt; CIS v2.0 &gt; 05 - Logging and Monitoring &gt; 5.02 - Monitoring using Activity Log Alerts
- Azure &gt; CIS v2.0 &gt; 05 - Logging and Monitoring &gt; 5.02 - Monitoring using Activity Log Alerts &gt; 5.02.01 - Ensure that Activity Log Alert exists for Create Policy Assignment
- Azure &gt; CIS v2.0 &gt; 05 - Logging and Monitoring &gt; 5.02 - Monitoring using Activity Log Alerts &gt; 5.02.02 - Ensure that Activity Log Alert exists for Delete Policy Assignment
- Azure &gt; CIS v2.0 &gt; 05 - Logging and Monitoring &gt; 5.02 - Monitoring using Activity Log Alerts &gt; 5.02.03 - Ensure that Activity Log Alert exists for Create or Update Network Security Group
- Azure &gt; CIS v2.0 &gt; 05 - Logging and Monitoring &gt; 5.02 - Monitoring using Activity Log Alerts &gt; 5.02.04 - Ensure that Activity Log Alert exists for Delete Network Security Group
- Azure &gt; CIS v2.0 &gt; 05 - Logging and Monitoring &gt; 5.02 - Monitoring using Activity Log Alerts &gt; 5.02.05 - Ensure that Activity Log Alert exists for Create or Update Security Solution
- Azure &gt; CIS v2.0 &gt; 05 - Logging and Monitoring &gt; 5.02 - Monitoring using Activity Log Alerts &gt; 5.02.06 - Ensure that Activity Log Alert exists for Delete Security Solution
- Azure &gt; CIS v2.0 &gt; 05 - Logging and Monitoring &gt; 5.02 - Monitoring using Activity Log Alerts &gt; 5.02.07 - Ensure that Activity Log Alert exists for Create or Update SQL Server Firewall Rule
- Azure &gt; CIS v2.0 &gt; 05 - Logging and Monitoring &gt; 5.02 - Monitoring using Activity Log Alerts &gt; 5.02.08 - Ensure that Activity Log Alert exists for Delete SQL Server Firewall Rule
- Azure &gt; CIS v2.0 &gt; 05 - Logging and Monitoring &gt; 5.02 - Monitoring using Activity Log Alerts &gt; 5.02.09 - Ensure that Activity Log Alert exists for Create or Update Public IP Address rule
- Azure &gt; CIS v2.0 &gt; 05 - Logging and Monitoring &gt; 5.02 - Monitoring using Activity Log Alerts &gt; 5.02.10 - Ensure that Activity Log Alert exists for Delete Public IP Address rule
- Azure &gt; CIS v2.0 &gt; 05 - Logging and Monitoring &gt; 5.03 - Configuring Application Insights
- Azure &gt; CIS v2.0 &gt; 05 - Logging and Monitoring &gt; 5.03 - Configuring Application Insights &gt; 5.03.01 - Ensure Application Insights are Configured
- Azure &gt; CIS v2.0 &gt; 05 - Logging and Monitoring &gt; 5.04 - Ensure that Azure Monitor Resource Logging is Enabled for All Services that Support it
- Azure &gt; CIS v2.0 &gt; 05 - Logging and Monitoring &gt; 5.05 - Ensure that SKU Basic/Consumption is not used on artifacts that need to be monitored (Particularly for Production Workloads)
- Azure &gt; CIS v2.0 &gt; 06 - Networking
- Azure &gt; CIS v2.0 &gt; 06 - Networking &gt; 6.01 - Ensure that RDP access from the Internet is evaluated and restricted
- Azure &gt; CIS v2.0 &gt; 06 - Networking &gt; 6.02 - Ensure that SSH access from the Internet is evaluated and restricted
- Azure &gt; CIS v2.0 &gt; 06 - Networking &gt; 6.03 - Ensure that UDP access from the Internet is evaluated and restricted
- Azure &gt; CIS v2.0 &gt; 06 - Networking &gt; 6.04 - Ensure that HTTP(S) access from the Internet is evaluated and restricted
- Azure &gt; CIS v2.0 &gt; 06 - Networking &gt; 6.05 - Ensure that Network Security Group Flow Log retention period is &apos;greater than 90 days&apos;
- Azure &gt; CIS v2.0 &gt; 06 - Networking &gt; 6.06 - Ensure that Network Watcher is &apos;Enabled&apos;
- Azure &gt; CIS v2.0 &gt; 06 - Networking &gt; 6.07 - Ensure that Public IP addresses are Evaluated on a Periodic Basis
- Azure &gt; CIS v2.0 &gt; 07 - Virtual Machines
- Azure &gt; CIS v2.0 &gt; 07 - Virtual Machines &gt; 7.02 - Ensure Virtual Machines are utilizing Managed Disks
- Azure &gt; CIS v2.0 &gt; 07 - Virtual Machines &gt; 7.03 - Ensure that &apos;OS and Data&apos; disks are encrypted with Customer Managed Key (CMK)
- Azure &gt; CIS v2.0 &gt; 07 - Virtual Machines &gt; 7.04 - Ensure that &apos;Unattached disks&apos; are encrypted with &apos;Customer Managed Key&apos; (CMK)
- Azure &gt; CIS v2.0 &gt; 07 - Virtual Machines &gt; 7.05 - Ensure that Only Approved Extensions Are Installed
- Azure &gt; CIS v2.0 &gt; 07 - Virtual Machines &gt; 7.06 - Ensure that Endpoint Protection for all Virtual Machines is installed
- Azure &gt; CIS v2.0 &gt; 07 - Virtual Machines &gt; 7.07 - [Legacy] Ensure that VHDs are Encrypted
- Azure &gt; CIS v2.0 &gt; 08 - Key Vault
- Azure &gt; CIS v2.0 &gt; 08 - Key Vault &gt; 8.01 - Ensure that the Expiration Date is set for all Keys in RBAC Key Vaults
- Azure &gt; CIS v2.0 &gt; 08 - Key Vault &gt; 8.02 - Ensure that the Expiration Date is set for all Keys in Non-RBAC Key Vaults
- Azure &gt; CIS v2.0 &gt; 08 - Key Vault &gt; 8.03 - Ensure that the Expiration Date is set for all Secrets in RBAC Key Vaults
- Azure &gt; CIS v2.0 &gt; 08 - Key Vault &gt; 8.04 - Ensure that the Expiration Date is set for all Secrets in Non-RBAC Key Vaults
- Azure &gt; CIS v2.0 &gt; 08 - Key Vault &gt; 8.05 - Ensure the key vault is recoverable
- Azure &gt; CIS v2.0 &gt; 08 - Key Vault &gt; 8.06 - Ensure Role Based Access Control for Azure Key Vault
- Azure &gt; CIS v2.0 &gt; 08 - Key Vault &gt; 8.07 - Ensure that Private Endpoints are Used for Azure Key Vault
- Azure &gt; CIS v2.0 &gt; 08 - Key Vault &gt; 8.08 - Ensure Automatic Key Rotation is Enabled Within Azure Key Vault for the Supported Services
- Azure &gt; CIS v2.0 &gt; 09 - Application Services
- Azure &gt; CIS v2.0 &gt; 09 - Application Services &gt; 9.01 - Ensure App Service Authentication is set up for apps in Azure App Service
- Azure &gt; CIS v2.0 &gt; 09 - Application Services &gt; 9.02 - Ensure Web App Redirects All HTTP traffic to HTTPS in Azure App Service
- Azure &gt; CIS v2.0 &gt; 09 - Application Services &gt; 9.03 - Ensure Web App is using the latest version of TLS encryption
- Azure &gt; CIS v2.0 &gt; 09 - Application Services &gt; 9.04 - Ensure the web app has &apos;Client Certificates (Incoming client certificates)&apos; set to &apos;On&apos;
- Azure &gt; CIS v2.0 &gt; 09 - Application Services &gt; 9.05 - Ensure that Register with Azure Active Directory is enabled on App Service
- Azure &gt; CIS v2.0 &gt; 09 - Application Services &gt; 9.06 - Ensure That &apos;PHP version&apos; is the Latest, If Used to Run the Web App
- Azure &gt; CIS v2.0 &gt; 09 - Application Services &gt; 9.07 - Ensure that &apos;Python version&apos; is the Latest Stable Version, if Used to Run the Web App
- Azure &gt; CIS v2.0 &gt; 09 - Application Services &gt; 9.08 - Ensure that &apos;Java version&apos; is the latest, if used to run the Web App
- Azure &gt; CIS v2.0 &gt; 09 - Application Services &gt; 9.09 - Ensure that &apos;HTTP Version&apos; is the Latest, if Used to Run the Web App
- Azure &gt; CIS v2.0 &gt; 09 - Application Services &gt; 9.10 - Ensure FTP deployments are Disabled
- Azure &gt; CIS v2.0 &gt; 09 - Application Services &gt; 9.11 - Ensure Azure Key Vaults are Used to Store Secrets
- Azure &gt; CIS v2.0 &gt; 10 - Miscellaneous
- Azure &gt; CIS v2.0 &gt; 10 - Miscellaneous &gt; 10.01 - Ensure that Resource Locks are set for Mission-Critical Azure Resources

_Policy Types_

- Azure &gt; CIS v2.0
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.01 - Security Defaults
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.01 - Security Defaults &gt; 1.01.01 - Ensure Security Defaults is enabled on Azure Active Directory
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.01 - Security Defaults &gt; 1.01.01 - Ensure Security Defaults is enabled on Azure Active Directory &gt; Attestation
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.01 - Security Defaults &gt; 1.01.02 Ensure that &apos;Multi-Factor Auth Status&apos; is &apos;Enabled&apos; for all Privileged Users
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.01 - Security Defaults &gt; 1.01.02 Ensure that &apos;Multi-Factor Auth Status&apos; is &apos;Enabled&apos; for all Privileged Users &gt; Attestation
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.01 - Security Defaults &gt; 1.01.03 Ensure that &apos;Multi-Factor Auth Status&apos; is &apos;Enabled&apos; for all Non-Privileged Users
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.01 - Security Defaults &gt; 1.01.03 Ensure that &apos;Multi-Factor Auth Status&apos; is &apos;Enabled&apos; for all Non-Privileged Users &gt; Attestation
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.01 - Security Defaults &gt; 1.01.04 Ensure that &apos;Allow users to remember multi-factor authentication on devices they trust&apos; is Disabled
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.01 - Security Defaults &gt; 1.01.04 Ensure that &apos;Allow users to remember multi-factor authentication on devices they trust&apos; is Disabled &gt; Attestation
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.02 - Conditional Access
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.02 - Conditional Access &gt; 1.02.01 - Ensure Trusted Locations Are Defined
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.02 - Conditional Access &gt; 1.02.02 - Ensure that an exclusionary Geographic Access Policy is considered
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.02 - Conditional Access &gt; 1.02.02 - Ensure that an exclusionary Geographic Access Policy is considered &gt; Attestation
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.02 - Conditional Access &gt; 1.02.03 - Ensure that A Multi-factor Authentication Policy Exists for Administrative Groups
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.02 - Conditional Access &gt; 1.02.03 - Ensure that A Multi-factor Authentication Policy Exists for Administrative Groups &gt; Attestation
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.02 - Conditional Access &gt; 1.02.04 - Ensure that A Multi-factor Authentication Policy Exists for All Users
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.02 - Conditional Access &gt; 1.02.04 - Ensure that A Multi-factor Authentication Policy Exists for All Users &gt; Attestation
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.02 - Conditional Access &gt; 1.02.05 - Ensure Multi-factor Authentication is Required for Risky Sign-ins
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.02 - Conditional Access &gt; 1.02.05 - Ensure Multi-factor Authentication is Required for Risky Sign-ins &gt; Attestation
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.02 - Conditional Access &gt; 1.02.06 - Ensure Multi-factor Authentication is Required for Azure Management
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.02 - Conditional Access &gt; 1.02.06 - Ensure Multi-factor Authentication is Required for Azure Management &gt; Attestation
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.03 - Ensure that &apos;Users can create Azure AD Tenants&apos; is set to &apos;No&apos;
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.03 - Ensure that &apos;Users can create Azure AD Tenants&apos; is set to &apos;No&apos; &gt; Attestation
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.04 - Ensure Access Review is Set Up for External Users in Azure AD Privileged Identity Management
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.04 - Ensure Access Review is Set Up for External Users in Azure AD Privileged Identity Management &gt; Attestation
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.05 - Ensure Guest Users Are Reviewed on a Regular Basis
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.06 - Ensure That &apos;Number of methods required to reset&apos; is set to &apos;2&apos;
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.06 - Ensure That &apos;Number of methods required to reset&apos; is set to &apos;2&apos; &gt; Attestation
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.07 - Ensure that a Custom Bad Password List is set to &apos;Enforce&apos; for your Organization
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.07 - Ensure that a Custom Bad Password List is set to &apos;Enforce&apos; for your Organization &gt; Attestation
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.08 Ensure that &apos;Number of days before users are asked to re-confirm their authentication information&apos; is not set to &apos;0&apos;
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.08 Ensure that &apos;Number of days before users are asked to re-confirm their authentication information&apos; is not set to &apos;0&apos; &gt; Attestation
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.09 Ensure that &apos;Notify users on password resets?&apos; is set to &apos;Yes&apos;
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.09 Ensure that &apos;Notify users on password resets?&apos; is set to &apos;Yes&apos; &gt; Attestation
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.10 Ensure That &apos;Notify all admins when other admins reset their password?&apos; is set to &apos;Yes&apos;
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.10 Ensure That &apos;Notify all admins when other admins reset their password?&apos; is set to &apos;Yes&apos; &gt; Attestation
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.11 - Ensure `User consent for applications` is set to `Do not allow user consent`
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.11 - Ensure `User consent for applications` is set to `Do not allow user consent` &gt; Attestation
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.12 Ensure &apos;User consent for applications&apos; Is Set To &apos;Allow for Verified Publishers&apos;
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.12 Ensure &apos;User consent for applications&apos; Is Set To &apos;Allow for Verified Publishers&apos; &gt; Attestation
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.13 Ensure that &apos;Users can add gallery apps to My Apps&apos; is set to &apos;No&apos;
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.13 Ensure that &apos;Users can add gallery apps to My Apps&apos; is set to &apos;No&apos; &gt; Attestation
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.14 - Ensure That &apos;Users Can Register Applications&apos; Is Set to &apos;No&apos;
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.15 Ensure That &apos;Guest users access restrictions&apos; is set to &apos;Guest user access is restricted to properties and memberships of their own directory objects&apos;
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.15 Ensure That &apos;Guest users access restrictions&apos; is set to &apos;Guest user access is restricted to properties and memberships of their own directory objects&apos; &gt; Attestation
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.16 Ensure that &apos;Guest invite restrictions&apos; is set to &quot;Only users assigned to specific admin roles can invite guest users&quot;
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.16 Ensure that &apos;Guest invite restrictions&apos; is set to &quot;Only users assigned to specific admin roles can invite guest users&quot; &gt; Attestation
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.17 Ensure That &apos;Restrict access to Azure AD administration portal&apos; is Set to &apos;Yes&apos;
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.17 Ensure That &apos;Restrict access to Azure AD administration portal&apos; is Set to &apos;Yes&apos; &gt; Attestation
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.18 Ensure that &apos;Restrict user ability to access groups features in the Access Pane&apos; is Set to &apos;Yes&apos;
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.18 Ensure that &apos;Restrict user ability to access groups features in the Access Pane&apos; is Set to &apos;Yes&apos; &gt; Attestation
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.19 - Ensure that &apos;Users can create security groups in Azure portals, API or PowerShell&apos; is set to &apos;No&apos;
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.20 Ensure that &apos;Owners can manage group membership requests in the Access Panel&apos; is set to &apos;No&apos;
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.20 Ensure that &apos;Owners can manage group membership requests in the Access Panel&apos; is set to &apos;No&apos; &gt; Attestation
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.21 Ensure that &apos;Users can create Microsoft 365 groups in Azure portals, API or PowerShell&apos; is set to &apos;No&apos;
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.21 Ensure that &apos;Users can create Microsoft 365 groups in Azure portals, API or PowerShell&apos; is set to &apos;No&apos; &gt; Attestation
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.22 Ensure that &apos;Require Multi-Factor Authentication to register or join devices with Azure AD&apos; is set to &apos;Yes&apos;
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.22 Ensure that &apos;Require Multi-Factor Authentication to register or join devices with Azure AD&apos; is set to &apos;Yes&apos; &gt; Attestation
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.23 - Ensure That No Custom Subscription Administrator Roles Exist
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.24  Ensure a Custom Role is Assigned Permissions for Administering Resource Locks
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.24  Ensure a Custom Role is Assigned Permissions for Administering Resource Locks &gt; Attestation
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.25 Ensure That &apos;Subscription Entering AAD Directory&apos; and &apos;Subscription Leaving AAD Directory&apos; Is Set To &apos;Permit No One&apos;
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; 1.25 Ensure That &apos;Subscription Entering AAD Directory&apos; and &apos;Subscription Leaving AAD Directory&apos; Is Set To &apos;Permit No One&apos; &gt; Attestation
- Azure &gt; CIS v2.0 &gt; 01 - Identity and Access Management &gt; Maximum Attestation Duration
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.01 - Microsoft Defender for Cloud
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.01 - Microsoft Defender for Cloud &gt; 2.01.01 - Ensure That Microsoft Defender for Servers Is Set to &apos;On&apos;
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.01 - Microsoft Defender for Cloud &gt; 2.01.02 - Ensure That Microsoft Defender for App Services Is Set To &apos;On&apos;
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.01 - Microsoft Defender for Cloud &gt; 2.01.03 -  Ensure That Microsoft Defender for Databases Is Set To &apos;On&apos;
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.01 - Microsoft Defender for Cloud &gt; 2.01.04 - Ensure That Microsoft Defender for Azure SQL Databases Is Set To &apos;On&apos;
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.01 - Microsoft Defender for Cloud &gt; 2.01.05 - Ensure That Microsoft Defender for SQL Servers on Machines Is Set To &apos;On&apos;
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.01 - Microsoft Defender for Cloud &gt; 2.01.06 - Ensure That Microsoft Defender for Open-Source Relational Databases Is Set To &apos;On&apos;
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.01 - Microsoft Defender for Cloud &gt; 2.01.07 - Ensure That Microsoft Defender for Storage Is Set To &apos;On&apos;
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.01 - Microsoft Defender for Cloud &gt; 2.01.08 - Ensure That Microsoft Defender for Containers Is Set To &apos;On&apos;
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.01 - Microsoft Defender for Cloud &gt; 2.01.09 - Ensure That Microsoft Defender for Azure Cosmos DB Is Set To &apos;On&apos;
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.01 - Microsoft Defender for Cloud &gt; 2.01.10 - Ensure That Microsoft Defender for Key Vault Is Set To &apos;On&apos;
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.01 - Microsoft Defender for Cloud &gt; 2.01.11 - Ensure That Microsoft Defender for DNS Is Set To &apos;On&apos;
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.01 - Microsoft Defender for Cloud &gt; 2.01.12 - Ensure That Microsoft Defender for Resource Manager Is Set To &apos;On&apos;
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.01 - Microsoft Defender for Cloud &gt; 2.01.13 - Ensure that Microsoft Defender Recommendation for &apos;Apply system updates&apos; status is &apos;Completed&apos;
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.01 - Microsoft Defender for Cloud &gt; 2.01.13 - Ensure that Microsoft Defender Recommendation for &apos;Apply system updates&apos; status is &apos;Completed&apos; &gt; Attestation
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.01 - Microsoft Defender for Cloud &gt; 2.01.14 - Ensure Any of the ASC Default Policy Settings are Not Set to &apos;Disabled&apos;
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.01 - Microsoft Defender for Cloud &gt; 2.01.15 - Ensure that Auto provisioning of &apos;Log Analytics agent for Azure VMs&apos; is Set to &apos;On&apos;
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.01 - Microsoft Defender for Cloud &gt; 2.01.16 - Ensure that Auto provisioning of &apos;Vulnerability assessment for machines&apos; is Set to &apos;On&apos;
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.01 - Microsoft Defender for Cloud &gt; 2.01.16 - Ensure that Auto provisioning of &apos;Vulnerability assessment for machines&apos; is Set to &apos;On&apos; &gt; Attestation
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.01 - Microsoft Defender for Cloud &gt; 2.01.17 - Ensure that Auto provisioning of &apos;Microsoft Defender for Containers components&apos; is Set to &apos;On&apos;
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.01 - Microsoft Defender for Cloud &gt; 2.01.17 - Ensure that Auto provisioning of &apos;Microsoft Defender for Containers components&apos; is Set to &apos;On&apos; &gt; Attestation
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.01 - Microsoft Defender for Cloud &gt; 2.01.18 - Ensure That &apos;All users with the following roles&apos; is set to &apos;Owner&apos;
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.01 - Microsoft Defender for Cloud &gt; 2.01.19 - Ensure &apos;Additional email addresses&apos; is Configured with a Security Contact Email
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.01 - Microsoft Defender for Cloud &gt; 2.01.20 - Ensure That &apos;Notify about alerts with the following severity&apos; is Set to &apos;High&apos;
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.01 - Microsoft Defender for Cloud &gt; 2.01.21 - Ensure that Microsoft Defender for Cloud Apps integration with Microsoft Defender for Cloud is Selected
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.01 - Microsoft Defender for Cloud &gt; 2.01.22 - Ensure that Microsoft Defender for Endpoint integration with Microsoft Defender for Cloud is selected
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.02 - Microsoft Defender for IoT
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.02 - Microsoft Defender for IoT &gt; 2.02.01 - Ensure That Microsoft Defender for IoT Hub Is Set To &apos;On&apos;
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.02 - Microsoft Defender for IoT &gt; 2.02.01 - Ensure That Microsoft Defender for IoT Hub Is Set To &apos;On&apos; &gt; Attestation
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; 2.03 - Microsoft Defender for External Attack Surface Monitoring
- Azure &gt; CIS v2.0 &gt; 02 - Microsoft Defender &gt; Maximum Attestation Duration
- Azure &gt; CIS v2.0 &gt; 03 - Storage Accounts
- Azure &gt; CIS v2.0 &gt; 03 - Storage Accounts &gt; 3.01 - Ensure that &apos;Secure transfer required&apos; is set to &apos;Enabled&apos;
- Azure &gt; CIS v2.0 &gt; 03 - Storage Accounts &gt; 3.02 - Ensure that `Enable Infrastructure Encryption` for Each Storage Account in Azure Storage is Set to `enabled`
- Azure &gt; CIS v2.0 &gt; 03 - Storage Accounts &gt; 3.03 - Ensure that &apos;Enable key rotation reminders&apos; is enabled for each Storage Account
- Azure &gt; CIS v2.0 &gt; 03 - Storage Accounts &gt; 3.03 - Ensure that &apos;Enable key rotation reminders&apos; is enabled for each Storage Account &gt; Attestation
- Azure &gt; CIS v2.0 &gt; 03 - Storage Accounts &gt; 3.04 - Ensure that Storage Account Access Keys are Periodically Regenerated
- Azure &gt; CIS v2.0 &gt; 03 - Storage Accounts &gt; 3.04 - Ensure that Storage Account Access Keys are Periodically Regenerated &gt; Attestation
- Azure &gt; CIS v2.0 &gt; 03 - Storage Accounts &gt; 3.05 - Ensure Storage Logging is Enabled for Queue Service for &apos;Read&apos;, &apos;Write&apos;, and &apos;Delete&apos; requests
- Azure &gt; CIS v2.0 &gt; 03 - Storage Accounts &gt; 3.06 - Ensure that Shared Access Signature Tokens Expire Within an Hour
- Azure &gt; CIS v2.0 &gt; 03 - Storage Accounts &gt; 3.06 - Ensure that Shared Access Signature Tokens Expire Within an Hour &gt; Attestation
- Azure &gt; CIS v2.0 &gt; 03 - Storage Accounts &gt; 3.08 - Ensure Default Network Access Rule for Storage Accounts is Set to Deny
- Azure &gt; CIS v2.0 &gt; 03 - Storage Accounts &gt; 3.09 - Ensure &apos;Allow Azure services on the trusted services list to access this storage account&apos; is Enabled for Storage Account Access
- Azure &gt; CIS v2.0 &gt; 03 - Storage Accounts &gt; 3.10 - Ensure Private Endpoints are used to access Storage Accounts
- Azure &gt; CIS v2.0 &gt; 03 - Storage Accounts &gt; 3.11 - Ensure Soft Delete is Enabled for Azure Containers and Blob Storage
- Azure &gt; CIS v2.0 &gt; 03 - Storage Accounts &gt; 3.12 - Ensure Storage for Critical Data are Encrypted with Customer Managed Keys
- Azure &gt; CIS v2.0 &gt; 03 - Storage Accounts &gt; 3.13 - Ensure Storage logging is Enabled for Blob Service for &apos;Read&apos;, &apos;Write&apos;, and &apos;Delete&apos; requests
- Azure &gt; CIS v2.0 &gt; 03 - Storage Accounts &gt; 3.15 - Ensure the &quot;Minimum TLS version&quot; for storage accounts is set to &quot;Version 1.2&quot;
- Azure &gt; CIS v2.0 &gt; 03 - Storage Accounts &gt; Maximum Attestation Duration
- Azure &gt; CIS v2.0 &gt; 04 - Database Services
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.01 SQL Server - Auditing
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.01 SQL Server - Auditing &gt; 4.01.01 - Ensure that &apos;Auditing&apos; is set to &apos;On&apos;
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.01 SQL Server - Auditing &gt; 4.01.02 - Ensure no Azure SQL Databases allow ingress from 0.0.0.0/0 (ANY IP)
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.01 SQL Server - Auditing &gt; 4.01.03 - Ensure SQL server&apos;s Transparent Data Encryption (TDE) protector is encrypted with Customer-managed key
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.01 SQL Server - Auditing &gt; 4.01.04 - Ensure that Azure Active Directory Admin is Configured for SQL Servers
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.01 SQL Server - Auditing &gt; 4.01.05 - Ensure that &apos;Data encryption&apos; is set to &apos;On&apos; on a SQL Database
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.01 SQL Server - Auditing &gt; 4.01.06 - Ensure that &apos;Auditing&apos; Retention is &apos;greater than 90 days&apos;
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.02 SQL Server - Microsoft Defender for SQL
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.02 SQL Server - Microsoft Defender for SQL &gt; 4.02.01 - Ensure that Microsoft Defender for SQL is set to &apos;On&apos; for critical SQL Servers
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.02 SQL Server - Microsoft Defender for SQL &gt; 4.02.02 - Ensure that Vulnerability Assessment (VA) is enabled on a SQL server by setting a Storage Account
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.02 SQL Server - Microsoft Defender for SQL &gt; 4.02.03 - Ensure that Vulnerability Assessment (VA) setting &apos;Periodic recurring scans&apos; is set to &apos;on&apos; for each SQL server
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.02 SQL Server - Microsoft Defender for SQL &gt; 4.02.04 - Ensure that Vulnerability Assessment (VA) setting &apos;Send scan reports to&apos; is configured for a SQL server
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.02 SQL Server - Microsoft Defender for SQL &gt; 4.02.05 - Ensure that Vulnerability Assessment (VA) setting &apos;Also send email notifications to admins and subscription owners&apos; is set for each SQL Server
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.03 PostgreSQL Database Server
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.03 PostgreSQL Database Server &gt; 4.03.01 - Ensure &apos;Enforce SSL connection&apos; is set to &apos;ENABLED&apos; for PostgreSQL Database Server
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.03 PostgreSQL Database Server &gt; 4.03.02 - Ensure Server Parameter &apos;log_checkpoints&apos; is set to &apos;ON&apos; for PostgreSQL Database Server
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.03 PostgreSQL Database Server &gt; 4.03.03 - Ensure server parameter &apos;log_connections&apos; is set to &apos;ON&apos; for PostgreSQL Database Server
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.03 PostgreSQL Database Server &gt; 4.03.04 - Ensure Server Parameter &apos;log_disconnections&apos; is set to &apos;ON&apos; for PostgreSQL Database Server
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.03 PostgreSQL Database Server &gt; 4.03.05 - Ensure Server Parameter &apos;connection_throttling&apos; is set to &apos;ON&apos; for PostgreSQL Database Server
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.03 PostgreSQL Database Server &gt; 4.03.06 - Ensure Server Parameter &apos;log_retention_days&apos; is greater than 3 days for PostgreSQL Database Server
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.03 PostgreSQL Database Server &gt; 4.03.07 - Ensure &apos;Allow access to Azure services&apos; for PostgreSQL Database Server is disabled
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.03 PostgreSQL Database Server &gt; 4.03.08 - Ensure &apos;Infrastructure double encryption&apos; for PostgreSQL Database Server is &apos;Enabled&apos;
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.04 - MySQL Database
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.04 - MySQL Database &gt; 4.04.01 - Ensure &apos;Enforce SSL connection&apos; is set to &apos;Enabled&apos; for Standard MySQL Database Server
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.04 - MySQL Database &gt; 4.04.02 - Ensure &apos;TLS Version&apos; is set to &apos;TLSV1.2&apos; for MySQL flexible Database Server
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.04 - MySQL Database &gt; 4.04.03 - Ensure server parameter &apos;audit_log_enabled&apos; is set to &apos;ON&apos; for MySQL Database Server
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.04 - MySQL Database &gt; 4.04.04 - Ensure server parameter &apos;audit_log_events&apos; has &apos;CONNECTION&apos; set for MySQL Database Server
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.05 - Cosmos DB
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.05 - Cosmos DB &gt; 4.05.01 - Ensure That &apos;Firewalls &amp; Networks&apos; Is Limited to Use Selected Networks Instead of All Networks
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.05 - Cosmos DB &gt; 4.05.02 - Ensure That Private Endpoints Are Used Where Possible
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.05 - Cosmos DB &gt; 4.05.03 - Use Azure Active Directory (AAD) Client Authentication and Azure RBAC where possible
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; 4.05 - Cosmos DB &gt; 4.05.03 - Use Azure Active Directory (AAD) Client Authentication and Azure RBAC where possible &gt; Attestation
- Azure &gt; CIS v2.0 &gt; 04 - Database Services &gt; Maximum Attestation Duration
- Azure &gt; CIS v2.0 &gt; 05 - Logging and Monitoring
- Azure &gt; CIS v2.0 &gt; 05 - Logging and Monitoring &gt; 5.01 - Configuring Diagnostic Settings
- Azure &gt; CIS v2.0 &gt; 05 - Logging and Monitoring &gt; 5.01 - Configuring Diagnostic Settings &gt; 5.01.03 - Ensure the Storage Container Storing the Activity Logs is not Publicly Accessible
- Azure &gt; CIS v2.0 &gt; 05 - Logging and Monitoring &gt; 5.01 - Configuring Diagnostic Settings &gt; 5.01.04 - Ensure the storage account containing the container with activity logs is encrypted with Customer Managed Key
- Azure &gt; CIS v2.0 &gt; 05 - Logging and Monitoring &gt; 5.01 - Configuring Diagnostic Settings &gt; 5.01.05 - Ensure that logging for Azure Key Vault is &apos;Enabled&apos;
- Azure &gt; CIS v2.0 &gt; 05 - Logging and Monitoring &gt; 5.01 - Configuring Diagnostic Settings &gt; 5.01.07 - Ensure that logging for Azure AppService &apos;HTTP logs&apos; is enabled
- Azure &gt; CIS v2.0 &gt; 05 - Logging and Monitoring &gt; 5.02 - Monitoring using Activity Log Alerts
- Azure &gt; CIS v2.0 &gt; 05 - Logging and Monitoring &gt; 5.02 - Monitoring using Activity Log Alerts &gt; 5.02.01 - Ensure that Activity Log Alert exists for Create Policy Assignment
- Azure &gt; CIS v2.0 &gt; 05 - Logging and Monitoring &gt; 5.02 - Monitoring using Activity Log Alerts &gt; 5.02.02 - Ensure that Activity Log Alert exists for Delete Policy Assignment
- Azure &gt; CIS v2.0 &gt; 05 - Logging and Monitoring &gt; 5.02 - Monitoring using Activity Log Alerts &gt; 5.02.03 - Ensure that Activity Log Alert exists for Create or Update Network Security Group
- Azure &gt; CIS v2.0 &gt; 05 - Logging and Monitoring &gt; 5.02 - Monitoring using Activity Log Alerts &gt; 5.02.04 - Ensure that Activity Log Alert exists for Delete Network Security Group
- Azure &gt; CIS v2.0 &gt; 05 - Logging and Monitoring &gt; 5.02 - Monitoring using Activity Log Alerts &gt; 5.02.05 - Ensure that Activity Log Alert exists for Create or Update Security Solution
- Azure &gt; CIS v2.0 &gt; 05 - Logging and Monitoring &gt; 5.02 - Monitoring using Activity Log Alerts &gt; 5.02.06 - Ensure that Activity Log Alert exists for Delete Security Solution
- Azure &gt; CIS v2.0 &gt; 05 - Logging and Monitoring &gt; 5.02 - Monitoring using Activity Log Alerts &gt; 5.02.07 - Ensure that Activity Log Alert exists for Create or Update SQL Server Firewall Rule
- Azure &gt; CIS v2.0 &gt; 05 - Logging and Monitoring &gt; 5.02 - Monitoring using Activity Log Alerts &gt; 5.02.08 - Ensure that Activity Log Alert exists for Delete SQL Server Firewall Rule
- Azure &gt; CIS v2.0 &gt; 05 - Logging and Monitoring &gt; 5.02 - Monitoring using Activity Log Alerts &gt; 5.02.09 - Ensure that Activity Log Alert exists for Create or Update Public IP Address rule
- Azure &gt; CIS v2.0 &gt; 05 - Logging and Monitoring &gt; 5.02 - Monitoring using Activity Log Alerts &gt; 5.02.10 - Ensure that Activity Log Alert exists for Delete Public IP Address rule
- Azure &gt; CIS v2.0 &gt; 05 - Logging and Monitoring &gt; 5.03 - Configuring Application Insights
- Azure &gt; CIS v2.0 &gt; 05 - Logging and Monitoring &gt; 5.03 - Configuring Application Insights &gt; 5.03.01 - Ensure Application Insights are Configured
- Azure &gt; CIS v2.0 &gt; 05 - Logging and Monitoring &gt; 5.04 - Ensure that Azure Monitor Resource Logging is Enabled for All Services that Support it
- Azure &gt; CIS v2.0 &gt; 05 - Logging and Monitoring &gt; 5.04 - Ensure that Azure Monitor Resource Logging is Enabled for All Services that Support it &gt; Attestation
- Azure &gt; CIS v2.0 &gt; 05 - Logging and Monitoring &gt; 5.05 - Ensure that SKU Basic/Consumption is not used on artifacts that need to be monitored (Particularly for Production Workloads)
- Azure &gt; CIS v2.0 &gt; 05 - Logging and Monitoring &gt; Maximum Attestation Duration
- Azure &gt; CIS v2.0 &gt; 06 - Networking
- Azure &gt; CIS v2.0 &gt; 06 - Networking &gt; 6.01 - Ensure that RDP access from the Internet is evaluated and restricted
- Azure &gt; CIS v2.0 &gt; 06 - Networking &gt; 6.02 - Ensure that SSH access from the Internet is evaluated and restricted
- Azure &gt; CIS v2.0 &gt; 06 - Networking &gt; 6.03 - Ensure that UDP access from the Internet is evaluated and restricted
- Azure &gt; CIS v2.0 &gt; 06 - Networking &gt; 6.04 - Ensure that HTTP(S) access from the Internet is evaluated and restricted
- Azure &gt; CIS v2.0 &gt; 06 - Networking &gt; 6.05 - Ensure that Network Security Group Flow Log retention period is &apos;greater than 90 days&apos;
- Azure &gt; CIS v2.0 &gt; 06 - Networking &gt; 6.06 - Ensure that Network Watcher is &apos;Enabled&apos;
- Azure &gt; CIS v2.0 &gt; 06 - Networking &gt; 6.07 - Ensure that Public IP addresses are Evaluated on a Periodic Basis
- Azure &gt; CIS v2.0 &gt; 06 - Networking &gt; 6.07 - Ensure that Public IP addresses are Evaluated on a Periodic Basis &gt; Attestation
- Azure &gt; CIS v2.0 &gt; 06 - Networking &gt; Maximum Attestation Duration
- Azure &gt; CIS v2.0 &gt; 07 - Virtual Machines
- Azure &gt; CIS v2.0 &gt; 07 - Virtual Machines &gt; 7.02 - Ensure Virtual Machines are utilizing Managed Disks
- Azure &gt; CIS v2.0 &gt; 07 - Virtual Machines &gt; 7.03 - Ensure that &apos;OS and Data&apos; disks are encrypted with Customer Managed Key (CMK)
- Azure &gt; CIS v2.0 &gt; 07 - Virtual Machines &gt; 7.04 - Ensure that &apos;Unattached disks&apos; are encrypted with &apos;Customer Managed Key&apos; (CMK)
- Azure &gt; CIS v2.0 &gt; 07 - Virtual Machines &gt; 7.05 - Ensure that Only Approved Extensions Are Installed
- Azure &gt; CIS v2.0 &gt; 07 - Virtual Machines &gt; 7.05 - Ensure that Only Approved Extensions Are Installed &gt; Attestation
- Azure &gt; CIS v2.0 &gt; 07 - Virtual Machines &gt; 7.06 - Ensure that Endpoint Protection for all Virtual Machines is installed
- Azure &gt; CIS v2.0 &gt; 07 - Virtual Machines &gt; 7.06 - Ensure that Endpoint Protection for all Virtual Machines is installed &gt; Attestation
- Azure &gt; CIS v2.0 &gt; 07 - Virtual Machines &gt; 7.07 - [Legacy] Ensure that VHDs are Encrypted
- Azure &gt; CIS v2.0 &gt; 07 - Virtual Machines &gt; 7.07 - [Legacy] Ensure that VHDs are Encrypted &gt; Attestation
- Azure &gt; CIS v2.0 &gt; 07 - Virtual Machines &gt; Maximum Attestation Duration
- Azure &gt; CIS v2.0 &gt; 08 - Key Vault
- Azure &gt; CIS v2.0 &gt; 08 - Key Vault &gt; 8.01 - Ensure that the Expiration Date is set for all Keys in RBAC Key Vaults
- Azure &gt; CIS v2.0 &gt; 08 - Key Vault &gt; 8.02 - Ensure that the Expiration Date is set for all Keys in Non-RBAC Key Vaults
- Azure &gt; CIS v2.0 &gt; 08 - Key Vault &gt; 8.03 - Ensure that the Expiration Date is set for all Secrets in RBAC Key Vaults
- Azure &gt; CIS v2.0 &gt; 08 - Key Vault &gt; 8.04 - Ensure that the Expiration Date is set for all Secrets in Non-RBAC Key Vaults
- Azure &gt; CIS v2.0 &gt; 08 - Key Vault &gt; 8.05 - Ensure the key vault is recoverable
- Azure &gt; CIS v2.0 &gt; 08 - Key Vault &gt; 8.06 - Ensure Role Based Access Control for Azure Key Vault
- Azure &gt; CIS v2.0 &gt; 08 - Key Vault &gt; 8.07 - Ensure that Private Endpoints are Used for Azure Key Vault
- Azure &gt; CIS v2.0 &gt; 08 - Key Vault &gt; 8.08 - Ensure Automatic Key Rotation is Enabled Within Azure Key Vault for the Supported Services
- Azure &gt; CIS v2.0 &gt; 08 - Key Vault &gt; 8.08 - Ensure Automatic Key Rotation is Enabled Within Azure Key Vault for the Supported Services &gt; Attestation
- Azure &gt; CIS v2.0 &gt; 08 - Key Vault &gt; Maximum Attestation Duration
- Azure &gt; CIS v2.0 &gt; 09 - Application Services
- Azure &gt; CIS v2.0 &gt; 09 - Application Services &gt; 9.01 - Ensure App Service Authentication is set up for apps in Azure App Service
- Azure &gt; CIS v2.0 &gt; 09 - Application Services &gt; 9.02 - Ensure Web App Redirects All HTTP traffic to HTTPS in Azure App Service
- Azure &gt; CIS v2.0 &gt; 09 - Application Services &gt; 9.03 - Ensure Web App is using the latest version of TLS encryption
- Azure &gt; CIS v2.0 &gt; 09 - Application Services &gt; 9.04 - Ensure the web app has &apos;Client Certificates (Incoming client certificates)&apos; set to &apos;On&apos;
- Azure &gt; CIS v2.0 &gt; 09 - Application Services &gt; 9.05 - Ensure that Register with Azure Active Directory is enabled on App Service
- Azure &gt; CIS v2.0 &gt; 09 - Application Services &gt; 9.06 - Ensure That &apos;PHP version&apos; is the Latest, If Used to Run the Web App
- Azure &gt; CIS v2.0 &gt; 09 - Application Services &gt; 9.06 - Ensure That &apos;PHP version&apos; is the Latest, If Used to Run the Web App &gt; Attestation
- Azure &gt; CIS v2.0 &gt; 09 - Application Services &gt; 9.07 - Ensure that &apos;Python version&apos; is the Latest Stable Version, if Used to Run the Web App
- Azure &gt; CIS v2.0 &gt; 09 - Application Services &gt; 9.07 - Ensure that &apos;Python version&apos; is the Latest Stable Version, if Used to Run the Web App &gt; Attestation
- Azure &gt; CIS v2.0 &gt; 09 - Application Services &gt; 9.08 - Ensure that &apos;Java version&apos; is the latest, if used to run the Web App
- Azure &gt; CIS v2.0 &gt; 09 - Application Services &gt; 9.08 - Ensure that &apos;Java version&apos; is the latest, if used to run the Web App &gt; Attestation
- Azure &gt; CIS v2.0 &gt; 09 - Application Services &gt; 9.09 - Ensure that &apos;HTTP Version&apos; is the Latest, if Used to Run the Web App
- Azure &gt; CIS v2.0 &gt; 09 - Application Services &gt; 9.10 - Ensure FTP deployments are Disabled
- Azure &gt; CIS v2.0 &gt; 09 - Application Services &gt; 9.11 - Ensure Azure Key Vaults are Used to Store Secrets
- Azure &gt; CIS v2.0 &gt; 09 - Application Services &gt; 9.11 - Ensure Azure Key Vaults are Used to Store Secrets &gt; Attestation
- Azure &gt; CIS v2.0 &gt; 09 - Application Services &gt; Maximum Attestation Duration
- Azure &gt; CIS v2.0 &gt; 10 - Miscellaneous
- Azure &gt; CIS v2.0 &gt; 10 - Miscellaneous &gt; 10.01 - Ensure that Resource Locks are set for Mission-Critical Azure Resources
- Azure &gt; CIS v2.0 &gt; 10 - Miscellaneous &gt; 10.01 - Ensure that Resource Locks are set for Mission-Critical Azure Resources &gt; Attestation
- Azure &gt; CIS v2.0 &gt; 10 - Miscellaneous &gt; Maximum Attestation Duration
- Azure &gt; CIS v2.0 &gt; Maximum Attestation Duration</description>
            <pubDate>Wed, 24 Apr 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-42-23</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.42.23 - Refined management of various processes to improve stability and reduce backlog issues</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-42-23</link>
            <description>_What&apos;s new?_

- Server
  - Implemented monitoring for `worker_factory` in the CloudWatch Dashboard widgets &quot;Events Queue Activity&quot; and &quot;Events Queue Backlog&quot;.
  - Established a CloudWatch Alarm for the `_worker_factory` queue.
  - Product, Vendor Tags to the IAM Role resources created by the TE stack.
  - Adjusted the threshold for the CloudWatch Alarm monitoring the `_worker` queue.

_Bug fixes_

- Server
  - Now, users with only Turbot/User access will no longer see grants or active grants belonging to other users. This ensures that you only view grants that are relevant to your permissions.
  - Control will move to error if it fails to determine the state at precheck.
  - System resilience has been enhanced through extended TTL settings and refined management of suspended processes, aiming to improve stability and reduce backlog issues.
  - Refined management of various processes to improve stability and reduce backlog issues.

- UI
  - Converted the `template_input` property of the policy setting in the Terraform plan to YAML format, improving clarity and manageability.


_Requirements_

- TEF: 1.57.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Tue, 23 Apr 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/turbot-v5-43-1</guid>
            <title>turbot v5.43.1 - Process Monitor control will now run in priority queue</title>
            <link>https://turbot.com/guardrails/changelog/turbot-v5-43-1</link>
            <description>_What&apos;s new?_

  - Moved the `Turbot &gt; Process Monitor` control to operate within the priority queue, ensuring more timely and efficient processing of critical tasks.
  - Updated the `Turbot &gt; Workspace &gt; Background Tasks` control to modify the next_tick_timestamp for any policy values that previously had incorrect defaults.</description>
            <pubDate>Tue, 23 Apr 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-cosmosdb-v5-5-1</guid>
            <title>azure-cosmosdb v5.5.1 - Minor fixes and improvements</title>
            <link>https://turbot.com/guardrails/changelog/azure-cosmosdb-v5-5-1</link>
            <description>_Bug fixes_

- Minor fixes and improvements.</description>
            <pubDate>Tue, 23 Apr 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-storage-v5-17-0</guid>
            <title>azure-storage v5.17.0 - Configure rotation reminders for access keys and soft delete for blobs and containers in storage accounts</title>
            <link>https://turbot.com/guardrails/changelog/azure-storage-v5-17-0</link>
            <description>_What&apos;s new?_

- You can now configure rotation reminders for access keys and soft delete for blobs and containers in storage accounts. To get started, set the `Azure &gt; Storage &gt; Storage Account &gt; Access Keys &gt; Rotation Reminder &gt; *` and `Azure &gt; Storage &gt; Storage Account &gt; Data Protection &gt; Soft Delete &gt; *` policies respectively.

_Control Types_

- Azure &gt; Storage &gt; Storage Account &gt; Access Keys
- Azure &gt; Storage &gt; Storage Account &gt; Access Keys &gt; Rotation Reminder
- Azure &gt; Storage &gt; Storage Account &gt; Data Protection
- Azure &gt; Storage &gt; Storage Account &gt; Data Protection &gt; Soft Delete

_Policy Types_

- Azure &gt; Storage &gt; Storage Account &gt; Access Keys
- Azure &gt; Storage &gt; Storage Account &gt; Access Keys &gt; Rotation Reminder
- Azure &gt; Storage &gt; Storage Account &gt; Access Keys &gt; Rotation Reminder &gt; Days
- Azure &gt; Storage &gt; Storage Account &gt; Data Protection
- Azure &gt; Storage &gt; Storage Account &gt; Data Protection &gt; Soft Delete
- Azure &gt; Storage &gt; Storage Account &gt; Data Protection &gt; Soft Delete &gt; Blobs
- Azure &gt; Storage &gt; Storage Account &gt; Data Protection &gt; Soft Delete &gt; Blobs &gt; Retention Days
- Azure &gt; Storage &gt; Storage Account &gt; Data Protection &gt; Soft Delete &gt; Containers
- Azure &gt; Storage &gt; Storage Account &gt; Data Protection &gt; Soft Delete &gt; Containers &gt; Retention Days

_Action Types_

- Azure &gt; Storage &gt; Storage Account &gt; Set Data Protection Soft Delete
- Azure &gt; Storage &gt; Storage Account &gt; Update Rotation Reminder</description>
            <pubDate>Mon, 22 Apr 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-sql-v5-14-0</guid>
            <title>azure-sql v5.14.0 - Remove unapproved firewall IP Ranges on SQL servers</title>
            <link>https://turbot.com/guardrails/changelog/azure-sql-v5-14-0</link>
            <description>_What&apos;s new?_

- You can now removed unapproved Firewall IP Ranges on SQL servers. To get started, set the `Azure &gt; SQL &gt; Server &gt; Firewall &gt; IP Ranges &gt; Approved &gt; *` policies.

_Control Types_

- Azure &gt; SQL &gt; Server &gt; Firewall
- Azure &gt; SQL &gt; Server &gt; Firewall &gt; IP Ranges
- Azure &gt; SQL &gt; Server &gt; Firewall &gt; IP Ranges &gt; Approved

_Policy Types_

- Azure &gt; SQL &gt; Server &gt; Firewall
- Azure &gt; SQL &gt; Server &gt; Firewall &gt; IP Ranges
- Azure &gt; SQL &gt; Server &gt; Firewall &gt; IP Ranges &gt; Approved
- Azure &gt; SQL &gt; Server &gt; Firewall &gt; IP Ranges &gt; Approved &gt; Compiled Rules
- Azure &gt; SQL &gt; Server &gt; Firewall &gt; IP Ranges &gt; Approved &gt; IP Addresses
- Azure &gt; SQL &gt; Server &gt; Firewall &gt; IP Ranges &gt; Approved &gt; Rules

_Action Types_

- Azure &gt; SQL &gt; Server &gt; Update Firewall IP Ranges</description>
            <pubDate>Mon, 22 Apr 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-kms-v5-8-2</guid>
            <title>gcp-kms v5.8.2 - Bug fixed - Rotation policy attributes for Crypto Keys did not update correctly in CMDB when the rotation policy was removed from such keys</title>
            <link>https://turbot.com/guardrails/changelog/gcp-kms-v5-8-2</link>
            <description>_Bug fixes_

- The `rotationPeriod` and `nextRotationTime` attributes for Crypto Keys did not update correctly in CMDB when the rotation policy for such keys was removed. This is now fixed.</description>
            <pubDate>Fri, 19 Apr 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-mysql-v5-10-0</guid>
            <title>azure-mysql v5.10.0 - Configure Encryption in Transit for Flexi Servers</title>
            <link>https://turbot.com/guardrails/changelog/azure-mysql-v5-10-0</link>
            <description>_What&apos;s new?_

- You can now configure Encryption in Transit for Flexi Servers. To get started, set the `Azure &gt; MySQL &gt; Flexible Server &gt; Encryption in Transit &gt; *` policies.
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

_Control Types_

- Azure &gt; MySQL &gt; Flexible Server &gt; Encryption in Transit

_Policy Types_

- Azure &gt; MySQL &gt; Flexible Server &gt; Encryption in Transit

_Action Types_

- Azure &gt; MySQL &gt; Flexible Server &gt; Update Encryption in Transit</description>
            <pubDate>Fri, 19 Apr 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-appservice-v5-9-0</guid>
            <title>azure-appservice v5.9.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/azure-appservice-v5-9-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

_Policy Types_

- Azure &gt; App Service &gt; App Service Plan &gt; Approved &gt; Custom
- Azure &gt; App Service &gt; Function App &gt; Approved &gt; Custom
- Azure &gt; App Service &gt; Web App &gt; Approved &gt; Custom</description>
            <pubDate>Fri, 19 Apr 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-vpc-security-v5-9-8</guid>
            <title>aws-vpc-security v5.9.8 - Bug fixed - Configured control for flow logs would sometimes go into an error state for flow logs claimed by a Guardrails stack</title>
            <link>https://turbot.com/guardrails/changelog/aws-vpc-security-v5-9-8</link>
            <description>_Bug fixes_

- The `AWS &gt; VPC &gt; Flow Log &gt; Configured` control would sometimes go into an error state for flow logs created via the AWS console, even though they were correctly claimed by a Guardrails stack. This is now fixed.</description>
            <pubDate>Fri, 19 Apr 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-postgresql-v5-14-0</guid>
            <title>azure-postgresql v5.14.0 - Configure log checkpoints for Flexi Servers</title>
            <link>https://turbot.com/guardrails/changelog/azure-postgresql-v5-14-0</link>
            <description>_What&apos;s new?_

- You can now configure log checkpoints for Flexi Servers. To get started, set the `Azure &gt; PostgreSQL &gt; Flexible Server &gt; Audit Logging &gt; *` policies.
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

_Control Types_

- Azure &gt; PostgreSQL &gt; Flexible Server &gt; Audit Logging

_Policy Types_

- Azure &gt; PostgreSQL &gt; Flexible Server &gt; Audit Logging
- Azure &gt; PostgreSQL &gt; Flexible Server &gt; Audit Logging &gt; Log Checkpoints

_Action Types_

- Azure &gt; PostgreSQL &gt; Flexible Server &gt; Update Audit Logging</description>
            <pubDate>Wed, 17 Apr 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-keyvault-v5-13-0</guid>
            <title>azure-keyvault v5.13.0 - Configure expiration for Key Vault Keys and Secrets</title>
            <link>https://turbot.com/guardrails/changelog/azure-keyvault-v5-13-0</link>
            <description>_What&apos;s new?_

- You can now configure expiration for Key Vault Keys and Secrets. To get started, set the `Azure &gt; Key Vault &gt; Key &gt; Expiration &gt; *` and `Azure &gt; Key Vault &gt; Secret &gt; Expiration &gt; *` policies respectively.

_Control Types_

- Azure &gt; Key Vault &gt; Key &gt; Expiration
- Azure &gt; Key Vault &gt; Secret &gt; Expiration

_Policy Types_

- Azure &gt; Key Vault &gt; Key &gt; Expiration
- Azure &gt; Key Vault &gt; Key &gt; Expiration &gt; Days [Default]
- Azure &gt; Key Vault &gt; Secret &gt; Expiration
- Azure &gt; Key Vault &gt; Secret &gt; Expiration &gt; Days [Default]

_Action Types_

- Azure &gt; Key Vault &gt; Key &gt; Set Expiration
- Azure &gt; Key Vault &gt; Secret &gt; Set Expiration</description>
            <pubDate>Wed, 17 Apr 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-directconnect-v5-4-0</guid>
            <title>aws-directconnect v5.4.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-directconnect-v5-4-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.</description>
            <pubDate>Wed, 17 Apr 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-xray-v5-4-0</guid>
            <title>aws-xray v5.4.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-xray-v5-4-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.</description>
            <pubDate>Tue, 16 Apr 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-storage-v5-16-1</guid>
            <title>azure-storage v5.16.1 - Storage Account Queue Logging control would go into a skipped state for storage accounts, irrespective of any policy setting</title>
            <link>https://turbot.com/guardrails/changelog/azure-storage-v5-16-1</link>
            <description>_Bug fixes_

- The `Azure &gt; Storage &gt; Storage Account &gt; Queue &gt; Logging` control would go into a skipped state for storage accounts, irrespective of any policy setting for Logging. This issue is fixed and the control will now work as expected.</description>
            <pubDate>Fri, 12 Apr 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-network-v5-16-0</guid>
            <title>azure-network v5.16.0 - Delete existing Public IP Addresses which are unapproved for use in the Subscription</title>
            <link>https://turbot.com/guardrails/changelog/azure-network-v5-16-0</link>
            <description>_What&apos;s new?_

- You can now delete existing Public IP Addresses which are unapproved for use in the Subscription. To get started, set the `Azure &gt; Network &gt; Public IP Address &gt; Approved` policy to `Enforce: Delete unapproved`.</description>
            <pubDate>Thu, 11 Apr 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/turbot-iam-v5-12-2</guid>
            <title>turbot-iam v5.12.2 - The Account compiled policy now correctly checks the workspace version</title>
            <link>https://turbot.com/guardrails/changelog/turbot-iam-v5-12-2</link>
            <description>_Bug fixes_

-  The `Turbot &gt; IAM &gt; Permissions &gt; Compiled &gt; Levels &gt; Account` policy now correctly checks the workspace version if it&apos;s installed on a workspace version &lt; 5.50.0.</description>
            <pubDate>Wed, 10 Apr 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-postgresql-v5-13-0</guid>
            <title>azure-postgresql v5.13.0 - Configure Encryption in Transit for Flexi Servers</title>
            <link>https://turbot.com/guardrails/changelog/azure-postgresql-v5-13-0</link>
            <description>_What&apos;s new?_

- You can now configure Encryption in Transit for Flexi Servers. To get started, set the `Azure &gt; PostgresSql &gt; Flexible Server &gt; Encryption in Transit &gt; *` policies.

_Control Types_
- Azure &gt; PostgreSQL &gt; Flexible Server &gt; Encryption in Transit

_Policy Types_
- Azure &gt; PostgreSQL &gt; Flexible Server &gt; Encryption in Transit

_Action Types_
- Azure &gt; PostgreSQL &gt; Flexible Server &gt; Update Encryption in Transit</description>
            <pubDate>Wed, 10 Apr 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-activedirectory-v5-5-0</guid>
            <title>azure-activedirectory v5.5.0 - Delete existing Entra ID users which are unapproved to be used in the Tenant</title>
            <link>https://turbot.com/guardrails/changelog/azure-activedirectory-v5-5-0</link>
            <description>_What&apos;s new?_

- You can now delete existing Entra ID users which are unapproved to be used in the Tenant. To get started, set the `Azure &gt; Active Directory &gt; User &gt; Approved` policy to `Enforce: Delete unapproved`.

_Policy Types_

- Azure &gt; Active Directory &gt; User &gt; Approved &gt; Custom</description>
            <pubDate>Tue, 09 Apr 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-mysql-v5-9-0</guid>
            <title>azure-mysql v5.9.0 - Configure TLS version for Flexi Servers</title>
            <link>https://turbot.com/guardrails/changelog/azure-mysql-v5-9-0</link>
            <description>_What&apos;s new?_

- You can now configure TLS version for Flexi Servers. To get started, set the `Azure &gt; MySQL &gt; Flexible Server &gt; Minimum TLS Version &gt; *` policies.</description>
            <pubDate>Mon, 08 Apr 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/turbot-iam-v5-12-1</guid>
            <title>turbot-iam v5.12.1 - Removed `Account/User` and `Account/Metadata` levels from the default Account &gt; Permission policy</title>
            <link>https://turbot.com/guardrails/changelog/turbot-iam-v5-12-1</link>
            <description>_Bug fixes_

- Removed `Account/User` and `Account/Metadata` levels from the default Account &gt; Permission policy</description>
            <pubDate>Fri, 05 Apr 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/ted-v1-41-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.41.0 - Added support for Postgres versions 11.21 and 11.22</title>
            <link>https://turbot.com/guardrails/changelog/ted-v1-41-0</link>
            <description>_What&apos;s new?_

- Added: Support for Postgres versions 11.21 and 11.22.</description>
            <pubDate>Fri, 05 Apr 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-v5-30-0</guid>
            <title>aws v5.30.0 - Account CMDB data will now also include alternate security contact details</title>
            <link>https://turbot.com/guardrails/changelog/aws-v5-30-0</link>
            <description>_What&apos;s new?_

- Account CMDB data will now also include alternate security contact details.</description>
            <pubDate>Fri, 05 Apr 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-cisv2-0-v5-0-0</guid>
            <title>aws-cisv2-0 v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/aws-cisv2-0-v5-0-0</link>
            <description>_What&apos;s new?_

_Control Types_

- AWS &gt; CIS v2.0
- AWS &gt; CIS v2.0 &gt; 1 - Identity and Access Management
- AWS &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.01 - Maintain current contact details
- AWS &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.02 - Ensure security contact information is registered
- AWS &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.03 - Ensure security questions are registered in the AWS account
- AWS &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.04 - Ensure no &apos;root&apos; user account access key exists
- AWS &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.05 - Ensure MFA is enabled for the &apos;root&apos; user account
- AWS &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.06 - Ensure hardware MFA is enabled for the &apos;root&apos; user account
- AWS &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.07 - Eliminate use of the &apos;root&apos; user for administrative and daily tasks
- AWS &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.08 - Ensure IAM password policy requires minimum length of 14 or greater
- AWS &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.09 - Ensure IAM password policy prevents password reuse
- AWS &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.10 - Ensure multi-factor authentication (MFA) is enabled for all IAM users that have a console password
- AWS &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.11 - Do not setup access keys during initial user setup for all IAM users that have a console password
- AWS &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.12 - Ensure credentials unused for 45 days or greater are disabled
- AWS &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.13 - Ensure there is only one active access key available for any single IAM user
- AWS &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.14 - Ensure access keys are rotated every 90 days or less
- AWS &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.15 - Ensure IAM Users Receive Permissions Only Through Groups
- AWS &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.16 - Ensure IAM policies that allow full &quot;_:_&quot; administrative privileges are not attached
- AWS &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.17 - Ensure a support role has been created to manage incidents with AWS Support
- AWS &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.18 - Ensure IAM instance roles are used for AWS resource access from instances
- AWS &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.19 - Ensure that all the expired SSL/TLS certificates stored in AWS IAM are removed
- AWS &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.20 - Ensure that IAM Access analyzer is enabled for all regions
- AWS &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.21 - Ensure IAM users are managed centrally via identity federation or AWS Organizations for multi-account environments
- AWS &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.22 - Ensure access to AWSCloudShellFullAccess is restricted
- AWS &gt; CIS v2.0 &gt; 2 - Storage
- AWS &gt; CIS v2.0 &gt; 2 - Storage &gt; 2.01 - Simple Storage Service (S3)
- AWS &gt; CIS v2.0 &gt; 2 - Storage &gt; 2.01 - Simple Storage Service (S3) &gt; 2.01.01 - Ensure S3 Bucket Policy is set to deny HTTP requests
- AWS &gt; CIS v2.0 &gt; 2 - Storage &gt; 2.01 - Simple Storage Service (S3) &gt; 2.01.02 - Ensure MFA Delete is enabled on S3 buckets
- AWS &gt; CIS v2.0 &gt; 2 - Storage &gt; 2.01 - Simple Storage Service (S3) &gt; 2.01.03 - Ensure all data in Amazon S3 has been discovered, classified and secured when required
- AWS &gt; CIS v2.0 &gt; 2 - Storage &gt; 2.01 - Simple Storage Service (S3) &gt; 2.01.04 - Ensure that S3 Buckets are configured with &apos;Block public access (bucket settings)&apos;
- AWS &gt; CIS v2.0 &gt; 2 - Storage &gt; 2.02 - Elastic Compute Cloud (EC2)
- AWS &gt; CIS v2.0 &gt; 2 - Storage &gt; 2.02 - Elastic Compute Cloud (EC2) &gt; 2.02.01 - Ensure EBS Volume Encryption is Enabled in all Regions
- AWS &gt; CIS v2.0 &gt; 2 - Storage &gt; 2.03 - Relational Database Service (RDS)
- AWS &gt; CIS v2.0 &gt; 2 - Storage &gt; 2.03 - Relational Database Service (RDS) &gt; 2.03.01 - Ensure that encryption-at-rest is enabled for RDS Instances
- AWS &gt; CIS v2.0 &gt; 2 - Storage &gt; 2.03 - Relational Database Service (RDS) &gt; 2.03.02 - Ensure Auto Minor Version Upgrade feature is Enabled for RDS Instances
- AWS &gt; CIS v2.0 &gt; 2 - Storage &gt; 2.03 - Relational Database Service (RDS) &gt; 2.03.03 - Ensure that public access is not given to RDS Instance
- AWS &gt; CIS v2.0 &gt; 2 - Storage &gt; 2.04 - Elastic File System (EFS)
- AWS &gt; CIS v2.0 &gt; 2 - Storage &gt; 2.04 - Elastic File System (EFS) &gt; 2.04.01 - Ensure that encryption is enabled for EFS file systems
- AWS &gt; CIS v2.0 &gt; 3 - Logging
- AWS &gt; CIS v2.0 &gt; 3 - Logging &gt; 3.01 - Ensure CloudTrail is enabled in all regions
- AWS &gt; CIS v2.0 &gt; 3 - Logging &gt; 3.02 - Ensure CloudTrail log file validation is enabled
- AWS &gt; CIS v2.0 &gt; 3 - Logging &gt; 3.03 - Ensure the S3 bucket used to store CloudTrail logs is not publicly accessible
- AWS &gt; CIS v2.0 &gt; 3 - Logging &gt; 3.04 - Ensure CloudTrail trails are integrated with CloudWatch Logs
- AWS &gt; CIS v2.0 &gt; 3 - Logging &gt; 3.05 - Ensure AWS Config is enabled in all regions
- AWS &gt; CIS v2.0 &gt; 3 - Logging &gt; 3.06 - Ensure S3 bucket access logging is enabled on the CloudTrail S3 bucket
- AWS &gt; CIS v2.0 &gt; 3 - Logging &gt; 3.07 - Ensure CloudTrail logs are encrypted at rest using KMS CMKs
- AWS &gt; CIS v2.0 &gt; 3 - Logging &gt; 3.08 - Ensure rotation for customer created symmetric CMKs is enabled
- AWS &gt; CIS v2.0 &gt; 3 - Logging &gt; 3.09 - Ensure VPC flow logging is enabled in all VPCs
- AWS &gt; CIS v2.0 &gt; 3 - Logging &gt; 3.10 - Ensure that Object-level logging for write events is enabled for S3 bucket
- AWS &gt; CIS v2.0 &gt; 3 - Logging &gt; 3.11 - Ensure that Object-level logging for read events is enabled for S3 bucket
- AWS &gt; CIS v2.0 &gt; 4 - Monitoring
- AWS &gt; CIS v2.0 &gt; 4 - Monitoring &gt; 4.01 - Ensure unauthorized API calls are monitored
- AWS &gt; CIS v2.0 &gt; 4 - Monitoring &gt; 4.02 - Ensure management console sign-in without MFA is monitored
- AWS &gt; CIS v2.0 &gt; 4 - Monitoring &gt; 4.03 - Ensure usage of &apos;root&apos; account is monitored
- AWS &gt; CIS v2.0 &gt; 4 - Monitoring &gt; 4.04 - Ensure IAM policy changes are monitored
- AWS &gt; CIS v2.0 &gt; 4 - Monitoring &gt; 4.05 - Ensure CloudTrail configuration changes are monitored
- AWS &gt; CIS v2.0 &gt; 4 - Monitoring &gt; 4.06 - Ensure AWS Management Console authentication failures are monitored
- AWS &gt; CIS v2.0 &gt; 4 - Monitoring &gt; 4.07 - Ensure disabling or scheduled deletion of customer created CMKs is monitored
- AWS &gt; CIS v2.0 &gt; 4 - Monitoring &gt; 4.08 - Ensure S3 bucket policy changes are monitored
- AWS &gt; CIS v2.0 &gt; 4 - Monitoring &gt; 4.09 - Ensure AWS Config configuration changes are monitored
- AWS &gt; CIS v2.0 &gt; 4 - Monitoring &gt; 4.10 - Ensure security group changes are monitored
- AWS &gt; CIS v2.0 &gt; 4 - Monitoring &gt; 4.11 - Ensure Network Access Control Lists (NACL) changes are monitored
- AWS &gt; CIS v2.0 &gt; 4 - Monitoring &gt; 4.12 - Ensure changes to network gateways are monitored
- AWS &gt; CIS v2.0 &gt; 4 - Monitoring &gt; 4.13 - Ensure route table changes are monitored
- AWS &gt; CIS v2.0 &gt; 4 - Monitoring &gt; 4.14 - Ensure VPC changes are monitored
- AWS &gt; CIS v2.0 &gt; 4 - Monitoring &gt; 4.15 - Ensure AWS Organizations changes are monitored
- AWS &gt; CIS v2.0 &gt; 4 - Monitoring &gt; 4.16 - Ensure AWS Security Hub is enabled
- AWS &gt; CIS v2.0 &gt; 5 - Networking
- AWS &gt; CIS v2.0 &gt; 5 - Networking &gt; 5.01 - Ensure no Network ACLs allow ingress from 0.0.0.0/0 to remote server administration ports
- AWS &gt; CIS v2.0 &gt; 5 - Networking &gt; 5.02 - Ensure no security groups allow ingress from 0.0.0.0/0 to remote server administration ports
- AWS &gt; CIS v2.0 &gt; 5 - Networking &gt; 5.03 - Ensure no security groups allow ingress from ::/0 to remote server administration ports
- AWS &gt; CIS v2.0 &gt; 5 - Networking &gt; 5.04 - Ensure the default security group of every VPC restricts all traffic
- AWS &gt; CIS v2.0 &gt; 5 - Networking &gt; 5.05 - Ensure routing tables for VPC peering are &apos;least access&apos;
- AWS &gt; CIS v2.0 &gt; 5 - Networking &gt; 5.06 - Ensure that EC2 Metadata Service only allows IMDSv2

_Policy Types_

- AWS &gt; CIS v2.0
- AWS &gt; CIS v2.0 &gt; 1 - Identity and Access Management
- AWS &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.01 - Maintain current contact details
- AWS &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.01 - Maintain current contact details &gt; Attestation
- AWS &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.02 - Ensure security contact information is registered
- AWS &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.03 - Ensure security questions are registered in the AWS account
- AWS &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.03 - Ensure security questions are registered in the AWS account &gt; Attestation
- AWS &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.04 - Ensure no &apos;root&apos; user account access key exists
- AWS &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.05 - Ensure MFA is enabled for the &apos;root&apos; user account
- AWS &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.06 - Ensure hardware MFA is enabled for the &apos;root&apos; user account
- AWS &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.07 - Eliminate use of the &apos;root&apos; user for administrative and daily tasks
- AWS &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.08 - Ensure IAM password policy requires minimum length of 14 or greater
- AWS &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.09 - Ensure IAM password policy prevents password reuse
- AWS &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.10 - Ensure multi-factor authentication (MFA) is enabled for all IAM users that have a console password
- AWS &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.11 - Do not setup access keys during initial user setup for all IAM users that have a console password
- AWS &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.12 - Ensure credentials unused for 45 days or greater are disabled
- AWS &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.13 - Ensure there is only one active access key available for any single IAM user
- AWS &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.14 - Ensure access keys are rotated every 90 days or less
- AWS &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.15 - Ensure IAM Users Receive Permissions Only Through Groups
- AWS &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.16 - Ensure IAM policies that allow full &quot;_:_&quot; administrative privileges are not attached
- AWS &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.17 - Ensure a support role has been created to manage incidents with AWS Support
- AWS &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.18 - Ensure IAM instance roles are used for AWS resource access from instances
- AWS &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.19 - Ensure that all the expired SSL/TLS certificates stored in AWS IAM are removed
- AWS &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.20 - Ensure that IAM Access analyzer is enabled for all regions
- AWS &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.21 - Ensure IAM users are managed centrally via identity federation or AWS Organizations for multi-account environments
- AWS &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.21 - Ensure IAM users are managed centrally via identity federation or AWS Organizations for multi-account environments &gt; Attestation
- AWS &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.22 - Ensure access to AWSCloudShellFullAccess is restricted
- AWS &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; 1.22 - Ensure access to AWSCloudShellFullAccess is restricted &gt; Attestation
- AWS &gt; CIS v2.0 &gt; 1 - Identity and Access Management &gt; Maximum Attestation Duration
- AWS &gt; CIS v2.0 &gt; 2 - Storage
- AWS &gt; CIS v2.0 &gt; 2 - Storage &gt; 2.01 - Simple Storage Service (S3)
- AWS &gt; CIS v2.0 &gt; 2 - Storage &gt; 2.01 - Simple Storage Service (S3) &gt; 2.01.01 - Ensure S3 Bucket Policy is set to deny HTTP requests
- AWS &gt; CIS v2.0 &gt; 2 - Storage &gt; 2.01 - Simple Storage Service (S3) &gt; 2.01.02 - Ensure MFA Delete is enable on S3 buckets
- AWS &gt; CIS v2.0 &gt; 2 - Storage &gt; 2.01 - Simple Storage Service (S3) &gt; 2.01.03 - Ensure all data in Amazon S3 has been discovered, classified and secured when required
- AWS &gt; CIS v2.0 &gt; 2 - Storage &gt; 2.01 - Simple Storage Service (S3) &gt; 2.01.03 - Ensure all data in Amazon S3 has been discovered, classified and secured when required &gt; Attestation
- AWS &gt; CIS v2.0 &gt; 2 - Storage &gt; 2.01 - Simple Storage Service (S3) &gt; 2.01.04 - Ensure that S3 Buckets are configured with &apos;Block public access (bucket settings)&apos;
- AWS &gt; CIS v2.0 &gt; 2 - Storage &gt; 2.02 - Elastic Compute Cloud (EC2)
- AWS &gt; CIS v2.0 &gt; 2 - Storage &gt; 2.02 - Elastic Compute Cloud (EC2) &gt; 2.02.01 - Ensure EBS Volume Encryption is Enabled in all Regions
- AWS &gt; CIS v2.0 &gt; 2 - Storage &gt; 2.03 - Relational Database Service (RDS)
- AWS &gt; CIS v2.0 &gt; 2 - Storage &gt; 2.03 - Relational Database Service (RDS) &gt; 2.03.01 - Ensure that encryption-at-rest is enabled for RDS Instances
- AWS &gt; CIS v2.0 &gt; 2 - Storage &gt; 2.03 - Relational Database Service (RDS) &gt; 2.03.02 - Ensure Auto Minor Version Upgrade feature is Enabled for RDS Instances
- AWS &gt; CIS v2.0 &gt; 2 - Storage &gt; 2.03 - Relational Database Service (RDS) &gt; 2.03.03 - Ensure that public access is not given to RDS Instance
- AWS &gt; CIS v2.0 &gt; 2 - Storage &gt; 2.04 - Elastic File System (EFS)
- AWS &gt; CIS v2.0 &gt; 2 - Storage &gt; 2.04 - Elastic File System (EFS) &gt; 2.04.01 - Ensure that encryption is enabled for EFS file systems
- AWS &gt; CIS v2.0 &gt; 2 - Storage &gt; Maximum Attestation Duration
- AWS &gt; CIS v2.0 &gt; 3 - Logging
- AWS &gt; CIS v2.0 &gt; 3 - Logging &gt; 3.01 - Ensure CloudTrail is enabled in all regions
- AWS &gt; CIS v2.0 &gt; 3 - Logging &gt; 3.02 - Ensure CloudTrail log file validation is enabled
- AWS &gt; CIS v2.0 &gt; 3 - Logging &gt; 3.03 - Ensure the S3 bucket used to store CloudTrail logs is not publicly accessible
- AWS &gt; CIS v2.0 &gt; 3 - Logging &gt; 3.04 - Ensure CloudTrail trails are integrated with CloudWatch Logs
- AWS &gt; CIS v2.0 &gt; 3 - Logging &gt; 3.05 - Ensure AWS Config is enabled in all regions
- AWS &gt; CIS v2.0 &gt; 3 - Logging &gt; 3.06 - Ensure S3 bucket access logging is enabled on the CloudTrail S3 bucket
- AWS &gt; CIS v2.0 &gt; 3 - Logging &gt; 3.07 - Ensure CloudTrail logs are encrypted at rest using KMS CMKs
- AWS &gt; CIS v2.0 &gt; 3 - Logging &gt; 3.08 - Ensure rotation for customer created symmetric CMKs is enabled
- AWS &gt; CIS v2.0 &gt; 3 - Logging &gt; 3.09 - Ensure VPC flow logging is enabled in all VPCs
- AWS &gt; CIS v2.0 &gt; 3 - Logging &gt; 3.10 - Ensure that Object-level logging for write events is enabled for S3 bucket
- AWS &gt; CIS v2.0 &gt; 3 - Logging &gt; 3.11 - Ensure that Object-level logging for read events is enabled for S3 bucket
- AWS &gt; CIS v2.0 &gt; 3 - Logging &gt; Maximum Attestation Duration
- AWS &gt; CIS v2.0 &gt; 4 - Monitoring
- AWS &gt; CIS v2.0 &gt; 4 - Monitoring &gt; 4.01 - Ensure unauthorized API calls are monitored
- AWS &gt; CIS v2.0 &gt; 4 - Monitoring &gt; 4.02 - Ensure management console sign-in without MFA is monitored
- AWS &gt; CIS v2.0 &gt; 4 - Monitoring &gt; 4.03 - Ensure usage of &apos;root&apos; account is monitored
- AWS &gt; CIS v2.0 &gt; 4 - Monitoring &gt; 4.04 - Ensure IAM policy changes are monitored
- AWS &gt; CIS v2.0 &gt; 4 - Monitoring &gt; 4.05 - Ensure CloudTrail configuration changes are monitored
- AWS &gt; CIS v2.0 &gt; 4 - Monitoring &gt; 4.06 - Ensure AWS Management Console authentication failures are monitored
- AWS &gt; CIS v2.0 &gt; 4 - Monitoring &gt; 4.07 - Ensure disabling or scheduled deletion of customer created CMKs is monitored
- AWS &gt; CIS v2.0 &gt; 4 - Monitoring &gt; 4.08 - Ensure S3 bucket policy changes are monitored
- AWS &gt; CIS v2.0 &gt; 4 - Monitoring &gt; 4.09 - Ensure AWS Config configuration changes are monitored
- AWS &gt; CIS v2.0 &gt; 4 - Monitoring &gt; 4.10 - Ensure security group changes are monitored
- AWS &gt; CIS v2.0 &gt; 4 - Monitoring &gt; 4.11 - Ensure Network Access Control Lists (NACL) changes are monitored
- AWS &gt; CIS v2.0 &gt; 4 - Monitoring &gt; 4.12 - Ensure changes to network gateways are monitored
- AWS &gt; CIS v2.0 &gt; 4 - Monitoring &gt; 4.13 - Ensure route table changes are monitored
- AWS &gt; CIS v2.0 &gt; 4 - Monitoring &gt; 4.14 - Ensure VPC changes are monitored
- AWS &gt; CIS v2.0 &gt; 4 - Monitoring &gt; 4.15 - Ensure AWS Organizations changes are monitored
- AWS &gt; CIS v2.0 &gt; 4 - Monitoring &gt; 4.16 - Ensure AWS Security Hub is enabled
- AWS &gt; CIS v2.0 &gt; 4 - Monitoring &gt; Maximum Attestation Duration
- AWS &gt; CIS v2.0 &gt; 5 - Networking
- AWS &gt; CIS v2.0 &gt; 5 - Networking &gt; 5.01 - Ensure no Network ACLs allow ingress from 0.0.0.0/0 to remote server administration ports
- AWS &gt; CIS v2.0 &gt; 5 - Networking &gt; 5.02 - Ensure no security groups allow ingress from 0.0.0.0/0 to remote server administration ports
- AWS &gt; CIS v2.0 &gt; 5 - Networking &gt; 5.03 - Ensure no security groups allow ingress from ::/0 to remote server administration ports
- AWS &gt; CIS v2.0 &gt; 5 - Networking &gt; 5.04 - Ensure the default security group of every VPC restricts all traffic
- AWS &gt; CIS v2.0 &gt; 5 - Networking &gt; 5.05 - Ensure routing tables for VPC peering are &apos;least access&apos;
- AWS &gt; CIS v2.0 &gt; 5 - Networking &gt; 5.05 - Ensure routing tables for VPC peering are &apos;least access&apos; &gt; Attestation
- AWS &gt; CIS v2.0 &gt; 5 - Networking &gt; 5.06 - Ensure that EC2 Metadata Service only allows IMDSv2
- AWS &gt; CIS v2.0 &gt; 5 - Networking &gt; Maximum Attestation Duration
- AWS &gt; CIS v2.0 &gt; Maximum Attestation Duration</description>
            <pubDate>Fri, 05 Apr 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-sql-v5-8-1</guid>
            <title>gcp-sql v5.8.1 - Bug Fixed - SQL Instances were not updated/cleaned up correctly via real-time events in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/gcp-sql-v5-8-1</link>
            <description>_Bug fixes_

- SQL Instances were sometimes not updated/cleaned up correctly via real-time events in Guardrails. This is now fixed.</description>
            <pubDate>Thu, 04 Apr 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ec2-v5-40-0</guid>
            <title>aws-ec2 v5.40.0 - Manage IMDS defaults for EC2 via the Account Attributes &gt; Instance Metadata Service Defaults control</title>
            <link>https://turbot.com/guardrails/changelog/aws-ec2-v5-40-0</link>
            <description>_What&apos;s new?_

- You can now manage IMDS defaults for EC2 per region. To get started, set the `AWS &gt; EC2 &gt; Account Attributes &gt; Instance Metadata Service Defaults &gt; *` policies.

_Bug fixes_

- The `AWS &gt; EC2 &gt; Instance &gt; Approved` control would sometimes fail to stop instances that were discovered in Guardrails via real-time events if the `AWS &gt; EC2 &gt; Instance &gt; Approved` policy was set to `Enforce: Stop unapproved if new`. This is now fixed.</description>
            <pubDate>Tue, 02 Apr 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-storage-v5-16-0</guid>
            <title>azure-storage v5.16.0 - Blob service property details will now be available in CMDB for Storage Accounts</title>
            <link>https://turbot.com/guardrails/changelog/azure-storage-v5-16-0</link>
            <description>_What&apos;s new?_

- Storage Account CMDB data will now also include details about the account&apos;s blob service properties.</description>
            <pubDate>Mon, 01 Apr 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-postgresql-v5-12-0</guid>
            <title>azure-postgresql v5.12.0 - Configure connection_throttling parameter for PostgreSQL servers</title>
            <link>https://turbot.com/guardrails/changelog/azure-postgresql-v5-12-0</link>
            <description>_What&apos;s new?_

- You can now configure `connection_throttling` parameter for PostgreSQL servers. To get started, set the `Azure &gt; PostgreSQL &gt; Server &gt; Audit Logging &gt; Connection Throttling` policy.</description>
            <pubDate>Mon, 01 Apr 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-mysql-v5-8-0</guid>
            <title>azure-mysql v5.8.0 - TLS version and audit log details will now be available in CMDB for Flexi Servers</title>
            <link>https://turbot.com/guardrails/changelog/azure-mysql-v5-8-0</link>
            <description>_What&apos;s new?_

- TLS version and audit log details will now be available in CMDB for Flexi Servers.</description>
            <pubDate>Mon, 01 Apr 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-kms-v5-18-0</guid>
            <title>aws-kms v5.18.0 - Disable unapproved Keys via the Key &gt; Approved control</title>
            <link>https://turbot.com/guardrails/changelog/aws-kms-v5-18-0</link>
            <description>_What&apos;s new?_

- Users can now disable unapproved Keys in AWS. To get started, set the `AWS &gt; KMS &gt; Key &gt; Approved` policy to `Enforce: Disable unapproved`.</description>
            <pubDate>Fri, 29 Mar 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-sns-v5-15-3</guid>
            <title>aws-sns v5.15.3 - Bug Fixed - EventBridge Rule for real-time SNS events, created by Event Handlers, will now respect `Enforce: Enabled but ignore permission errors` policy value for Subscription CMDB</title>
            <link>https://turbot.com/guardrails/changelog/aws-sns-v5-15-3</link>
            <description>_Bug fixes_

- In v5.15.1, we introduced the policy value `Enforce: Enabled but ignore permission errors` for the `AWS &gt; SNS &gt; Subscription &gt; CMDB` policy, allowing the corresponding CMDB control to ignore permission errors, if any, and proceed to completion. However, configuring the CMDB policy to `Enforce: Enabled but ignore permission errors` inadvertently introduced a bug, resulting in the removal of real-time events for Subscription from the SNS EventBridge rule created by the Event Handlers. This issue has now been fixed.</description>
            <pubDate>Wed, 27 Mar 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-kms-v5-17-1</guid>
            <title>aws-kms v5.17.1 - Bug Fixed - EventBridge Rule for real-time KMS events, created by Event Handlers, will now respect `Enforce: Enabled but ignore permission errors` policy value for Key CMDB</title>
            <link>https://turbot.com/guardrails/changelog/aws-kms-v5-17-1</link>
            <description>_Bug fixes_

- In v5.13.0, we introduced the policy value `Enforce: Enabled but ignore permission errors` for the `AWS &gt; KMS &gt; Key &gt; CMDB` policy, allowing the corresponding CMDB control to ignore permission errors, if any, and proceed to completion. However, configuring the CMDB policy to `Enforce: Enabled but ignore permission errors` inadvertently introduced a bug, resulting in the removal of the EventBridge Rule for KMS by the Event Handlers. This issue has now been fixed.</description>
            <pubDate>Wed, 27 Mar 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-42-22</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.42.22 - Minor internal improvements</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-42-22</link>
            <description>_Bug fixes_

- Server
  - Minor internal improvements.

_Requirements_

- TEF: 1.57.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Tue, 19 Mar 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ecr-v5-13-0</guid>
            <title>aws-ecr v5.13.0 - You can now configure IAM resource policies on repositories</title>
            <link>https://turbot.com/guardrails/changelog/aws-ecr-v5-13-0</link>
            <description>_What&apos;s new?_

- Control Types:

  - AWS &gt; ECR &gt; Repository &gt; Policy
  - AWS &gt; ECR &gt; Repository &gt; Policy &gt; Required

- Policy Types:

  - AWS &gt; ECR &gt; Repository &gt; Policy
  - AWS &gt; ECR &gt; Repository &gt; Policy &gt; Required
  - AWS &gt; ECR &gt; Repository &gt; Policy &gt; Required &gt; Items

- Action Types:
  - AWS &gt; ECR &gt; Repository &gt; Update Repository policy</description>
            <pubDate>Tue, 19 Mar 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-42-21</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.42.21 - Account import will be smoother and more consistent than before</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-42-21</link>
            <description>_Bug fixes_
- Server
  - Account import will be smoother and more consistent than before.

_Requirements_

- TEF: 1.57.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Mon, 18 Mar 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-vpc-connect-v5-9-1</guid>
            <title>aws-vpc-connect v5.9.1 - Bug fixed - Guardrails will now exclude upserting VPC resources that are shared from other accounts and only upsert resources that belong to the owner account</title>
            <link>https://turbot.com/guardrails/changelog/aws-vpc-connect-v5-9-1</link>
            <description>_Bug fixes_

- Guardrails will now exclude upserting VPC resources that are shared from other accounts and only upsert resources that belong to the owner account.
- Guardrails failed to filter out real-time events for resource types if their parent resource types&apos; CMDB policy was set to `Enforce: Disabled`. This is now fixed.</description>
            <pubDate>Mon, 18 Mar 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-vpc-security-v5-9-7</guid>
            <title>aws-vpc-security v5.9.7 - `AWS &gt; VPC &gt; VPC &gt; Stack` control failed to claim security group rules correctly if the `protocol` for such rules was set to `All` or `TCP` in the stack&apos;s source policy</title>
            <link>https://turbot.com/guardrails/changelog/aws-vpc-security-v5-9-7</link>
            <description>_Bug fixes_

- The `AWS &gt; VPC &gt; VPC &gt; Stack` control failed to claim security group rules correctly if the `protocol` for such rules was set to `All` or `TCP` in the stack&apos;s source policy. This issue has been fixed, and the control will now claim such rules correctly.</description>
            <pubDate>Fri, 15 Mar 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-v5-29-4</guid>
            <title>aws v5.29.4 - Various policy definitions have been updated to allow for a smoother account import experience</title>
            <link>https://turbot.com/guardrails/changelog/aws-v5-29-4</link>
            <description>_Bug fixes_

- We have updated various policy definitions set during account imports to allow for a smoother account import experience. We recommend upgrading your TE to v5.42.21 or higher to enable these changes to take effect.</description>
            <pubDate>Fri, 15 Mar 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-42-20</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.42.20 - Bug Fixed - AWS login dropdown button to accurately display both existing and new grants</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-42-20</link>
            <description>_Bug fixes_
- UI
  - Fixed the AWS login dropdown button to accurately display both existing and new grants.

_Requirements_

- TEF: 1.57.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Wed, 13 Mar 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-sagemaker-v5-10-0</guid>
            <title>aws-sagemaker v5.10.0 - Bug fixed - Unsupported US Gov cloud regions for Code Repository are now removed from the Regions policy</title>
            <link>https://turbot.com/guardrails/changelog/aws-sagemaker-v5-10-0</link>
            <description>_Bug fixes_

- Unsupported US Gov cloud regions were inadvertently included in the `AWS &gt; SageMaker &gt; Code Repository &gt; Regions` policy, which led to the `AWS &gt; SageMaker &gt; Code Repository &gt; Discovery` control being in an error state for those regions. We&apos;ve now removed the unsupported US Gov cloud regions from the Regions policy.

_What&apos;s new?_

- Policy Types:
  - AWS &gt; SageMaker &gt; Notebook Instance &gt; Approved &gt; Custom</description>
            <pubDate>Wed, 13 Mar 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-iam-v5-35-1</guid>
            <title>aws-iam v5.35.1 - Bug fixed - Guardrails failed to filter out real-time events for resource types if their parent resource types&apos; CMDB policy was set to `Enforce: Disabled`</title>
            <link>https://turbot.com/guardrails/changelog/aws-iam-v5-35-1</link>
            <description>_Bug fixes_

- Guardrails failed to filter out real-time events for resource types if their parent resource types&apos; CMDB policy was set to `Enforce: Disabled`. This is now fixed.</description>
            <pubDate>Wed, 13 Mar 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-vpc-security-v5-9-6</guid>
            <title>aws-vpc-security v5.9.6 - Guardrails failed to filter out real-time events for resource types if their parent resource types&apos; CMDB policy was set to `Enforce: Disabled`</title>
            <link>https://turbot.com/guardrails/changelog/aws-vpc-security-v5-9-6</link>
            <description>_Bug fixes_

- Guardrails failed to filter out real-time events for resource types if their parent resource types&apos; CMDB policy was set to `Enforce: Disabled`. This is now fixed.
- In the previous version, we fixed an issue with the `AWS &gt; VPC &gt; VPC &gt; Stack` control that prevented it from recognizing security group rules with the port range set to 0 correctly. However, the control still failed to claim existing security group rules available in Guardrails CMDB, due to an inadvertent bug introduced in v5.9.2. This issue has now been fixed, and the control will correctly claim existing security group rules.</description>
            <pubDate>Mon, 11 Mar 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-sns-v5-15-2</guid>
            <title>aws-sns v5.15.2 - Bug fixed - Guardrails failed to filter out real-time events for resource types if their parent resource types&apos; CMDB policy was set to `Enforce: Disabled`</title>
            <link>https://turbot.com/guardrails/changelog/aws-sns-v5-15-2</link>
            <description>_Bug fixes_

- Guardrails failed to filter out real-time events for resource types if their parent resource types&apos; CMDB policy was set to `Enforce: Disabled`. This is now fixed.</description>
            <pubDate>Mon, 11 Mar 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-storage-v5-11-1</guid>
            <title>gcp-storage v5.11.1 - Bug fixed - Guardrails unnecessarily listened to and processed real-time `lists` events for various storage resources</title>
            <link>https://turbot.com/guardrails/changelog/gcp-storage-v5-11-1</link>
            <description>_Bug fixes_

- Previously, Guardrails unnecessarily listened to and processed real-time `lists` events for various storage resources. We&apos;ve now improved our events filter to ignore these `lists` events, thereby reducing unnecessary processing.</description>
            <pubDate>Fri, 08 Mar 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-lambda-v5-13-3</guid>
            <title>aws-lambda v5.13.3 - Bug fixed - Guardrails failed to filter out real-time events for resource types if their parent resource types&apos; CMDB policy was set to `Enforce: Disabled`</title>
            <link>https://turbot.com/guardrails/changelog/aws-lambda-v5-13-3</link>
            <description>_Bug fixes_

- Guardrails failed to filter out real-time events for resource types if their parent resource types&apos; CMDB policy was set to `Enforce: Disabled`. This is now fixed.</description>
            <pubDate>Fri, 08 Mar 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-glue-v5-11-1</guid>
            <title>aws-glue v5.11.1 - Bug fixed - Guardrails failed to filter out real-time events for resource types if their parent resource types&apos; CMDB policy was set to `Enforce: Disabled`</title>
            <link>https://turbot.com/guardrails/changelog/aws-glue-v5-11-1</link>
            <description>_Bug fixes_

- Guardrails failed to filter out real-time events for resource types if their parent resource types&apos; CMDB policy was set to `Enforce: Disabled`. This is now fixed.</description>
            <pubDate>Fri, 08 Mar 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ec2-v5-39-2</guid>
            <title>aws-ec2 v5.39.2 - Guardrails failed to filter out real-time events for resource types if their parent resource types&apos; CMDB policy was set to `Enforce: Disabled`</title>
            <link>https://turbot.com/guardrails/changelog/aws-ec2-v5-39-2</link>
            <description>_Bug fixes_

- Guardrails failed to filter out real-time events for resource types if their parent resource types&apos; CMDB policy was set to `Enforce: Disabled`. This is now fixed.
- The `AWS &gt; EC2 &gt; Snapshot &gt; Active` and  `AWS &gt; EC2 &gt; Snapshot &gt; Approved` controls will now not attempt to delete a snapshot if it has one or more AMIs attached to it.
- In the previous version, although we fixed a bug to prevent upserting volumes and snapshots with incorrect AKAs, there was still a provision for instances to be upserted with incorrect AKAs. We have now addressed this issue as well, ensuring instances are upserted more correctly and consistently than before.
- The deprecated `ec2-reports:*` permissions are now removed from the mod.</description>
            <pubDate>Fri, 08 Mar 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-vpc-internet-v5-11-2</guid>
            <title>aws-vpc-internet v5.11.2 - Bug fixed - Guardrails failed to filter out real-time events for resource types if their parent resource types&apos; CMDB policy was set to `Enforce: Disabled`</title>
            <link>https://turbot.com/guardrails/changelog/aws-vpc-internet-v5-11-2</link>
            <description>_Bug fixes_

- Guardrails will now exclude upserting VPC resources that are shared from other accounts and only upsert resources that belong to the owner account.
- In the previous version, we believed we had resolved an issue with Internet Gateways not being upserted into the CMDB while processing real-time `CreateDefaultVpc` events. However, we overlooked an edge case in the fix. We have now addressed this issue, ensuring that Internet Gateways will be reliably discovered and upserted into the Guardrails CMDB. We recommend updating the `aws-vpc-core` mod to version 5.17.1 or higher to enable Guardrails to correctly process real-time CreateDefaultVpc events for Internet Gateways.
- Guardrails failed to filter out real-time events for resource types if their parent resource types&apos; CMDB policy was set to `Enforce: Disabled`. This is now fixed.</description>
            <pubDate>Thu, 07 Mar 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-vpc-security-v5-9-5</guid>
            <title>aws-vpc-security v5.9.5 - Bug fixed - The `AWS &gt; VPC &gt; VPC &gt; Stack` control would sometimes go into an error state after creating security group rules with port range set to 0</title>
            <link>https://turbot.com/guardrails/changelog/aws-vpc-security-v5-9-5</link>
            <description>_Bug fixes_

- The `AWS &gt; VPC &gt; VPC &gt; Stack` control would sometimes go into an error state after creating security group rules with port range set to 0. This occurred because the control failed to recognize the existing rule in Guardrails CMDB and attempted to create a new rule instead. This issue has been fixed, and the stack control will now work correctly as expected.
- The `AWS &gt; VPC &gt; Security Group &gt; CMDB` control would sometimes go into an error state for security groups shared from other AWS accounts. We will now exclude shared security groups and only upsert security groups that belong to the owner account.</description>
            <pubDate>Wed, 06 Mar 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-iam-v5-35-0</guid>
            <title>aws-iam v5.35.0 - You can now also manage the IAM Permissions model for Guardrails Users via AWS &gt; Turbot &gt; IAM &gt; Managed control</title>
            <link>https://turbot.com/guardrails/changelog/aws-iam-v5-35-0</link>
            <description>_What&apos;s new?_

- You can now also manage the IAM Permissions model for Guardrails Users via the `AWS &gt; Turbot &gt; IAM &gt; Managed` control. The `AWS &gt; Turbot &gt; IAM &gt; Managed` control is faster and more efficient than the existing `AWS &gt; Turbot &gt; IAM` control because it utilizes Native AWS APIs rather than Terraform to manage IAM resources. Please note that this feature will work as intended only on TE v5.42.19 or higher and `turbot-iam` mod v5.11.0 or higher.

- Control Types
  - AWS &gt; Turbot &gt; IAM &gt; Group
  - AWS &gt; Turbot &gt; IAM &gt; Group &gt; Managed
  - AWS &gt; Turbot &gt; IAM &gt; Managed
  - AWS &gt; Turbot &gt; IAM &gt; Policy
  - AWS &gt; Turbot &gt; IAM &gt; Policy &gt; Managed
  - AWS &gt; Turbot &gt; IAM &gt; Role
  - AWS &gt; Turbot &gt; IAM &gt; Role &gt; Managed
  - AWS &gt; Turbot &gt; IAM &gt; User
  - AWS &gt; Turbot &gt; IAM &gt; User &gt; Managed

- Policy Types
  - AWS &gt; Turbot &gt; IAM &gt; Managed

- Policy Types Renamed
  - AWS &gt; IAM &gt; Turbot to AWS &gt; Turbot &gt; IAM

- Action Types
  - AWS &gt; Account &gt; Provision Managed Resources
  - AWS &gt; IAM &gt; Group &gt; Detach and delete
  - AWS &gt; IAM &gt; Group &gt; IAM Group Managed
  - AWS &gt; IAM &gt; Policy &gt; Detach and delete
  - AWS &gt; IAM &gt; Role &gt; IAM Role Managed
  - AWS &gt; IAM &gt; User &gt; IAM User Managed

_Bug fixes_

The `AWS &gt; IAM &gt; Group &gt; CMDB`, `AWS &gt; IAM &gt; Role &gt; CMDB`, and `AWS &gt; IAM &gt; User &gt; CMDB` controls previously failed to fetch all attachments for groups, roles, and users, respectively, due to the lack of pagination support. This issue has been fixed, and the controls will now correctly fetch all respective attachments.</description>
            <pubDate>Wed, 06 Mar 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-42-19</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.42.19 - Delete operations for resources is now faster and more efficient than before</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-42-19</link>
            <description>_Bug fixes_

- Server
  - Updated the tier for the SSM parameter `/tenant/${workspaceFullId}` to `Advanced`.
  - Delete operations for resources is now faster and more efficient than before.
  - Auto mod update control for mods will now look only for recommended versions instead of available and recommended.
  - Fixed policy value resolution to default to the value of `resolvedSchema` if not available in the schema.

- UI
  - Fixed a table typo in the Steampipe query used in the resources developer tab.
  - Display the AWS login button when setting permissions via the `AWS &gt; Turbot &gt; IAM &gt; Managed` control.

_Requirements_

- TEF: 1.57.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Tue, 05 Mar 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/turbot-iam-v5-11-1</guid>
            <title>turbot-iam v5.11.1 - The default value for `Turbot &gt; IAM &gt; Permissions &gt; Compiled &gt; Levels &gt; Turbot` policy will now be evaluated correctly and consistently</title>
            <link>https://turbot.com/guardrails/changelog/turbot-iam-v5-11-1</link>
            <description>_Bug fixes_

- The default value for `Turbot &gt; IAM &gt; Permissions &gt; Compiled &gt; Levels &gt; Turbot` policy will now be evaluated correctly and consistently.</description>
            <pubDate>Tue, 05 Mar 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ssm-v5-15-1</guid>
            <title>aws-ssm v5.15.1 - Bug fixed - SSM Parameters with incorrect names would sometimes be inadvertently upserted in Guardrails CMDB</title>
            <link>https://turbot.com/guardrails/changelog/aws-ssm-v5-15-1</link>
            <description>_Bug fixes_

- SSM Parameters with incorrect names would sometimes be inadvertently upserted in Guardrails CMDB. This issue has now been fixed.</description>
            <pubDate>Tue, 05 Mar 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-s3-v5-24-0</guid>
            <title>aws-s3 v5.24.0 - Bucket CMDB data will now also include information about Bucket Intelligent Tiering Configuration</title>
            <link>https://turbot.com/guardrails/changelog/aws-s3-v5-24-0</link>
            <description>_What&apos;s new?_

- The `AWS &gt; S3 &gt; Bucket` CMDB data will now also include information about Bucket Intelligent Tiering Configuration.
- A few policy values in the `AWS &gt; S3 &gt; Bucket &gt; Encyprion at Rest` policy have now been deprecated and will be removed in the next major mod version (v6.0.0) because they are no longer supported by AWS.

  | Deprecated Values                                                                     
  |-
  | Check: None                             
  | Check: None or higher           
  | Enforce: None         
  | Enforce: None or higher</description>
            <pubDate>Tue, 05 Mar 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-vpc-internet-v5-11-1</guid>
            <title>aws-vpc-internet v5.11.1 - Bug fixed - Guardrails will now upsert Internet Gateways into CMDB correctly while processing real-time `CreateDefaultVpc` events</title>
            <link>https://turbot.com/guardrails/changelog/aws-vpc-internet-v5-11-1</link>
            <description>_Bug fixes_

- Previously, Guardrails did not upsert Internet Gateways into the CMDB while processing real-time `CreateDefaultVpc` events. This issue has been fixed, and Internet Gateways will now be more reliably upserted into the Guardrails CMDB.
  We recommend updating the `aws-vpc-core` mod to v5.17.1 or higher to allow Guardrails to process the `CreateDefaultVpc` event for Internet Gateways correctly.</description>
            <pubDate>Mon, 04 Mar 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-vpc-core-v5-17-1</guid>
            <title>aws-vpc-core v5.17.1 - Bug fixed - Guardrails will now upsert DHCP Options into CMDB correctly while processing real-time `CreateDefaultVpc` events</title>
            <link>https://turbot.com/guardrails/changelog/aws-vpc-core-v5-17-1</link>
            <description>_Bug fixes_

- Previously, Guardrails did not upsert DHCP Options into the CMDB while processing real-time `CreateDefaultVpc` events. This issue has been fixed, and DHCP Options will now be more reliably upserted into the Guardrails CMDB.</description>
            <pubDate>Mon, 04 Mar 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-dataproc-v5-8-1</guid>
            <title>gcp-dataproc v5.8.1 - Bug fixed - Improved filters for real-time Dataproc lists events to reduce unnecessary processing</title>
            <link>https://turbot.com/guardrails/changelog/gcp-dataproc-v5-8-1</link>
            <description>_Bug fixes_

- Previously, Guardrails unnecessarily listened to and processed real-time `lists` events for various Dataproc resources. We&apos;ve now improved our events filter to ignore these `lists` events, thereby reducing unnecessary processing.</description>
            <pubDate>Sat, 02 Mar 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-v5-23-4</guid>
            <title>gcp v5.23.4 - Bug fixed - The Event Handlers &gt; Pub/Sub stack control will now transition to an Invalid state until Guardrails can correctly fetch the project number</title>
            <link>https://turbot.com/guardrails/changelog/gcp-v5-23-4</link>
            <description>_Bug fixes_

- The `GCP &gt; Turbot &gt; Event Handlers &gt; Pub/Sub` stack control previously attempted to create a topic and its IAM member incorrectly when the `GCP &gt; Turbot &gt; Event Handlers &gt; Logging &gt; Unique Writer Identity` policy was set to `Enforce: Unique Identity`, but the project number for the project was not available. This is fixed and the control will transition to an Invalid state until Guardrails can correctly fetch the project number.</description>
            <pubDate>Thu, 29 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-pubsub-v5-9-0</guid>
            <title>gcp-pubsub v5.9.0 - You can now manage labels for Pub/Sub Topics via Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/gcp-pubsub-v5-9-0</link>
            <description>_What&apos;s new?_

- Control Types:
  - GCP &gt; Pub/Sub &gt; Topic &gt; Labels

- Policy Types:
  - GCP &gt; Pub/Sub &gt; Topic &gt; Labels
  - GCP &gt; Pub/Sub &gt; Topic &gt; Labels &gt; Template

- Action Types
  - GCP &gt; Pub/Sub &gt; Topic &gt; Set Labels</description>
            <pubDate>Wed, 28 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-s3-v5-23-1</guid>
            <title>aws-s3 v5.23.1 - Bug fixed - Encryption in Transit and Encryption at Rest controls will now wait for a few minutes before applying their respective enforcements</title>
            <link>https://turbot.com/guardrails/changelog/aws-s3-v5-23-1</link>
            <description>_Bug fixes_

- In a previous version (v5.6.2), we introduced a change in the `AWS &gt; S3 &gt; Bucket &gt; Encryption in Transit` and `AWS &gt; S3 &gt; Bucket &gt; Encryption at Rest` control to wait for a few minutes before applying the respective policies to new buckets created via Cloudformation Stacks. We&apos;ve now extended this feature to all buckets regardless of how they were created, to ensure that IaC changes can be correctly applied to buckets without interference from immediate policy enforcements.</description>
            <pubDate>Wed, 28 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-57-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.57.0 - Added support for Advanced Tier for SSM Parameters</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-57-0</link>
            <description>_What&apos;s new?_

- Added support for Advanced Tier for SSM Parameters.
- Increased the visibility timeout from 60 seconds to 7200 seconds and decreased the message retention period to 7 days for runnable DLQ.</description>
            <pubDate>Tue, 27 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/ted-v1-40-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.40.0 - Added support for Postgres versions 15.5 and Redis 7.1</title>
            <link>https://turbot.com/guardrails/changelog/ted-v1-40-0</link>
            <description>_What&apos;s new?_

- Added: Support for Postgres versions 14.9, 14.10, 15.4 and 15.5.
- Added: Support for Redis 7.1.
- Added: m6gd.medium to instance type parameter for RDS.
- Added: Support for Advanced Tier for SSM Parameters.
- Removed: t4.micro and t4.small from instance type parameter for RDS.

_Note_

To use the latest RDS certificate in commercial cloud, please upgrade TE to 5.42.3 or higher and update the `RDS CA Certificate for Commercial Cloud` parameter.</description>
            <pubDate>Tue, 27 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-42-18</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.42.18 - Added support for AWS Custom Group Levels</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-42-18</link>
            <description>_Bug fixes_

- Server
  - Added: Support for AWS Custom Group Levels.
  - Updated: The DLQ lambda timeout has been updated to 2 minutes instead of 1 minute.
  - Updated: The Events DLQ visibility timeout has been increased from 15 minutes to 4 hours.
  - Updated: The Events DLQ MessageRetentionPeriod has been decreased from 14 days to 7 days.

- UI
  - Added: Action button to run immediate policy value.

_Requirements_

- TEF: 1.57.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Tue, 27 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/turbot-iam-v5-11-0</guid>
            <title>turbot-iam v5.11.0 - Added support for group permission levels</title>
            <link>https://turbot.com/guardrails/changelog/turbot-iam-v5-11-0</link>
            <description>_What&apos;s new?_

- Added support for group permission levels.</description>
            <pubDate>Tue, 27 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-firebase-v5-0-0</guid>
            <title>servicenow-gcp-firebase v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-firebase-v5-0-0</link>
            <description>_What&apos;s new?_

- Control Types:

  - GCP &gt; Firebase &gt; Android App &gt; ServiceNow
  - GCP &gt; Firebase &gt; Android App &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Firebase &gt; Android App &gt; ServiceNow &gt; Table
  - GCP &gt; Firebase &gt; Firebase Project &gt; ServiceNow
  - GCP &gt; Firebase &gt; Firebase Project &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Firebase &gt; Firebase Project &gt; ServiceNow &gt; Table
  - GCP &gt; Firebase &gt; Web App &gt; ServiceNow
  - GCP &gt; Firebase &gt; Web App &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Firebase &gt; Web App &gt; ServiceNow &gt; Table
  - GCP &gt; Firebase &gt; iOS App &gt; ServiceNow
  - GCP &gt; Firebase &gt; iOS App &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Firebase &gt; iOS App &gt; ServiceNow &gt; Table

- Policy Types:

  - GCP &gt; Firebase &gt; Android App &gt; ServiceNow
  - GCP &gt; Firebase &gt; Android App &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Firebase &gt; Android App &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Firebase &gt; Android App &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Firebase &gt; Android App &gt; ServiceNow &gt; Table
  - GCP &gt; Firebase &gt; Android App &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; Firebase &gt; Firebase Project &gt; ServiceNow
  - GCP &gt; Firebase &gt; Firebase Project &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Firebase &gt; Firebase Project &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Firebase &gt; Firebase Project &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Firebase &gt; Firebase Project &gt; ServiceNow &gt; Table
  - GCP &gt; Firebase &gt; Firebase Project &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; Firebase &gt; Web App &gt; ServiceNow
  - GCP &gt; Firebase &gt; Web App &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Firebase &gt; Web App &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Firebase &gt; Web App &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Firebase &gt; Web App &gt; ServiceNow &gt; Table
  - GCP &gt; Firebase &gt; Web App &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; Firebase &gt; iOS App &gt; ServiceNow
  - GCP &gt; Firebase &gt; iOS App &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Firebase &gt; iOS App &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Firebase &gt; iOS App &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Firebase &gt; iOS App &gt; ServiceNow &gt; Table
  - GCP &gt; Firebase &gt; iOS App &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Tue, 27 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-secretsmanager-v5-7-0</guid>
            <title>aws-secretsmanager v5.7.0 - Secret CMDB control would go into an error state if Guardrails did not have permissions to describe a secret</title>
            <link>https://turbot.com/guardrails/changelog/aws-secretsmanager-v5-7-0</link>
            <description>_What&apos;s new?_

- The `AWS &gt; Secrets Manager &gt; Secret &gt; CMDB` control would go into an error state if Guardrails did not have permissions to describe a secret. Users can now ignore such permission errors and allow the CMDB control to run its course to completion. To get started, set the `AWS &gt; Secrets Manager &gt; Secret &gt; CMDB` policy to `Enforce: Enabled but ignore permission errors`.</description>
            <pubDate>Tue, 27 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-iam-v5-34-0</guid>
            <title>aws-iam v5.34.0 - You can now attach custom IAM Groups to Guardrails users</title>
            <link>https://turbot.com/guardrails/changelog/aws-iam-v5-34-0</link>
            <description>_What&apos;s new?_

- You can now attach custom IAM Groups to Guardrails users if the `AWS &gt; Turbot &gt; Permissions` policy is set to `Enforce: User Mode`. To get started, set the `AWS &gt; Turbot &gt; Permissions &gt; Custom Group Levels [Account]` policy and then attach the custom group to a user via the Grant Permission button on the Permissions page. Please note that this feature will work as intended only on TE v5.42.18 or higher and `turbot-iam` mod v5.11.0 or higher.

- Policy Types:
  - AWS &gt; Turbot &gt; Permissions &gt; Custom Group Levels [Account]

- Policy Types renamed:
  - AWS &gt; Turbot &gt; Permissions &gt; Custom Levels [Account] to AWS &gt; Turbot &gt; Permissions &gt; Custom Role Levels [Account]
  - AWS &gt; Turbot &gt; Permissions &gt; Custom Levels [Folder] to AWS &gt; Turbot &gt; Permissions &gt; Custom Role Levels [Folder]</description>
            <pubDate>Tue, 27 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-network-v5-1-0</guid>
            <title>servicenow-gcp-network v5.1.0 - Added support for various network resources</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-network-v5-1-0</link>
            <description>_What&apos;s new?_

- Control Types:

  - GCP &gt; Network &gt; Address &gt; ServiceNow
  - GCP &gt; Network &gt; Address &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Network &gt; Address &gt; ServiceNow &gt; Table
  - GCP &gt; Network &gt; Backend Bucket &gt; ServiceNow
  - GCP &gt; Network &gt; Backend Bucket &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Network &gt; Backend Bucket &gt; ServiceNow &gt; Table
  - GCP &gt; Network &gt; Backend Service &gt; ServiceNow
  - GCP &gt; Network &gt; Backend Service &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Network &gt; Backend Service &gt; ServiceNow &gt; Table
  - GCP &gt; Network &gt; Firewall &gt; ServiceNow
  - GCP &gt; Network &gt; Firewall &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Network &gt; Firewall &gt; ServiceNow &gt; Table
  - GCP &gt; Network &gt; Forwarding Rule &gt; ServiceNow
  - GCP &gt; Network &gt; Forwarding Rule &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Network &gt; Forwarding Rule &gt; ServiceNow &gt; Table
  - GCP &gt; Network &gt; Global Address &gt; ServiceNow
  - GCP &gt; Network &gt; Global Address &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Network &gt; Global Address &gt; ServiceNow &gt; Table
  - GCP &gt; Network &gt; Global Forwarding Rule &gt; ServiceNow
  - GCP &gt; Network &gt; Global Forwarding Rule &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Network &gt; Global Forwarding Rule &gt; ServiceNow &gt; Table
  - GCP &gt; Network &gt; Interconnect &gt; ServiceNow
  - GCP &gt; Network &gt; Interconnect &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Network &gt; Interconnect &gt; ServiceNow &gt; Table
  - GCP &gt; Network &gt; Packet Mirroring &gt; ServiceNow
  - GCP &gt; Network &gt; Packet Mirroring &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Network &gt; Packet Mirroring &gt; ServiceNow &gt; Table
  - GCP &gt; Network &gt; Region Backend Service &gt; ServiceNow
  - GCP &gt; Network &gt; Region Backend Service &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Network &gt; Region Backend Service &gt; ServiceNow &gt; Table
  - GCP &gt; Network &gt; Region SSL Certificate &gt; ServiceNow
  - GCP &gt; Network &gt; Region SSL Certificate &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Network &gt; Region SSL Certificate &gt; ServiceNow &gt; Table
  - GCP &gt; Network &gt; Region Target HTTPS Proxy &gt; ServiceNow
  - GCP &gt; Network &gt; Region Target HTTPS Proxy &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Network &gt; Region Target HTTPS Proxy &gt; ServiceNow &gt; Table
  - GCP &gt; Network &gt; Region URL Map &gt; ServiceNow
  - GCP &gt; Network &gt; Region URL Map &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Network &gt; Region URL Map &gt; ServiceNow &gt; Table
  - GCP &gt; Network &gt; Route &gt; ServiceNow
  - GCP &gt; Network &gt; Route &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Network &gt; Route &gt; ServiceNow &gt; Table
  - GCP &gt; Network &gt; Router &gt; ServiceNow
  - GCP &gt; Network &gt; Router &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Network &gt; Router &gt; ServiceNow &gt; Table
  - GCP &gt; Network &gt; SSL Certificate &gt; ServiceNow
  - GCP &gt; Network &gt; SSL Certificate &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Network &gt; SSL Certificate &gt; ServiceNow &gt; Table
  - GCP &gt; Network &gt; SSL Policy &gt; ServiceNow
  - GCP &gt; Network &gt; SSL Policy &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Network &gt; SSL Policy &gt; ServiceNow &gt; Table
  - GCP &gt; Network &gt; Target HTTPS Proxy &gt; ServiceNow
  - GCP &gt; Network &gt; Target HTTPS Proxy &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Network &gt; Target HTTPS Proxy &gt; ServiceNow &gt; Table
  - GCP &gt; Network &gt; Target Pool &gt; ServiceNow
  - GCP &gt; Network &gt; Target Pool &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Network &gt; Target Pool &gt; ServiceNow &gt; Table
  - GCP &gt; Network &gt; Target SSL Proxy &gt; ServiceNow
  - GCP &gt; Network &gt; Target SSL Proxy &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Network &gt; Target SSL Proxy &gt; ServiceNow &gt; Table
  - GCP &gt; Network &gt; Target TCP Proxy &gt; ServiceNow
  - GCP &gt; Network &gt; Target TCP Proxy &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Network &gt; Target TCP Proxy &gt; ServiceNow &gt; Table
  - GCP &gt; Network &gt; Target VPN Gateway &gt; ServiceNow
  - GCP &gt; Network &gt; Target VPN Gateway &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Network &gt; Target VPN Gateway &gt; ServiceNow &gt; Table
  - GCP &gt; Network &gt; URL Map &gt; ServiceNow
  - GCP &gt; Network &gt; URL Map &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Network &gt; URL Map &gt; ServiceNow &gt; Table
  - GCP &gt; Network &gt; VPN Tunnel &gt; ServiceNow
  - GCP &gt; Network &gt; VPN Tunnel &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Network &gt; VPN Tunnel &gt; ServiceNow &gt; Table

- Policy Types:

  - GCP &gt; Network &gt; Address &gt; ServiceNow
  - GCP &gt; Network &gt; Address &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Network &gt; Address &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Network &gt; Address &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Network &gt; Address &gt; ServiceNow &gt; Table
  - GCP &gt; Network &gt; Address &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; Network &gt; Backend Bucket &gt; ServiceNow
  - GCP &gt; Network &gt; Backend Bucket &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Network &gt; Backend Bucket &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Network &gt; Backend Bucket &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Network &gt; Backend Bucket &gt; ServiceNow &gt; Table
  - GCP &gt; Network &gt; Backend Bucket &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; Network &gt; Backend Service &gt; ServiceNow
  - GCP &gt; Network &gt; Backend Service &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Network &gt; Backend Service &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Network &gt; Backend Service &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Network &gt; Backend Service &gt; ServiceNow &gt; Table
  - GCP &gt; Network &gt; Backend Service &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; Network &gt; Firewall &gt; ServiceNow
  - GCP &gt; Network &gt; Firewall &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Network &gt; Firewall &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Network &gt; Firewall &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Network &gt; Firewall &gt; ServiceNow &gt; Table
  - GCP &gt; Network &gt; Firewall &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; Network &gt; Forwarding Rule &gt; ServiceNow
  - GCP &gt; Network &gt; Forwarding Rule &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Network &gt; Forwarding Rule &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Network &gt; Forwarding Rule &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Network &gt; Forwarding Rule &gt; ServiceNow &gt; Table
  - GCP &gt; Network &gt; Forwarding Rule &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; Network &gt; Global Address &gt; ServiceNow
  - GCP &gt; Network &gt; Global Address &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Network &gt; Global Address &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Network &gt; Global Address &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Network &gt; Global Address &gt; ServiceNow &gt; Table
  - GCP &gt; Network &gt; Global Address &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; Network &gt; Global Forwarding Rule &gt; ServiceNow
  - GCP &gt; Network &gt; Global Forwarding Rule &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Network &gt; Global Forwarding Rule &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Network &gt; Global Forwarding Rule &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Network &gt; Global Forwarding Rule &gt; ServiceNow &gt; Table
  - GCP &gt; Network &gt; Global Forwarding Rule &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; Network &gt; Interconnect &gt; ServiceNow
  - GCP &gt; Network &gt; Interconnect &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Network &gt; Interconnect &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Network &gt; Interconnect &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Network &gt; Interconnect &gt; ServiceNow &gt; Table
  - GCP &gt; Network &gt; Interconnect &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; Network &gt; Packet Mirroring &gt; ServiceNow
  - GCP &gt; Network &gt; Packet Mirroring &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Network &gt; Packet Mirroring &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Network &gt; Packet Mirroring &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Network &gt; Packet Mirroring &gt; ServiceNow &gt; Table
  - GCP &gt; Network &gt; Packet Mirroring &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; Network &gt; Region Backend Service &gt; ServiceNow
  - GCP &gt; Network &gt; Region Backend Service &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Network &gt; Region Backend Service &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Network &gt; Region Backend Service &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Network &gt; Region Backend Service &gt; ServiceNow &gt; Table
  - GCP &gt; Network &gt; Region Backend Service &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; Network &gt; Region SSL Certificate &gt; ServiceNow
  - GCP &gt; Network &gt; Region SSL Certificate &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Network &gt; Region SSL Certificate &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Network &gt; Region SSL Certificate &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Network &gt; Region SSL Certificate &gt; ServiceNow &gt; Table
  - GCP &gt; Network &gt; Region SSL Certificate &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; Network &gt; Region Target HTTPS Proxy &gt; ServiceNow
  - GCP &gt; Network &gt; Region Target HTTPS Proxy &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Network &gt; Region Target HTTPS Proxy &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Network &gt; Region Target HTTPS Proxy &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Network &gt; Region Target HTTPS Proxy &gt; ServiceNow &gt; Table
  - GCP &gt; Network &gt; Region Target HTTPS Proxy &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; Network &gt; Region URL Map &gt; ServiceNow
  - GCP &gt; Network &gt; Region URL Map &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Network &gt; Region URL Map &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Network &gt; Region URL Map &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Network &gt; Region URL Map &gt; ServiceNow &gt; Table
  - GCP &gt; Network &gt; Region URL Map &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; Network &gt; Route &gt; ServiceNow
  - GCP &gt; Network &gt; Route &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Network &gt; Route &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Network &gt; Route &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Network &gt; Route &gt; ServiceNow &gt; Table
  - GCP &gt; Network &gt; Route &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; Network &gt; Router &gt; ServiceNow
  - GCP &gt; Network &gt; Router &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Network &gt; Router &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Network &gt; Router &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Network &gt; Router &gt; ServiceNow &gt; Table
  - GCP &gt; Network &gt; Router &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; Network &gt; SSL Certificate &gt; ServiceNow
  - GCP &gt; Network &gt; SSL Certificate &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Network &gt; SSL Certificate &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Network &gt; SSL Certificate &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Network &gt; SSL Certificate &gt; ServiceNow &gt; Table
  - GCP &gt; Network &gt; SSL Certificate &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; Network &gt; SSL Policy &gt; ServiceNow
  - GCP &gt; Network &gt; SSL Policy &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Network &gt; SSL Policy &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Network &gt; SSL Policy &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Network &gt; SSL Policy &gt; ServiceNow &gt; Table
  - GCP &gt; Network &gt; SSL Policy &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; Network &gt; Target HTTPS Proxy &gt; ServiceNow
  - GCP &gt; Network &gt; Target HTTPS Proxy &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Network &gt; Target HTTPS Proxy &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Network &gt; Target HTTPS Proxy &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Network &gt; Target HTTPS Proxy &gt; ServiceNow &gt; Table
  - GCP &gt; Network &gt; Target HTTPS Proxy &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; Network &gt; Target Pool &gt; ServiceNow
  - GCP &gt; Network &gt; Target Pool &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Network &gt; Target Pool &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Network &gt; Target Pool &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Network &gt; Target Pool &gt; ServiceNow &gt; Table
  - GCP &gt; Network &gt; Target Pool &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; Network &gt; Target SSL Proxy &gt; ServiceNow
  - GCP &gt; Network &gt; Target SSL Proxy &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Network &gt; Target SSL Proxy &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Network &gt; Target SSL Proxy &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Network &gt; Target SSL Proxy &gt; ServiceNow &gt; Table
  - GCP &gt; Network &gt; Target SSL Proxy &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; Network &gt; Target TCP Proxy &gt; ServiceNow
  - GCP &gt; Network &gt; Target TCP Proxy &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Network &gt; Target TCP Proxy &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Network &gt; Target TCP Proxy &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Network &gt; Target TCP Proxy &gt; ServiceNow &gt; Table
  - GCP &gt; Network &gt; Target TCP Proxy &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; Network &gt; Target VPN Gateway &gt; ServiceNow
  - GCP &gt; Network &gt; Target VPN Gateway &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Network &gt; Target VPN Gateway &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Network &gt; Target VPN Gateway &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Network &gt; Target VPN Gateway &gt; ServiceNow &gt; Table
  - GCP &gt; Network &gt; Target VPN Gateway &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; Network &gt; URL Map &gt; ServiceNow
  - GCP &gt; Network &gt; URL Map &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Network &gt; URL Map &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Network &gt; URL Map &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Network &gt; URL Map &gt; ServiceNow &gt; Table
  - GCP &gt; Network &gt; URL Map &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; Network &gt; VPN Tunnel &gt; ServiceNow
  - GCP &gt; Network &gt; VPN Tunnel &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Network &gt; VPN Tunnel &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Network &gt; VPN Tunnel &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Network &gt; VPN Tunnel &gt; ServiceNow &gt; Table
  - GCP &gt; Network &gt; VPN Tunnel &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Fri, 23 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-vpc-security-v5-9-4</guid>
            <title>aws-vpc-security v5.9.4 - Bug fixed - VPC Stack control would sometimes fail to claim existing Flow Logs in Guardrails CMDB</title>
            <link>https://turbot.com/guardrails/changelog/aws-vpc-security-v5-9-4</link>
            <description>_Bug fixes_

- The `AWS &gt; VPC &gt; VPC &gt; Stack` control would sometimes fail to claim existing Flow Logs in Guardrails CMDB. This is now fixed.</description>
            <pubDate>Thu, 22 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-iam-v5-0-0</guid>
            <title>servicenow-gcp-iam v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-iam-v5-0-0</link>
            <description>_What&apos;s new?_

- Control Types:

  - GCP &gt; IAM &gt; Project Role &gt; ServiceNow
  - GCP &gt; IAM &gt; Project Role &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; IAM &gt; Project Role &gt; ServiceNow &gt; Table
  - GCP &gt; IAM &gt; Project User &gt; ServiceNow
  - GCP &gt; IAM &gt; Project User &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; IAM &gt; Project User &gt; ServiceNow &gt; Table
  - GCP &gt; IAM &gt; Service Account &gt; ServiceNow
  - GCP &gt; IAM &gt; Service Account &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; IAM &gt; Service Account &gt; ServiceNow &gt; Table
  - GCP &gt; IAM &gt; Service Account Key &gt; ServiceNow
  - GCP &gt; IAM &gt; Service Account Key &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; IAM &gt; Service Account Key &gt; ServiceNow &gt; Table
  - GCP &gt; Project &gt; Policy &gt; ServiceNow
  - GCP &gt; Project &gt; Policy &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Project &gt; Policy &gt; ServiceNow &gt; Table

- Policy Types:

  - GCP &gt; IAM &gt; Project Role &gt; ServiceNow
  - GCP &gt; IAM &gt; Project Role &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; IAM &gt; Project Role &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; IAM &gt; Project Role &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; IAM &gt; Project Role &gt; ServiceNow &gt; Table
  - GCP &gt; IAM &gt; Project Role &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; IAM &gt; Project User &gt; ServiceNow
  - GCP &gt; IAM &gt; Project User &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; IAM &gt; Project User &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; IAM &gt; Project User &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; IAM &gt; Project User &gt; ServiceNow &gt; Table
  - GCP &gt; IAM &gt; Project User &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; IAM &gt; Service Account &gt; ServiceNow
  - GCP &gt; IAM &gt; Service Account &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; IAM &gt; Service Account &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; IAM &gt; Service Account &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; IAM &gt; Service Account &gt; ServiceNow &gt; Table
  - GCP &gt; IAM &gt; Service Account &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; IAM &gt; Service Account Key &gt; ServiceNow
  - GCP &gt; IAM &gt; Service Account Key &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; IAM &gt; Service Account Key &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; IAM &gt; Service Account Key &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; IAM &gt; Service Account Key &gt; ServiceNow &gt; Table
  - GCP &gt; IAM &gt; Service Account Key &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; Project &gt; Policy &gt; ServiceNow
  - GCP &gt; Project &gt; Policy &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Project &gt; Policy &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Project &gt; Policy &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Project &gt; Policy &gt; ServiceNow &gt; Table
  - GCP &gt; Project &gt; Policy &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Wed, 21 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-functions-v5-0-0</guid>
            <title>servicenow-gcp-functions v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-functions-v5-0-0</link>
            <description>_What&apos;s new?_

- Control Types:

  - GCP &gt; Functions &gt; Function &gt; ServiceNow
  - GCP &gt; Functions &gt; Function &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Functions &gt; Function &gt; ServiceNow &gt; Table

- Policy Types:

  - GCP &gt; Functions &gt; Function &gt; ServiceNow
  - GCP &gt; Functions &gt; Function &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Functions &gt; Function &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Functions &gt; Function &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Functions &gt; Function &gt; ServiceNow &gt; Table
  - GCP &gt; Functions &gt; Function &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Wed, 21 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-sns-v5-15-1</guid>
            <title>aws-sns v5.15.1 - Bug fixed - SNS Subscription CMDB control would go into an error state if Guardrails did not have permissions to describe a subscription</title>
            <link>https://turbot.com/guardrails/changelog/aws-sns-v5-15-1</link>
            <description>_Bug fixes_

- The `AWS &gt; SNS &gt; Subscription &gt; CMDB` control would go into an error state if Guardrails did not have permissions to describe a subscription. Users can now ignore such permission errors and allow the CMDB control to run its course to completion. To get started, set the `AWS &gt; SNS &gt; Subscription &gt; CMDB` policy to `Enforce: Enabled but ignore permission errors`.</description>
            <pubDate>Wed, 21 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-v5-1-0</guid>
            <title>servicenow-gcp v5.1.0 - Added support for GCP Projects</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-v5-1-0</link>
            <description>_What&apos;s new?_

- Control Types:

  - GCP &gt; Project &gt; ServiceNow
  - GCP &gt; Project &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Project &gt; ServiceNow &gt; Table

- Policy Types:

  - GCP &gt; Project &gt; ServiceNow
  - GCP &gt; Project &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Project &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Project &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Project &gt; ServiceNow &gt; Table
  - GCP &gt; Project &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Tue, 20 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-memorystore-v5-0-0</guid>
            <title>servicenow-gcp-memorystore v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-memorystore-v5-0-0</link>
            <description>_What&apos;s new?_

- Control Types:

  - GCP &gt; Memorystore &gt; Instance &gt; ServiceNow
  - GCP &gt; Memorystore &gt; Instance &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Memorystore &gt; Instance &gt; ServiceNow &gt; Table

- Policy Types:

  - GCP &gt; Memorystore &gt; Instance &gt; ServiceNow
  - GCP &gt; Memorystore &gt; Instance &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Memorystore &gt; Instance &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Memorystore &gt; Instance &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Memorystore &gt; Instance &gt; ServiceNow &gt; Table
  - GCP &gt; Memorystore &gt; Instance &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Tue, 20 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-storage-v5-1-0</guid>
            <title>servicenow-gcp-storage v5.1.0 - Added support for Storage Objects</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-storage-v5-1-0</link>
            <description>_What&apos;s new?_

- Control Types:

  - GCP &gt; Storage &gt; Object &gt; ServiceNow
  - GCP &gt; Storage &gt; Object &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Storage &gt; Object &gt; ServiceNow &gt; Table

- Policy Types:

  - GCP &gt; Storage &gt; Object &gt; ServiceNow
  - GCP &gt; Storage &gt; Object &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Storage &gt; Object &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Storage &gt; Object &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Storage &gt; Object &gt; ServiceNow &gt; Table
  - GCP &gt; Storage &gt; Object &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Mon, 19 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-secretmanager-v5-0-0</guid>
            <title>servicenow-gcp-secretmanager v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-secretmanager-v5-0-0</link>
            <description>_What&apos;s new?_

- Control Types:

  - GCP &gt; Secret Manager &gt; Secret &gt; ServiceNow
  - GCP &gt; Secret Manager &gt; Secret &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Secret Manager &gt; Secret &gt; ServiceNow &gt; Table

- Policy Types:

  - GCP &gt; Secret Manager &gt; Secret &gt; ServiceNow
  - GCP &gt; Secret Manager &gt; Secret &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Secret Manager &gt; Secret &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Secret Manager &gt; Secret &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Secret Manager &gt; Secret &gt; ServiceNow &gt; Table
  - GCP &gt; Secret Manager &gt; Secret &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Mon, 19 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-scheduler-v5-0-0</guid>
            <title>servicenow-gcp-scheduler v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-scheduler-v5-0-0</link>
            <description>_What&apos;s new?_

- Control Types:

  - GCP &gt; Scheduler &gt; Job &gt; ServiceNow
  - GCP &gt; Scheduler &gt; Job &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Scheduler &gt; Job &gt; ServiceNow &gt; Table

- Policy Types:

  - GCP &gt; Scheduler &gt; Job &gt; ServiceNow
  - GCP &gt; Scheduler &gt; Job &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Scheduler &gt; Job &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Scheduler &gt; Job &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Scheduler &gt; Job &gt; ServiceNow &gt; Table
  - GCP &gt; Scheduler &gt; Job &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Mon, 19 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-dataproc-v5-0-0</guid>
            <title>servicenow-gcp-dataproc v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-dataproc-v5-0-0</link>
            <description>_What&apos;s new?_

- Control Types:

  - GCP &gt; Dataproc &gt; Cluster &gt; ServiceNow
  - GCP &gt; Dataproc &gt; Cluster &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Dataproc &gt; Cluster &gt; ServiceNow &gt; Table
  - GCP &gt; Dataproc &gt; Job &gt; ServiceNow
  - GCP &gt; Dataproc &gt; Job &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Dataproc &gt; Job &gt; ServiceNow &gt; Table
  - GCP &gt; Dataproc &gt; Workflow Template &gt; ServiceNow
  - GCP &gt; Dataproc &gt; Workflow Template &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Dataproc &gt; Workflow Template &gt; ServiceNow &gt; Table

- Policy Types:

  - GCP &gt; Dataproc &gt; Cluster &gt; ServiceNow
  - GCP &gt; Dataproc &gt; Cluster &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Dataproc &gt; Cluster &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Dataproc &gt; Cluster &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Dataproc &gt; Cluster &gt; ServiceNow &gt; Table
  - GCP &gt; Dataproc &gt; Cluster &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; Dataproc &gt; Job &gt; ServiceNow
  - GCP &gt; Dataproc &gt; Job &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Dataproc &gt; Job &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Dataproc &gt; Job &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Dataproc &gt; Job &gt; ServiceNow &gt; Table
  - GCP &gt; Dataproc &gt; Job &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; Dataproc &gt; Workflow Template &gt; ServiceNow
  - GCP &gt; Dataproc &gt; Workflow Template &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Dataproc &gt; Workflow Template &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Dataproc &gt; Workflow Template &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Dataproc &gt; Workflow Template &gt; ServiceNow &gt; Table
  - GCP &gt; Dataproc &gt; Workflow Template &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Mon, 19 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-composer-v5-0-0</guid>
            <title>servicenow-gcp-composer v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-composer-v5-0-0</link>
            <description>_What&apos;s new?_

- Control Types:

  - GCP &gt; Composer &gt; Environment &gt; ServiceNow
  - GCP &gt; Composer &gt; Environment &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Composer &gt; Environment &gt; ServiceNow &gt; Table

- Policy Types:

  - GCP &gt; Composer &gt; Environment &gt; ServiceNow
  - GCP &gt; Composer &gt; Environment &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Composer &gt; Environment &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Composer &gt; Environment &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Composer &gt; Environment &gt; ServiceNow &gt; Table
  - GCP &gt; Composer &gt; Environment &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Mon, 19 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-monitoring-v5-0-0</guid>
            <title>servicenow-gcp-monitoring v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-monitoring-v5-0-0</link>
            <description>_What&apos;s new?_

- Control Types:

  - GCP &gt; Monitoring &gt; Alert Policy &gt; ServiceNow
  - GCP &gt; Monitoring &gt; Alert Policy &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Monitoring &gt; Alert Policy &gt; ServiceNow &gt; Table
  - GCP &gt; Monitoring &gt; Group &gt; ServiceNow
  - GCP &gt; Monitoring &gt; Group &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Monitoring &gt; Group &gt; ServiceNow &gt; Table
  - GCP &gt; Monitoring &gt; Notification Channel &gt; ServiceNow
  - GCP &gt; Monitoring &gt; Notification Channel &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Monitoring &gt; Notification Channel &gt; ServiceNow &gt; Table

- Policy Types:

  - GCP &gt; Monitoring &gt; Alert Policy &gt; ServiceNow
  - GCP &gt; Monitoring &gt; Alert Policy &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Monitoring &gt; Alert Policy &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Monitoring &gt; Alert Policy &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Monitoring &gt; Alert Policy &gt; ServiceNow &gt; Table
  - GCP &gt; Monitoring &gt; Alert Policy &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; Monitoring &gt; Group &gt; ServiceNow
  - GCP &gt; Monitoring &gt; Group &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Monitoring &gt; Group &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Monitoring &gt; Group &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Monitoring &gt; Group &gt; ServiceNow &gt; Table
  - GCP &gt; Monitoring &gt; Group &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; Monitoring &gt; Notification Channel &gt; ServiceNow
  - GCP &gt; Monitoring &gt; Notification Channel &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Monitoring &gt; Notification Channel &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Monitoring &gt; Notification Channel &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Monitoring &gt; Notification Channel &gt; ServiceNow &gt; Table
  - GCP &gt; Monitoring &gt; Notification Channel &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Fri, 16 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-dns-v5-0-0</guid>
            <title>servicenow-gcp-dns v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-dns-v5-0-0</link>
            <description>_What&apos;s new?_

- Control Types:

  - GCP &gt; DNS &gt; Managed Zone &gt; ServiceNow
  - GCP &gt; DNS &gt; Managed Zone &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; DNS &gt; Managed Zone &gt; ServiceNow &gt; Table

- Policy Types:

  - GCP &gt; DNS &gt; Managed Zone &gt; ServiceNow
  - GCP &gt; DNS &gt; Managed Zone &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; DNS &gt; Managed Zone &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; DNS &gt; Managed Zone &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; DNS &gt; Managed Zone &gt; ServiceNow &gt; Table
  - GCP &gt; DNS &gt; Managed Zone &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Fri, 16 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-datapipeline-v5-0-0</guid>
            <title>servicenow-gcp-datapipeline v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-datapipeline-v5-0-0</link>
            <description>_What&apos;s new?_

- Control Types:

  - GCP &gt; Datapipeline &gt; Pipeline &gt; ServiceNow
  - GCP &gt; Datapipeline &gt; Pipeline &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Datapipeline &gt; Pipeline &gt; ServiceNow &gt; Table

- Policy Types:

  - GCP &gt; Datapipeline &gt; Pipeline &gt; ServiceNow
  - GCP &gt; Datapipeline &gt; Pipeline &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Datapipeline &gt; Pipeline &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Datapipeline &gt; Pipeline &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Datapipeline &gt; Pipeline &gt; ServiceNow &gt; Table
  - GCP &gt; Datapipeline &gt; Pipeline &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Fri, 16 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-dataflow-v5-0-0</guid>
            <title>servicenow-gcp-dataflow v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-dataflow-v5-0-0</link>
            <description>_What&apos;s new?_

- Control Types:

  - GCP &gt; Dataflow &gt; Job &gt; ServiceNow
  - GCP &gt; Dataflow &gt; Job &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Dataflow &gt; Job &gt; ServiceNow &gt; Table

- Policy Types:

  - GCP &gt; Dataflow &gt; Job &gt; ServiceNow
  - GCP &gt; Dataflow &gt; Job &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Dataflow &gt; Job &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Dataflow &gt; Job &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Dataflow &gt; Job &gt; ServiceNow &gt; Table
  - GCP &gt; Dataflow &gt; Job &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Fri, 16 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-computeengine-v5-18-1</guid>
            <title>gcp-computeengine v5.18.1 - Bug fixed - Instance Template CMDB control would go into an error state due to a bad internal build</title>
            <link>https://turbot.com/guardrails/changelog/gcp-computeengine-v5-18-1</link>
            <description>_Bug fixes_

- The `GCP &gt; Compute Engine &gt; Instance Template &gt; CMDB` control would sometimes go into an error state due to a bad internal build. This is fixed and the control will now work as expected.</description>
            <pubDate>Fri, 16 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-v5-18-2</guid>
            <title>azure v5.18.2 - Bug fixed - Guardrails would sometimes fail to import Azure Subscriptions</title>
            <link>https://turbot.com/guardrails/changelog/azure-v5-18-2</link>
            <description>_Bug fixes_

- Due to an inadvertently introduced issue with an internal build for `Azure &gt; Subscription`, importing subscriptions encountered schema validation problems. This issue has been resolved, and you can now successfully import subscriptions as before.</description>
            <pubDate>Fri, 16 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ec2-v5-39-1</guid>
            <title>aws-ec2 v5.39.1 - Bugs fixed - Guardrails would sometimes upsert Snapshots and Volumes with incorrect AKAs</title>
            <link>https://turbot.com/guardrails/changelog/aws-ec2-v5-39-1</link>
            <description>_Bug fixes_

- In the previous version, while we improved on the way we discovered missing Snapshots and Volumes while processing their update events, we inadvertently introduced a bug where some resources were upserted with incorrect AKAs. Such resources with malformed AKAs should now be cleaned up automatically from the environment, and Guardrails will now discover resources more correctly and consistently than before.
- In a previous version (v5.31.4), we implemented a feature to Discover Instances while processing their update events respectively, if those resources were missing from Guardrails CMDB. In busy environments, this would sometimes cause unnecessary Lambda executions. We&apos;ve now improved this behavior to upsert the missing resources in a lighter and faster way.</description>
            <pubDate>Fri, 16 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-v5-29-3</guid>
            <title>aws v5.29.3 - Added support for `ap-northeast-3` in the `AWS &gt; Account &gt; Regions` policy</title>
            <link>https://turbot.com/guardrails/changelog/aws-v5-29-3</link>
            <description>_What&apos;s new?_

- Added support for `ap-northeast-3` in the `AWS &gt; Account &gt; Regions` policy.</description>
            <pubDate>Tue, 13 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-logs-v5-12-1</guid>
            <title>aws-logs v5.12.1 - Added support for newer `ap-*` and `eu-*` regions in the `AWS &gt; Logs &gt; Regions` policy</title>
            <link>https://turbot.com/guardrails/changelog/aws-logs-v5-12-1</link>
            <description>_What&apos;s new?_

- Added support for `af-south-1`, `ap-northeast-3`, `ap-south-2`, `ap-southeast-3`, `ap-southeast-4`, `ca-west-1`, `eu-central-2`, `eu-south-1`, `eu-south-2`, `il-central-1` and `me-central-1` regions in the `AWS &gt; Logs &gt; Regions` policy.</description>
            <pubDate>Tue, 13 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ec2-v5-39-0</guid>
            <title>aws-ec2 v5.39.0 - You can now configure Block Public Access for Snapshots</title>
            <link>https://turbot.com/guardrails/changelog/aws-ec2-v5-39-0</link>
            <description>_What&apos;s new?_

- You can now configure Block Public Access for Snapshots. To get started, set the `AWS &gt; EC2 &gt; Account Attributes &gt; Block Public Access for Snapshots` policy.
- You can now also disable Block Public Access for AMIs. To get started, set the `AWS &gt; EC2 &gt; Account Attributes &gt; Block Public Access for AMIs` policy.
- `AWS/EC2/Admin`, `AWS/EC2/Metadata` and `AWS/EC2/Operator` now includes permissions for Verified Access Endpoints, Verified Access Groups and Verified Access Trust Providers.

- Control Types:
  - AWS &gt; EC2 &gt; Account Attributes &gt; Block Public Access for Snapshots

- Policy Types:
  - AWS &gt; EC2 &gt; Account Attributes &gt; Block Public Access for Snapshots

- Action Types:
  - AWS &gt; EC2 &gt; Account Attributes &gt; Update Block Public Access for Snapshots

_Bug fixes_

- In a previous version (v5.31.4), we implemented a feature to Discover Snapshots and Volumes while processing their update events respectively, if those resources were missing from Guardrails CMDB. In busy environments, this would sometimes cause unnecessary Lambda executions. We&apos;ve now improved this behavior to upsert the missing resources in a lighter and faster way.</description>
            <pubDate>Tue, 13 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-56-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.56.0 - Added `Deny: *` for HTTP traffic in Turbot Policy Parameter for SNS Policy</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-56-0</link>
            <description>_What&apos;s new?_

- Updated: MaxPalyloadSize parameter description.
- Updated: Turbot Policy Parameter to add back `Deny: *` for HTTP in SNS Policy.</description>
            <pubDate>Wed, 07 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/ted-v1-39-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.39.0 - Added support for Postgres versions 13.12 and 13.13</title>
            <link>https://turbot.com/guardrails/changelog/ted-v1-39-0</link>
            <description>_What&apos;s new?_

- Added: Postgres versions 13.12 and 13.13.
- Updated: CloudWatch Alarms will now use TEF SNS topic.</description>
            <pubDate>Wed, 07 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-42-17</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.42.17 - Added explicit Deny policy for HTTP traffic</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-42-17</link>
            <description>_Bug fixes_

- Server
  - Added the `Deny:*` policy for HTTP traffic back to the turbot-policy-parameter custom lambda code.
  - Event DLQ should not set the control or policy value to error if there has been a new process started for the control or policy value.
  - Run next should drop the events in case of recursive loop.
  - Add additional retryable throttling codes for actions.

_Requirements_

- TEF: 1.55.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Wed, 07 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-dataproc-v5-8-0</guid>
            <title>gcp-dataproc v5.8.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/gcp-dataproc-v5-8-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.</description>
            <pubDate>Wed, 07 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-composer-v5-4-0</guid>
            <title>gcp-composer v5.4.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/gcp-composer-v5-4-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.</description>
            <pubDate>Wed, 07 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-spanner-v5-8-0</guid>
            <title>gcp-spanner v5.8.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/gcp-spanner-v5-8-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.</description>
            <pubDate>Tue, 06 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/terraform-provider-v1-10-1</guid>
            <title>Terraform Provider v1.10.1 is now available</title>
            <link>https://turbot.com/guardrails/changelog/terraform-provider-v1-10-1</link>
            <description>v1.10.1 of the [Terraform Provider for Guardrails](https://registry.terraform.io/providers/turbot/turbot/1.10.1) is now available.

_Bug fixes_

- `resource/turbot_file`: terraform apply failed to update `content` of an existing File in Guardrails. This is now fixed.</description>
            <pubDate>Mon, 05 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-logging-v5-4-0</guid>
            <title>gcp-logging v5.4.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/gcp-logging-v5-4-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Policy Types:
  - GCP &gt; Logging &gt; Exclusion &gt; Approved &gt; Custom
  - GCP &gt; Logging &gt; Metric &gt; Approved &gt; Custom
  - GCP &gt; Logging &gt; Sink &gt; Approved &gt; Custom</description>
            <pubDate>Mon, 05 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-kubernetesengine-v5-5-0</guid>
            <title>gcp-kubernetesengine v5.5.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/gcp-kubernetesengine-v5-5-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

- Policy Types:
  - GCP &gt; Kubernetes Engine &gt; Region Cluster &gt; Approved &gt; Custom
  - GCP &gt; Kubernetes Engine &gt; Region Node Pool &gt; Approved &gt; Custom
  - GCP &gt; Kubernetes Engine &gt; Zone Cluster &gt; Approved &gt; Custom
  - GCP &gt; Kubernetes Engine &gt; Zone Node Pool &gt; Approved &gt; Custom</description>
            <pubDate>Mon, 05 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-dataflow-v5-5-0</guid>
            <title>gcp-dataflow v5.5.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/gcp-dataflow-v5-5-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Policy Types:
  - GCP &gt; Dataflow &gt; Job &gt; Approved &gt; Custom</description>
            <pubDate>Mon, 05 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-computeengine-v5-18-0</guid>
            <title>gcp-computeengine v5.18.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/gcp-computeengine-v5-18-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.</description>
            <pubDate>Mon, 05 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-monitor-v5-7-0</guid>
            <title>azure-monitor v5.7.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/azure-monitor-v5-7-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.</description>
            <pubDate>Mon, 05 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-keyvault-v5-12-0</guid>
            <title>azure-keyvault v5.12.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/azure-keyvault-v5-12-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.</description>
            <pubDate>Mon, 05 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-compute-v5-16-0</guid>
            <title>azure-compute v5.16.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/azure-compute-v5-16-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.</description>
            <pubDate>Mon, 05 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-applicationgateway-v5-7-0</guid>
            <title>azure-applicationgateway v5.7.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/azure-applicationgateway-v5-7-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.</description>
            <pubDate>Mon, 05 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ec2-v5-38-1</guid>
            <title>aws-ec2 v5.38.1 - Bugs Fixed - Discovery control for Key Pair would go into an error state due to unhandled escape characters</title>
            <link>https://turbot.com/guardrails/changelog/aws-ec2-v5-38-1</link>
            <description>_Bug fixes_
- The `AWS &gt; EC2 &gt; Key Pair &gt; Discovery` control would sometimes go into an error state if a Key Pair alias included escape characters. This is now fixed.

- Control Types renamed:
  - `AWS &gt; EC2 &gt; Volume &gt; Configuration` to `AWS &gt; EC2 &gt; Volume &gt; Performance Configuration`

- Policy Types renamed:
  - `AWS &gt; EC2 &gt; Volume &gt; Configuration` to `AWS &gt; EC2 &gt; Volume &gt; Performance Configuration`
  - `AWS &gt; EC2 &gt; Volume &gt; Configuration &gt; IOPS Capacity` to `AWS &gt; EC2 &gt; Volume &gt; Performance Configuration &gt; IOPS Capacity`
  - `AWS &gt; EC2 &gt; Volume &gt; Configuration &gt; Throughput` to `AWS &gt; EC2 &gt; Volume &gt; Performance Configuration &gt; Throughput`
  - `AWS &gt; EC2 &gt; Volume &gt; Configuration &gt; Type` to `AWS &gt; EC2 &gt; Volume &gt; Performance Configuration &gt; Type`

- Action Types renamed:
  - `AWS &gt; EC2 &gt; Volume &gt; Update Configuration` to `AWS &gt; EC2 &gt; Volume &gt; Update Performance Configuration`</description>
            <pubDate>Mon, 05 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/turbot-v5-42-1</guid>
            <title>turbot v5.42.1 - Policy Setting Expiration control will now run every 12 hours by default</title>
            <link>https://turbot.com/guardrails/changelog/turbot-v5-42-1</link>
            <description>_Bug fixes_

- The `Turbot &gt; Policy Setting Expiration` control will now run every 12 hours to manage policy setting expirations more consistently than before.</description>
            <pubDate>Sun, 04 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-network-v5-13-0</guid>
            <title>gcp-network v5.13.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/gcp-network-v5-13-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.</description>
            <pubDate>Fri, 02 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-iam-v5-13-0</guid>
            <title>gcp-iam v5.13.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/gcp-iam-v5-13-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.</description>
            <pubDate>Fri, 02 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-bigtable-v5-8-0</guid>
            <title>gcp-bigtable v5.8.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/gcp-bigtable-v5-8-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.</description>
            <pubDate>Fri, 02 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-appengine-v5-3-0</guid>
            <title>gcp-appengine v5.3.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/gcp-appengine-v5-3-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.</description>
            <pubDate>Fri, 02 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-sql-v5-13-0</guid>
            <title>azure-sql v5.13.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/azure-sql-v5-13-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.</description>
            <pubDate>Fri, 02 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-provider-v5-10-0</guid>
            <title>azure-provider v5.10.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/azure-provider-v5-10-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.</description>
            <pubDate>Fri, 02 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-loganalytics-v5-8-0</guid>
            <title>azure-loganalytics v5.8.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/azure-loganalytics-v5-8-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.</description>
            <pubDate>Fri, 02 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-loadbalancer-v5-7-0</guid>
            <title>azure-loadbalancer v5.7.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/azure-loadbalancer-v5-7-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.</description>
            <pubDate>Fri, 02 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-iam-v5-11-0</guid>
            <title>azure-iam v5.11.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/azure-iam-v5-11-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.</description>
            <pubDate>Fri, 02 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-dns-v5-8-0</guid>
            <title>azure-dns v5.8.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/azure-dns-v5-8-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.</description>
            <pubDate>Fri, 02 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-v5-23-3</guid>
            <title>gcp v5.23.3 - Bug fixed - Org Policy details will now be properly and consistently sorted for Projects</title>
            <link>https://turbot.com/guardrails/changelog/gcp-v5-23-3</link>
            <description>_Bug fixes_

- The Org policy details in the Project CMDB data will now be properly and consistently sorted.</description>
            <pubDate>Thu, 01 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-storage-v5-11-0</guid>
            <title>gcp-storage v5.11.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/gcp-storage-v5-11-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.</description>
            <pubDate>Thu, 01 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-sql-v5-8-0</guid>
            <title>gcp-sql v5.8.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/gcp-sql-v5-8-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.</description>
            <pubDate>Thu, 01 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-scheduler-v5-4-0</guid>
            <title>gcp-scheduler v5.4.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/gcp-scheduler-v5-4-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

- Policy Types:

  - GCP &gt; Scheduler &gt; Job &gt; Approved &gt; Custom</description>
            <pubDate>Thu, 01 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-pubsub-v5-8-0</guid>
            <title>gcp-pubsub v5.8.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/gcp-pubsub-v5-8-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.</description>
            <pubDate>Thu, 01 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-monitoring-v5-6-0</guid>
            <title>gcp-monitoring v5.6.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/gcp-monitoring-v5-6-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.</description>
            <pubDate>Thu, 01 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-dns-v5-6-0</guid>
            <title>gcp-dns v5.6.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/gcp-dns-v5-6-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.</description>
            <pubDate>Thu, 01 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-build-v5-2-0</guid>
            <title>gcp-build v5.2.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/gcp-build-v5-2-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.</description>
            <pubDate>Thu, 01 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-storage-v5-15-0</guid>
            <title>azure-storage v5.15.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/azure-storage-v5-15-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.</description>
            <pubDate>Thu, 01 Feb 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-spanner-v5-0-0</guid>
            <title>servicenow-gcp-spanner v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-spanner-v5-0-0</link>
            <description>_What&apos;s new?_

- Control Types:

  - GCP &gt; Cloud Run &gt; Service &gt; ServiceNow
  - GCP &gt; Cloud Run &gt; Service &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Cloud Run &gt; Service &gt; ServiceNow &gt; Table

- Policy Types:

  - GCP &gt; Cloud Run &gt; Service &gt; ServiceNow
  - GCP &gt; Cloud Run &gt; Service &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Cloud Run &gt; Service &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Cloud Run &gt; Service &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Cloud Run &gt; Service &gt; ServiceNow &gt; Table
  - GCP &gt; Cloud Run &gt; Service &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Thu, 25 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-run-v5-0-0</guid>
            <title>servicenow-gcp-run v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-run-v5-0-0</link>
            <description>_What&apos;s new?_

- Control Types:

  - GCP &gt; Spanner &gt; Database &gt; ServiceNow
  - GCP &gt; Spanner &gt; Database &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Spanner &gt; Database &gt; ServiceNow &gt; Table
  - GCP &gt; Spanner &gt; Instance &gt; ServiceNow
  - GCP &gt; Spanner &gt; Instance &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Spanner &gt; Instance &gt; ServiceNow &gt; Table

- Policy Types:

  - GCP &gt; Spanner &gt; Database &gt; ServiceNow
  - GCP &gt; Spanner &gt; Database &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Spanner &gt; Database &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Spanner &gt; Database &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Spanner &gt; Database &gt; ServiceNow &gt; Table
  - GCP &gt; Spanner &gt; Database &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; Spanner &gt; Instance &gt; ServiceNow
  - GCP &gt; Spanner &gt; Instance &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Spanner &gt; Instance &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Spanner &gt; Instance &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Spanner &gt; Instance &gt; ServiceNow &gt; Table
  - GCP &gt; Spanner &gt; Instance &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Thu, 25 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ec2-v5-38-0</guid>
            <title>aws-ec2 v5.38.0 - You can now configure Volume Type, IOPS Capacity and Throughput for EBS Volumes</title>
            <link>https://turbot.com/guardrails/changelog/aws-ec2-v5-38-0</link>
            <description>_What&apos;s new?_

- Control Types:

  - AWS &gt; EC2 &gt; Volume &gt; Configuration

- Policy Types:

  - AWS &gt; EC2 &gt; Volume &gt; Configuration
  - AWS &gt; EC2 &gt; Volume &gt; Configuration &gt; IOPS Capacity
  - AWS &gt; EC2 &gt; Volume &gt; Configuration &gt; Throughput
  - AWS &gt; EC2 &gt; Volume &gt; Configuration &gt; Type

- Action Types:
  - AWS &gt; EC2 &gt; Volume &gt; Update Configuration</description>
            <pubDate>Thu, 25 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-42-16</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.42.16 - Added MAX_PAYLOAD_SIZE parameter to customize API size limit</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-42-16</link>
            <description>_What&apos;s new?_

- Server
  - You can now update API size limit via the MAX_PAYLOAD_SIZE parameter.

_Requirements_

- TEF: 1.55.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Fri, 19 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-datapipeline-v5-1-0</guid>
            <title>gcp-datapipeline v5.1.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/gcp-datapipeline-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Rebranded to a Turbot Guardrails Mod. To maintain compatibility, none of the existing resource types, control types or policy types have changed, your existing configurations and settings will continue to work as before.</description>
            <pubDate>Fri, 19 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-kinesis-v5-9-0</guid>
            <title>aws-kinesis v5.9.0 - Added support for Kinesis Video Streams</title>
            <link>https://turbot.com/guardrails/changelog/aws-kinesis-v5-9-0</link>
            <description>_What&apos;s new?_

- Resource Types:

  - AWS &gt; Kinesis &gt; Kinesis Video Stream

- Control Types:

  - AWS &gt; Kinesis &gt; Kinesis Video Stream &gt; Active
  - AWS &gt; Kinesis &gt; Kinesis Video Stream &gt; Approved
  - AWS &gt; Kinesis &gt; Kinesis Video Stream &gt; CMDB
  - AWS &gt; Kinesis &gt; Kinesis Video Stream &gt; Discovery
  - AWS &gt; Kinesis &gt; Kinesis Video Stream &gt; Tags

- Policy Types:

  - AWS &gt; Kinesis &gt; Kinesis Video Stream &gt; Active
  - AWS &gt; Kinesis &gt; Kinesis Video Stream &gt; Active &gt; Age
  - AWS &gt; Kinesis &gt; Kinesis Video Stream &gt; Active &gt; Budget
  - AWS &gt; Kinesis &gt; Kinesis Video Stream &gt; Active &gt; Last Modified
  - AWS &gt; Kinesis &gt; Kinesis Video Stream &gt; Approved
  - AWS &gt; Kinesis &gt; Kinesis Video Stream &gt; Approved &gt; Budget
  - AWS &gt; Kinesis &gt; Kinesis Video Stream &gt; Approved &gt; Custom
  - AWS &gt; Kinesis &gt; Kinesis Video Stream &gt; Approved &gt; Regions
  - AWS &gt; Kinesis &gt; Kinesis Video Stream &gt; Approved &gt; Usage
  - AWS &gt; Kinesis &gt; Kinesis Video Stream &gt; CMDB
  - AWS &gt; Kinesis &gt; Kinesis Video Stream &gt; Regions
  - AWS &gt; Kinesis &gt; Kinesis Video Stream &gt; Tags
  - AWS &gt; Kinesis &gt; Kinesis Video Stream &gt; Tags &gt; Template

- Action Types:
  - AWS &gt; Kinesis &gt; Kinesis Video Stream &gt; Delete
  - AWS &gt; Kinesis &gt; Kinesis Video Stream &gt; Delete from AWS
  - AWS &gt; Kinesis &gt; Kinesis Video Stream &gt; Router
  - AWS &gt; Kinesis &gt; Kinesis Video Stream &gt; Set Tags
  - AWS &gt; Kinesis &gt; Kinesis Video Stream &gt; Skip alarm for Active control
  - AWS &gt; Kinesis &gt; Kinesis Video Stream &gt; Skip alarm for Active control [90 days]
  - AWS &gt; Kinesis &gt; Kinesis Video Stream &gt; Skip alarm for Approved control
  - AWS &gt; Kinesis &gt; Kinesis Video Stream &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; Kinesis &gt; Kinesis Video Stream &gt; Skip alarm for Tags control
  - AWS &gt; Kinesis &gt; Kinesis Video Stream &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; Kinesis &gt; Kinesis Video Stream &gt; Update Tags</description>
            <pubDate>Fri, 19 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-logging-v5-0-0</guid>
            <title>servicenow-gcp-logging v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-logging-v5-0-0</link>
            <description>_What&apos;s new?_

- Control Types:

  - GCP &gt; Logging &gt; Exclusion &gt; ServiceNow
  - GCP &gt; Logging &gt; Exclusion &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Logging &gt; Exclusion &gt; ServiceNow &gt; Table
  - GCP &gt; Logging &gt; Metric &gt; ServiceNow
  - GCP &gt; Logging &gt; Metric &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Logging &gt; Metric &gt; ServiceNow &gt; Table
  - GCP &gt; Logging &gt; Sink &gt; ServiceNow
  - GCP &gt; Logging &gt; Sink &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Logging &gt; Sink &gt; ServiceNow &gt; Table

- Policy Types:

  - GCP &gt; Logging &gt; Exclusion &gt; ServiceNow
  - GCP &gt; Logging &gt; Exclusion &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Logging &gt; Exclusion &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Logging &gt; Exclusion &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Logging &gt; Exclusion &gt; ServiceNow &gt; Table
  - GCP &gt; Logging &gt; Exclusion &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; Logging &gt; Metric &gt; ServiceNow
  - GCP &gt; Logging &gt; Metric &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Logging &gt; Metric &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Logging &gt; Metric &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Logging &gt; Metric &gt; ServiceNow &gt; Table
  - GCP &gt; Logging &gt; Metric &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; Logging &gt; Sink &gt; ServiceNow
  - GCP &gt; Logging &gt; Sink &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Logging &gt; Sink &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Logging &gt; Sink &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Logging &gt; Sink &gt; ServiceNow &gt; Table
  - GCP &gt; Logging &gt; Sink &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Thu, 18 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-computeengine-v5-1-0</guid>
            <title>servicenow-gcp-computeengine v5.1.0 - Added support for HTTP Health Check, HTTPS Health Check, Health Check, Instance Template, Node Group, Node Template, Project, Region Disk and Region Health Check</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-computeengine-v5-1-0</link>
            <description>_What&apos;s new?_

- Control Types:

  - GCP &gt; Compute Engine &gt; HTTP Health Check &gt; ServiceNow
  - GCP &gt; Compute Engine &gt; HTTP Health Check &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Compute Engine &gt; HTTP Health Check &gt; ServiceNow &gt; Table
  - GCP &gt; Compute Engine &gt; HTTPS Health Check &gt; ServiceNow
  - GCP &gt; Compute Engine &gt; HTTPS Health Check &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Compute Engine &gt; HTTPS Health Check &gt; ServiceNow &gt; Table
  - GCP &gt; Compute Engine &gt; Health Check &gt; ServiceNow
  - GCP &gt; Compute Engine &gt; Health Check &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Compute Engine &gt; Health Check &gt; ServiceNow &gt; Table
  - GCP &gt; Compute Engine &gt; Instance Template &gt; ServiceNow
  - GCP &gt; Compute Engine &gt; Instance Template &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Compute Engine &gt; Instance Template &gt; ServiceNow &gt; Table
  - GCP &gt; Compute Engine &gt; Node Group &gt; ServiceNow
  - GCP &gt; Compute Engine &gt; Node Group &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Compute Engine &gt; Node Group &gt; ServiceNow &gt; Table
  - GCP &gt; Compute Engine &gt; Node Template &gt; ServiceNow
  - GCP &gt; Compute Engine &gt; Node Template &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Compute Engine &gt; Node Template &gt; ServiceNow &gt; Table
  - GCP &gt; Compute Engine &gt; Project &gt; ServiceNow
  - GCP &gt; Compute Engine &gt; Project &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Compute Engine &gt; Project &gt; ServiceNow &gt; Table
  - GCP &gt; Compute Engine &gt; Region Disk &gt; ServiceNow
  - GCP &gt; Compute Engine &gt; Region Disk &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Compute Engine &gt; Region Disk &gt; ServiceNow &gt; Table
  - GCP &gt; Compute Engine &gt; Region Health Check &gt; ServiceNow
  - GCP &gt; Compute Engine &gt; Region Health Check &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Compute Engine &gt; Region Health Check &gt; ServiceNow &gt; Table

- Policy Types:

  - GCP &gt; Compute Engine &gt; HTTP Health Check &gt; ServiceNow
  - GCP &gt; Compute Engine &gt; HTTP Health Check &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Compute Engine &gt; HTTP Health Check &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Compute Engine &gt; HTTP Health Check &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Compute Engine &gt; HTTP Health Check &gt; ServiceNow &gt; Table
  - GCP &gt; Compute Engine &gt; HTTP Health Check &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; Compute Engine &gt; HTTPS Health Check &gt; ServiceNow
  - GCP &gt; Compute Engine &gt; HTTPS Health Check &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Compute Engine &gt; HTTPS Health Check &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Compute Engine &gt; HTTPS Health Check &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Compute Engine &gt; HTTPS Health Check &gt; ServiceNow &gt; Table
  - GCP &gt; Compute Engine &gt; HTTPS Health Check &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; Compute Engine &gt; Health Check &gt; ServiceNow
  - GCP &gt; Compute Engine &gt; Health Check &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Compute Engine &gt; Health Check &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Compute Engine &gt; Health Check &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Compute Engine &gt; Health Check &gt; ServiceNow &gt; Table
  - GCP &gt; Compute Engine &gt; Health Check &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; Compute Engine &gt; Instance Template &gt; ServiceNow
  - GCP &gt; Compute Engine &gt; Instance Template &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Compute Engine &gt; Instance Template &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Compute Engine &gt; Instance Template &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Compute Engine &gt; Instance Template &gt; ServiceNow &gt; Table
  - GCP &gt; Compute Engine &gt; Instance Template &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; Compute Engine &gt; Node Group &gt; ServiceNow
  - GCP &gt; Compute Engine &gt; Node Group &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Compute Engine &gt; Node Group &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Compute Engine &gt; Node Group &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Compute Engine &gt; Node Group &gt; ServiceNow &gt; Table
  - GCP &gt; Compute Engine &gt; Node Group &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; Compute Engine &gt; Node Template &gt; ServiceNow
  - GCP &gt; Compute Engine &gt; Node Template &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Compute Engine &gt; Node Template &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Compute Engine &gt; Node Template &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Compute Engine &gt; Node Template &gt; ServiceNow &gt; Table
  - GCP &gt; Compute Engine &gt; Node Template &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; Compute Engine &gt; Project &gt; ServiceNow
  - GCP &gt; Compute Engine &gt; Project &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Compute Engine &gt; Project &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Compute Engine &gt; Project &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Compute Engine &gt; Project &gt; ServiceNow &gt; Table
  - GCP &gt; Compute Engine &gt; Project &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; Compute Engine &gt; Region Disk &gt; ServiceNow
  - GCP &gt; Compute Engine &gt; Region Disk &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Compute Engine &gt; Region Disk &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Compute Engine &gt; Region Disk &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Compute Engine &gt; Region Disk &gt; ServiceNow &gt; Table
  - GCP &gt; Compute Engine &gt; Region Disk &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; Compute Engine &gt; Region Health Check &gt; ServiceNow
  - GCP &gt; Compute Engine &gt; Region Health Check &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Compute Engine &gt; Region Health Check &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Compute Engine &gt; Region Health Check &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Compute Engine &gt; Region Health Check &gt; ServiceNow &gt; Table
  - GCP &gt; Compute Engine &gt; Region Health Check &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Thu, 18 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/turbot-v5-47-0</guid>
            <title>turbot v5.47.0 - Added policy to set native stack version</title>
            <link>https://turbot.com/guardrails/changelog/turbot-v5-47-0</link>
            <description>_What&apos;s new?_

- Policy Types:
  - Turbot &gt; Stack &gt; Native Stack Version [Default]

_Requirements_

- TE: 5.35.4</description>
            <pubDate>Wed, 17 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-sql-v5-1-0</guid>
            <title>servicenow-gcp-sql v5.1.0 - Added support for Backup and Database</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-sql-v5-1-0</link>
            <description>_What&apos;s new?_

- Control Types:

  - GCP &gt; SQL &gt; Backup &gt; ServiceNow
  - GCP &gt; SQL &gt; Backup &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; SQL &gt; Backup &gt; ServiceNow &gt; Table
  - GCP &gt; SQL &gt; Database &gt; ServiceNow
  - GCP &gt; SQL &gt; Database &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; SQL &gt; Database &gt; ServiceNow &gt; Table

- Policy Types:

  - GCP &gt; SQL &gt; Backup &gt; ServiceNow
  - GCP &gt; SQL &gt; Backup &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; SQL &gt; Backup &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; SQL &gt; Backup &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; SQL &gt; Backup &gt; ServiceNow &gt; Table
  - GCP &gt; SQL &gt; Backup &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; SQL &gt; Database &gt; ServiceNow
  - GCP &gt; SQL &gt; Database &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; SQL &gt; Database &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; SQL &gt; Database &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; SQL &gt; Database &gt; ServiceNow &gt; Table
  - GCP &gt; SQL &gt; Database &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Wed, 17 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-kms-v5-0-0</guid>
            <title>servicenow-gcp-kms v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-kms-v5-0-0</link>
            <description>_What&apos;s new?_

- Control Types:

  - GCP &gt; KMS &gt; Crypto Key &gt; ServiceNow
  - GCP &gt; KMS &gt; Crypto Key &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; KMS &gt; Crypto Key &gt; ServiceNow &gt; Table
  - GCP &gt; KMS &gt; Key Ring &gt; ServiceNow
  - GCP &gt; KMS &gt; Key Ring &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; KMS &gt; Key Ring &gt; ServiceNow &gt; Table

- Policy Types:

  - GCP &gt; KMS &gt; Crypto Key &gt; ServiceNow
  - GCP &gt; KMS &gt; Crypto Key &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; KMS &gt; Crypto Key &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; KMS &gt; Crypto Key &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; KMS &gt; Crypto Key &gt; ServiceNow &gt; Table
  - GCP &gt; KMS &gt; Crypto Key &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; KMS &gt; Key Ring &gt; ServiceNow
  - GCP &gt; KMS &gt; Key Ring &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; KMS &gt; Key Ring &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; KMS &gt; Key Ring &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; KMS &gt; Key Ring &gt; ServiceNow &gt; Table
  - GCP &gt; KMS &gt; Key Ring &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Wed, 17 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-bigquery-v5-0-0</guid>
            <title>servicenow-gcp-bigquery v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-bigquery-v5-0-0</link>
            <description>_What&apos;s new?_

- Control Types:

  - GCP &gt; BigQuery &gt; Dataset &gt; ServiceNow
  - GCP &gt; BigQuery &gt; Dataset &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; BigQuery &gt; Dataset &gt; ServiceNow &gt; Table
  - GCP &gt; BigQuery &gt; Table &gt; ServiceNow
  - GCP &gt; BigQuery &gt; Table &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; BigQuery &gt; Table &gt; ServiceNow &gt; Table

- Policy Types:

  - GCP &gt; BigQuery &gt; Dataset &gt; ServiceNow
  - GCP &gt; BigQuery &gt; Dataset &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; BigQuery &gt; Dataset &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; BigQuery &gt; Dataset &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; BigQuery &gt; Dataset &gt; ServiceNow &gt; Table
  - GCP &gt; BigQuery &gt; Dataset &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; BigQuery &gt; Table &gt; ServiceNow
  - GCP &gt; BigQuery &gt; Table &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; BigQuery &gt; Table &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; BigQuery &gt; Table &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; BigQuery &gt; Table &gt; ServiceNow &gt; Table
  - GCP &gt; BigQuery &gt; Table &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Wed, 17 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-42-15</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.42.15 - Minor internal improvements</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-42-15</link>
            <description>_Bug fixes_

- Server
  - Updated: Enhanced IAM policy for tighter access around custom Lambda.
  - Fixed: Turbot &gt; Workspace &gt; Health Control should not break if there is no input.

_Requirements_

- TEF: 1.55.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Tue, 16 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-bigtable-v5-0-0</guid>
            <title>servicenow-gcp-bigtable v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-bigtable-v5-0-0</link>
            <description>_What&apos;s new?_

- Control Types:

  - GCP &gt; Bigtable &gt; Cluster &gt; ServiceNow
  - GCP &gt; Bigtable &gt; Cluster &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Bigtable &gt; Cluster &gt; ServiceNow &gt; Table
  - GCP &gt; Bigtable &gt; Instance &gt; ServiceNow
  - GCP &gt; Bigtable &gt; Instance &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Bigtable &gt; Instance &gt; ServiceNow &gt; Table
  - GCP &gt; Bigtable &gt; Table &gt; ServiceNow
  - GCP &gt; Bigtable &gt; Table &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Bigtable &gt; Table &gt; ServiceNow &gt; Table

- Policy Types:

  - GCP &gt; Bigtable &gt; Cluster &gt; ServiceNow
  - GCP &gt; Bigtable &gt; Cluster &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Bigtable &gt; Cluster &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Bigtable &gt; Cluster &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Bigtable &gt; Cluster &gt; ServiceNow &gt; Table
  - GCP &gt; Bigtable &gt; Cluster &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; Bigtable &gt; Instance &gt; ServiceNow
  - GCP &gt; Bigtable &gt; Instance &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Bigtable &gt; Instance &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Bigtable &gt; Instance &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Bigtable &gt; Instance &gt; ServiceNow &gt; Table
  - GCP &gt; Bigtable &gt; Instance &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; Bigtable &gt; Table &gt; ServiceNow
  - GCP &gt; Bigtable &gt; Table &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Bigtable &gt; Table &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Bigtable &gt; Table &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Bigtable &gt; Table &gt; ServiceNow &gt; Table
  - GCP &gt; Bigtable &gt; Table &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Tue, 16 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-appengine-v5-0-0</guid>
            <title>servicenow-gcp-appengine v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-appengine-v5-0-0</link>
            <description>_What&apos;s new?_

- Control Types:

  - GCP &gt; App Engine &gt; Application &gt; ServiceNow
  - GCP &gt; App Engine &gt; Application &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; App Engine &gt; Application &gt; ServiceNow &gt; Table
  - GCP &gt; App Engine &gt; Firewall Rule &gt; ServiceNow
  - GCP &gt; App Engine &gt; Firewall Rule &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; App Engine &gt; Firewall Rule &gt; ServiceNow &gt; Table
  - GCP &gt; App Engine &gt; Instance &gt; ServiceNow
  - GCP &gt; App Engine &gt; Instance &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; App Engine &gt; Instance &gt; ServiceNow &gt; Table
  - GCP &gt; App Engine &gt; Service &gt; ServiceNow
  - GCP &gt; App Engine &gt; Service &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; App Engine &gt; Service &gt; ServiceNow &gt; Table
  - GCP &gt; App Engine &gt; Version &gt; ServiceNow
  - GCP &gt; App Engine &gt; Version &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; App Engine &gt; Version &gt; ServiceNow &gt; Table

- Policy Types:

  - GCP &gt; App Engine &gt; Application &gt; ServiceNow
  - GCP &gt; App Engine &gt; Application &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; App Engine &gt; Application &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; App Engine &gt; Application &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; App Engine &gt; Application &gt; ServiceNow &gt; Table
  - GCP &gt; App Engine &gt; Application &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; App Engine &gt; Firewall Rule &gt; ServiceNow
  - GCP &gt; App Engine &gt; Firewall Rule &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; App Engine &gt; Firewall Rule &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; App Engine &gt; Firewall Rule &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; App Engine &gt; Firewall Rule &gt; ServiceNow &gt; Table
  - GCP &gt; App Engine &gt; Firewall Rule &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; App Engine &gt; Instance &gt; ServiceNow
  - GCP &gt; App Engine &gt; Instance &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; App Engine &gt; Instance &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; App Engine &gt; Instance &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; App Engine &gt; Instance &gt; ServiceNow &gt; Table
  - GCP &gt; App Engine &gt; Instance &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; App Engine &gt; Service &gt; ServiceNow
  - GCP &gt; App Engine &gt; Service &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; App Engine &gt; Service &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; App Engine &gt; Service &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; App Engine &gt; Service &gt; ServiceNow &gt; Table
  - GCP &gt; App Engine &gt; Service &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; App Engine &gt; Version &gt; ServiceNow
  - GCP &gt; App Engine &gt; Version &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; App Engine &gt; Version &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; App Engine &gt; Version &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; App Engine &gt; Version &gt; ServiceNow &gt; Table
  - GCP &gt; App Engine &gt; Version &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Tue, 16 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-v5-23-2</guid>
            <title>gcp v5.23.2 - Bug Fixed - Event Poller control will now run lighter and quicker than before</title>
            <link>https://turbot.com/guardrails/changelog/gcp-v5-23-2</link>
            <description>_Bug fixes_

- The `GCP &gt; Turbot &gt; Event Poller` control now includes a precheck condition to avoid running GraphQL input queries when the `GCP &gt; Turbot &gt; Event Poller` policy is set to `Disabled`. You won’t notice any difference and the control should run lighter and quicker than before.</description>
            <pubDate>Tue, 16 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-v5-18-1</guid>
            <title>azure v5.18.1 - Bug Fixed - Event Poller controls will now run lighter and quicker than before</title>
            <link>https://turbot.com/guardrails/changelog/azure-v5-18-1</link>
            <description>_Bug fixes_

- The `Azure &gt; Turbot &gt; Event Poller` and `Azure &gt; Turbot &gt; Management Group Event Poller` controls now include a precheck condition to avoid running GraphQL input queries when the `Azure &gt; Turbot &gt; Event Poller` and `Azure &gt; Turbot &gt; Management Group Event Poller` policies are set to `Disabled` respectively. You won’t notice any difference and the controls should run lighter and quicker than before.</description>
            <pubDate>Tue, 16 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-activedirectory-v5-4-1</guid>
            <title>azure-activedirectory v5.4.1 - Bug Fixed - Event Poller control will now run lighter and quicker than before</title>
            <link>https://turbot.com/guardrails/changelog/azure-activedirectory-v5-4-1</link>
            <description>_Bug fixes_

- The `Azure &gt; Turbot &gt; Directory Event Poller` control now includes a precheck condition to avoid running GraphQL input queries when the `Azure &gt; Turbot &gt; Directory Event Poller` policy is set to `Disabled`. You won’t notice any difference and the control should run lighter and quicker than before.</description>
            <pubDate>Tue, 16 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-v5-29-2</guid>
            <title>aws v5.29.2 - Bug Fixed - Event Poller control will now run lighter and quicker than before</title>
            <link>https://turbot.com/guardrails/changelog/aws-v5-29-2</link>
            <description>_Bug fixes_

- The `AWS &gt; Turbot &gt; Event Poller` control now includes a precheck condition to avoid running GraphQL input queries when the `AWS &gt; Turbot &gt; Event Poller` policy is set to `Disabled`. You won’t notice any difference and the control should run lighter and quicker than before.</description>
            <pubDate>Tue, 16 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-opensearch-v5-0-0</guid>
            <title>aws-opensearch v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/aws-opensearch-v5-0-0</link>
            <description>_What&apos;s new?_

- Resource Types:
  - AWS &gt; OpenSearch

- Policy Types:
  - AWS &gt; OpenSearch &gt; API Enabled
  - AWS &gt; OpenSearch &gt; Approved Regions [Default]
  - AWS &gt; OpenSearch &gt; Enabled
  - AWS &gt; OpenSearch &gt; Permissions
  - AWS &gt; OpenSearch &gt; Permissions &gt; Levels
  - AWS &gt; OpenSearch &gt; Permissions &gt; Levels &gt; Modifiers
  - AWS &gt; OpenSearch &gt; Permissions &gt; Lockdown
  - AWS &gt; OpenSearch &gt; Permissions &gt; Lockdown &gt; API Boundary
  - AWS &gt; OpenSearch &gt; Regions
  - AWS &gt; OpenSearch &gt; Tags Template [Default]
  - AWS &gt; Turbot &gt; Permissions &gt; Compiled &gt; API Boundary &gt; @turbot/aws-opensearch
  - AWS &gt; Turbot &gt; Permissions &gt; Compiled &gt; Levels &gt; @turbot/aws-opensearch
  - AWS &gt; Turbot &gt; Permissions &gt; Compiled &gt; Service Permissions &gt; @turbot/aws-opensearch</description>
            <pubDate>Tue, 16 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-v5-1-0</guid>
            <title>servicenow-azure v5.1.0 - Added support for Resource Group, Subscription and Tenant</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-v5-1-0</link>
            <description>_What&apos;s new?_

- Control Types:

  - Azure &gt; Resource Group &gt; ServiceNow
  - Azure &gt; Resource Group &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Resource Group &gt; ServiceNow &gt; Table
  - Azure &gt; Subscription &gt; ServiceNow
  - Azure &gt; Subscription &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Subscription &gt; ServiceNow &gt; Table
  - Azure &gt; Tenant &gt; ServiceNow
  - Azure &gt; Tenant &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Tenant &gt; ServiceNow &gt; Table

- Policy Types:
  - Azure &gt; Resource Group &gt; ServiceNow
  - Azure &gt; Resource Group &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Resource Group &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Resource Group &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Resource Group &gt; ServiceNow &gt; Table
  - Azure &gt; Resource Group &gt; ServiceNow &gt; Table &gt; Definition
  - Azure &gt; Subscription &gt; ServiceNow
  - Azure &gt; Subscription &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Subscription &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Subscription &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Subscription &gt; ServiceNow &gt; Table
  - Azure &gt; Subscription &gt; ServiceNow &gt; Table &gt; Definition
  - Azure &gt; Tenant &gt; ServiceNow
  - Azure &gt; Tenant &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Tenant &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Tenant &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Tenant &gt; ServiceNow &gt; Table
  - Azure &gt; Tenant &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Fri, 12 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-network-v5-2-0</guid>
            <title>servicenow-azure-network v5.2.0 - Added support for Private Endpoints</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-network-v5-2-0</link>
            <description>_What&apos;s new?_

- Control Types:

  - Azure &gt; Network &gt; Private Endpoints &gt; ServiceNow
  - Azure &gt; Network &gt; Private Endpoints &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Network &gt; Private Endpoints &gt; ServiceNow &gt; Table

- Policy Types:
  - Azure &gt; Network &gt; Private Endpoints &gt; ServiceNow
  - Azure &gt; Network &gt; Private Endpoints &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Network &gt; Private Endpoints &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Network &gt; Private Endpoints &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Network &gt; Private Endpoints &gt; ServiceNow &gt; Table
  - Azure &gt; Network &gt; Private Endpoints &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Thu, 11 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-automation-v5-0-0</guid>
            <title>servicenow-azure-automation v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-automation-v5-0-0</link>
            <description>_What&apos;s new?_

- Control Types:

  - Azure &gt; Automation &gt; Automation Account &gt; ServiceNow
  - Azure &gt; Automation &gt; Automation Account &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Automation &gt; Automation Account &gt; ServiceNow &gt; Table
  - Azure &gt; Automation &gt; Runbook &gt; ServiceNow
  - Azure &gt; Automation &gt; Runbook &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Automation &gt; Runbook &gt; ServiceNow &gt; Table

- Policy Types:
  - Azure &gt; Automation &gt; Automation Account &gt; ServiceNow
  - Azure &gt; Automation &gt; Automation Account &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Automation &gt; Automation Account &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Automation &gt; Automation Account &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Automation &gt; Automation Account &gt; ServiceNow &gt; Table
  - Azure &gt; Automation &gt; Automation Account &gt; ServiceNow &gt; Table &gt; Definition
  - Azure &gt; Automation &gt; Runbook &gt; ServiceNow
  - Azure &gt; Automation &gt; Runbook &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Automation &gt; Runbook &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Automation &gt; Runbook &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Automation &gt; Runbook &gt; ServiceNow &gt; Table
  - Azure &gt; Automation &gt; Runbook &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Thu, 11 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ec2-v5-37-0</guid>
            <title>aws-ec2 v5.37.0 - Added support for `aws_network_interface_sg_attachment` Terraform resource for Elastic Network Interfaces</title>
            <link>https://turbot.com/guardrails/changelog/aws-ec2-v5-37-0</link>
            <description>_What&apos;s new?_

- Added support for `aws_network_interface_sg_attachment` Terraform resource for `AWS &gt; EC2 &gt; Network Interface`.

_Bug fixes_

- The `AWS &gt; EC2 &gt; Instance &gt; CMDB` control would sometimes trigger multiple times if `EnclaveOptions` was not set as part of the `AWS &gt; EC2 &gt; Instance &gt; CMDB &gt; Attributes` policy. This would result in unnecessary Lambda runs for the control. The `EnclaveOptions` attribute is now available in the CMDB data by default and the `EnclaveOptions` policy value in `AWS &gt; EC2 &gt; Instance &gt; CMDB &gt; Attributes` policy has now been deprecated, and will be removed in the next major version.</description>
            <pubDate>Thu, 11 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-54-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.54.0 - Updated Launch Template to prevent association of Network Interface with public IPs</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-54-0</link>
            <description>_What&apos;s new?_

- Updated: Launch Template to prevent association of Network Interface with public IPs.</description>
            <pubDate>Wed, 10 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-storage-v5-1-0</guid>
            <title>servicenow-azure-storage v5.1.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-storage-v5-1-0</link>
            <description>_What&apos;s new?_

- Control Types:

  - Azure &gt; Storage &gt; Container &gt; ServiceNow
  - Azure &gt; Storage &gt; Container &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Storage &gt; Container &gt; ServiceNow &gt; Table
  - Azure &gt; Storage &gt; FileShare &gt; ServiceNow
  - Azure &gt; Storage &gt; FileShare &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Storage &gt; FileShare &gt; ServiceNow &gt; Table
  - Azure &gt; Storage &gt; Queue &gt; ServiceNow
  - Azure &gt; Storage &gt; Queue &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Storage &gt; Queue &gt; ServiceNow &gt; Table

- Policy Types:
  - Azure &gt; Storage &gt; Container &gt; ServiceNow
  - Azure &gt; Storage &gt; Container &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Storage &gt; Container &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Storage &gt; Container &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Storage &gt; Container &gt; ServiceNow &gt; Table
  - Azure &gt; Storage &gt; Container &gt; ServiceNow &gt; Table &gt; Definition
  - Azure &gt; Storage &gt; FileShare &gt; ServiceNow
  - Azure &gt; Storage &gt; FileShare &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Storage &gt; FileShare &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Storage &gt; FileShare &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Storage &gt; FileShare &gt; ServiceNow &gt; Table
  - Azure &gt; Storage &gt; FileShare &gt; ServiceNow &gt; Table &gt; Definition
  - Azure &gt; Storage &gt; Queue &gt; ServiceNow
  - Azure &gt; Storage &gt; Queue &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Storage &gt; Queue &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Storage &gt; Queue &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Storage &gt; Queue &gt; ServiceNow &gt; Table
  - Azure &gt; Storage &gt; Queue &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Wed, 10 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-recoveryservice-v5-0-0</guid>
            <title>servicenow-azure-recoveryservice v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-recoveryservice-v5-0-0</link>
            <description>_What&apos;s new?_

- Control Types:

  - Azure &gt; Recovery Service &gt; Backup &gt; ServiceNow
  - Azure &gt; Recovery Service &gt; Backup &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Recovery Service &gt; Backup &gt; ServiceNow &gt; Table
  - Azure &gt; Recovery Service &gt; Vault &gt; ServiceNow
  - Azure &gt; Recovery Service &gt; Vault &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Recovery Service &gt; Vault &gt; ServiceNow &gt; Table

- Policy Types:
  - Azure &gt; Recovery Service &gt; Backup &gt; ServiceNow
  - Azure &gt; Recovery Service &gt; Backup &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Recovery Service &gt; Backup &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Recovery Service &gt; Backup &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Recovery Service &gt; Backup &gt; ServiceNow &gt; Table
  - Azure &gt; Recovery Service &gt; Backup &gt; ServiceNow &gt; Table &gt; Definition
  - Azure &gt; Recovery Service &gt; Vault &gt; ServiceNow
  - Azure &gt; Recovery Service &gt; Vault &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Recovery Service &gt; Vault &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Recovery Service &gt; Vault &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Recovery Service &gt; Vault &gt; ServiceNow &gt; Table
  - Azure &gt; Recovery Service &gt; Vault &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Wed, 10 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-monitor-v5-0-0</guid>
            <title>servicenow-azure-monitor v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-monitor-v5-0-0</link>
            <description>_What&apos;s new?_

- Control Types:

  - Azure &gt; Monitor &gt; Action Group &gt; ServiceNow
  - Azure &gt; Monitor &gt; Action Group &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Monitor &gt; Action Group &gt; ServiceNow &gt; Table
  - Azure &gt; Monitor &gt; Alerts &gt; ServiceNow
  - Azure &gt; Monitor &gt; Alerts &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Monitor &gt; Alerts &gt; ServiceNow &gt; Table
  - Azure &gt; Monitor &gt; Log Profile &gt; ServiceNow
  - Azure &gt; Monitor &gt; Log Profile &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Monitor &gt; Log Profile &gt; ServiceNow &gt; Table

- Policy Types:
  - Azure &gt; Monitor &gt; Action Group &gt; ServiceNow
  - Azure &gt; Monitor &gt; Action Group &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Monitor &gt; Action Group &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Monitor &gt; Action Group &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Monitor &gt; Action Group &gt; ServiceNow &gt; Table
  - Azure &gt; Monitor &gt; Action Group &gt; ServiceNow &gt; Table &gt; Definition
  - Azure &gt; Monitor &gt; Alerts &gt; ServiceNow
  - Azure &gt; Monitor &gt; Alerts &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Monitor &gt; Alerts &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Monitor &gt; Alerts &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Monitor &gt; Alerts &gt; ServiceNow &gt; Table
  - Azure &gt; Monitor &gt; Alerts &gt; ServiceNow &gt; Table &gt; Definition
  - Azure &gt; Monitor &gt; Log Profile &gt; ServiceNow
  - Azure &gt; Monitor &gt; Log Profile &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Monitor &gt; Log Profile &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Monitor &gt; Log Profile &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Monitor &gt; Log Profile &gt; ServiceNow &gt; Table
  - Azure &gt; Monitor &gt; Log Profile &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Wed, 10 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-kubernetesengine-v5-0-0</guid>
            <title>servicenow-gcp-kubernetesengine v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-kubernetesengine-v5-0-0</link>
            <description>_What&apos;s new?_

- Control Types:

  - GCP &gt; Kubernetes Engine &gt; Region Cluster &gt; ServiceNow
  - GCP &gt; Kubernetes Engine &gt; Region Cluster &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Kubernetes Engine &gt; Region Cluster &gt; ServiceNow &gt; Table
  - GCP &gt; Kubernetes Engine &gt; Region Node Pool &gt; ServiceNow
  - GCP &gt; Kubernetes Engine &gt; Region Node Pool &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Kubernetes Engine &gt; Region Node Pool &gt; ServiceNow &gt; Table
  - GCP &gt; Kubernetes Engine &gt; Zone Cluster &gt; ServiceNow
  - GCP &gt; Kubernetes Engine &gt; Zone Cluster &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Kubernetes Engine &gt; Zone Cluster &gt; ServiceNow &gt; Table
  - GCP &gt; Kubernetes Engine &gt; Zone Node Pool &gt; ServiceNow
  - GCP &gt; Kubernetes Engine &gt; Zone Node Pool &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Kubernetes Engine &gt; Zone Node Pool &gt; ServiceNow &gt; Table

- Policy Types:

  - GCP &gt; Kubernetes Engine &gt; Region Cluster &gt; ServiceNow
  - GCP &gt; Kubernetes Engine &gt; Region Cluster &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Kubernetes Engine &gt; Region Cluster &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Kubernetes Engine &gt; Region Cluster &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Kubernetes Engine &gt; Region Cluster &gt; ServiceNow &gt; Table
  - GCP &gt; Kubernetes Engine &gt; Region Cluster &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; Kubernetes Engine &gt; Region Node Pool &gt; ServiceNow
  - GCP &gt; Kubernetes Engine &gt; Region Node Pool &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Kubernetes Engine &gt; Region Node Pool &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Kubernetes Engine &gt; Region Node Pool &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Kubernetes Engine &gt; Region Node Pool &gt; ServiceNow &gt; Table
  - GCP &gt; Kubernetes Engine &gt; Region Node Pool &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; Kubernetes Engine &gt; Zone Cluster &gt; ServiceNow
  - GCP &gt; Kubernetes Engine &gt; Zone Cluster &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Kubernetes Engine &gt; Zone Cluster &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Kubernetes Engine &gt; Zone Cluster &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Kubernetes Engine &gt; Zone Cluster &gt; ServiceNow &gt; Table
  - GCP &gt; Kubernetes Engine &gt; Zone Cluster &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; Kubernetes Engine &gt; Zone Node Pool &gt; ServiceNow
  - GCP &gt; Kubernetes Engine &gt; Zone Node Pool &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Kubernetes Engine &gt; Zone Node Pool &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Kubernetes Engine &gt; Zone Node Pool &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Kubernetes Engine &gt; Zone Node Pool &gt; ServiceNow &gt; Table
  - GCP &gt; Kubernetes Engine &gt; Zone Node Pool &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Tue, 09 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-iam-v5-0-0</guid>
            <title>servicenow-azure-iam v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-iam-v5-0-0</link>
            <description>_What&apos;s new?_

- Control Types:

  - Azure &gt; IAM &gt; Role Assignment &gt; ServiceNow
  - Azure &gt; IAM &gt; Role Assignment &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; IAM &gt; Role Assignment &gt; ServiceNow &gt; Table
  - Azure &gt; IAM &gt; Role Definition &gt; ServiceNow
  - Azure &gt; IAM &gt; Role Definition &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; IAM &gt; Role Definition &gt; ServiceNow &gt; Table

- Policy Types:
  - Azure &gt; IAM &gt; Role Assignment &gt; ServiceNow
  - Azure &gt; IAM &gt; Role Assignment &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; IAM &gt; Role Assignment &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; IAM &gt; Role Assignment &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; IAM &gt; Role Assignment &gt; ServiceNow &gt; Table
  - Azure &gt; IAM &gt; Role Assignment &gt; ServiceNow &gt; Table &gt; Definition
  - Azure &gt; IAM &gt; Role Definition &gt; ServiceNow
  - Azure &gt; IAM &gt; Role Definition &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; IAM &gt; Role Definition &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; IAM &gt; Role Definition &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; IAM &gt; Role Definition &gt; ServiceNow &gt; Table
  - Azure &gt; IAM &gt; Role Definition &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Tue, 09 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-datafactory-v5-0-0</guid>
            <title>servicenow-azure-datafactory v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-datafactory-v5-0-0</link>
            <description>_What&apos;s new?_

- Control Types:

  - Azure &gt; Data Factory &gt; Dataset &gt; ServiceNow
  - Azure &gt; Data Factory &gt; Dataset &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Data Factory &gt; Dataset &gt; ServiceNow &gt; Table
  - Azure &gt; Data Factory &gt; Factory &gt; ServiceNow
  - Azure &gt; Data Factory &gt; Factory &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Data Factory &gt; Factory &gt; ServiceNow &gt; Table
  - Azure &gt; Data Factory &gt; Pipeline &gt; ServiceNow
  - Azure &gt; Data Factory &gt; Pipeline &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Data Factory &gt; Pipeline &gt; ServiceNow &gt; Table

- Policy Types:
  - Azure &gt; Data Factory &gt; Dataset &gt; ServiceNow
  - Azure &gt; Data Factory &gt; Dataset &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Data Factory &gt; Dataset &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Data Factory &gt; Dataset &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Data Factory &gt; Dataset &gt; ServiceNow &gt; Table
  - Azure &gt; Data Factory &gt; Dataset &gt; ServiceNow &gt; Table &gt; Definition
  - Azure &gt; Data Factory &gt; Factory &gt; ServiceNow
  - Azure &gt; Data Factory &gt; Factory &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Data Factory &gt; Factory &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Data Factory &gt; Factory &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Data Factory &gt; Factory &gt; ServiceNow &gt; Table
  - Azure &gt; Data Factory &gt; Factory &gt; ServiceNow &gt; Table &gt; Definition
  - Azure &gt; Data Factory &gt; Pipeline &gt; ServiceNow
  - Azure &gt; Data Factory &gt; Pipeline &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Data Factory &gt; Pipeline &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Data Factory &gt; Pipeline &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Data Factory &gt; Pipeline &gt; ServiceNow &gt; Table
  - Azure &gt; Data Factory &gt; Pipeline &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Tue, 09 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-databricks-v5-0-0</guid>
            <title>servicenow-azure-databricks v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-databricks-v5-0-0</link>
            <description>_What&apos;s new?_

- Control Types:

  - Azure &gt; Databricks &gt; Workspace &gt; ServiceNow
  - Azure &gt; Databricks &gt; Workspace &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Databricks &gt; Workspace &gt; ServiceNow &gt; Table

- Policy Types:
  - Azure &gt; Databricks &gt; Workspace &gt; ServiceNow
  - Azure &gt; Databricks &gt; Workspace &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Databricks &gt; Workspace &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Databricks &gt; Workspace &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Databricks &gt; Workspace &gt; ServiceNow &gt; Table
  - Azure &gt; Databricks &gt; Workspace &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Tue, 09 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-42-14</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.42.14 - Minor internal improvements</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-42-14</link>
            <description>_Bug fixes_

- Server
  - Minor internal improvements.

_Requirements_

- TEF: 1.51.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Tue, 09 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-42-13</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.42.13 - Bug Fixed - Scheduled actions will now not fail for firehose-aws-sns mod</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-42-13</link>
            <description>_Bug fixes_

- Server
  - The scheduled actions would sometimes fail to work for the firehose-aws-sns mod due an inadvertent bug introduced in TE v5.42.10. This is now fixed.

_Requirements_

- TEF: 1.51.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Mon, 08 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-activedirectory-v5-0-0</guid>
            <title>servicenow-azure-activedirectory v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-activedirectory-v5-0-0</link>
            <description>_What&apos;s new?_

- Control Types:

  - Azure &gt; Active Directory &gt; Application &gt; ServiceNow
  - Azure &gt; Active Directory &gt; Application &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Active Directory &gt; Application &gt; ServiceNow &gt; Table
  - Azure &gt; Active Directory &gt; Client Secret &gt; ServiceNow
  - Azure &gt; Active Directory &gt; Client Secret &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Active Directory &gt; Client Secret &gt; ServiceNow &gt; Table
  - Azure &gt; Active Directory &gt; Custom Domain &gt; ServiceNow
  - Azure &gt; Active Directory &gt; Custom Domain &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Active Directory &gt; Custom Domain &gt; ServiceNow &gt; Table
  - Azure &gt; Active Directory &gt; Directory &gt; ServiceNow
  - Azure &gt; Active Directory &gt; Directory &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Active Directory &gt; Directory &gt; ServiceNow &gt; Table
  - Azure &gt; Active Directory &gt; Group &gt; ServiceNow
  - Azure &gt; Active Directory &gt; Group &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Active Directory &gt; Group &gt; ServiceNow &gt; Table
  - Azure &gt; Active Directory &gt; Service Principal &gt; ServiceNow
  - Azure &gt; Active Directory &gt; Service Principal &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Active Directory &gt; Service Principal &gt; ServiceNow &gt; Table
  - Azure &gt; Active Directory &gt; User &gt; ServiceNow
  - Azure &gt; Active Directory &gt; User &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Active Directory &gt; User &gt; ServiceNow &gt; Table

- Policy Types:

  - Azure &gt; Active Directory &gt; Application &gt; ServiceNow
  - Azure &gt; Active Directory &gt; Application &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Active Directory &gt; Application &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Active Directory &gt; Application &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Active Directory &gt; Application &gt; ServiceNow &gt; Table
  - Azure &gt; Active Directory &gt; Application &gt; ServiceNow &gt; Table &gt; Definition
  - Azure &gt; Active Directory &gt; Client Secret &gt; ServiceNow
  - Azure &gt; Active Directory &gt; Client Secret &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Active Directory &gt; Client Secret &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Active Directory &gt; Client Secret &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Active Directory &gt; Client Secret &gt; ServiceNow &gt; Table
  - Azure &gt; Active Directory &gt; Client Secret &gt; ServiceNow &gt; Table &gt; Definition
  - Azure &gt; Active Directory &gt; Custom Domain &gt; ServiceNow
  - Azure &gt; Active Directory &gt; Custom Domain &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Active Directory &gt; Custom Domain &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Active Directory &gt; Custom Domain &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Active Directory &gt; Custom Domain &gt; ServiceNow &gt; Table
  - Azure &gt; Active Directory &gt; Custom Domain &gt; ServiceNow &gt; Table &gt; Definition
  - Azure &gt; Active Directory &gt; Directory &gt; ServiceNow
  - Azure &gt; Active Directory &gt; Directory &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Active Directory &gt; Directory &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Active Directory &gt; Directory &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Active Directory &gt; Directory &gt; ServiceNow &gt; Table
  - Azure &gt; Active Directory &gt; Directory &gt; ServiceNow &gt; Table &gt; Definition
  - Azure &gt; Active Directory &gt; Group &gt; ServiceNow
  - Azure &gt; Active Directory &gt; Group &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Active Directory &gt; Group &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Active Directory &gt; Group &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Active Directory &gt; Group &gt; ServiceNow &gt; Table
  - Azure &gt; Active Directory &gt; Group &gt; ServiceNow &gt; Table &gt; Definition
  - Azure &gt; Active Directory &gt; Service Principal &gt; ServiceNow
  - Azure &gt; Active Directory &gt; Service Principal &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Active Directory &gt; Service Principal &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Active Directory &gt; Service Principal &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Active Directory &gt; Service Principal &gt; ServiceNow &gt; Table
  - Azure &gt; Active Directory &gt; Service Principal &gt; ServiceNow &gt; Table &gt; Definition
  - Azure &gt; Active Directory &gt; User &gt; ServiceNow
  - Azure &gt; Active Directory &gt; User &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Active Directory &gt; User &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Active Directory &gt; User &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Active Directory &gt; User &gt; ServiceNow &gt; Table
  - Azure &gt; Active Directory &gt; User &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Mon, 08 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-pubsub-v5-0-0</guid>
            <title>servicenow-gcp-pubsub v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-pubsub-v5-0-0</link>
            <description>_What&apos;s new?_

- Control Types:

  - GCP &gt; Pub/Sub &gt; Snapshot &gt; ServiceNow
  - GCP &gt; Pub/Sub &gt; Snapshot &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Pub/Sub &gt; Snapshot &gt; ServiceNow &gt; Table
  - GCP &gt; Pub/Sub &gt; Subscription &gt; ServiceNow
  - GCP &gt; Pub/Sub &gt; Subscription &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Pub/Sub &gt; Subscription &gt; ServiceNow &gt; Table
  - GCP &gt; Pub/Sub &gt; Topic &gt; ServiceNow
  - GCP &gt; Pub/Sub &gt; Topic &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Pub/Sub &gt; Topic &gt; ServiceNow &gt; Table

- Policy Types:

  - GCP &gt; Pub/Sub &gt; Snapshot &gt; ServiceNow
  - GCP &gt; Pub/Sub &gt; Snapshot &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Pub/Sub &gt; Snapshot &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Pub/Sub &gt; Snapshot &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Pub/Sub &gt; Snapshot &gt; ServiceNow &gt; Table
  - GCP &gt; Pub/Sub &gt; Snapshot &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; Pub/Sub &gt; Subscription &gt; ServiceNow
  - GCP &gt; Pub/Sub &gt; Subscription &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Pub/Sub &gt; Subscription &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Pub/Sub &gt; Subscription &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Pub/Sub &gt; Subscription &gt; ServiceNow &gt; Table
  - GCP &gt; Pub/Sub &gt; Subscription &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; Pub/Sub &gt; Topic &gt; ServiceNow
  - GCP &gt; Pub/Sub &gt; Topic &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Pub/Sub &gt; Topic &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Pub/Sub &gt; Topic &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Pub/Sub &gt; Topic &gt; ServiceNow &gt; Table
  - GCP &gt; Pub/Sub &gt; Topic &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Fri, 05 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-synapseanalytics-v5-0-0</guid>
            <title>servicenow-azure-synapseanalytics v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-synapseanalytics-v5-0-0</link>
            <description>_What&apos;s new?_

- Control Types:

  - Azure &gt; Synapse Analytics &gt; SQL Pool &gt; ServiceNow
  - Azure &gt; Synapse Analytics &gt; SQL Pool &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Synapse Analytics &gt; SQL Pool &gt; ServiceNow &gt; Table
  - Azure &gt; Synapse Analytics &gt; Workspace &gt; ServiceNow
  - Azure &gt; Synapse Analytics &gt; Workspace &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Synapse Analytics &gt; Workspace &gt; ServiceNow &gt; Table

- Policy Types:

  - Azure &gt; Synapse Analytics &gt; SQL Pool &gt; ServiceNow
  - Azure &gt; Synapse Analytics &gt; SQL Pool &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Synapse Analytics &gt; SQL Pool &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Synapse Analytics &gt; SQL Pool &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Synapse Analytics &gt; SQL Pool &gt; ServiceNow &gt; Table
  - Azure &gt; Synapse Analytics &gt; SQL Pool &gt; ServiceNow &gt; Table &gt; Definition
  - Azure &gt; Synapse Analytics &gt; Workspace &gt; ServiceNow
  - Azure &gt; Synapse Analytics &gt; Workspace &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Synapse Analytics &gt; Workspace &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Synapse Analytics &gt; Workspace &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Synapse Analytics &gt; Workspace &gt; ServiceNow &gt; Table
  - Azure &gt; Synapse Analytics &gt; Workspace &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Fri, 05 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-sqlvirtualmachine-v5-0-0</guid>
            <title>servicenow-azure-sqlvirtualmachine v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-sqlvirtualmachine-v5-0-0</link>
            <description>_What&apos;s new?_

- Control Types:

  - Azure &gt; Search Management &gt; Search Service &gt; ServiceNow
  - Azure &gt; Search Management &gt; Search Service &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Search Management &gt; Search Service &gt; ServiceNow &gt; Table

- Policy Types:
  - Azure &gt; Search Management &gt; Search Service &gt; ServiceNow
  - Azure &gt; Search Management &gt; Search Service &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Search Management &gt; Search Service &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Search Management &gt; Search Service &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Search Management &gt; Search Service &gt; ServiceNow &gt; Table
  - Azure &gt; Search Management &gt; Search Service &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Fri, 05 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-servicebus-v5-0-0</guid>
            <title>servicenow-azure-servicebus v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-servicebus-v5-0-0</link>
            <description>_What&apos;s new?_

- Control Types:

  - Azure &gt; Service Bus &gt; Namespace &gt; ServiceNow
  - Azure &gt; Service Bus &gt; Namespace &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Service Bus &gt; Namespace &gt; ServiceNow &gt; Table
  - Azure &gt; Service Bus &gt; Queue &gt; ServiceNow
  - Azure &gt; Service Bus &gt; Queue &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Service Bus &gt; Queue &gt; ServiceNow &gt; Table
  - Azure &gt; Service Bus &gt; Topic &gt; ServiceNow
  - Azure &gt; Service Bus &gt; Topic &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Service Bus &gt; Topic &gt; ServiceNow &gt; Table

- Policy Types:
  - Azure &gt; Service Bus &gt; Namespace &gt; ServiceNow
  - Azure &gt; Service Bus &gt; Namespace &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Service Bus &gt; Namespace &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Service Bus &gt; Namespace &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Service Bus &gt; Namespace &gt; ServiceNow &gt; Table
  - Azure &gt; Service Bus &gt; Namespace &gt; ServiceNow &gt; Table &gt; Definition
  - Azure &gt; Service Bus &gt; Queue &gt; ServiceNow
  - Azure &gt; Service Bus &gt; Queue &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Service Bus &gt; Queue &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Service Bus &gt; Queue &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Service Bus &gt; Queue &gt; ServiceNow &gt; Table
  - Azure &gt; Service Bus &gt; Queue &gt; ServiceNow &gt; Table &gt; Definition
  - Azure &gt; Service Bus &gt; Topic &gt; ServiceNow
  - Azure &gt; Service Bus &gt; Topic &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Service Bus &gt; Topic &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Service Bus &gt; Topic &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Service Bus &gt; Topic &gt; ServiceNow &gt; Table
  - Azure &gt; Service Bus &gt; Topic &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Fri, 05 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-loadbalancer-v5-0-0</guid>
            <title>servicenow-azure-loadbalancer v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-loadbalancer-v5-0-0</link>
            <description>_What&apos;s new?_

- Control Types:

  - Azure &gt; Load Balancer &gt; Load Balance &gt; ServiceNow
  - Azure &gt; Load Balancer &gt; Load Balance &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Load Balancer &gt; Load Balance &gt; ServiceNow &gt; Table

- Policy Types:
  - Azure &gt; Load Balancer &gt; Load Balance &gt; ServiceNow
  - Azure &gt; Load Balancer &gt; Load Balance &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Load Balancer &gt; Load Balance &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Load Balancer &gt; Load Balance &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Load Balancer &gt; Load Balance &gt; ServiceNow &gt; Table
  - Azure &gt; Load Balancer &gt; Load Balance &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Fri, 05 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-dns-v5-0-0</guid>
            <title>servicenow-azure-dns v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-dns-v5-0-0</link>
            <description>_What&apos;s new?_

- Control Types:

  - Azure &gt; DNS &gt; Record Set &gt; ServiceNow
  - Azure &gt; DNS &gt; Record Set &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; DNS &gt; Record Set &gt; ServiceNow &gt; Table
  - Azure &gt; DNS &gt; Zone &gt; ServiceNow
  - Azure &gt; DNS &gt; Zone &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; DNS &gt; Zone &gt; ServiceNow &gt; Table

- Policy Types:
  - Azure &gt; DNS &gt; Record Set &gt; ServiceNow
  - Azure &gt; DNS &gt; Record Set &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; DNS &gt; Record Set &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; DNS &gt; Record Set &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; DNS &gt; Record Set &gt; ServiceNow &gt; Table
  - Azure &gt; DNS &gt; Record Set &gt; ServiceNow &gt; Table &gt; Definition
  - Azure &gt; DNS &gt; Zone &gt; ServiceNow
  - Azure &gt; DNS &gt; Zone &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; DNS &gt; Zone &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; DNS &gt; Zone &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; DNS &gt; Zone &gt; ServiceNow &gt; Table
  - Azure &gt; DNS &gt; Zone &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Fri, 05 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-cosmosdb-v5-0-0</guid>
            <title>servicenow-azure-cosmosdb v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-cosmosdb-v5-0-0</link>
            <description>_What&apos;s new?_

- Control Types:

  - Azure &gt; Cosmos DB &gt; Database Account &gt; ServiceNow
  - Azure &gt; Cosmos DB &gt; Database Account &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Cosmos DB &gt; Database Account &gt; ServiceNow &gt; Table
  - Azure &gt; Cosmos DB &gt; MongoDB Collection &gt; ServiceNow
  - Azure &gt; Cosmos DB &gt; MongoDB Collection &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Cosmos DB &gt; MongoDB Collection &gt; ServiceNow &gt; Table
  - Azure &gt; Cosmos DB &gt; MongoDB Database &gt; ServiceNow
  - Azure &gt; Cosmos DB &gt; MongoDB Database &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Cosmos DB &gt; MongoDB Database &gt; ServiceNow &gt; Table
  - Azure &gt; Cosmos DB &gt; SQL Container &gt; ServiceNow
  - Azure &gt; Cosmos DB &gt; SQL Container &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Cosmos DB &gt; SQL Container &gt; ServiceNow &gt; Table
  - Azure &gt; Cosmos DB &gt; SQL Database &gt; ServiceNow
  - Azure &gt; Cosmos DB &gt; SQL Database &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Cosmos DB &gt; SQL Database &gt; ServiceNow &gt; Table

- Policy Types:
  - Azure &gt; Cosmos DB &gt; Database Account &gt; ServiceNow
  - Azure &gt; Cosmos DB &gt; Database Account &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Cosmos DB &gt; Database Account &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Cosmos DB &gt; Database Account &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Cosmos DB &gt; Database Account &gt; ServiceNow &gt; Table
  - Azure &gt; Cosmos DB &gt; Database Account &gt; ServiceNow &gt; Table &gt; Definition
  - Azure &gt; Cosmos DB &gt; MongoDB Collection &gt; ServiceNow
  - Azure &gt; Cosmos DB &gt; MongoDB Collection &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Cosmos DB &gt; MongoDB Collection &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Cosmos DB &gt; MongoDB Collection &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Cosmos DB &gt; MongoDB Collection &gt; ServiceNow &gt; Table
  - Azure &gt; Cosmos DB &gt; MongoDB Collection &gt; ServiceNow &gt; Table &gt; Definition
  - Azure &gt; Cosmos DB &gt; MongoDB Database &gt; ServiceNow
  - Azure &gt; Cosmos DB &gt; MongoDB Database &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Cosmos DB &gt; MongoDB Database &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Cosmos DB &gt; MongoDB Database &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Cosmos DB &gt; MongoDB Database &gt; ServiceNow &gt; Table
  - Azure &gt; Cosmos DB &gt; MongoDB Database &gt; ServiceNow &gt; Table &gt; Definition
  - Azure &gt; Cosmos DB &gt; SQL Container &gt; ServiceNow
  - Azure &gt; Cosmos DB &gt; SQL Container &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Cosmos DB &gt; SQL Container &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Cosmos DB &gt; SQL Container &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Cosmos DB &gt; SQL Container &gt; ServiceNow &gt; Table
  - Azure &gt; Cosmos DB &gt; SQL Container &gt; ServiceNow &gt; Table &gt; Definition
  - Azure &gt; Cosmos DB &gt; SQL Database &gt; ServiceNow
  - Azure &gt; Cosmos DB &gt; SQL Database &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Cosmos DB &gt; SQL Database &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Cosmos DB &gt; SQL Database &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Cosmos DB &gt; SQL Database &gt; ServiceNow &gt; Table
  - Azure &gt; Cosmos DB &gt; SQL Database &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Fri, 05 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-42-12</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.42.12 - Policy updated for Mod Lambda SNS topic</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-42-12</link>
            <description>_What&apos;s new?_

- Server
  - Updated: Enhanced IAM policy for tighter access around Mod Lambda SNS topic.

_Requirements_

- TEF: 1.51.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Thu, 04 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-searchmanagement-v5-0-0</guid>
            <title>servicenow-azure-searchmanagement v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-searchmanagement-v5-0-0</link>
            <description>_What&apos;s new?_

- Control Types:
  - Azure &gt; Search Management &gt; Search Service &gt; ServiceNow
  - Azure &gt; Search Management &gt; Search Service &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Search Management &gt; Search Service &gt; ServiceNow &gt; Table

- Policy Types:
  - Azure &gt; Search Management &gt; Search Service &gt; ServiceNow
  - Azure &gt; Search Management &gt; Search Service &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Search Management &gt; Search Service &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Search Management &gt; Search Service &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Search Management &gt; Search Service &gt; ServiceNow &gt; Table
  - Azure &gt; Search Management &gt; Search Service &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Thu, 04 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-networkwatcher-v5-0-0</guid>
            <title>servicenow-azure-networkwatcher v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-networkwatcher-v5-0-0</link>
            <description>_What&apos;s new?_

- Control Types:
  - Azure &gt; Network Watcher &gt; Flow Log &gt; ServiceNow
  - Azure &gt; Network Watcher &gt; Flow Log &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Network Watcher &gt; Flow Log &gt; ServiceNow &gt; Table
  - Azure &gt; Network Watcher &gt; Network Watcher &gt; ServiceNow
  - Azure &gt; Network Watcher &gt; Network Watcher &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Network Watcher &gt; Network Watcher &gt; ServiceNow &gt; Table

- Policy Types:
  - Azure &gt; Network Watcher &gt; Flow Log &gt; ServiceNow
  - Azure &gt; Network Watcher &gt; Flow Log &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Network Watcher &gt; Flow Log &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Network Watcher &gt; Flow Log &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Network Watcher &gt; Flow Log &gt; ServiceNow &gt; Table
  - Azure &gt; Network Watcher &gt; Flow Log &gt; ServiceNow &gt; Table &gt; Definition
  - Azure &gt; Network Watcher &gt; Network Watcher &gt; ServiceNow
  - Azure &gt; Network Watcher &gt; Network Watcher &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Network Watcher &gt; Network Watcher &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Network Watcher &gt; Network Watcher &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Network Watcher &gt; Network Watcher &gt; ServiceNow &gt; Table
  - Azure &gt; Network Watcher &gt; Network Watcher &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Thu, 04 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-frontdoorservice-v5-0-0</guid>
            <title>servicenow-azure-frontdoorservice v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-frontdoorservice-v5-0-0</link>
            <description>_What&apos;s new?_

- Control Types:
  - Azure &gt; Front Door &gt; Front Door &gt; ServiceNow
  - Azure &gt; Front Door &gt; Front Door &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Front Door &gt; Front Door &gt; ServiceNow &gt; Table

- Policy Types:
  - Azure &gt; Front Door &gt; Front Door &gt; ServiceNow
  - Azure &gt; Front Door &gt; Front Door &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Front Door &gt; Front Door &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Front Door &gt; Front Door &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Front Door &gt; Front Door &gt; ServiceNow &gt; Table
  - Azure &gt; Front Door &gt; Front Door &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Thu, 04 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-applicationinsights-v5-0-0</guid>
            <title>servicenow-azure-applicationinsights v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-applicationinsights-v5-0-0</link>
            <description>_What&apos;s new?_

- Control Types:
  - Azure &gt; Application Insights &gt; Application Insight &gt; ServiceNow
  - Azure &gt; Application Insights &gt; Application Insight &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Application Insights &gt; Application Insight &gt; ServiceNow &gt; Table

- Policy Types:
  - Azure &gt; Application Insights &gt; Application Insight &gt; ServiceNow
  - Azure &gt; Application Insights &gt; Application Insight &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Application Insights &gt; Application Insight &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Application Insights &gt; Application Insight &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Application Insights &gt; Application Insight &gt; ServiceNow &gt; Table
  - Azure &gt; Application Insights &gt; Application Insight &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Thu, 04 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/firehose-aws-sns-v1-1-6</guid>
            <title>firehose-aws-sns v1.1.6 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/firehose-aws-sns-v1-1-6</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.</description>
            <pubDate>Thu, 04 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-securitycenter-v5-0-0</guid>
            <title>servicenow-azure-securitycenter v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-securitycenter-v5-0-0</link>
            <description>_What&apos;s new?_

- Control Types:
  - Azure &gt; Security Center &gt; Security Center &gt; ServiceNow
  - Azure &gt; Security Center &gt; Security Center &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Security Center &gt; Security Center &gt; ServiceNow &gt; Table

- Policy Types:
  - Azure &gt; Security Center &gt; Security Center &gt; ServiceNow
  - Azure &gt; Security Center &gt; Security Center &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Security Center &gt; Security Center &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Security Center &gt; Security Center &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Security Center &gt; Security Center &gt; ServiceNow &gt; Table
  - Azure &gt; Security Center &gt; Security Center &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Wed, 03 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-firewall-v5-0-0</guid>
            <title>servicenow-azure-firewall v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-firewall-v5-0-0</link>
            <description>_What&apos;s new?_

- Control Types:
  - Azure &gt; Firewall &gt; Firewall &gt; ServiceNow
  - Azure &gt; Firewall &gt; Firewall &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Firewall &gt; Firewall &gt; ServiceNow &gt; Table

- Policy Types:
  - Azure &gt; Firewall &gt; Firewall &gt; ServiceNow
  - Azure &gt; Firewall &gt; Firewall &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Firewall &gt; Firewall &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Firewall &gt; Firewall &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Firewall &gt; Firewall &gt; ServiceNow &gt; Table
  - Azure &gt; Firewall &gt; Firewall &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Wed, 03 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-applicationgateway-v5-0-0</guid>
            <title>servicenow-azure-applicationgateway v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-applicationgateway-v5-0-0</link>
            <description>_What&apos;s new?_

- Control Types:
  - Azure &gt; Application Gateway Service &gt; Application Gateway &gt; ServiceNow
  - Azure &gt; Application Gateway Service &gt; Application Gateway &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Application Gateway Service &gt; Application Gateway &gt; ServiceNow &gt; Table

- Policy Types:
  - Azure &gt; Application Gateway Service &gt; Application Gateway &gt; ServiceNow
  - Azure &gt; Application Gateway Service &gt; Application Gateway &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Application Gateway Service &gt; Application Gateway &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Application Gateway Service &gt; Application Gateway &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Application Gateway Service &gt; Application Gateway &gt; ServiceNow &gt; Table
  - Azure &gt; Application Gateway Service &gt; Application Gateway &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Wed, 03 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-apimanagement-v5-0-0</guid>
            <title>servicenow-azure-apimanagement v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-apimanagement-v5-0-0</link>
            <description>_What&apos;s new?_

- Control Types:
  - Azure &gt; API Management &gt; API Management Service &gt; ServiceNow
  - Azure &gt; API Management &gt; API Management Service &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; API Management &gt; API Management Service &gt; ServiceNow &gt; Table

- Policy Types:
  - Azure &gt; API Management &gt; API Management Service &gt; ServiceNow
  - Azure &gt; API Management &gt; API Management Service &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; API Management &gt; API Management Service &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; API Management &gt; API Management Service &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; API Management &gt; API Management Service &gt; ServiceNow &gt; Table
  - Azure &gt; API Management &gt; API Management Service &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Wed, 03 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-42-11</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.42.11 - SAML Security Enhancements</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-42-11</link>
            <description>_What&apos;s new?_

- Server
  - Updated: The directory API to support `Require Signed Assertion Response`.

- UI:
  - Added: Introduced UI options for `Require Signed Assertion Response` for enhanced security in SAML authentication.

_Requirements_

- TEF: 1.51.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3

**Enhanced Security and Compatibility Guide for SAML Authentication**

**Description:**
The recent update to `@node-saml/passport-saml` mandates the signing of the assertion response. To ensure backward compatibility, we have introduced a new configuration option in the UI:

- **Require Signed Assertion Response**

By default, this option is set to `Disabled` to maintain compatibility with existing setups.

**Recommendations:**
We recommend enabling this option as it adds an additional layer of security. However, please be aware that enabling this setting might impact the SAML login functionality.</description>
            <pubDate>Tue, 02 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-relay-v5-0-0</guid>
            <title>servicenow-azure-relay v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-relay-v5-0-0</link>
            <description>_What&apos;s new?_

- Control Types:
  - Azure &gt; Relay &gt; Namespace &gt; ServiceNow
  - Azure &gt; Relay &gt; Namespace &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Relay &gt; Namespace &gt; ServiceNow &gt; Table

- Policy Types:
  - Azure &gt; Relay &gt; Namespace &gt; ServiceNow
  - Azure &gt; Relay &gt; Namespace &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Relay &gt; Namespace &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Relay &gt; Namespace &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Relay &gt; Namespace &gt; ServiceNow &gt; Table
  - Azure &gt; Relay &gt; Namespace &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Tue, 02 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-loganalytics-v5-0-0</guid>
            <title>servicenow-azure-loganalytics v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-loganalytics-v5-0-0</link>
            <description>_What&apos;s new?_

- Control Types:
  - Azure &gt; Log Analytics &gt; Log Analytics Workspace &gt; ServiceNow
  - Azure &gt; Log Analytics &gt; Log Analytics Workspace &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Log Analytics &gt; Log Analytics Workspace &gt; ServiceNow &gt; Table

- Policy Types:
  - Azure &gt; Log Analytics &gt; Log Analytics Workspace &gt; ServiceNow
  - Azure &gt; Log Analytics &gt; Log Analytics Workspace &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Log Analytics &gt; Log Analytics Workspace &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Log Analytics &gt; Log Analytics Workspace &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Log Analytics &gt; Log Analytics Workspace &gt; ServiceNow &gt; Table
  - Azure &gt; Log Analytics &gt; Log Analytics Workspace &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Tue, 02 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-appservice-v5-0-0</guid>
            <title>servicenow-azure-appservice v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-appservice-v5-0-0</link>
            <description>_What&apos;s new?_

- Control Types:
  - Azure &gt; App Service &gt; App Service Plan &gt; ServiceNow
  - Azure &gt; App Service &gt; App Service Plan &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; App Service &gt; App Service Plan &gt; ServiceNow &gt; Table
  - Azure &gt; App Service &gt; Function App &gt; ServiceNow
  - Azure &gt; App Service &gt; Function App &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; App Service &gt; Function App &gt; ServiceNow &gt; Table
  - Azure &gt; App Service &gt; Web App &gt; ServiceNow
  - Azure &gt; App Service &gt; Web App &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; App Service &gt; Web App &gt; ServiceNow &gt; Table

- Policy Types:
  - Azure &gt; App Service &gt; App Service Plan &gt; ServiceNow
  - Azure &gt; App Service &gt; App Service Plan &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; App Service &gt; App Service Plan &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; App Service &gt; App Service Plan &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; App Service &gt; App Service Plan &gt; ServiceNow &gt; Table
  - Azure &gt; App Service &gt; App Service Plan &gt; ServiceNow &gt; Table &gt; Definition
  - Azure &gt; App Service &gt; Function App &gt; ServiceNow
  - Azure &gt; App Service &gt; Function App &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; App Service &gt; Function App &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; App Service &gt; Function App &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; App Service &gt; Function App &gt; ServiceNow &gt; Table
  - Azure &gt; App Service &gt; Function App &gt; ServiceNow &gt; Table &gt; Definition
  - Azure &gt; App Service &gt; Web App &gt; ServiceNow
  - Azure &gt; App Service &gt; Web App &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; App Service &gt; Web App &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; App Service &gt; Web App &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; App Service &gt; Web App &gt; ServiceNow &gt; Table
  - Azure &gt; App Service &gt; Web App &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Tue, 02 Jan 2024 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-signalr-v5-0-0</guid>
            <title>servicenow-azure-signalr v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-signalr-v5-0-0</link>
            <description>_What&apos;s new?_

- Control Types:

  - Azure &gt; SignalR Service &gt; SignalR &gt; ServiceNow
  - Azure &gt; SignalR Service &gt; SignalR &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; SignalR Service &gt; SignalR &gt; ServiceNow &gt; Table

- Policy Types:

  - Azure &gt; SignalR Service &gt; SignalR &gt; ServiceNow
  - Azure &gt; SignalR Service &gt; SignalR &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; SignalR Service &gt; SignalR &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; SignalR Service &gt; SignalR &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; SignalR Service &gt; SignalR &gt; ServiceNow &gt; Table
  - Azure &gt; SignalR Service &gt; SignalR &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Sat, 23 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-aks-v5-0-0</guid>
            <title>servicenow-azure-aks v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-aks-v5-0-0</link>
            <description>_What&apos;s new?_

- Control Types:

  - Azure &gt; AKS &gt; Managed Cluster &gt; ServiceNow
  - Azure &gt; AKS &gt; Managed Cluster &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; AKS &gt; Managed Cluster &gt; ServiceNow &gt; Table

- Policy Types:

  - Azure &gt; AKS &gt; Managed Cluster &gt; ServiceNow
  - Azure &gt; AKS &gt; Managed Cluster &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; AKS &gt; Managed Cluster &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; AKS &gt; Managed Cluster &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; AKS &gt; Managed Cluster &gt; ServiceNow &gt; Table
  - Azure &gt; AKS &gt; Managed Cluster &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Sat, 23 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-sql-v5-1-0</guid>
            <title>servicenow-azure-sql v5.1.0 - Added support for Database and Elastic Pool</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-sql-v5-1-0</link>
            <description>_What&apos;s new?_

- Control Types:
  - Azure &gt; SQL &gt; Database &gt; ServiceNow
  - Azure &gt; SQL &gt; Database &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; SQL &gt; Database &gt; ServiceNow &gt; Table
  - Azure &gt; SQL &gt; Elastic Pool &gt; ServiceNow
  - Azure &gt; SQL &gt; Elastic Pool &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; SQL &gt; Elastic Pool &gt; ServiceNow &gt; Table

- Policy Types:
  - Azure &gt; SQL &gt; Database &gt; ServiceNow
  - Azure &gt; SQL &gt; Database &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; SQL &gt; Database &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; SQL &gt; Database &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; SQL &gt; Database &gt; ServiceNow &gt; Table
  - Azure &gt; SQL &gt; Database &gt; ServiceNow &gt; Table &gt; Definition
  - Azure &gt; SQL &gt; Elastic Pool &gt; ServiceNow
  - Azure &gt; SQL &gt; Elastic Pool &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; SQL &gt; Elastic Pool &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; SQL &gt; Elastic Pool &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; SQL &gt; Elastic Pool &gt; ServiceNow &gt; Table
  - Azure &gt; SQL &gt; Elastic Pool &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Tue, 19 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-network-v5-1-0</guid>
            <title>servicenow-azure-network v5.1.0 - Added support for Application Security Group, Express Route Circuits, Network Interface, Private DNS Zones, Public IP Address, Route Table and Virtual Network Gateway</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-network-v5-1-0</link>
            <description>_What&apos;s new?_

- Control Types:
  - Azure &gt; Network &gt; Application Security Group &gt; ServiceNow
  - Azure &gt; Network &gt; Application Security Group &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Network &gt; Application Security Group &gt; ServiceNow &gt; Table
  - Azure &gt; Network &gt; Express Route Circuits &gt; ServiceNow
  - Azure &gt; Network &gt; Express Route Circuits &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Network &gt; Express Route Circuits &gt; ServiceNow &gt; Table
  - Azure &gt; Network &gt; Network Interface &gt; ServiceNow
  - Azure &gt; Network &gt; Network Interface &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Network &gt; Network Interface &gt; ServiceNow &gt; Table
  - Azure &gt; Network &gt; Private DNS Zones &gt; ServiceNow
  - Azure &gt; Network &gt; Private DNS Zones &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Network &gt; Private DNS Zones &gt; ServiceNow &gt; Table
  - Azure &gt; Network &gt; Public IP Address &gt; ServiceNow
  - Azure &gt; Network &gt; Public IP Address &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Network &gt; Public IP Address &gt; ServiceNow &gt; Table
  - Azure &gt; Network &gt; Route Table &gt; ServiceNow
  - Azure &gt; Network &gt; Route Table &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Network &gt; Route Table &gt; ServiceNow &gt; Table
  - Azure &gt; Network &gt; Virtual Network Gateway &gt; ServiceNow
  - Azure &gt; Network &gt; Virtual Network Gateway &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Network &gt; Virtual Network Gateway &gt; ServiceNow &gt; Table


- Policy Types:
  - Azure &gt; Network &gt; Application Security Group &gt; ServiceNow
  - Azure &gt; Network &gt; Application Security Group &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Network &gt; Application Security Group &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Network &gt; Application Security Group &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Network &gt; Application Security Group &gt; ServiceNow &gt; Table
  - Azure &gt; Network &gt; Application Security Group &gt; ServiceNow &gt; Table &gt; Definition
  - Azure &gt; Network &gt; Express Route Circuits &gt; ServiceNow
  - Azure &gt; Network &gt; Express Route Circuits &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Network &gt; Express Route Circuits &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Network &gt; Express Route Circuits &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Network &gt; Express Route Circuits &gt; ServiceNow &gt; Table
  - Azure &gt; Network &gt; Express Route Circuits &gt; ServiceNow &gt; Table &gt; Definition
  - Azure &gt; Network &gt; Network Interface &gt; ServiceNow
  - Azure &gt; Network &gt; Network Interface &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Network &gt; Network Interface &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Network &gt; Network Interface &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Network &gt; Network Interface &gt; ServiceNow &gt; Table
  - Azure &gt; Network &gt; Network Interface &gt; ServiceNow &gt; Table &gt; Definition
  - Azure &gt; Network &gt; Private DNS Zones &gt; ServiceNow
  - Azure &gt; Network &gt; Private DNS Zones &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Network &gt; Private DNS Zones &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Network &gt; Private DNS Zones &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Network &gt; Private DNS Zones &gt; ServiceNow &gt; Table
  - Azure &gt; Network &gt; Private DNS Zones &gt; ServiceNow &gt; Table &gt; Definition
  - Azure &gt; Network &gt; Public IP Address &gt; ServiceNow
  - Azure &gt; Network &gt; Public IP Address &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Network &gt; Public IP Address &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Network &gt; Public IP Address &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Network &gt; Public IP Address &gt; ServiceNow &gt; Table
  - Azure &gt; Network &gt; Public IP Address &gt; ServiceNow &gt; Table &gt; Definition
  - Azure &gt; Network &gt; Route Table &gt; ServiceNow
  - Azure &gt; Network &gt; Route Table &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Network &gt; Route Table &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Network &gt; Route Table &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Network &gt; Route Table &gt; ServiceNow &gt; Table
  - Azure &gt; Network &gt; Route Table &gt; ServiceNow &gt; Table &gt; Definition
  - Azure &gt; Network &gt; Virtual Network Gateway &gt; ServiceNow
  - Azure &gt; Network &gt; Virtual Network Gateway &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Network &gt; Virtual Network Gateway &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Network &gt; Virtual Network Gateway &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Network &gt; Virtual Network Gateway &gt; ServiceNow &gt; Table
  - Azure &gt; Network &gt; Virtual Network Gateway &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Tue, 19 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-keyvault-v5-0-0</guid>
            <title>servicenow-azure-keyvault v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-keyvault-v5-0-0</link>
            <description>_What&apos;s new?_

- Control Types:
  - Azure &gt; Key Vault &gt; Key &gt; ServiceNow
  - Azure &gt; Key Vault &gt; Key &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Key Vault &gt; Key &gt; ServiceNow &gt; Table
  - Azure &gt; Key Vault &gt; Secret &gt; ServiceNow
  - Azure &gt; Key Vault &gt; Secret &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Key Vault &gt; Secret &gt; ServiceNow &gt; Table
  - Azure &gt; Key Vault &gt; Vault &gt; ServiceNow
  - Azure &gt; Key Vault &gt; Vault &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Key Vault &gt; Vault &gt; ServiceNow &gt; Table

- Policy Types:
  - Azure &gt; Key Vault &gt; Key &gt; ServiceNow
  - Azure &gt; Key Vault &gt; Key &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Key Vault &gt; Key &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Key Vault &gt; Key &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Key Vault &gt; Key &gt; ServiceNow &gt; Table
  - Azure &gt; Key Vault &gt; Key &gt; ServiceNow &gt; Table &gt; Definition
  - Azure &gt; Key Vault &gt; Secret &gt; ServiceNow
  - Azure &gt; Key Vault &gt; Secret &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Key Vault &gt; Secret &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Key Vault &gt; Secret &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Key Vault &gt; Secret &gt; ServiceNow &gt; Table
  - Azure &gt; Key Vault &gt; Secret &gt; ServiceNow &gt; Table &gt; Definition
  - Azure &gt; Key Vault &gt; Vault &gt; ServiceNow
  - Azure &gt; Key Vault &gt; Vault &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Key Vault &gt; Vault &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Key Vault &gt; Vault &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Key Vault &gt; Vault &gt; ServiceNow &gt; Table
  - Azure &gt; Key Vault &gt; Vault &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Tue, 19 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-postgresql-v5-1-0</guid>
            <title>servicenow-azure-postgresql v5.1.0 - Added support for Flexible Server</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-postgresql-v5-1-0</link>
            <description>_What&apos;s new?_

- Control Types:
  - Azure &gt; PostgreSQL &gt; Flexible Server &gt; ServiceNow
  - Azure &gt; PostgreSQL &gt; Flexible Server &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; PostgreSQL &gt; Flexible Server &gt; ServiceNow &gt; Table

- Policy Types:
  - Azure &gt; PostgreSQL &gt; Flexible Server &gt; ServiceNow
  - Azure &gt; PostgreSQL &gt; Flexible Server &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; PostgreSQL &gt; Flexible Server &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; PostgreSQL &gt; Flexible Server &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; PostgreSQL &gt; Flexible Server &gt; ServiceNow &gt; Table
  - Azure &gt; PostgreSQL &gt; Flexible Server &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Mon, 18 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-mysql-v5-1-0</guid>
            <title>servicenow-azure-mysql v5.1.0 - Added support for Flexible Server</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-mysql-v5-1-0</link>
            <description>_What&apos;s new?_

- Control Types:

  - Azure &gt; MySQL &gt; Flexible Server &gt; ServiceNow
  - Azure &gt; MySQL &gt; Flexible Server &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; MySQL &gt; Flexible Server &gt; ServiceNow &gt; Table

- Policy Types:
  - Azure &gt; MySQL &gt; Flexible Server &gt; ServiceNow
  - Azure &gt; MySQL &gt; Flexible Server &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; MySQL &gt; Flexible Server &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; MySQL &gt; Flexible Server &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; MySQL &gt; Flexible Server &gt; ServiceNow &gt; Table
  - Azure &gt; MySQL &gt; Flexible Server &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Mon, 18 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-aws-kms-v5-0-0</guid>
            <title>servicenow-aws-kms v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-aws-kms-v5-0-0</link>
            <description>_What&apos;s new?_

- Control Types:
  - AWS &gt; KMS &gt; Key &gt; ServiceNow
  - AWS &gt; KMS &gt; Key &gt; ServiceNow &gt; Configuration Item
  - AWS &gt; KMS &gt; Key &gt; ServiceNow &gt; Table

- Policy Types:
  - AWS &gt; KMS &gt; Key &gt; ServiceNow
  - AWS &gt; KMS &gt; Key &gt; ServiceNow &gt; Configuration Item
  - AWS &gt; KMS &gt; Key &gt; ServiceNow &gt; Configuration Item &gt; Record
  - AWS &gt; KMS &gt; Key &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - AWS &gt; KMS &gt; Key &gt; ServiceNow &gt; Table
  - AWS &gt; KMS &gt; Key &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Mon, 18 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-aws-cloudwatch-v5-0-0</guid>
            <title>servicenow-aws-cloudwatch v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-aws-cloudwatch-v5-0-0</link>
            <description>_What&apos;s new?_

- Control Types:
  - AWS &gt; CloudWatch &gt; Alarm &gt; ServiceNow
  - AWS &gt; CloudWatch &gt; Alarm &gt; ServiceNow &gt; Configuration Item
  - AWS &gt; CloudWatch &gt; Alarm &gt; ServiceNow &gt; Table

- Policy Types:
  - AWS &gt; CloudWatch &gt; Alarm &gt; ServiceNow
  - AWS &gt; CloudWatch &gt; Alarm &gt; ServiceNow &gt; Configuration Item
  - AWS &gt; CloudWatch &gt; Alarm &gt; ServiceNow &gt; Configuration Item &gt; Record
  - AWS &gt; CloudWatch &gt; Alarm &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - AWS &gt; CloudWatch &gt; Alarm &gt; ServiceNow &gt; Table
  - AWS &gt; CloudWatch &gt; Alarm &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Mon, 18 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-aws-cloudtrail-v5-0-0</guid>
            <title>servicenow-aws-cloudtrail v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-aws-cloudtrail-v5-0-0</link>
            <description>_What&apos;s new?_

- Control Types:
  - AWS &gt; CloudTrail &gt; Trail &gt; ServiceNow
  - AWS &gt; CloudTrail &gt; Trail &gt; ServiceNow &gt; Configuration Item
  - AWS &gt; CloudTrail &gt; Trail &gt; ServiceNow &gt; Table

- Policy Types:
  - AWS &gt; CloudTrail &gt; Trail &gt; ServiceNow
  - AWS &gt; CloudTrail &gt; Trail &gt; ServiceNow &gt; Configuration Item
  - AWS &gt; CloudTrail &gt; Trail &gt; ServiceNow &gt; Configuration Item &gt; Record
  - AWS &gt; CloudTrail &gt; Trail &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - AWS &gt; CloudTrail &gt; Trail &gt; ServiceNow &gt; Table
  - AWS &gt; CloudTrail &gt; Trail &gt; ServiceNow &gt; Table &gt; Definition</description>
            <pubDate>Mon, 18 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-rds-v5-26-1</guid>
            <title>aws-rds v5.26.1 - Bug Fixed - DB Instance Discovery control would sometimes incorrectly upsert DocumentDB Instances</title>
            <link>https://turbot.com/guardrails/changelog/aws-rds-v5-26-1</link>
            <description>_Bug fixes_

- The `AWS &gt; RDS &gt; DB Instance &gt; Discovery` control would sometimes upsert DocumentDB Instances as RDS Instances in Guardrails CMDB. This is fixed and the control will now filter out DocumentDB Instances while upserting resources in CMDB.</description>
            <pubDate>Fri, 15 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-lambda-v5-13-2</guid>
            <title>aws-lambda v5.13.2 - Added support for latest Lambda runtimes in the `AWS &gt; Lambda &gt; Function &gt; Allowed Runtime &gt; Values` policy</title>
            <link>https://turbot.com/guardrails/changelog/aws-lambda-v5-13-2</link>
            <description>_What&apos;s new?_
- Added support for latest lambda runtimes in the AWS &gt; Lambda &gt; Function &gt; Allowed Runtime &gt; Values policy.</description>
            <pubDate>Wed, 13 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-iam-v5-33-0</guid>
            <title>aws-iam v5.33.0 - Added support for Approved policies and control for Root Resource Type</title>
            <link>https://turbot.com/guardrails/changelog/aws-iam-v5-33-0</link>
            <description>_What&apos;s new?_
- Control Types:
  - AWS &gt; IAM &gt; Root &gt; Approved

- Policy Types:
  - AWS &gt; IAM &gt; Root &gt; Approved
  - AWS &gt; IAM &gt; Root &gt; Approved &gt; Custom
  - AWS &gt; IAM &gt; Root &gt; Approved &gt; Usage

- Action Types:
  - AWS &gt; IAM &gt; Root &gt; Skip alarm for Approved control
  - AWS &gt; IAM &gt; Root &gt; Skip alarm for Approved control [90 days]

_Bug fixes_
- The `AWS &gt; IAM &gt; Account Password Policy &gt; CMDB` control would incorrectly go into an Alarm state when Guardrails was denied access to fetch the Account Password Policy data. This is fixed and the control will now move to an Error state instead for such cases.
- Guardrails stack controls would sometimes fail to update IAM resources if the Terraform plan in the stack&apos;s source policy was updated. This is fixed and the stack controls will now update such resources correctly, as expected. Please note that this fix will only work for workspaces on TE v5.42.0 or higher.</description>
            <pubDate>Wed, 13 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-v5-0-2</guid>
            <title>servicenow v5.0.2 - README.md file is now available for users to check details about resource types that the mod covers</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-v5-0-2</link>
            <description>_Bug fixes_

- README.md file is now available for users to check details about resource types that the mod covers.</description>
            <pubDate>Mon, 11 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-cloudfront-v5-5-0</guid>
            <title>aws-cloudfront v5.5.0 - Added support for CloudFront KeyValueStore permissions</title>
            <link>https://turbot.com/guardrails/changelog/aws-cloudfront-v5-5-0</link>
            <description>_What&apos;s new?_

- `AWS/CloudFront/Admin` and `AWS/CloudFront/Metadata` will now also include permissions for CloudFront KeyValueStore.</description>
            <pubDate>Mon, 11 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-42-10</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.42.10 - Bug fixed - Guardrails will now process notifications correctly for a matching watch created via @turbot/sdk</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-42-10</link>
            <description>_Bug fixes_

- Server
  - Guardrails will now process notifications correctly for a matching watch created via @turbot/sdk.

_Requirements_

- TEF: 1.51.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Fri, 08 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-v5-0-0</guid>
            <title>servicenow-gcp v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-v5-0-0</link>
            <description>_What&apos;s new?_

- Policy Types:
  - ServiceNow &gt; Turbot &gt; Watches &gt; GCP

- Control Types:
  - ServiceNow &gt; Turbot &gt; Watches &gt; GCP

- Action Types:
  - ServiceNow &gt; Turbot &gt; Watches &gt; GCP Archive And Delete Record</description>
            <pubDate>Fri, 08 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-storage-v5-0-0</guid>
            <title>servicenow-gcp-storage v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-storage-v5-0-0</link>
            <description>_What&apos;s new?_

- Policy Types:
  - GCP &gt; Storage &gt; Bucket &gt; ServiceNow
  - GCP &gt; Storage &gt; Bucket &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Storage &gt; Bucket &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Storage &gt; Bucket &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Storage &gt; Bucket &gt; ServiceNow &gt; Table
  - GCP &gt; Storage &gt; Bucket &gt; ServiceNow &gt; Table &gt; Definition

- Control Types:
  - GCP &gt; Storage &gt; Bucket &gt; ServiceNow
  - GCP &gt; Storage &gt; Bucket &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Storage &gt; Bucket &gt; ServiceNow &gt; Table</description>
            <pubDate>Fri, 08 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-sql-v5-0-0</guid>
            <title>servicenow-gcp-sql v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-sql-v5-0-0</link>
            <description>_What&apos;s new?_

- Policy Types:
  - GCP &gt; SQL &gt; Instance &gt; ServiceNow
  - GCP &gt; SQL &gt; Instance &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; SQL &gt; Instance &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; SQL &gt; Instance &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; SQL &gt; Instance &gt; ServiceNow &gt; Table
  - GCP &gt; SQL &gt; Instance &gt; ServiceNow &gt; Table &gt; Definition

- Control Types:
  - GCP &gt; SQL &gt; Instance &gt; ServiceNow
  - GCP &gt; SQL &gt; Instance &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; SQL &gt; Instance &gt; ServiceNow &gt; Table</description>
            <pubDate>Fri, 08 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-network-v5-0-0</guid>
            <title>servicenow-gcp-network v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-network-v5-0-0</link>
            <description>_What&apos;s new?_

- Policy Types:
  - GCP &gt; Network &gt; Network &gt; ServiceNow
  - GCP &gt; Network &gt; Network &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Network &gt; Network &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Network &gt; Network &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Network &gt; Network &gt; ServiceNow &gt; Table
  - GCP &gt; Network &gt; Network &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; Network &gt; Subnetwork &gt; ServiceNow
  - GCP &gt; Network &gt; Subnetwork &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Network &gt; Subnetwork &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Network &gt; Subnetwork &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Network &gt; Subnetwork &gt; ServiceNow &gt; Table
  - GCP &gt; Network &gt; Subnetwork &gt; ServiceNow &gt; Table &gt; Definition

- Control Types:
  - GCP &gt; Network &gt; Network &gt; ServiceNow
  - GCP &gt; Network &gt; Network &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Network &gt; Network &gt; ServiceNow &gt; Table
  - GCP &gt; Network &gt; Subnetwork &gt; ServiceNow
  - GCP &gt; Network &gt; Subnetwork &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Network &gt; Subnetwork &gt; ServiceNow &gt; Table</description>
            <pubDate>Fri, 08 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-gcp-computeengine-v5-0-0</guid>
            <title>servicenow-gcp-computeengine v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-gcp-computeengine-v5-0-0</link>
            <description>_What&apos;s new?_

- Policy Types:
  - GCP &gt; Compute Engine &gt; Disk &gt; ServiceNow
  - GCP &gt; Compute Engine &gt; Disk &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Compute Engine &gt; Disk &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Compute Engine &gt; Disk &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Compute Engine &gt; Disk &gt; ServiceNow &gt; Table
  - GCP &gt; Compute Engine &gt; Disk &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; Compute Engine &gt; Image &gt; ServiceNow
  - GCP &gt; Compute Engine &gt; Image &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Compute Engine &gt; Image &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Compute Engine &gt; Image &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Compute Engine &gt; Image &gt; ServiceNow &gt; Table
  - GCP &gt; Compute Engine &gt; Image &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; Compute Engine &gt; Instance &gt; ServiceNow
  - GCP &gt; Compute Engine &gt; Instance &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Compute Engine &gt; Instance &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Compute Engine &gt; Instance &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Compute Engine &gt; Instance &gt; ServiceNow &gt; Table
  - GCP &gt; Compute Engine &gt; Instance &gt; ServiceNow &gt; Table &gt; Definition
  - GCP &gt; Compute Engine &gt; Snapshot &gt; ServiceNow
  - GCP &gt; Compute Engine &gt; Snapshot &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Compute Engine &gt; Snapshot &gt; ServiceNow &gt; Configuration Item &gt; Record
  - GCP &gt; Compute Engine &gt; Snapshot &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - GCP &gt; Compute Engine &gt; Snapshot &gt; ServiceNow &gt; Table
  - GCP &gt; Compute Engine &gt; Snapshot &gt; ServiceNow &gt; Table &gt; Definition

- Control Types:
  - GCP &gt; Compute Engine &gt; Disk &gt; ServiceNow
  - GCP &gt; Compute Engine &gt; Disk &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Compute Engine &gt; Disk &gt; ServiceNow &gt; Table
  - GCP &gt; Compute Engine &gt; Image &gt; ServiceNow
  - GCP &gt; Compute Engine &gt; Image &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Compute Engine &gt; Image &gt; ServiceNow &gt; Table
  - GCP &gt; Compute Engine &gt; Instance &gt; ServiceNow
  - GCP &gt; Compute Engine &gt; Instance &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Compute Engine &gt; Instance &gt; ServiceNow &gt; Table
  - GCP &gt; Compute Engine &gt; Snapshot &gt; ServiceNow
  - GCP &gt; Compute Engine &gt; Snapshot &gt; ServiceNow &gt; Configuration Item
  - GCP &gt; Compute Engine &gt; Snapshot &gt; ServiceNow &gt; Table</description>
            <pubDate>Fri, 08 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-v5-0-0</guid>
            <title>servicenow-azure v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-v5-0-0</link>
            <description>_What&apos;s new?_

- Policy Types:
  - ServiceNow &gt; Turbot &gt; Watches &gt; Azure

- Control Types:
  - ServiceNow &gt; Turbot &gt; Watches &gt; Azure

- Action Types:
  - ServiceNow &gt; Turbot &gt; Watches &gt; Azure Archive And Delete Record</description>
            <pubDate>Fri, 08 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-storage-v5-0-0</guid>
            <title>servicenow-azure-storage v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-storage-v5-0-0</link>
            <description>_What&apos;s new?_

- Policy Types:
  - Azure &gt; Storage &gt; Storage Account &gt; ServiceNow
  - Azure &gt; Storage &gt; Storage Account &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Storage &gt; Storage Account &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Storage &gt; Storage Account &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Storage &gt; Storage Account &gt; ServiceNow &gt; Table
  - Azure &gt; Storage &gt; Storage Account &gt; ServiceNow &gt; Table &gt; Definition

- Control Types:
  - Azure &gt; Storage &gt; Storage Account &gt; ServiceNow
  - Azure &gt; Storage &gt; Storage Account &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Storage &gt; Storage Account &gt; ServiceNow &gt; Table</description>
            <pubDate>Fri, 08 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-sql-v5-0-0</guid>
            <title>servicenow-azure-sql v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-sql-v5-0-0</link>
            <description>_What&apos;s new?_

- Policy Types:
  - Azure &gt; SQL &gt; Server &gt; ServiceNow
  - Azure &gt; SQL &gt; Server &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; SQL &gt; Server &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; SQL &gt; Server &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; SQL &gt; Server &gt; ServiceNow &gt; Table
  - Azure &gt; SQL &gt; Server &gt; ServiceNow &gt; Table &gt; Definition

- Control Types:
  - Azure &gt; SQL &gt; Server &gt; ServiceNow
  - Azure &gt; SQL &gt; Server &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; SQL &gt; Server &gt; ServiceNow &gt; Table</description>
            <pubDate>Fri, 08 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-postgresql-v5-0-0</guid>
            <title>servicenow-azure-postgresql v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-postgresql-v5-0-0</link>
            <description>_What&apos;s new?_

- Policy Types:
  - Azure &gt; PostgreSQL &gt; Server &gt; ServiceNow
  - Azure &gt; PostgreSQL &gt; Server &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; PostgreSQL &gt; Server &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; PostgreSQL &gt; Server &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; PostgreSQL &gt; Server &gt; ServiceNow &gt; Table
  - Azure &gt; PostgreSQL &gt; Server &gt; ServiceNow &gt; Table &gt; Definition

- Control Types:
  - Azure &gt; PostgreSQL &gt; Server &gt; ServiceNow
  - Azure &gt; PostgreSQL &gt; Server &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; PostgreSQL &gt; Server &gt; ServiceNow &gt; Table</description>
            <pubDate>Fri, 08 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-network-v5-0-0</guid>
            <title>servicenow-azure-network v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-network-v5-0-0</link>
            <description>_What&apos;s new?_

- Policy Types:
  - Azure &gt; Network &gt; Network Security Group &gt; ServiceNow
  - Azure &gt; Network &gt; Network Security Group &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Network &gt; Network Security Group &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Network &gt; Network Security Group &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Network &gt; Network Security Group &gt; ServiceNow &gt; Table
  - Azure &gt; Network &gt; Network Security Group &gt; ServiceNow &gt; Table &gt; Definition
  - Azure &gt; Network &gt; Subnet &gt; ServiceNow
  - Azure &gt; Network &gt; Subnet &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Network &gt; Subnet &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Network &gt; Subnet &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Network &gt; Subnet &gt; ServiceNow &gt; Table
  - Azure &gt; Network &gt; Subnet &gt; ServiceNow &gt; Table &gt; Definition
  - Azure &gt; Network &gt; Virtual Network &gt; ServiceNow
  - Azure &gt; Network &gt; Virtual Network &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Network &gt; Virtual Network &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Network &gt; Virtual Network &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Network &gt; Virtual Network &gt; ServiceNow &gt; Table
  - Azure &gt; Network &gt; Virtual Network &gt; ServiceNow &gt; Table &gt; Definition

- Control Types:
  - Azure &gt; Network &gt; Network Security Group &gt; ServiceNow
  - Azure &gt; Network &gt; Network Security Group &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Network &gt; Network Security Group &gt; ServiceNow &gt; Table
  - Azure &gt; Network &gt; Subnet &gt; ServiceNow
  - Azure &gt; Network &gt; Subnet &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Network &gt; Subnet &gt; ServiceNow &gt; Table
  - Azure &gt; Network &gt; Virtual Network &gt; ServiceNow
  - Azure &gt; Network &gt; Virtual Network &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Network &gt; Virtual Network &gt; ServiceNow &gt; Table</description>
            <pubDate>Fri, 08 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-mysql-v5-0-0</guid>
            <title>servicenow-azure-mysql v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-mysql-v5-0-0</link>
            <description>_What&apos;s new?_

- Policy Types:
  - Azure &gt; MySQL &gt; Server &gt; ServiceNow
  - Azure &gt; MySQL &gt; Server &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; MySQL &gt; Server &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; MySQL &gt; Server &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; MySQL &gt; Server &gt; ServiceNow &gt; Table
  - Azure &gt; MySQL &gt; Server &gt; ServiceNow &gt; Table &gt; Definition

- Control Types:
  - Azure &gt; MySQL &gt; Server &gt; ServiceNow
  - Azure &gt; MySQL &gt; Server &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; MySQL &gt; Server &gt; ServiceNow &gt; Table</description>
            <pubDate>Fri, 08 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-azure-compute-v5-0-0</guid>
            <title>servicenow-azure-compute v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-azure-compute-v5-0-0</link>
            <description>_What&apos;s new?_

- Policy Types:
  - Azure &gt; Compute &gt; Availability Set &gt; ServiceNow
  - Azure &gt; Compute &gt; Availability Set &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Compute &gt; Availability Set &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Compute &gt; Availability Set &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Compute &gt; Availability Set &gt; ServiceNow &gt; Table
  - Azure &gt; Compute &gt; Availability Set &gt; ServiceNow &gt; Table &gt; Definition
  - Azure &gt; Compute &gt; Disk &gt; ServiceNow
  - Azure &gt; Compute &gt; Disk &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Compute &gt; Disk &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Compute &gt; Disk &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Compute &gt; Disk &gt; ServiceNow &gt; Table
  - Azure &gt; Compute &gt; Disk &gt; ServiceNow &gt; Table &gt; Definition
  - Azure &gt; Compute &gt; Disk Encryption Set &gt; ServiceNow
  - Azure &gt; Compute &gt; Disk Encryption Set &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Compute &gt; Disk Encryption Set &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Compute &gt; Disk Encryption Set &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Compute &gt; Disk Encryption Set &gt; ServiceNow &gt; Table
  - Azure &gt; Compute &gt; Disk Encryption Set &gt; ServiceNow &gt; Table &gt; Definition
  - Azure &gt; Compute &gt; Image &gt; ServiceNow
  - Azure &gt; Compute &gt; Image &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Compute &gt; Image &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Compute &gt; Image &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Compute &gt; Image &gt; ServiceNow &gt; Table
  - Azure &gt; Compute &gt; Image &gt; ServiceNow &gt; Table &gt; Definition
  - Azure &gt; Compute &gt; Snapshot &gt; ServiceNow
  - Azure &gt; Compute &gt; Snapshot &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Compute &gt; Snapshot &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Compute &gt; Snapshot &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Compute &gt; Snapshot &gt; ServiceNow &gt; Table
  - Azure &gt; Compute &gt; Snapshot &gt; ServiceNow &gt; Table &gt; Definition
  - Azure &gt; Compute &gt; Ssh Public Key &gt; ServiceNow
  - Azure &gt; Compute &gt; Ssh Public Key &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Compute &gt; Ssh Public Key &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Compute &gt; Ssh Public Key &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Compute &gt; Ssh Public Key &gt; ServiceNow &gt; Table
  - Azure &gt; Compute &gt; Ssh Public Key &gt; ServiceNow &gt; Table &gt; Definition
  - Azure &gt; Compute &gt; Virtual Machine &gt; ServiceNow
  - Azure &gt; Compute &gt; Virtual Machine &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Compute &gt; Virtual Machine &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Compute &gt; Virtual Machine &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Compute &gt; Virtual Machine &gt; ServiceNow &gt; Table
  - Azure &gt; Compute &gt; Virtual Machine &gt; ServiceNow &gt; Table &gt; Definition
  - Azure &gt; Compute &gt; Virtual Machine Scale Set &gt; ServiceNow
  - Azure &gt; Compute &gt; Virtual Machine Scale Set &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Compute &gt; Virtual Machine Scale Set &gt; ServiceNow &gt; Configuration Item &gt; Record
  - Azure &gt; Compute &gt; Virtual Machine Scale Set &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - Azure &gt; Compute &gt; Virtual Machine Scale Set &gt; ServiceNow &gt; Table
  - Azure &gt; Compute &gt; Virtual Machine Scale Set &gt; ServiceNow &gt; Table &gt; Definition

- Control Types:
  - Azure &gt; Compute &gt; Availability Set &gt; ServiceNow
  - Azure &gt; Compute &gt; Availability Set &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Compute &gt; Availability Set &gt; ServiceNow &gt; Table
  - Azure &gt; Compute &gt; Disk &gt; ServiceNow
  - Azure &gt; Compute &gt; Disk &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Compute &gt; Disk &gt; ServiceNow &gt; Table
  - Azure &gt; Compute &gt; Disk Encryption Set &gt; ServiceNow
  - Azure &gt; Compute &gt; Disk Encryption Set &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Compute &gt; Disk Encryption Set &gt; ServiceNow &gt; Table
  - Azure &gt; Compute &gt; Image &gt; ServiceNow
  - Azure &gt; Compute &gt; Image &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Compute &gt; Image &gt; ServiceNow &gt; Table
  - Azure &gt; Compute &gt; Snapshot &gt; ServiceNow
  - Azure &gt; Compute &gt; Snapshot &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Compute &gt; Snapshot &gt; ServiceNow &gt; Table
  - Azure &gt; Compute &gt; Ssh Public Key &gt; ServiceNow
  - Azure &gt; Compute &gt; Ssh Public Key &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Compute &gt; Ssh Public Key &gt; ServiceNow &gt; Table
  - Azure &gt; Compute &gt; Virtual Machine &gt; ServiceNow
  - Azure &gt; Compute &gt; Virtual Machine &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Compute &gt; Virtual Machine &gt; ServiceNow &gt; Table
  - Azure &gt; Compute &gt; Virtual Machine Scale Set &gt; ServiceNow
  - Azure &gt; Compute &gt; Virtual Machine Scale Set &gt; ServiceNow &gt; Configuration Item
  - Azure &gt; Compute &gt; Virtual Machine Scale Set &gt; ServiceNow &gt; Table</description>
            <pubDate>Fri, 08 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-aws-v5-0-1</guid>
            <title>servicenow-aws v5.0.1 - Bug Fixed - Watches control would fail to delete/archive records in ServiceNow</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-aws-v5-0-1</link>
            <description>_Bug fixes_

- The `ServiceNow &gt; Turbot &gt; Watches &gt; AWS` control would fail to delete/archive records in ServiceNow. This is now fixed.</description>
            <pubDate>Fri, 08 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-42-9</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.42.9 - Minor fixes - TE stack will now enable propagation of custom tags to ECS tasks</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-42-9</link>
            <description>_Bug fixes_

- Server
  - Updated TE stack to enable propagation of custom tags to ECS tasks.
  - Updated @turbot/aws-sdk to 5.13.0, @turbot/fn to 5.21.0 and aws-sdk to 2.922.

_Requirements_

- TEF: 1.51.0
- TED: 1.9.1

_Base images_

Alpine: 3.17.5
Ubuntu: 22.04.3</description>
            <pubDate>Thu, 07 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-aws-vpc-security-v5-0-2</guid>
            <title>servicenow-aws-vpc-security v5.0.2 - Minor fixes on Configuration Item and Table controls</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-aws-vpc-security-v5-0-2</link>
            <description>_Bug fixes_

- The Table control did not allow extending the resource&apos;s Table from any other Table in ServiceNow but the `cmdb_ci*` Table. This is fixed and users will now be able to extend the resource&apos;s Table off of any Table in ServiceNow.
- The Configuration Item control would sometimes go into an invalid state if the corresponding Table was not found in ServiceNow. The control will now go to an error state instead, which will allow Guardrails to retry running the control automatically.
- The Configuration Item control would sometimes fail to detect if any columns were missing from the corresponding Table before creating a record in ServiceNow. This is fixed and the control will now work correctly as expected.</description>
            <pubDate>Thu, 07 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-aws-vpc-internet-v5-0-2</guid>
            <title>servicenow-aws-vpc-internet v5.0.2 - Minor fixes on Configuration Item and Table controls</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-aws-vpc-internet-v5-0-2</link>
            <description>_Bug fixes_

- The Table control did not allow extending the resource&apos;s Table from any other Table in ServiceNow but the `cmdb_ci*` Table. This is fixed and users will now be able to extend the resource&apos;s Table off of any Table in ServiceNow.
- The Configuration Item control would sometimes go into an invalid state if the corresponding Table was not found in ServiceNow. The control will now go to an error state instead, which will allow Guardrails to retry running the control automatically.
- The Configuration Item control would sometimes fail to detect if any columns were missing from the corresponding Table before creating a record in ServiceNow. This is fixed and the control will now work correctly as expected.</description>
            <pubDate>Thu, 07 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-aws-vpc-core-v5-0-2</guid>
            <title>servicenow-aws-vpc-core v5.0.2 - Minor fixes on Configuration Item and Table controls</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-aws-vpc-core-v5-0-2</link>
            <description>_Bug fixes_

- The Table control did not allow extending the resource&apos;s Table from any other Table in ServiceNow but the `cmdb_ci*` Table. This is fixed and users will now be able to extend the resource&apos;s Table off of any Table in ServiceNow.
- The Configuration Item control would sometimes go into an invalid state if the corresponding Table was not found in ServiceNow. The control will now go to an error state instead, which will allow Guardrails to retry running the control automatically.
- The Configuration Item control would sometimes fail to detect if any columns were missing from the corresponding Table before creating a record in ServiceNow. This is fixed and the control will now work correctly as expected.</description>
            <pubDate>Thu, 07 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-aws-s3-v5-0-2</guid>
            <title>servicenow-aws-s3 v5.0.2 - Minor fixes on Configuration Item and Table controls</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-aws-s3-v5-0-2</link>
            <description>_Bug fixes_

- The Table control did not allow extending the resource&apos;s Table from any other Table in ServiceNow but the `cmdb_ci*` Table. This is fixed and users will now be able to extend the resource&apos;s Table off of any Table in ServiceNow.
- The Configuration Item control would sometimes go into an invalid state if the corresponding Table was not found in ServiceNow. The control will now go to an error state instead, which will allow Guardrails to retry running the control automatically.
- The Configuration Item control would sometimes fail to detect if any columns were missing from the corresponding Table before creating a record in ServiceNow. This is fixed and the control will now work correctly as expected.</description>
            <pubDate>Thu, 07 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-aws-rds-v5-0-2</guid>
            <title>servicenow-aws-rds v5.0.2 - Minor fixes on Configuration Item and Table controls</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-aws-rds-v5-0-2</link>
            <description>_Bug fixes_

- The Table control did not allow extending the resource&apos;s Table from any other Table in ServiceNow but the `cmdb_ci*` Table. This is fixed and users will now be able to extend the resource&apos;s Table off of any Table in ServiceNow.
- The Configuration Item control would sometimes go into an invalid state if the corresponding Table was not found in ServiceNow. The control will now go to an error state instead, which will allow Guardrails to retry running the control automatically.
- The Configuration Item control would sometimes fail to detect if any columns were missing from the corresponding Table before creating a record in ServiceNow. This is fixed and the control will now work correctly as expected.</description>
            <pubDate>Thu, 07 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-aws-iam-v5-0-2</guid>
            <title>servicenow-aws-iam v5.0.2 - Minor fixes on Configuration Item and Table controls</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-aws-iam-v5-0-2</link>
            <description>_Bug fixes_

- The Table control did not allow extending the resource&apos;s Table from any other Table in ServiceNow but the `cmdb_ci*` Table. This is fixed and users will now be able to extend the resource&apos;s Table off of any Table in ServiceNow.
- The Configuration Item control would sometimes go into an invalid state if the corresponding Table was not found in ServiceNow. The control will now go to an error state instead, which will allow Guardrails to retry running the control automatically.
- The Configuration Item control would sometimes fail to detect if any columns were missing from the corresponding Table before creating a record in ServiceNow. This is fixed and the control will now work correctly as expected.</description>
            <pubDate>Thu, 07 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-aws-ec2-v5-0-2</guid>
            <title>servicenow-aws-ec2 v5.0.2 - Minor fixes on Configuration Item and Table controls</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-aws-ec2-v5-0-2</link>
            <description>_Bug fixes_

- The Table control did not allow extending the resource&apos;s Table from any other Table in ServiceNow but the `cmdb_ci*` Table. This is fixed and users will now be able to extend the resource&apos;s Table off of any Table in ServiceNow.
- The Configuration Item control would sometimes go into an invalid state if the corresponding Table was not found in ServiceNow. The control will now go to an error state instead, which will allow Guardrails to retry running the control automatically.
- The Configuration Item control would sometimes fail to detect if any columns were missing from the corresponding Table before creating a record in ServiceNow. This is fixed and the control will now work correctly as expected.</description>
            <pubDate>Thu, 07 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-v5-0-1</guid>
            <title>servicenow v5.0.1 - Bug Fixed - Discovery controls would sometimes upsert resources with incorrect AKAs</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-v5-0-1</link>
            <description>_Bug fixes_

- The Discovery controls for Application, Cost Center and User would sometimes upsert resources with incorrect AKAs for a freshly imported ServiceNow Instance in Guardrails CMDB. This is fixed and the controls will now work as expected.</description>
            <pubDate>Wed, 06 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-aws-vpc-security-v5-0-1</guid>
            <title>servicenow-aws-vpc-security v5.0.1 - Bug Fixed - ServiceNow Table control would sometimes fail create tables correctly in ServiceNow</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-aws-vpc-security-v5-0-1</link>
            <description>_Bug fixes_

- The ServiceNow Table control would sometimes fail to create tables correctly in ServiceNow. This is now fixed.</description>
            <pubDate>Wed, 06 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-aws-vpc-internet-v5-0-1</guid>
            <title>servicenow-aws-vpc-internet v5.0.1 - Bug Fixed - ServiceNow Table control would sometimes fail create tables correctly in ServiceNow</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-aws-vpc-internet-v5-0-1</link>
            <description>_Bug fixes_

- The ServiceNow Table control would sometimes fail to create tables correctly in ServiceNow. This is now fixed.</description>
            <pubDate>Wed, 06 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-aws-vpc-core-v5-0-1</guid>
            <title>servicenow-aws-vpc-core v5.0.1 - Bug Fixed - ServiceNow Table control would sometimes fail create tables correctly in ServiceNow</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-aws-vpc-core-v5-0-1</link>
            <description>_Bug fixes_

- The ServiceNow Table control would sometimes fail to create tables correctly in ServiceNow. This is now fixed.</description>
            <pubDate>Wed, 06 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-aws-s3-v5-0-1</guid>
            <title>servicenow-aws-s3 v5.0.1 - Bug Fixed - ServiceNow Table control would sometimes fail create tables correctly in ServiceNow</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-aws-s3-v5-0-1</link>
            <description>_Bug fixes_

- The ServiceNow Table control would sometimes fail to create tables correctly in ServiceNow. This is now fixed.</description>
            <pubDate>Wed, 06 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-aws-rds-v5-0-1</guid>
            <title>servicenow-aws-rds v5.0.1 - Bug Fixed - ServiceNow Table control would sometimes fail create tables correctly in ServiceNow</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-aws-rds-v5-0-1</link>
            <description>_Bug fixes_

- The ServiceNow Table control would sometimes fail to create tables correctly in ServiceNow. This is now fixed.</description>
            <pubDate>Wed, 06 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-aws-iam-v5-0-1</guid>
            <title>servicenow-aws-iam v5.0.1 - Bug Fixed - ServiceNow Table control would sometimes fail create tables correctly in ServiceNow</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-aws-iam-v5-0-1</link>
            <description>_Bug fixes_

- The ServiceNow Table control would sometimes fail to create tables correctly in ServiceNow. This is now fixed.</description>
            <pubDate>Wed, 06 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-aws-ec2-v5-0-1</guid>
            <title>servicenow-aws-ec2 v5.0.1 - Bug Fixed - ServiceNow Table control would sometimes fail create tables correctly in ServiceNow</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-aws-ec2-v5-0-1</link>
            <description>_Bug fixes_

- The ServiceNow Table control would sometimes fail to create tables correctly in ServiceNow. This is now fixed.</description>
            <pubDate>Wed, 06 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-v5-29-1</guid>
            <title>aws v5.29.1 - Event Poller will now be automatically set to `Disabled` if either the Event Handlers or Event Handlers [Global] is set to `Enforce: Configured`</title>
            <link>https://turbot.com/guardrails/changelog/aws-v5-29-1</link>
            <description>_Bug fixes_

- The `AWS &gt; Turbot &gt; Event Poller` policy will now be automatically set to `Disabled` if any of the `AWS &gt; Turbot &gt; Event Handlers` or `AWS &gt; Turbot &gt; Event Handlers [Global]` policies is set to `Enforce: Configured`.</description>
            <pubDate>Wed, 06 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-42-8</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.42.8 - Bug Fixed - ServiceNow Instance Client Secret and Password were processed incorrectly while fetching credentials for the Instance</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-42-8</link>
            <description>_Bug fixes_

- Server
  - ServiceNow Instance Client Secret and Password were processed incorrectly while fetching credentials for the Instance.</description>
            <pubDate>Tue, 05 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-42-7</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.42.7 - Bug Fixed - Create mutation for ServiceNow instance failed if no instances were available in a Guardrails workspace</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-42-7</link>
            <description>_Bug fixes_

- Server
  - Create mutation for ServiceNow instance failed if no instances were available in a Guardrails workspace.</description>
            <pubDate>Tue, 05 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-v5-0-0</guid>
            <title>servicenow v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-v5-0-0</link>
            <description>_What&apos;s new?_

- Resource Types:
  - ServiceNow
  - ServiceNow &gt; Application
  - ServiceNow &gt; Cost Center
  - ServiceNow &gt; Instance
  - ServiceNow &gt; User

- Policy Types:
  - ServiceNow &gt; Application &gt; Business Rule
  - ServiceNow &gt; Application &gt; Business Rule &gt; Name
  - ServiceNow &gt; Application &gt; CMDB
  - ServiceNow &gt; Config
  - ServiceNow &gt; Config &gt; Application Scope
  - ServiceNow &gt; Config &gt; Client ID
  - ServiceNow &gt; Config &gt; Client Secret
  - ServiceNow &gt; Config &gt; Instance URL
  - ServiceNow &gt; Config &gt; Password
  - ServiceNow &gt; Config &gt; System Properties
  - ServiceNow &gt; Config &gt; System Properties &gt; Template
  - ServiceNow &gt; Config &gt; Username
  - ServiceNow &gt; Cost Center &gt; Business Rule
  - ServiceNow &gt; Cost Center &gt; Business Rule &gt; Name
  - ServiceNow &gt; Cost Center &gt; CMDB
  - ServiceNow &gt; Instance &gt; CMDB
  - ServiceNow &gt; Login Names
  - ServiceNow &gt; Turbot
  - ServiceNow &gt; Turbot &gt; Watches
  - ServiceNow &gt; User &gt; Business Rule
  - ServiceNow &gt; User &gt; Business Rule &gt; Name
  - ServiceNow &gt; User &gt; CMDB

- Control Types:
  - ServiceNow &gt; Application &gt; Business Rule
  - ServiceNow &gt; Application &gt; CMDB
  - ServiceNow &gt; Application &gt; Discovery
  - ServiceNow &gt; Config
  - ServiceNow &gt; Config &gt; System Properties
  - ServiceNow &gt; Cost Center &gt; Business Rule
  - ServiceNow &gt; Cost Center &gt; CMDB
  - ServiceNow &gt; Cost Center &gt; Discovery
  - ServiceNow &gt; Instance &gt; CMDB
  - ServiceNow &gt; Turbot
  - ServiceNow &gt; Turbot &gt; Watches
  - ServiceNow &gt; User &gt; Business Rule
  - ServiceNow &gt; User &gt; CMDB
  - ServiceNow &gt; User &gt; Discovery

- Action Types:
  - ServiceNow &gt; Instance &gt; Event Handler
  - ServiceNow &gt; Turbot
  - ServiceNow &gt; Turbot &gt; Watches</description>
            <pubDate>Tue, 05 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-aws-vpc-security-v5-0-0</guid>
            <title>servicenow-aws-vpc-security v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-aws-vpc-security-v5-0-0</link>
            <description>_What&apos;s new?_

- Policy Types:
  - AWS &gt; VPC &gt; Network ACL &gt; ServiceNow
  - AWS &gt; VPC &gt; Network ACL &gt; ServiceNow &gt; Configuration Item
  - AWS &gt; VPC &gt; Network ACL &gt; ServiceNow &gt; Configuration Item &gt; Record
  - AWS &gt; VPC &gt; Network ACL &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - AWS &gt; VPC &gt; Network ACL &gt; ServiceNow &gt; Table
  - AWS &gt; VPC &gt; Network ACL &gt; ServiceNow &gt; Table &gt; Definition
  - AWS &gt; VPC &gt; Security Group &gt; ServiceNow
  - AWS &gt; VPC &gt; Security Group &gt; ServiceNow &gt; Configuration Item
  - AWS &gt; VPC &gt; Security Group &gt; ServiceNow &gt; Configuration Item &gt; Record
  - AWS &gt; VPC &gt; Security Group &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - AWS &gt; VPC &gt; Security Group &gt; ServiceNow &gt; Table
  - AWS &gt; VPC &gt; Security Group &gt; ServiceNow &gt; Table &gt; Definition

- Control Types:
  - AWS &gt; VPC &gt; Network ACL &gt; ServiceNow
  - AWS &gt; VPC &gt; Network ACL &gt; ServiceNow &gt; Configuration Item
  - AWS &gt; VPC &gt; Network ACL &gt; ServiceNow &gt; Table
  - AWS &gt; VPC &gt; Security Group &gt; ServiceNow
  - AWS &gt; VPC &gt; Security Group &gt; ServiceNow &gt; Configuration Item
  - AWS &gt; VPC &gt; Security Group &gt; ServiceNow &gt; Table</description>
            <pubDate>Tue, 05 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-aws-vpc-internet-v5-0-0</guid>
            <title>servicenow-aws-vpc-internet v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-aws-vpc-internet-v5-0-0</link>
            <description>_What&apos;s new?_

- Policy Types:
  - AWS &gt; VPC &gt; Elastic IP &gt; ServiceNow
  - AWS &gt; VPC &gt; Elastic IP &gt; ServiceNow &gt; Configuration Item
  - AWS &gt; VPC &gt; Elastic IP &gt; ServiceNow &gt; Configuration Item &gt; Record
  - AWS &gt; VPC &gt; Elastic IP &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - AWS &gt; VPC &gt; Elastic IP &gt; ServiceNow &gt; Table
  - AWS &gt; VPC &gt; Elastic IP &gt; ServiceNow &gt; Table &gt; Definition

- Control Types:
  - AWS &gt; VPC &gt; Elastic IP &gt; ServiceNow
  - AWS &gt; VPC &gt; Elastic IP &gt; ServiceNow &gt; Configuration Item
  - AWS &gt; VPC &gt; Elastic IP &gt; ServiceNow &gt; Table</description>
            <pubDate>Tue, 05 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-aws-vpc-core-v5-0-0</guid>
            <title>servicenow-aws-vpc-core v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-aws-vpc-core-v5-0-0</link>
            <description>_What&apos;s new?_

- Policy Types:
  - AWS &gt; VPC &gt; Route Table &gt; ServiceNow
  - AWS &gt; VPC &gt; Route Table &gt; ServiceNow &gt; Configuration Item
  - AWS &gt; VPC &gt; Route Table &gt; ServiceNow &gt; Configuration Item &gt; Record
  - AWS &gt; VPC &gt; Route Table &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - AWS &gt; VPC &gt; Route Table &gt; ServiceNow &gt; Table
  - AWS &gt; VPC &gt; Route Table &gt; ServiceNow &gt; Table &gt; Definition
  - AWS &gt; VPC &gt; Subnet &gt; ServiceNow
  - AWS &gt; VPC &gt; Subnet &gt; ServiceNow &gt; Configuration Item
  - AWS &gt; VPC &gt; Subnet &gt; ServiceNow &gt; Configuration Item &gt; Record
  - AWS &gt; VPC &gt; Subnet &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - AWS &gt; VPC &gt; Subnet &gt; ServiceNow &gt; Table
  - AWS &gt; VPC &gt; Subnet &gt; ServiceNow &gt; Table &gt; Definition
  - AWS &gt; VPC &gt; VPC &gt; ServiceNow
  - AWS &gt; VPC &gt; VPC &gt; ServiceNow &gt; Configuration Item
  - AWS &gt; VPC &gt; VPC &gt; ServiceNow &gt; Configuration Item &gt; Record
  - AWS &gt; VPC &gt; VPC &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - AWS &gt; VPC &gt; VPC &gt; ServiceNow &gt; Table
  - AWS &gt; VPC &gt; VPC &gt; ServiceNow &gt; Table &gt; Definition

- Control Types:
  - AWS &gt; VPC &gt; Route Table &gt; ServiceNow
  - AWS &gt; VPC &gt; Route Table &gt; ServiceNow &gt; Configuration Item
  - AWS &gt; VPC &gt; Route Table &gt; ServiceNow &gt; Table
  - AWS &gt; VPC &gt; Subnet &gt; ServiceNow
  - AWS &gt; VPC &gt; Subnet &gt; ServiceNow &gt; Configuration Item
  - AWS &gt; VPC &gt; Subnet &gt; ServiceNow &gt; Table
  - AWS &gt; VPC &gt; VPC &gt; ServiceNow
  - AWS &gt; VPC &gt; VPC &gt; ServiceNow &gt; Configuration Item
  - AWS &gt; VPC &gt; VPC &gt; ServiceNow &gt; Table</description>
            <pubDate>Tue, 05 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-aws-v5-0-0</guid>
            <title>servicenow-aws v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-aws-v5-0-0</link>
            <description>_What&apos;s new?_

- Policy Types:
  - ServiceNow &gt; Turbot &gt; Watches &gt; AWS

- Control Types:
  - ServiceNow &gt; Turbot &gt; Watches &gt; AWS

- Action Types:
  - ServiceNow &gt; Turbot &gt; Watches &gt; AWS Archive And Delete Record</description>
            <pubDate>Tue, 05 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-aws-s3-v5-0-0</guid>
            <title>servicenow-aws-s3 v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-aws-s3-v5-0-0</link>
            <description>_What&apos;s new?_

- Policy Types:
  - AWS &gt; S3 &gt; Bucket &gt; ServiceNow
  - AWS &gt; S3 &gt; Bucket &gt; ServiceNow &gt; Configuration Item
  - AWS &gt; S3 &gt; Bucket &gt; ServiceNow &gt; Configuration Item &gt; Record
  - AWS &gt; S3 &gt; Bucket &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - AWS &gt; S3 &gt; Bucket &gt; ServiceNow &gt; Table
  - AWS &gt; S3 &gt; Bucket &gt; ServiceNow &gt; Table &gt; Definition

- Control Types:
  - AWS &gt; S3 &gt; Bucket &gt; ServiceNow
  - AWS &gt; S3 &gt; Bucket &gt; ServiceNow &gt; Configuration Item
  - AWS &gt; S3 &gt; Bucket &gt; ServiceNow &gt; Table</description>
            <pubDate>Tue, 05 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-aws-iam-v5-0-0</guid>
            <title>servicenow-aws-iam v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-aws-iam-v5-0-0</link>
            <description>_What&apos;s new?_

- Policy Types:
  - AWS &gt; IAM &gt; Group &gt; ServiceNow
  - AWS &gt; IAM &gt; Group &gt; ServiceNow &gt; Configuration Item
  - AWS &gt; IAM &gt; Group &gt; ServiceNow &gt; Configuration Item &gt; Record
  - AWS &gt; IAM &gt; Group &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - AWS &gt; IAM &gt; Group &gt; ServiceNow &gt; Table
  - AWS &gt; IAM &gt; Group &gt; ServiceNow &gt; Table &gt; Definition
  - AWS &gt; IAM &gt; Role &gt; ServiceNow
  - AWS &gt; IAM &gt; Role &gt; ServiceNow &gt; Configuration Item
  - AWS &gt; IAM &gt; Role &gt; ServiceNow &gt; Configuration Item &gt; Record
  - AWS &gt; IAM &gt; Role &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - AWS &gt; IAM &gt; Role &gt; ServiceNow &gt; Table
  - AWS &gt; IAM &gt; Role &gt; ServiceNow &gt; Table &gt; Definition
  - AWS &gt; IAM &gt; User &gt; ServiceNow
  - AWS &gt; IAM &gt; User &gt; ServiceNow &gt; Configuration Item
  - AWS &gt; IAM &gt; User &gt; ServiceNow &gt; Configuration Item &gt; Record
  - AWS &gt; IAM &gt; User &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - AWS &gt; IAM &gt; User &gt; ServiceNow &gt; Table
  - AWS &gt; IAM &gt; User &gt; ServiceNow &gt; Table &gt; Definition

- Control Types:
  - AWS &gt; IAM &gt; Group &gt; ServiceNow
  - AWS &gt; IAM &gt; Group &gt; ServiceNow &gt; Configuration Item
  - AWS &gt; IAM &gt; Group &gt; ServiceNow &gt; Table
  - AWS &gt; IAM &gt; Role &gt; ServiceNow
  - AWS &gt; IAM &gt; Role &gt; ServiceNow &gt; Configuration Item
  - AWS &gt; IAM &gt; Role &gt; ServiceNow &gt; Table
  - AWS &gt; IAM &gt; User &gt; ServiceNow
  - AWS &gt; IAM &gt; User &gt; ServiceNow &gt; Configuration Item
  - AWS &gt; IAM &gt; User &gt; ServiceNow &gt; Table</description>
            <pubDate>Tue, 05 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/servicenow-aws-ec2-v5-0-0</guid>
            <title>servicenow-aws-ec2 v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/servicenow-aws-ec2-v5-0-0</link>
            <description>_What&apos;s new?_

- Policy Types:
  - AWS &gt; EC2 &gt; Instance &gt; ServiceNow
  - AWS &gt; EC2 &gt; Instance &gt; ServiceNow &gt; Configuration Item
  - AWS &gt; EC2 &gt; Instance &gt; ServiceNow &gt; Configuration Item &gt; Record
  - AWS &gt; EC2 &gt; Instance &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - AWS &gt; EC2 &gt; Instance &gt; ServiceNow &gt; Table
  - AWS &gt; EC2 &gt; Instance &gt; ServiceNow &gt; Table &gt; Definition
  - AWS &gt; EC2 &gt; Snapshot &gt; ServiceNow
  - AWS &gt; EC2 &gt; Snapshot &gt; ServiceNow &gt; Configuration Item
  - AWS &gt; EC2 &gt; Snapshot &gt; ServiceNow &gt; Configuration Item &gt; Record
  - AWS &gt; EC2 &gt; Snapshot &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - AWS &gt; EC2 &gt; Snapshot &gt; ServiceNow &gt; Table
  - AWS &gt; EC2 &gt; Snapshot &gt; ServiceNow &gt; Table &gt; Definition
  - AWS &gt; EC2 &gt; Volume &gt; ServiceNow
  - AWS &gt; EC2 &gt; Volume &gt; ServiceNow &gt; Configuration Item
  - AWS &gt; EC2 &gt; Volume &gt; ServiceNow &gt; Configuration Item &gt; Record
  - AWS &gt; EC2 &gt; Volume &gt; ServiceNow &gt; Configuration Item &gt; Table Definition
  - AWS &gt; EC2 &gt; Volume &gt; ServiceNow &gt; Table
  - AWS &gt; EC2 &gt; Volume &gt; ServiceNow &gt; Table &gt; Definition

- Control Types:
  - AWS &gt; EC2 &gt; Instance &gt; ServiceNow
  - AWS &gt; EC2 &gt; Instance &gt; ServiceNow &gt; Configuration Item
  - AWS &gt; EC2 &gt; Instance &gt; ServiceNow &gt; Table
  - AWS &gt; EC2 &gt; Snapshot &gt; ServiceNow
  - AWS &gt; EC2 &gt; Snapshot &gt; ServiceNow &gt; Configuration Item
  - AWS &gt; EC2 &gt; Snapshot &gt; ServiceNow &gt; Table
  - AWS &gt; EC2 &gt; Volume &gt; ServiceNow
  - AWS &gt; EC2 &gt; Volume &gt; ServiceNow &gt; Configuration Item
  - AWS &gt; EC2 &gt; Volume &gt; ServiceNow &gt; Table</description>
            <pubDate>Tue, 05 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-42-6</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.42.6 - Added support to import ServiceNow Instances in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-42-6</link>
            <description>_What&apos;s new?_

- Server
  - Added: Support for creating and deleting watches using @turbot/sdk.
  - Updated: @turbot/fn, @turbot/aws-sdk, aws-sdk, @turbot/utils, @turbot/errors, @turbot/log, @turbot/responses packages.
  - Added: Support for ServiceNow credentials.

- UI:
  - Added: Support to import ServiceNow Instance in Guardrails.</description>
            <pubDate>Fri, 01 Dec 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/turbot-v5-42-0</guid>
            <title>turbot v5.42.0 - Added support for new Control Categories in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/turbot-v5-42-0</link>
            <description>_What&apos;s new?_

- Control Category Types:
  - CMDB &gt; External
  - Cloud &gt; Integration</description>
            <pubDate>Thu, 30 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-kendra-v5-0-0</guid>
            <title>aws-kendra v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/aws-kendra-v5-0-0</link>
            <description>_What&apos;s new?_

- Resource Types:
  - AWS &gt; Kendra

- Policy Types:
  - AWS &gt; Kendra &gt; API Enabled
  - AWS &gt; Kendra &gt; Approved Regions [Default]
  - AWS &gt; Kendra &gt; Enabled
  - AWS &gt; Kendra &gt; Permissions
  - AWS &gt; Kendra &gt; Permissions &gt; Levels
  - AWS &gt; Kendra &gt; Permissions &gt; Levels &gt; Modifiers
  - AWS &gt; Kendra &gt; Permissions &gt; Lockdown
  - AWS &gt; Kendra &gt; Permissions &gt; Lockdown &gt; API Boundary
  - AWS &gt; Kendra &gt; Regions
  - AWS &gt; Kendra &gt; Tags Template [Default]
  - AWS &gt; Turbot &gt; Permissions &gt; Compiled &gt; API Boundary &gt; @turbot/aws-kendra
  - AWS &gt; Turbot &gt; Permissions &gt; Compiled &gt; Levels &gt; @turbot/aws-kendra
  - AWS &gt; Turbot &gt; Permissions &gt; Compiled &gt; Service Permissions &gt; @turbot/aws-kendra</description>
            <pubDate>Tue, 28 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/turbot-v5-41-0</guid>
            <title>turbot v5.41.0 - Added support for new Categories in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/turbot-v5-41-0</link>
            <description>_What&apos;s new?_

- Category Types:
  - Turbot &gt; Resource &gt; Category &gt; Business Application
  - Turbot &gt; Resource &gt; Category &gt; Cloud &gt; Api
  - Turbot &gt; Resource &gt; Category &gt; Cloud &gt; Provider
  - Turbot &gt; Resource &gt; Category &gt; Cloud &gt; Resource Group
  - Turbot &gt; Resource &gt; Category &gt; Container
  - Turbot &gt; Resource &gt; Category &gt; Cost Management
  - Turbot &gt; Resource &gt; Category &gt; End User Computing
  - Turbot &gt; Resource &gt; Category &gt; Migration
  - Turbot &gt; Resource &gt; Category &gt; Robotics</description>
            <pubDate>Fri, 24 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-v5-23-1</guid>
            <title>gcp v5.23.1 - Added support to process enable and disable real-time events for Firebase Management APIs</title>
            <link>https://turbot.com/guardrails/changelog/gcp-v5-23-1</link>
            <description>_What&apos;s new?_

- Added support to process enable and disable real-time events for Firebase Management APIs.</description>
            <pubDate>Fri, 24 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-firebase-v5-1-0</guid>
            <title>gcp-firebase v5.1.0 - You can can now enable Firebase Management API via Guardrails; Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/gcp-firebase-v5-1-0</link>
            <description>_What&apos;s new?_

- You can now Enable/Disable Firebase Management API via Guardrails. To get started, set the `GCP &gt; Firebase &gt; API Enabled` policy.
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

- Control Types:
  - GCP &gt; Firebase &gt; API Enabled

- Policy Types:
  - GCP &gt; Firebase &gt; API Enabled
  - GCP &gt; Firebase &gt; Android App &gt; Approved &gt; Custom
  - GCP &gt; Firebase &gt; Web App &gt; Approved &gt; Custom
  - GCP &gt; Firebase &gt; iOS App &gt; Approved &gt; Custom

- Action Types:
  - GCP &gt; Firebase &gt; Set API Enabled</description>
            <pubDate>Fri, 24 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-synapseanalytics-v5-7-0</guid>
            <title>azure-synapseanalytics v5.7.0 - Added support for newer Europe, India, US and US Government regions; Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/azure-synapseanalytics-v5-7-0</link>
            <description>_What&apos;s new?_

- Added support for newer US, Europe, India and US Government regions in the `Azure &gt; Synapse Analytics &gt; Regions` policy.
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Policy Types:
  - Azure &gt; Synapse Analytics &gt; SQL Pool &gt; Approved &gt; Custom
  - Azure &gt; Synapse Analytics &gt; SQL Pool &gt; Regions
  - Azure &gt; Synapse Analytics &gt; Workspace &gt; Approved &gt; Custom</description>
            <pubDate>Fri, 24 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-apimanagement-v5-3-0</guid>
            <title>azure-apimanagement v5.3.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/azure-apimanagement-v5-3-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Policy Types:
  - Azure &gt; API Management &gt; API Management Service &gt; Approved &gt; Custom</description>
            <pubDate>Fri, 24 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-aks-v5-6-0</guid>
            <title>azure-aks v5.6.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/azure-aks-v5-6-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Policy Types:
  - Azure &gt; AKS &gt; Managed Cluster &gt; Approved &gt; Custom</description>
            <pubDate>Fri, 24 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-networkwatcher-v5-8-0</guid>
            <title>azure-networkwatcher v5.8.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/azure-networkwatcher-v5-8-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Policy Types:
  - Azure &gt; Network Watcher &gt; Flow Log &gt; Approved &gt; Custom
  - Azure &gt; Network Watcher &gt; Network Watcher &gt; Approved &gt; Custom</description>
            <pubDate>Thu, 23 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-datafactory-v5-6-0</guid>
            <title>azure-datafactory v5.6.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/azure-datafactory-v5-6-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Policy Types:
  - Azure &gt; Data Factory &gt; Dataset &gt; Approved &gt; Custom
  - Azure &gt; Data Factory &gt; Factory &gt; Approved &gt; Custom
  - Azure &gt; Data Factory &gt; Pipeline &gt; Approved &gt; Custom</description>
            <pubDate>Thu, 23 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-notebooks-v5-1-0</guid>
            <title>gcp-notebooks v5.1.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/gcp-notebooks-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.</description>
            <pubDate>Tue, 21 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-datacatalog-v5-2-0</guid>
            <title>gcp-datacatalog v5.2.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/gcp-datacatalog-v5-2-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.</description>
            <pubDate>Tue, 21 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-firewall-v5-6-0</guid>
            <title>azure-firewall v5.6.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/azure-firewall-v5-6-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Policy Types:
  - Azure &gt; Firewall &gt; Firewall &gt; Approved &gt; Custom</description>
            <pubDate>Tue, 21 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-securitycenter-v5-2-0</guid>
            <title>azure-securitycenter v5.2.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/azure-securitycenter-v5-2-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.</description>
            <pubDate>Mon, 20 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-frontdoorservice-v5-7-0</guid>
            <title>azure-frontdoorservice v5.7.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/azure-frontdoorservice-v5-7-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Policy Types:
  - Azure &gt; Front Door &gt; Front Door &gt; Approved &gt; Custom</description>
            <pubDate>Mon, 20 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-databricks-v5-3-0</guid>
            <title>azure-databricks v5.3.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/azure-databricks-v5-3-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Policy Types:
  - Azure &gt; Databricks &gt; Workspace &gt; Approved &gt; Custom</description>
            <pubDate>Mon, 20 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-cosmosdb-v5-5-0</guid>
            <title>azure-cosmosdb v5.5.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/azure-cosmosdb-v5-5-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.</description>
            <pubDate>Mon, 20 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-computeengine-v5-17-0</guid>
            <title>gcp-computeengine v5.17.0 - Trusted Access control for Images now also supports All Authenticated and All Users policies</title>
            <link>https://turbot.com/guardrails/changelog/gcp-computeengine-v5-17-0</link>
            <description>_What&apos;s new?_

- Policy Types:
  - GCP &gt; Compute Engine &gt; Image &gt; Policy &gt; Trusted Access &gt; All Authenticated
  - GCP &gt; Compute Engine &gt; Image &gt; Policy &gt; Trusted Access &gt; All Users</description>
            <pubDate>Fri, 17 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-signalr-v5-1-0</guid>
            <title>azure-signalr v5.1.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/azure-signalr-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Policy Types:
  - Azure &gt; SignalR Service &gt; SignalR &gt; Approved &gt; Custom</description>
            <pubDate>Fri, 17 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-relay-v5-1-0</guid>
            <title>azure-relay v5.1.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/azure-relay-v5-1-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Policy Types:
  - Azure &gt; Relay &gt; Namespace &gt; Approved &gt; Custom</description>
            <pubDate>Fri, 17 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-functions-v5-8-0</guid>
            <title>gcp-functions v5.8.0 - Trusted Access control now also supports All Authenticated and All Users policies</title>
            <link>https://turbot.com/guardrails/changelog/gcp-functions-v5-8-0</link>
            <description>_What&apos;s new?_

- Policy Types:
  - GCP &gt; Functions &gt; Function &gt; Policy &gt; Trusted Access &gt; All Authenticated
  - GCP &gt; Functions &gt; Function &gt; Policy &gt; Trusted Access &gt; All Users</description>
            <pubDate>Thu, 16 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-searchmanagement-v5-7-0</guid>
            <title>azure-searchmanagement v5.7.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/azure-searchmanagement-v5-7-0</link>
            <description>_What&apos;s new?_
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Policy Types:
  - Azure &gt; Search Management &gt; Search Service &gt; Approved &gt; Custom</description>
            <pubDate>Thu, 16 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-recoveryservice-v5-5-0</guid>
            <title>azure-recoveryservice v5.5.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/azure-recoveryservice-v5-5-0</link>
            <description>_What&apos;s new?_
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Policy Types:
  - Azure &gt; Recovery Service &gt; Vault &gt; Approved &gt; Custom</description>
            <pubDate>Thu, 16 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-swf-v5-4-0</guid>
            <title>aws-swf v5.4.0 - Quick Actions now available for Domains; Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-swf-v5-4-0</link>
            <description>_What&apos;s new?_

- Users can now perform quick actions on resources to remediate cloud configuration issues or skip Turbot alarms for issues that they want to come back to later. To get started, click on the `Actions` button, which will reveal a dropdown menu with available actions, and select one. See [Quick Actions](https://turbot.com/v5/docs/guides/quick-actions) for more information.
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Policy Types:
  - AWS &gt; SWF &gt; Domain &gt; Approved &gt; Custom

- Action Types:
  - AWS &gt; SWF &gt; Domain &gt; Set Tags
  - AWS &gt; SWF &gt; Domain &gt; Skip alarm for Active control
  - AWS &gt; SWF &gt; Domain &gt; Skip alarm for Active control [90 days]
  - AWS &gt; SWF &gt; Domain &gt; Skip alarm for Approved control
  - AWS &gt; SWF &gt; Domain &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; SWF &gt; Domain &gt; Skip alarm for Tags control
  - AWS &gt; SWF &gt; Domain &gt; Skip alarm for Tags control [90 days]</description>
            <pubDate>Thu, 16 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-qldb-v5-3-0</guid>
            <title>aws-qldb v5.3.0 - Quick Actions now available for Ledgers; Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-qldb-v5-3-0</link>
            <description>_What&apos;s new?_

- Users can now perform quick actions on resources to remediate cloud configuration issues or skip Turbot alarms for issues that they want to come back to later. To get started, click on the `Actions` button, which will reveal a dropdown menu with available actions, and select one. See [Quick Actions](https://turbot.com/v5/docs/guides/quick-actions) for more information.
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

- Policy Types:
  - AWS &gt; QLDB &gt; Ledger &gt; Approved &gt; Custom

- Action Types:
  - AWS &gt; QLDB &gt; Ledger &gt; Delete from AWS
  - AWS &gt; QLDB &gt; Ledger &gt; Set Tags
  - AWS &gt; QLDB &gt; Ledger &gt; Skip alarm for Active control
  - AWS &gt; QLDB &gt; Ledger &gt; Skip alarm for Active control [90 days]
  - AWS &gt; QLDB &gt; Ledger &gt; Skip alarm for Approved control
  - AWS &gt; QLDB &gt; Ledger &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; QLDB &gt; Ledger &gt; Skip alarm for Tags control
  - AWS &gt; QLDB &gt; Ledger &gt; Skip alarm for Tags control [90 days]</description>
            <pubDate>Thu, 09 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-neptune-v5-4-0</guid>
            <title>aws-neptune v5.4.0 - Quick Actions now available for DB Clusters and Instances; Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-neptune-v5-4-0</link>
            <description>_What&apos;s new?_

- Users can now perform quick actions on resources to remediate cloud configuration issues or skip Turbot alarms for issues that they want to come back to later. To get started, click on the `Actions` button, which will reveal a dropdown menu with available actions, and select one. See [Quick Actions](https://turbot.com/v5/docs/guides/quick-actions) for more information.
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Policy Types:
  - AWS &gt; Neptune &gt; DB Cluster &gt; Approved &gt; Custom
  - AWS &gt; Neptune &gt; DB Instance &gt; Approved &gt; Custom

- Action Types:
  - AWS &gt; Neptune &gt; DB Cluster &gt; Delete from AWS
  - AWS &gt; Neptune &gt; DB Cluster &gt; Set Tags
  - AWS &gt; Neptune &gt; DB Cluster &gt; Skip alarm for Active control
  - AWS &gt; Neptune &gt; DB Cluster &gt; Skip alarm for Active control [90 days]
  - AWS &gt; Neptune &gt; DB Cluster &gt; Skip alarm for Approved control
  - AWS &gt; Neptune &gt; DB Cluster &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; Neptune &gt; DB Cluster &gt; Skip alarm for Tags control
  - AWS &gt; Neptune &gt; DB Cluster &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; Neptune &gt; DB Instance &gt; Delete from AWS
  - AWS &gt; Neptune &gt; DB Instance &gt; Set Tags
  - AWS &gt; Neptune &gt; DB Instance &gt; Skip alarm for Active control
  - AWS &gt; Neptune &gt; DB Instance &gt; Skip alarm for Active control [90 days]
  - AWS &gt; Neptune &gt; DB Instance &gt; Skip alarm for Approved control
  - AWS &gt; Neptune &gt; DB Instance &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; Neptune &gt; DB Instance &gt; Skip alarm for Tags control
  - AWS &gt; Neptune &gt; DB Instance &gt; Skip alarm for Tags control [90 days]</description>
            <pubDate>Thu, 09 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-inspector-v5-2-0</guid>
            <title>aws-inspector v5.2.0 - Quick Actions now available for Assessment Targets and Templates; Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-inspector-v5-2-0</link>
            <description>_What&apos;s new?_

- Users can now perform quick actions on resources to remediate cloud configuration issues or skip Turbot alarms for issues that they want to come back to later. To get started, click on the `Actions` button, which will reveal a dropdown menu with available actions, and select one. See [Quick Actions](https://turbot.com/v5/docs/guides/quick-actions) for more information.
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Policy Types:
  - AWS &gt; Inspector &gt; Assessment Target &gt; Approved &gt; Custom
  - AWS &gt; Inspector &gt; Assessment Template &gt; Approved &gt; Custom

- Action Types:
  - AWS &gt; Inspector &gt; Assessment Target &gt; Delete from AWS
  - AWS &gt; Inspector &gt; Assessment Target &gt; Skip alarm for Active control
  - AWS &gt; Inspector &gt; Assessment Target &gt; Skip alarm for Active control [90 days]
  - AWS &gt; Inspector &gt; Assessment Target &gt; Skip alarm for Approved control
  - AWS &gt; Inspector &gt; Assessment Target &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; Inspector &gt; Assessment Template &gt; Delete from AWS
  - AWS &gt; Inspector &gt; Assessment Template &gt; Set Tags
  - AWS &gt; Inspector &gt; Assessment Template &gt; Skip alarm for Active control
  - AWS &gt; Inspector &gt; Assessment Template &gt; Skip alarm for Active control [90 days]
  - AWS &gt; Inspector &gt; Assessment Template &gt; Skip alarm for Approved control
  - AWS &gt; Inspector &gt; Assessment Template &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; Inspector &gt; Assessment Template &gt; Skip alarm for Tags control
  - AWS &gt; Inspector &gt; Assessment Template &gt; Skip alarm for Tags control [90 days]</description>
            <pubDate>Thu, 09 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-dax-v5-4-0</guid>
            <title>aws-dax v5.4.0 - Quick Actions now available for Clusters; Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-dax-v5-4-0</link>
            <description>_What&apos;s new?_

- Users can now perform quick actions on resources to remediate cloud configuration issues or skip Turbot alarms for issues that they want to come back to later. To get started, click on the `Actions` button, which will reveal a dropdown menu with available actions, and select one. See [Quick Actions](https://turbot.com/v5/docs/guides/quick-actions) for more information.
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Policy Types:
  - AWS &gt; DAX &gt; Cluster &gt; Approved &gt; Custom

- Action Types:
  - AWS &gt; DAX &gt; Cluster &gt; Delete from AWS
  - AWS &gt; DAX &gt; Cluster &gt; Set Tags
  - AWS &gt; DAX &gt; Cluster &gt; Skip alarm for Active control
  - AWS &gt; DAX &gt; Cluster &gt; Skip alarm for Active control [90 days]
  - AWS &gt; DAX &gt; Cluster &gt; Skip alarm for Approved control
  - AWS &gt; DAX &gt; Cluster &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; DAX &gt; Cluster &gt; Skip alarm for Tags control
  - AWS &gt; DAX &gt; Cluster &gt; Skip alarm for Tags control [90 days]</description>
            <pubDate>Thu, 09 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-42-5</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.42.5 - SAML Security Enhancements and Package Update (v4.0.4).</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-42-5</link>
            <description>_What&apos;s new?_

- Server
  - Updated: Updated the package `passport-saml` to `@node-saml/passport-saml`: 4.0.4
  - Updated: The directory API to support `Require Signed Authentication Response` and `Strict Audience Validation`.

- UI:
  - Added: Introduced UI options for `Require Signed Authentication Response` and `Strict Audience Validation` for enhanced security in SAML authentication.


**Enhanced Security and Compatibility Guide for SAML Authentication**

**Description**

The recent package change for `@node-saml/passport-saml` has made it mandatory to sign the audience response and perform audience validation. To maintain backward compatibility, we have introduced two new options in the UI:

1. **Require Signed Authentication Response**
2. **Strict Audience Validation**


To make it backward compatible, both of these options are initially set to `Disabled` by default.

**Important Note:** This change ensures that the audience response is signed and audience validation is enforced. These checks were not available in earlier versions of the package.

**Recommendations**

We recommend customers enable both of these properties as they add an additional layer of security. However, it&apos;s important to be aware that enabling these properties might potentially break SAML login functionality. Therefore, certain steps need to be taken before enabling them.

Here are specific recommendations for popular Identity Providers (IDPs):

**Okta**

- **Strict Audience Validation:** If enabled, ensure that the &quot;Issuer ID&quot; matches the &quot;Audience Restriction.&quot;

**OneLogin**

- **Require Signed Authentication Response:** This feature should be disabled in OneLogin, as OneLogin does not support it. 
- **Strict Audience Validation:** If enabled, ensure that the &quot;Issuer ID&quot; matches the &quot;Audience&quot;.

**Azure Entra ID (Previously Known as Azure AD)**

- **Require Signed Authentication Response:** If enabled, make sure you choose the `Signing option` to be &quot;SIGN SAML response and assertion&quot;. The `Signing option` is available on the Signing Certificate page of Entra ID

Please follow these recommendations carefully to make sure you&apos;re able to transition smoothly to the updated SAML package.</description>
            <pubDate>Wed, 08 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-outposts-v5-3-0</guid>
            <title>aws-outposts v5.3.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-outposts-v5-3-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.</description>
            <pubDate>Wed, 08 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-lightsail-v5-5-0</guid>
            <title>aws-lightsail v5.5.0 - Quick Actions now available for all Lightsail resources; Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-lightsail-v5-5-0</link>
            <description>_What&apos;s new?_

- Users can now perform quick actions on resources to remediate cloud configuration issues or skip Turbot alarms for issues that they want to come back to later. To get started, click on the `Actions` button, which will reveal a dropdown menu with available actions, and select one. See [Quick Actions](https://turbot.com/v5/docs/guides/quick-actions) for more information.
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

- Policy Types:
  - AWS &gt; Lightsail &gt; Instance &gt; Approved &gt; Custom
  - AWS &gt; Lightsail &gt; Load Balancer &gt; Approved &gt; Custom
  - AWS &gt; Lightsail &gt; Relational Database &gt; Approved &gt; Custom

- Action Types:
  - AWS &gt; Lightsail &gt; Instance &gt; Delete from AWS
  - AWS &gt; Lightsail &gt; Instance &gt; Set Tags
  - AWS &gt; Lightsail &gt; Instance &gt; Skip alarm for Active control
  - AWS &gt; Lightsail &gt; Instance &gt; Skip alarm for Active control [90 days]
  - AWS &gt; Lightsail &gt; Instance &gt; Skip alarm for Approved control
  - AWS &gt; Lightsail &gt; Instance &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; Lightsail &gt; Instance &gt; Skip alarm for Tags control
  - AWS &gt; Lightsail &gt; Instance &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; Lightsail &gt; Load Balancer &gt; Delete from AWS
  - AWS &gt; Lightsail &gt; Load Balancer &gt; Set Tags
  - AWS &gt; Lightsail &gt; Load Balancer &gt; Skip alarm for Active control
  - AWS &gt; Lightsail &gt; Load Balancer &gt; Skip alarm for Active control [90 days]
  - AWS &gt; Lightsail &gt; Load Balancer &gt; Skip alarm for Approved control
  - AWS &gt; Lightsail &gt; Load Balancer &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; Lightsail &gt; Load Balancer &gt; Skip alarm for Tags control
  - AWS &gt; Lightsail &gt; Load Balancer &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; Lightsail &gt; Relational Database &gt; Delete from AWS
  - AWS &gt; Lightsail &gt; Relational Database &gt; Set Tags
  - AWS &gt; Lightsail &gt; Relational Database &gt; Skip alarm for Active control
  - AWS &gt; Lightsail &gt; Relational Database &gt; Skip alarm for Active control [90 days]
  - AWS &gt; Lightsail &gt; Relational Database &gt; Skip alarm for Approved control
  - AWS &gt; Lightsail &gt; Relational Database &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; Lightsail &gt; Relational Database &gt; Skip alarm for Tags control
  - AWS &gt; Lightsail &gt; Relational Database &gt; Skip alarm for Tags control [90 days]</description>
            <pubDate>Wed, 08 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-bedrock-v5-0-0</guid>
            <title>aws-bedrock v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/aws-bedrock-v5-0-0</link>
            <description>_What&apos;s new?_

- Resource Types:
  - AWS &gt; Bedrock

- Policy Types:
  - AWS &gt; Bedrock &gt; API Enabled
  - AWS &gt; Bedrock &gt; Approved Regions [Default]
  - AWS &gt; Bedrock &gt; Enabled
  - AWS &gt; Bedrock &gt; Permissions
  - AWS &gt; Bedrock &gt; Permissions &gt; Levels
  - AWS &gt; Bedrock &gt; Permissions &gt; Levels &gt; Modifiers
  - AWS &gt; Bedrock &gt; Permissions &gt; Lockdown
  - AWS &gt; Bedrock &gt; Permissions &gt; Lockdown &gt; API Boundary
  - AWS &gt; Bedrock &gt; Regions
  - AWS &gt; Turbot &gt; Permissions &gt; Compiled &gt; API Boundary &gt; @turbot/aws-bedrock
  - AWS &gt; Turbot &gt; Permissions &gt; Compiled &gt; Levels &gt; @turbot/aws-bedrock
  - AWS &gt; Turbot &gt; Permissions &gt; Compiled &gt; Service Permissions &gt; @turbot/aws-bedrock</description>
            <pubDate>Wed, 08 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-appmesh-v5-4-0</guid>
            <title>aws-appmesh v5.4.0 - Quick Actions now available for Mesh; Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-appmesh-v5-4-0</link>
            <description>_What&apos;s new?_

- Users can now perform quick actions on resources to remediate cloud configuration issues or skip Turbot alarms for issues that they want to come back to later. To get started, click on the `Actions` button, which will reveal a dropdown menu with available actions, and select one. See [Quick Actions](https://turbot.com/v5/docs/guides/quick-actions) for more information.
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Policy Types:
  - AWS &gt; App Mesh &gt; Mesh &gt; Approved &gt; Custom

- Action Types:
  - AWS &gt; App Mesh &gt; Mesh &gt; Delete from AWS
  - AWS &gt; App Mesh &gt; Mesh &gt; Set Tags
  - AWS &gt; App Mesh &gt; Mesh &gt; Skip alarm for Active control
  - AWS &gt; App Mesh &gt; Mesh &gt; Skip alarm for Active control [90 days]
  - AWS &gt; App Mesh &gt; Mesh &gt; Skip alarm for Approved control
  - AWS &gt; App Mesh &gt; Mesh &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; App Mesh &gt; Mesh &gt; Skip alarm for Tags control
  - AWS &gt; App Mesh &gt; Mesh &gt; Skip alarm for Tags control [90 days]</description>
            <pubDate>Wed, 08 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-rds-v5-26-0</guid>
            <title>aws-rds v5.26.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-rds-v5-26-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.</description>
            <pubDate>Tue, 07 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-elasticache-v5-9-1</guid>
            <title>aws-elasticache v5.9.1 - Bug Squashed - ElastiCache Snapshot CMDB control would go into an error state due to a bad internal build</title>
            <link>https://turbot.com/guardrails/changelog/aws-elasticache-v5-9-1</link>
            <description>_Bug fixes_

- The `AWS &gt; ElastiCache &gt; Snapshot &gt; CMDB` control would go into an error state due to a bad internal build. This is fixed and the control will now work correctly as expected.</description>
            <pubDate>Tue, 07 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-glue-v5-11-0</guid>
            <title>aws-glue v5.11.0 - Quick Actions now available for all Glue resources; Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-glue-v5-11-0</link>
            <description>_What&apos;s new?_

- Users can now perform quick actions on resources to remediate cloud configuration issues or skip Turbot alarms for issues that they want to come back to later. To get started, click on the `Actions` button, which will reveal a dropdown menu with available actions, and select one. See [Quick Actions](https://turbot.com/v5/docs/guides/quick-actions) for more information.
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Action Types:
  - AWS &gt; Glue &gt; Crawler &gt; Delete from AWS
  - AWS &gt; Glue &gt; Crawler &gt; Set Tags
  - AWS &gt; Glue &gt; Crawler &gt; Skip alarm for Active control
  - AWS &gt; Glue &gt; Crawler &gt; Skip alarm for Active control [90 days]
  - AWS &gt; Glue &gt; Crawler &gt; Skip alarm for Approved control
  - AWS &gt; Glue &gt; Crawler &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; Glue &gt; Crawler &gt; Skip alarm for Tags control
  - AWS &gt; Glue &gt; Crawler &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; Glue &gt; Data Catalog &gt; Skip alarm for Encryption at Rest control
  - AWS &gt; Glue &gt; Data Catalog &gt; Skip alarm for Encryption at Rest control [90 days]
  - AWS &gt; Glue &gt; Database &gt; Delete from AWS
  - AWS &gt; Glue &gt; Database &gt; Skip alarm for Active control
  - AWS &gt; Glue &gt; Database &gt; Skip alarm for Active control [90 days]
  - AWS &gt; Glue &gt; Database &gt; Skip alarm for Approved control
  - AWS &gt; Glue &gt; Database &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; Glue &gt; Development Endpoint [Deprecated] &gt; Delete from AWS
  - AWS &gt; Glue &gt; Development Endpoint [Deprecated] &gt; Set Tags
  - AWS &gt; Glue &gt; Development Endpoint [Deprecated] &gt; Skip alarm for Active control
  - AWS &gt; Glue &gt; Development Endpoint [Deprecated] &gt; Skip alarm for Active control [90 days]
  - AWS &gt; Glue &gt; Development Endpoint [Deprecated] &gt; Skip alarm for Approved control
  - AWS &gt; Glue &gt; Development Endpoint [Deprecated] &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; Glue &gt; Development Endpoint [Deprecated] &gt; Skip alarm for Tags control
  - AWS &gt; Glue &gt; Development Endpoint [Deprecated] &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; Glue &gt; Job &gt; Delete from AWS
  - AWS &gt; Glue &gt; Job &gt; Set Tags
  - AWS &gt; Glue &gt; Job &gt; Skip alarm for Active control
  - AWS &gt; Glue &gt; Job &gt; Skip alarm for Active control [90 days]
  - AWS &gt; Glue &gt; Job &gt; Skip alarm for Approved control
  - AWS &gt; Glue &gt; Job &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; Glue &gt; Job &gt; Skip alarm for Tags control
  - AWS &gt; Glue &gt; Job &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; Glue &gt; ML Transform &gt; Delete from AWS
  - AWS &gt; Glue &gt; ML Transform &gt; Set Tags
  - AWS &gt; Glue &gt; ML Transform &gt; Skip alarm for Active control
  - AWS &gt; Glue &gt; ML Transform &gt; Skip alarm for Active control [90 days]
  - AWS &gt; Glue &gt; ML Transform &gt; Skip alarm for Approved control
  - AWS &gt; Glue &gt; ML Transform &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; Glue &gt; ML Transform &gt; Skip alarm for Tags control
  - AWS &gt; Glue &gt; ML Transform &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; Glue &gt; Security Configuration &gt; Delete from AWS
  - AWS &gt; Glue &gt; Security Configuration &gt; Skip alarm for Active control
  - AWS &gt; Glue &gt; Security Configuration &gt; Skip alarm for Active control [90 days]
  - AWS &gt; Glue &gt; Security Configuration &gt; Skip alarm for Approved control
  - AWS &gt; Glue &gt; Security Configuration &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; Glue &gt; Table &gt; Delete from AWS
  - AWS &gt; Glue &gt; Table &gt; Skip alarm for Active control
  - AWS &gt; Glue &gt; Table &gt; Skip alarm for Active control [90 days]
  - AWS &gt; Glue &gt; Table &gt; Skip alarm for Approved control
  - AWS &gt; Glue &gt; Table &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; Glue &gt; Trigger &gt; Delete from AWS
  - AWS &gt; Glue &gt; Trigger &gt; Set Tags
  - AWS &gt; Glue &gt; Trigger &gt; Skip alarm for Active control
  - AWS &gt; Glue &gt; Trigger &gt; Skip alarm for Active control [90 days]
  - AWS &gt; Glue &gt; Trigger &gt; Skip alarm for Approved control
  - AWS &gt; Glue &gt; Trigger &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; Glue &gt; Trigger &gt; Skip alarm for Tags control
  - AWS &gt; Glue &gt; Trigger &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; Glue &gt; Workflow &gt; Delete from AWS
  - AWS &gt; Glue &gt; Workflow &gt; Set Tags
  - AWS &gt; Glue &gt; Workflow &gt; Skip alarm for Active control
  - AWS &gt; Glue &gt; Workflow &gt; Skip alarm for Active control [90 days]
  - AWS &gt; Glue &gt; Workflow &gt; Skip alarm for Approved control
  - AWS &gt; Glue &gt; Workflow &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; Glue &gt; Workflow &gt; Skip alarm for Tags control
  - AWS &gt; Glue &gt; Workflow &gt; Skip alarm for Tags control [90 days]</description>
            <pubDate>Mon, 06 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-codecommit-v5-5-0</guid>
            <title>aws-codecommit v5.5.0 - Quick Actions now available for Repositories; Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-codecommit-v5-5-0</link>
            <description>_What&apos;s new?_

- Users can now perform quick actions on resources to remediate cloud configuration issues or skip Turbot alarms for issues that they want to come back to later. To get started, click on the `Actions` button, which will reveal a dropdown menu with available actions, and select one. See [Quick Actions](https://turbot.com/v5/docs/guides/quick-actions) for more information.
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Policy Types:
  - AWS &gt; CodeCommit &gt; Repository &gt; Approved &gt; Custom

- Action Types:
  - AWS &gt; CodeCommit &gt; Repository &gt; Delete from AWS
  - AWS &gt; CodeCommit &gt; Repository &gt; Set Tags
  - AWS &gt; CodeCommit &gt; Repository &gt; Skip alarm for Active control
  - AWS &gt; CodeCommit &gt; Repository &gt; Skip alarm for Active control [90 days]
  - AWS &gt; CodeCommit &gt; Repository &gt; Skip alarm for Approved control
  - AWS &gt; CodeCommit &gt; Repository &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; CodeCommit &gt; Repository &gt; Skip alarm for Tags control
  - AWS &gt; CodeCommit &gt; Repository &gt; Skip alarm for Tags control [90 days]</description>
            <pubDate>Mon, 06 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-v5-23-0</guid>
            <title>gcp v5.23.0 - You can now set a Unique Writer Identity for Logging Sinks created via Event Handlers stack</title>
            <link>https://turbot.com/guardrails/changelog/gcp-v5-23-0</link>
            <description>_What&apos;s new?_

- Users can now set a Unique Writer Identity for Logging Sink created via the `GCP &gt; Turbot &gt; Event Handlers` stack. To get started, set the `GCP &gt; Turbot &gt; Event Handlers &gt; Logging &gt; Unique Writer Identity` policy.</description>
            <pubDate>Fri, 03 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-pubsub-v5-7-2</guid>
            <title>gcp-pubsub v5.7.2 - Guardrails&apos; stack controls will now manage Pub/Sub Topics more reliably than before</title>
            <link>https://turbot.com/guardrails/changelog/gcp-pubsub-v5-7-2</link>
            <description>_Bug fixes_

- Guardrails stack controls would sometimes fail to update Pub/Sub Topic resources if the Terraform plan in the stack&apos;s source policy was updated. This is fixed and the stack controls will now update such resources correctly, as expected. Please note that this fix will only work for workspaces on TE v5.42.0 or higher.</description>
            <pubDate>Fri, 03 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-logging-v5-3-3</guid>
            <title>gcp-logging v5.3.3 - Guardrails&apos; stack controls will now manage Logging Sinks more reliably than before</title>
            <link>https://turbot.com/guardrails/changelog/gcp-logging-v5-3-3</link>
            <description>_Bug fixes_

- Guardrails stack controls would sometimes fail to update Logging Sink resources if the Terraform plan in the stack&apos;s source policy was updated. This is fixed and the stack controls will now update such resources correctly, as expected. Please note that this fix will only work for workspaces on TE v5.42.0 or higher.</description>
            <pubDate>Fri, 03 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-wellarchitected-v5-7-0</guid>
            <title>aws-wellarchitected v5.7.0 - Quick Actions now available for Workloads; Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-wellarchitected-v5-7-0</link>
            <description>_What&apos;s new?_

- Users can now perform quick actions on resources to remediate cloud configuration issues or skip Turbot alarms for issues that they want to come back to later. To get started, click on the `Actions` button, which will reveal a dropdown menu with available actions, and select one. See [Quick Actions](https://turbot.com/v5/docs/guides/quick-actions) for more information.
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Policy Types:
  - AWS &gt; Well-Architected Tool &gt; Workload &gt; Approved &gt; Custom

- Action Types:
  - AWS &gt; Well-Architected Tool &gt; Workload &gt; Delete from AWS
  - AWS &gt; Well-Architected Tool &gt; Workload &gt; Set Tags
  - AWS &gt; Well-Architected Tool &gt; Workload &gt; Skip alarm for Active control
  - AWS &gt; Well-Architected Tool &gt; Workload &gt; Skip alarm for Active control [90 days]
  - AWS &gt; Well-Architected Tool &gt; Workload &gt; Skip alarm for Approved control
  - AWS &gt; Well-Architected Tool &gt; Workload &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; Well-Architected Tool &gt; Workload &gt; Skip alarm for Tags control
  - AWS &gt; Well-Architected Tool &gt; Workload &gt; Skip alarm for Tags control [90 days]</description>
            <pubDate>Fri, 03 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-storagegateway-v5-4-0</guid>
            <title>aws-storagegateway v5.4.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-storagegateway-v5-4-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.</description>
            <pubDate>Fri, 03 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-secretsmanager-v5-6-0</guid>
            <title>aws-secretsmanager v5.6.0 - Quick Actions now available for Secrets; Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-secretsmanager-v5-6-0</link>
            <description>_What&apos;s new?_

- Users can now perform quick actions on resources to remediate cloud configuration issues or skip Turbot alarms for issues that they want to come back to later. To get started, click on the `Actions` button, which will reveal a dropdown menu with available actions, and select one. See [Quick Actions](https://turbot.com/v5/docs/guides/quick-actions) for more information.
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Policy Types:
  - AWS &gt; Secrets Manager &gt; Secret &gt; Approved &gt; Custom

- Action Types:
  - AWS &gt; Secrets Manager &gt; Secret &gt; Delete from AWS
  - AWS &gt; Secrets Manager &gt; Secret &gt; Set Tags
  - AWS &gt; Secrets Manager &gt; Secret &gt; Skip alarm for Active control
  - AWS &gt; Secrets Manager &gt; Secret &gt; Skip alarm for Active control [90 days]
  - AWS &gt; Secrets Manager &gt; Secret &gt; Skip alarm for Approved control
  - AWS &gt; Secrets Manager &gt; Secret &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; Secrets Manager &gt; Secret &gt; Skip alarm for Encryption at Rest control
  - AWS &gt; Secrets Manager &gt; Secret &gt; Skip alarm for Encryption at Rest control [90 days]
  - AWS &gt; Secrets Manager &gt; Secret &gt; Skip alarm for Tags control
  - AWS &gt; Secrets Manager &gt; Secret &gt; Skip alarm for Tags control [90 days]</description>
            <pubDate>Fri, 03 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-glacier-v5-6-0</guid>
            <title>aws-glacier v5.6.0 - Quick Actions now available for Vaults; Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-glacier-v5-6-0</link>
            <description>_What&apos;s new?_

- Users can now perform quick actions on resources to remediate cloud configuration issues or skip Turbot alarms for issues that they want to come back to later. To get started, click on the `Actions` button, which will reveal a dropdown menu with available actions, and select one. See [Quick Actions](https://turbot.com/v5/docs/guides/quick-actions) for more information.
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Policy Types:
  - AWS &gt; Glacier &gt; Vault &gt; Approved &gt; Custom

- Action Types:
  - AWS &gt; Glacier &gt; Vault &gt; Delete from AWS
  - AWS &gt; Glacier &gt; Vault &gt; Set Tags
  - AWS &gt; Glacier &gt; Vault &gt; Skip alarm for Active control
  - AWS &gt; Glacier &gt; Vault &gt; Skip alarm for Active control [90 days]
  - AWS &gt; Glacier &gt; Vault &gt; Skip alarm for Approved control
  - AWS &gt; Glacier &gt; Vault &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; Glacier &gt; Vault &gt; Skip alarm for Tags control
  - AWS &gt; Glacier &gt; Vault &gt; Skip alarm for Tags control [90 days]</description>
            <pubDate>Fri, 03 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-elasticbeanstalk-v5-3-0</guid>
            <title>aws-elasticbeanstalk v5.3.0 - Quick Actions now available for Applications; Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-elasticbeanstalk-v5-3-0</link>
            <description>_What&apos;s new?_

- Users can now perform quick actions on resources to remediate cloud configuration issues or skip Turbot alarms for issues that they want to come back to later. To get started, click on the `Actions` button, which will reveal a dropdown menu with available actions, and select one. See [Quick Actions](https://turbot.com/v5/docs/guides/quick-actions) for more information.
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Policy Types:
  - AWS &gt; Elastic Beanstalk &gt; Application &gt; Approved &gt; Custom

- Action Types:
  - AWS &gt; Elastic Beanstalk &gt; Application &gt; Delete from AWS
  - AWS &gt; Elastic Beanstalk &gt; Application &gt; Set Tags
  - AWS &gt; Elastic Beanstalk &gt; Application &gt; Skip alarm for Active control
  - AWS &gt; Elastic Beanstalk &gt; Application &gt; Skip alarm for Active control [90 days]
  - AWS &gt; Elastic Beanstalk &gt; Application &gt; Skip alarm for Approved control
  - AWS &gt; Elastic Beanstalk &gt; Application &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; Elastic Beanstalk &gt; Application &gt; Skip alarm for Tags control
  - AWS &gt; Elastic Beanstalk &gt; Application &gt; Skip alarm for Tags control [90 days]</description>
            <pubDate>Fri, 03 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-batch-v5-6-0</guid>
            <title>aws-batch v5.6.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-batch-v5-6-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.</description>
            <pubDate>Fri, 03 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-wafregional-v5-4-0</guid>
            <title>aws-wafregional v5.4.0 - Quick Actions now available for WAF Regional Rules; Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-wafregional-v5-4-0</link>
            <description>_What&apos;s new?_

- Users can now perform quick actions on resources to remediate cloud configuration issues or skip Turbot alarms for issues that they want to come back to later. To get started, click on the `Actions` button, which will reveal a dropdown menu with available actions, and select one. See [Quick Actions](https://turbot.com/v5/docs/guides/quick-actions) for more information.
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Policy Types:
  - AWS &gt; WAF Regional &gt; Rule &gt; Approved &gt; Custom

- Action Types:
  - AWS &gt; WAF Regional &gt; Rule &gt; Delete from AWS
  - AWS &gt; WAF Regional &gt; Rule &gt; Skip alarm for Active control
  - AWS &gt; WAF Regional &gt; Rule &gt; Skip alarm for Active control [90 days]
  - AWS &gt; WAF Regional &gt; Rule &gt; Skip alarm for Approved control
  - AWS &gt; WAF Regional &gt; Rule &gt; Skip alarm for Approved control [90 days]</description>
            <pubDate>Thu, 02 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-vpc-internet-v5-11-0</guid>
            <title>aws-vpc-internet v5.11.0 - Quick Actions now available for all VPC Internet resources; Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-vpc-internet-v5-11-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

- Action Types:
  - AWS &gt; VPC &gt; Egress Only Internet Gateway &gt; Delete from AWS
  - AWS &gt; VPC &gt; Egress Only Internet Gateway &gt; Set Tags
  - AWS &gt; VPC &gt; Egress Only Internet Gateway &gt; Skip alarm for Active control
  - AWS &gt; VPC &gt; Egress Only Internet Gateway &gt; Skip alarm for Active control [90 days]
  - AWS &gt; VPC &gt; Egress Only Internet Gateway &gt; Skip alarm for Approved control
  - AWS &gt; VPC &gt; Egress Only Internet Gateway &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; VPC &gt; Egress Only Internet Gateway &gt; Skip alarm for Tags control
  - AWS &gt; VPC &gt; Egress Only Internet Gateway &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; VPC &gt; Elastic IP &gt; Delete from AWS
  - AWS &gt; VPC &gt; Elastic IP &gt; Set Tags
  - AWS &gt; VPC &gt; Elastic IP &gt; Skip alarm for Active control
  - AWS &gt; VPC &gt; Elastic IP &gt; Skip alarm for Active control [90 days]
  - AWS &gt; VPC &gt; Elastic IP &gt; Skip alarm for Approved control
  - AWS &gt; VPC &gt; Elastic IP &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; VPC &gt; Elastic IP &gt; Skip alarm for Tags control
  - AWS &gt; VPC &gt; Elastic IP &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; VPC &gt; Endpoint &gt; Delete from AWS
  - AWS &gt; VPC &gt; Endpoint &gt; Set Tags
  - AWS &gt; VPC &gt; Endpoint &gt; Skip alarm for Active control
  - AWS &gt; VPC &gt; Endpoint &gt; Skip alarm for Active control [90 days]
  - AWS &gt; VPC &gt; Endpoint &gt; Skip alarm for Approved control
  - AWS &gt; VPC &gt; Endpoint &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; VPC &gt; Endpoint &gt; Skip alarm for Tags control
  - AWS &gt; VPC &gt; Endpoint &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; VPC &gt; Endpoint Service &gt; Delete from AWS
  - AWS &gt; VPC &gt; Endpoint Service &gt; Set Tags
  - AWS &gt; VPC &gt; Endpoint Service &gt; Skip alarm for Active control
  - AWS &gt; VPC &gt; Endpoint Service &gt; Skip alarm for Active control [90 days]
  - AWS &gt; VPC &gt; Endpoint Service &gt; Skip alarm for Approved control
  - AWS &gt; VPC &gt; Endpoint Service &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; VPC &gt; Endpoint Service &gt; Skip alarm for Tags control
  - AWS &gt; VPC &gt; Endpoint Service &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; VPC &gt; Internet Gateway &gt; Delete from AWS
  - AWS &gt; VPC &gt; Internet Gateway &gt; Set Tags
  - AWS &gt; VPC &gt; Internet Gateway &gt; Skip alarm for Active control
  - AWS &gt; VPC &gt; Internet Gateway &gt; Skip alarm for Active control [90 days]
  - AWS &gt; VPC &gt; Internet Gateway &gt; Skip alarm for Approved control
  - AWS &gt; VPC &gt; Internet Gateway &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; VPC &gt; Internet Gateway &gt; Skip alarm for Tags control
  - AWS &gt; VPC &gt; Internet Gateway &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; VPC &gt; NAT Gateway &gt; Delete from AWS
  - AWS &gt; VPC &gt; NAT Gateway &gt; Set Tags
  - AWS &gt; VPC &gt; NAT Gateway &gt; Skip alarm for Active control
  - AWS &gt; VPC &gt; NAT Gateway &gt; Skip alarm for Active control [90 days]
  - AWS &gt; VPC &gt; NAT Gateway &gt; Skip alarm for Approved control
  - AWS &gt; VPC &gt; NAT Gateway &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; VPC &gt; NAT Gateway &gt; Skip alarm for Tags control
  - AWS &gt; VPC &gt; NAT Gateway &gt; Skip alarm for Tags control [90 days]</description>
            <pubDate>Thu, 02 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-vpc-core-v5-17-0</guid>
            <title>aws-vpc-core v5.17.0 - Quick Actions now available for all VPC Core resources; Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-vpc-core-v5-17-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

- Action Types:
  - AWS &gt; VPC &gt; DHCP Options &gt; Delete from AWS
  - AWS &gt; VPC &gt; DHCP Options &gt; Set Tags
  - AWS &gt; VPC &gt; DHCP Options &gt; Skip alarm for Active control
  - AWS &gt; VPC &gt; DHCP Options &gt; Skip alarm for Active control [90 days]
  - AWS &gt; VPC &gt; DHCP Options &gt; Skip alarm for Tags control
  - AWS &gt; VPC &gt; DHCP Options &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; VPC &gt; Route Table &gt; Delete from AWS
  - AWS &gt; VPC &gt; Route Table &gt; Set Tags
  - AWS &gt; VPC &gt; Route Table &gt; Skip alarm for Active control
  - AWS &gt; VPC &gt; Route Table &gt; Skip alarm for Active control [90 days]
  - AWS &gt; VPC &gt; Route Table &gt; Skip alarm for Tags control
  - AWS &gt; VPC &gt; Route Table &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; VPC &gt; Subnet &gt; Delete from AWS
  - AWS &gt; VPC &gt; Subnet &gt; Set Tags
  - AWS &gt; VPC &gt; Subnet &gt; Skip alarm for Active control
  - AWS &gt; VPC &gt; Subnet &gt; Skip alarm for Active control [90 days]
  - AWS &gt; VPC &gt; Subnet &gt; Skip alarm for Tags control
  - AWS &gt; VPC &gt; Subnet &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; VPC &gt; VPC &gt; Delete from AWS
  - AWS &gt; VPC &gt; VPC &gt; Set Tags
  - AWS &gt; VPC &gt; VPC &gt; Skip alarm for Active control
  - AWS &gt; VPC &gt; VPC &gt; Skip alarm for Active control [90 days]
  - AWS &gt; VPC &gt; VPC &gt; Skip alarm for Tags control
  - AWS &gt; VPC &gt; VPC &gt; Skip alarm for Tags control [90 days]</description>
            <pubDate>Thu, 02 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-sqs-v5-14-0</guid>
            <title>aws-sqs v5.14.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-sqs-v5-14-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.</description>
            <pubDate>Thu, 02 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-sns-v5-15-0</guid>
            <title>aws-sns v5.15.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-sns-v5-15-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.</description>
            <pubDate>Thu, 02 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-elasticsearch-v5-5-0</guid>
            <title>aws-elasticsearch v5.5.0 - Quick Actions now available for Domains; Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-elasticsearch-v5-5-0</link>
            <description>_What&apos;s new?_

- Users can now perform quick actions on resources to remediate cloud configuration issues or skip Turbot alarms for issues that they want to come back to later. To get started, click on the `Actions` button, which will reveal a dropdown menu with available actions, and select one. See [Quick Actions](https://turbot.com/v5/docs/guides/quick-actions) for more information.
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Policy Types:
  - AWS &gt; Elasticsearch &gt; Domain &gt; Approved &gt; Custom

- Action Types:
  - AWS &gt; Elasticsearch &gt; Domain &gt; Delete from AWS
  - AWS &gt; Elasticsearch &gt; Domain &gt; Set Tags
  - AWS &gt; Elasticsearch &gt; Domain &gt; Skip alarm for Active control
  - AWS &gt; Elasticsearch &gt; Domain &gt; Skip alarm for Active control [90 days]
  - AWS &gt; Elasticsearch &gt; Domain &gt; Skip alarm for Approved control
  - AWS &gt; Elasticsearch &gt; Domain &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; Elasticsearch &gt; Domain &gt; Skip alarm for Tags control
  - AWS &gt; Elasticsearch &gt; Domain &gt; Skip alarm for Tags control [90 days]</description>
            <pubDate>Thu, 02 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ec2-v5-36-2</guid>
            <title>aws-ec2 v5.36.2 - Bug Squashed - Account Attributes CMDB control would go into an error state due to a bad internal build</title>
            <link>https://turbot.com/guardrails/changelog/aws-ec2-v5-36-2</link>
            <description>_Bug fixes_

- The `AWS &gt; EC2 &gt; Account Attributes &gt; CMDB` control would go into an error state due to a bad internal build. This is fixed and the control will now work correctly as expected.</description>
            <pubDate>Thu, 02 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-v5-29-0</guid>
            <title>aws v5.29.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-v5-29-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.</description>
            <pubDate>Wed, 01 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ssm-v5-15-0</guid>
            <title>aws-ssm v5.15.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-ssm-v5-15-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include createdBy details in Turbot CMDB.</description>
            <pubDate>Wed, 01 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-elasticache-v5-9-0</guid>
            <title>aws-elasticache v5.9.0 - Quick Actions now available for all ElasticCache resources; Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-elasticache-v5-9-0</link>
            <description>_What&apos;s new?_

- Users can now perform quick actions on resources to remediate cloud configuration issues or skip Turbot alarms for issues that they want to come back to later. To get started, click on the `Actions` button, which will reveal a dropdown menu with available actions, and select one. See [Quick Actions](https://turbot.com/v5/docs/guides/quick-actions) for more information.
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Action Types:
  - AWS &gt; ElastiCache &gt; Cache Cluster &gt; Delete from AWS
  - AWS &gt; ElastiCache &gt; Cache Cluster &gt; Set Tags
  - AWS &gt; ElastiCache &gt; Cache Cluster &gt; Skip alarm for Active control
  - AWS &gt; ElastiCache &gt; Cache Cluster &gt; Skip alarm for Active control [90 days]
  - AWS &gt; ElastiCache &gt; Cache Cluster &gt; Skip alarm for Tags control
  - AWS &gt; ElastiCache &gt; Cache Cluster &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; ElastiCache &gt; Cache Parameter Group &gt; Delete from AWS
  - AWS &gt; ElastiCache &gt; Cache Parameter Group &gt; Skip alarm for Active control
  - AWS &gt; ElastiCache &gt; Cache Parameter Group &gt; Skip alarm for Active control [90 days]
  - AWS &gt; ElastiCache &gt; Replication Group &gt; Delete from AWS
  - AWS &gt; ElastiCache &gt; Replication Group &gt; Skip alarm for Active control
  - AWS &gt; ElastiCache &gt; Replication Group &gt; Skip alarm for Active control [90 days]
  - AWS &gt; ElastiCache &gt; Snapshot &gt; Delete from AWS
  - AWS &gt; ElastiCache &gt; Snapshot &gt; Set Tags
  - AWS &gt; ElastiCache &gt; Snapshot &gt; Skip alarm for Active control
  - AWS &gt; ElastiCache &gt; Snapshot &gt; Skip alarm for Active control [90 days]
  - AWS &gt; ElastiCache &gt; Snapshot &gt; Skip alarm for Tags control
  - AWS &gt; ElastiCache &gt; Snapshot &gt; Skip alarm for Tags control [90 days]</description>
            <pubDate>Wed, 01 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-datapipeline-v5-3-0</guid>
            <title>aws-datapipeline v5.3.0 - Quick Actions now available for Pipelines; Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-datapipeline-v5-3-0</link>
            <description>_What&apos;s new?_

- Users can now perform quick actions on resources to remediate cloud configuration issues or skip Turbot alarms for issues that they want to come back to later. To get started, click on the `Actions` button, which will reveal a dropdown menu with available actions, and select one. See [Quick Actions](https://turbot.com/v5/docs/guides/quick-actions) for more information.
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Policy Types:
  - AWS &gt; Data Pipeline &gt; Pipeline &gt; Approved &gt; Custom

- Action Types:
  - AWS &gt; Data Pipeline &gt; Pipeline &gt; Delete from AWS
  - AWS &gt; Data Pipeline &gt; Pipeline &gt; Set Tags
  - AWS &gt; Data Pipeline &gt; Pipeline &gt; Skip alarm for Active control
  - AWS &gt; Data Pipeline &gt; Pipeline &gt; Skip alarm for Active control [90 days]
  - AWS &gt; Data Pipeline &gt; Pipeline &gt; Skip alarm for Approved control
  - AWS &gt; Data Pipeline &gt; Pipeline &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; Data Pipeline &gt; Pipeline &gt; Skip alarm for Tags control
  - AWS &gt; Data Pipeline &gt; Pipeline &gt; Skip alarm for Tags control [90 days]</description>
            <pubDate>Wed, 01 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-backup-v5-10-1</guid>
            <title>aws-backup v5.10.1 - Bugs Squashed - Recovery Points deleted in AWS were not cleaned up automatically via real-time events in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/aws-backup-v5-10-1</link>
            <description>_Bug fixes_

- Recovery Points deleted in AWS were not cleaned up automatically via real-time events in Guardrails. This is now fixed.</description>
            <pubDate>Wed, 01 Nov 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-vpc-connect-v5-9-0</guid>
            <title>aws-vpc-connect v5.9.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-vpc-connect-v5-9-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.</description>
            <pubDate>Tue, 31 Oct 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-sagemaker-v5-9-0</guid>
            <title>aws-sagemaker v5.9.0 - Quick Actions now available for all SageMaker resources; Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-sagemaker-v5-9-0</link>
            <description>_What&apos;s new?_
- Users can now perform quick actions on resources to remediate cloud configuration issues or skip Turbot alarms for issues that they want to come back to later. To get started, click on the `Actions` button, which will reveal a dropdown menu with available actions, and select one. See [Quick Actions](https://turbot.com/v5/docs/guides/quick-actions) for more information.
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.
- Added support for `ap-northeast-3` and `us-gov-east-1` regions in the `AWS &gt; SageMaker &gt; Regions` policy.

- Policy Types:
  - AWS &gt; SageMaker &gt; Code Repository &gt; Approved &gt; Custom
  - AWS &gt; SageMaker &gt; Endpoint &gt; Approved &gt; Custom
  - AWS &gt; SageMaker &gt; Endpoint Configuration &gt; Approved &gt; Custom
  - AWS &gt; SageMaker &gt; Lifecycle Configuration &gt; Approved &gt; Custom
  - AWS &gt; SageMaker &gt; Model &gt; Approved &gt; Custom
  - AWS &gt; SageMaker &gt; Training Job &gt; Approved &gt; Custom

- Action Types:
  - AWS &gt; SageMaker &gt; Code Repository &gt; Delete from AWS
  - AWS &gt; SageMaker &gt; Code Repository &gt; Skip alarm for Active control
  - AWS &gt; SageMaker &gt; Code Repository &gt; Skip alarm for Active control [90 days]
  - AWS &gt; SageMaker &gt; Code Repository &gt; Skip alarm for Approved control
  - AWS &gt; SageMaker &gt; Code Repository &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; SageMaker &gt; Domain &gt; Delete from AWS
  - AWS &gt; SageMaker &gt; Endpoint &gt; Delete from AWS
  - AWS &gt; SageMaker &gt; Endpoint &gt; Set Tags
  - AWS &gt; SageMaker &gt; Endpoint &gt; Skip alarm for Active control
  - AWS &gt; SageMaker &gt; Endpoint &gt; Skip alarm for Active control [90 days]
  - AWS &gt; SageMaker &gt; Endpoint &gt; Skip alarm for Approved control
  - AWS &gt; SageMaker &gt; Endpoint &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; SageMaker &gt; Endpoint &gt; Skip alarm for Tags control
  - AWS &gt; SageMaker &gt; Endpoint &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; SageMaker &gt; Endpoint Configuration &gt; Delete from AWS
  - AWS &gt; SageMaker &gt; Endpoint Configuration &gt; Set Tags
  - AWS &gt; SageMaker &gt; Endpoint Configuration &gt; Skip alarm for Active control
  - AWS &gt; SageMaker &gt; Endpoint Configuration &gt; Skip alarm for Active control [90 days]
  - AWS &gt; SageMaker &gt; Endpoint Configuration &gt; Skip alarm for Approved control
  - AWS &gt; SageMaker &gt; Endpoint Configuration &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; SageMaker &gt; Endpoint Configuration &gt; Skip alarm for Tags control
  - AWS &gt; SageMaker &gt; Endpoint Configuration &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; SageMaker &gt; Lifecycle Configuration &gt; Delete from AWS
  - AWS &gt; SageMaker &gt; Lifecycle Configuration &gt; Skip alarm for Active control
  - AWS &gt; SageMaker &gt; Lifecycle Configuration &gt; Skip alarm for Active control [90 days]
  - AWS &gt; SageMaker &gt; Lifecycle Configuration &gt; Skip alarm for Approved control
  - AWS &gt; SageMaker &gt; Lifecycle Configuration &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; SageMaker &gt; Model &gt; Delete from AWS
  - AWS &gt; SageMaker &gt; Model &gt; Set Tags
  - AWS &gt; SageMaker &gt; Model &gt; Skip alarm for Active control
  - AWS &gt; SageMaker &gt; Model &gt; Skip alarm for Active control [90 days]
  - AWS &gt; SageMaker &gt; Model &gt; Skip alarm for Approved control
  - AWS &gt; SageMaker &gt; Model &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; SageMaker &gt; Model &gt; Skip alarm for Tags control
  - AWS &gt; SageMaker &gt; Model &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; SageMaker &gt; Notebook Instance &gt; Delete from AWS
  - AWS &gt; SageMaker &gt; Notebook Instance &gt; Set Tags
  - AWS &gt; SageMaker &gt; Notebook Instance &gt; Skip alarm for Active control
  - AWS &gt; SageMaker &gt; Notebook Instance &gt; Skip alarm for Active control [90 days]
  - AWS &gt; SageMaker &gt; Notebook Instance &gt; Skip alarm for Approved control
  - AWS &gt; SageMaker &gt; Notebook Instance &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; SageMaker &gt; Notebook Instance &gt; Skip alarm for Tags control
  - AWS &gt; SageMaker &gt; Notebook Instance &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; SageMaker &gt; Training Job &gt; Set Tags
  - AWS &gt; SageMaker &gt; Training Job &gt; Skip alarm for Active control
  - AWS &gt; SageMaker &gt; Training Job &gt; Skip alarm for Active control [90 days]
  - AWS &gt; SageMaker &gt; Training Job &gt; Skip alarm for Approved control
  - AWS &gt; SageMaker &gt; Training Job &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; SageMaker &gt; Training Job &gt; Skip alarm for Tags control
  - AWS &gt; SageMaker &gt; Training Job &gt; Skip alarm for Tags control [90 days]</description>
            <pubDate>Tue, 31 Oct 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-route53resolver-v5-4-0</guid>
            <title>aws-route53resolver v5.4.0 - Quick Actions now available for Resolver Endpoints and Rules; Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-route53resolver-v5-4-0</link>
            <description>_What&apos;s new?_
- Users can now perform quick actions on resources to remediate cloud configuration issues or skip Turbot alarms for issues that they want to come back to later. To get started, click on the `Actions` button, which will reveal a dropdown menu with available actions, and select one. See [Quick Actions](https://turbot.com/v5/docs/guides/quick-actions) for more information.
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Policy Types:
  - AWS &gt; Route 53 Resolver &gt; Resolver Endpoint &gt; Approved &gt; Custom
  - AWS &gt; Route 53 Resolver &gt; Resolver Rule &gt; Approved &gt; Custom

- Action Types:
  - AWS &gt; Route 53 Resolver &gt; Resolver Endpoint &gt; Delete from AWS
  - AWS &gt; Route 53 Resolver &gt; Resolver Endpoint &gt; Set Tags
  - AWS &gt; Route 53 Resolver &gt; Resolver Endpoint &gt; Skip alarm for Active control
  - AWS &gt; Route 53 Resolver &gt; Resolver Endpoint &gt; Skip alarm for Active control [90 days]
  - AWS &gt; Route 53 Resolver &gt; Resolver Endpoint &gt; Skip alarm for Approved control
  - AWS &gt; Route 53 Resolver &gt; Resolver Endpoint &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; Route 53 Resolver &gt; Resolver Endpoint &gt; Skip alarm for Tags control
  - AWS &gt; Route 53 Resolver &gt; Resolver Endpoint &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; Route 53 Resolver &gt; Resolver Rule &gt; Delete from AWS
  - AWS &gt; Route 53 Resolver &gt; Resolver Rule &gt; Set Tags
  - AWS &gt; Route 53 Resolver &gt; Resolver Rule &gt; Skip alarm for Active control
  - AWS &gt; Route 53 Resolver &gt; Resolver Rule &gt; Skip alarm for Active control [90 days]
  - AWS &gt; Route 53 Resolver &gt; Resolver Rule &gt; Skip alarm for Approved control
  - AWS &gt; Route 53 Resolver &gt; Resolver Rule &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; Route 53 Resolver &gt; Resolver Rule &gt; Skip alarm for Tags control
  - AWS &gt; Route 53 Resolver &gt; Resolver Rule &gt; Skip alarm for Tags control [90 days]</description>
            <pubDate>Mon, 30 Oct 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-route53-v6-6-0</guid>
            <title>aws-route53 v6.6.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-route53-v6-6-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.</description>
            <pubDate>Mon, 30 Oct 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-kms-v5-17-0</guid>
            <title>aws-kms v5.17.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-kms-v5-17-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.</description>
            <pubDate>Mon, 30 Oct 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-events-v5-12-0</guid>
            <title>aws-events v5.12.0 - Quick Actions now available for Rules and Targets; Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-events-v5-12-0</link>
            <description>_What&apos;s new?_

- Users can now perform quick actions on resources to remediate cloud configuration issues or skip Turbot alarms for issues that they want to come back to later. To get started, click on the `Actions` button, which will reveal a dropdown menu with available actions, and select one. See [Quick Actions](https://turbot.com/v5/docs/guides/quick-actions) for more information.
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

- Action Types:
  - AWS &gt; Events &gt; Rule &gt; Skip alarm for Approved control
  - AWS &gt; Events &gt; Rule &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; Events &gt; Target &gt; Skip alarm for Active control
  - AWS &gt; Events &gt; Target &gt; Skip alarm for Active control [90 days]
  - AWS &gt; Events &gt; Target &gt; Skip alarm for Approved control
  - AWS &gt; Events &gt; Target &gt; Skip alarm for Approved control [90 days]</description>
            <pubDate>Mon, 30 Oct 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-waf-v5-7-0</guid>
            <title>aws-waf v5.7.0 - Quick Actions now available for all WAF resources; Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-waf-v5-7-0</link>
            <description>_What&apos;s new?_

- Users can now perform quick actions on resources to remediate cloud configuration issues or skip Turbot alarms for issues that they want to come back to later. To get started, click on the `Actions` button, which will reveal a dropdown menu with available actions, and select one. See [Quick Actions](https://turbot.com/v5/docs/guides/quick-actions) for more information.
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Action Types:
  - AWS &gt; WAF &gt; IP Set &gt; Delete from AWS
  - AWS &gt; WAF &gt; IP Set &gt; Skip alarm for Active control
  - AWS &gt; WAF &gt; IP Set &gt; Skip alarm for Active control [90 days]
  - AWS &gt; WAF &gt; IP Set &gt; Skip alarm for Approved control
  - AWS &gt; WAF &gt; IP Set &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; WAF &gt; IP Set v2 Global &gt; Delete from AWS
  - AWS &gt; WAF &gt; IP Set v2 Global &gt; Set Tags
  - AWS &gt; WAF &gt; IP Set v2 Global &gt; Skip alarm for Active control
  - AWS &gt; WAF &gt; IP Set v2 Global &gt; Skip alarm for Active control [90 days]
  - AWS &gt; WAF &gt; IP Set v2 Global &gt; Skip alarm for Approved control
  - AWS &gt; WAF &gt; IP Set v2 Global &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; WAF &gt; IP Set v2 Global &gt; Skip alarm for Tags control
  - AWS &gt; WAF &gt; IP Set v2 Global &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; WAF &gt; IP Set v2 Regional &gt; Delete from AWS
  - AWS &gt; WAF &gt; IP Set v2 Regional &gt; Set Tags
  - AWS &gt; WAF &gt; IP Set v2 Regional &gt; Skip alarm for Active control
  - AWS &gt; WAF &gt; IP Set v2 Regional &gt; Skip alarm for Active control [90 days]
  - AWS &gt; WAF &gt; IP Set v2 Regional &gt; Skip alarm for Approved control
  - AWS &gt; WAF &gt; IP Set v2 Regional &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; WAF &gt; IP Set v2 Regional &gt; Skip alarm for Tags control
  - AWS &gt; WAF &gt; IP Set v2 Regional &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; WAF &gt; Rate Based Rule &gt; Delete from AWS
  - AWS &gt; WAF &gt; Rate Based Rule &gt; Skip alarm for Active control
  - AWS &gt; WAF &gt; Rate Based Rule &gt; Skip alarm for Active control [90 days]
  - AWS &gt; WAF &gt; Rate Based Rule &gt; Skip alarm for Approved control
  - AWS &gt; WAF &gt; Rate Based Rule &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; WAF &gt; Regex Pattern Set v2 Global &gt; Delete from AWS
  - AWS &gt; WAF &gt; Regex Pattern Set v2 Global &gt; Set Tags
  - AWS &gt; WAF &gt; Regex Pattern Set v2 Global &gt; Skip alarm for Active control
  - AWS &gt; WAF &gt; Regex Pattern Set v2 Global &gt; Skip alarm for Active control [90 days]
  - AWS &gt; WAF &gt; Regex Pattern Set v2 Global &gt; Skip alarm for Approved control
  - AWS &gt; WAF &gt; Regex Pattern Set v2 Global &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; WAF &gt; Regex Pattern Set v2 Global &gt; Skip alarm for Tags control
  - AWS &gt; WAF &gt; Regex Pattern Set v2 Global &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; WAF &gt; Regex Pattern Set v2 Regional &gt; Delete from AWS
  - AWS &gt; WAF &gt; Regex Pattern Set v2 Regional &gt; Set Tags
  - AWS &gt; WAF &gt; Regex Pattern Set v2 Regional &gt; Skip alarm for Active control
  - AWS &gt; WAF &gt; Regex Pattern Set v2 Regional &gt; Skip alarm for Active control [90 days]
  - AWS &gt; WAF &gt; Regex Pattern Set v2 Regional &gt; Skip alarm for Approved control
  - AWS &gt; WAF &gt; Regex Pattern Set v2 Regional &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; WAF &gt; Regex Pattern Set v2 Regional &gt; Skip alarm for Tags control
  - AWS &gt; WAF &gt; Regex Pattern Set v2 Regional &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; WAF &gt; Rule &gt; Delete from AWS
  - AWS &gt; WAF &gt; Rule &gt; Skip alarm for Active control
  - AWS &gt; WAF &gt; Rule &gt; Skip alarm for Active control [90 days]
  - AWS &gt; WAF &gt; Rule &gt; Skip alarm for Approved control
  - AWS &gt; WAF &gt; Rule &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; WAF &gt; Rule Group v2 Global &gt; Delete from AWS
  - AWS &gt; WAF &gt; Rule Group v2 Global &gt; Set Tags
  - AWS &gt; WAF &gt; Rule Group v2 Global &gt; Skip alarm for Active control
  - AWS &gt; WAF &gt; Rule Group v2 Global &gt; Skip alarm for Active control [90 days]
  - AWS &gt; WAF &gt; Rule Group v2 Global &gt; Skip alarm for Approved control
  - AWS &gt; WAF &gt; Rule Group v2 Global &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; WAF &gt; Rule Group v2 Global &gt; Skip alarm for Tags control
  - AWS &gt; WAF &gt; Rule Group v2 Global &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; WAF &gt; Rule Group v2 Regional &gt; Delete from AWS
  - AWS &gt; WAF &gt; Rule Group v2 Regional &gt; Set Tags
  - AWS &gt; WAF &gt; Rule Group v2 Regional &gt; Skip alarm for Active control
  - AWS &gt; WAF &gt; Rule Group v2 Regional &gt; Skip alarm for Active control [90 days]
  - AWS &gt; WAF &gt; Rule Group v2 Regional &gt; Skip alarm for Approved control
  - AWS &gt; WAF &gt; Rule Group v2 Regional &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; WAF &gt; Rule Group v2 Regional &gt; Skip alarm for Tags control
  - AWS &gt; WAF &gt; Rule Group v2 Regional &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; WAF &gt; Web ACL &gt; Delete from AWS
  - AWS &gt; WAF &gt; Web ACL &gt; Set Tags
  - AWS &gt; WAF &gt; Web ACL &gt; Skip alarm for Active control
  - AWS &gt; WAF &gt; Web ACL &gt; Skip alarm for Active control [90 days]
  - AWS &gt; WAF &gt; Web ACL &gt; Skip alarm for Approved control
  - AWS &gt; WAF &gt; Web ACL &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; WAF &gt; Web ACL &gt; Skip alarm for Tags control
  - AWS &gt; WAF &gt; Web ACL &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; WAF &gt; Web ACL v2 Global &gt; Delete from AWS
  - AWS &gt; WAF &gt; Web ACL v2 Global &gt; Set Tags
  - AWS &gt; WAF &gt; Web ACL v2 Global &gt; Skip alarm for Active control
  - AWS &gt; WAF &gt; Web ACL v2 Global &gt; Skip alarm for Active control [90 days]
  - AWS &gt; WAF &gt; Web ACL v2 Global &gt; Skip alarm for Approved control
  - AWS &gt; WAF &gt; Web ACL v2 Global &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; WAF &gt; Web ACL v2 Global &gt; Skip alarm for Tags control
  - AWS &gt; WAF &gt; Web ACL v2 Global &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; WAF &gt; Web ACL v2 Regional &gt; Delete from AWS
  - AWS &gt; WAF &gt; Web ACL v2 Regional &gt; Set Tags
  - AWS &gt; WAF &gt; Web ACL v2 Regional &gt; Skip alarm for Active control
  - AWS &gt; WAF &gt; Web ACL v2 Regional &gt; Skip alarm for Active control [90 days]
  - AWS &gt; WAF &gt; Web ACL v2 Regional &gt; Skip alarm for Approved control
  - AWS &gt; WAF &gt; Web ACL v2 Regional &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; WAF &gt; Web ACL v2 Regional &gt; Skip alarm for Tags control
  - AWS &gt; WAF &gt; Web ACL v2 Regional &gt; Skip alarm for Tags control [90 days]</description>
            <pubDate>Fri, 27 Oct 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-backup-v5-10-0</guid>
            <title>aws-backup v5.10.0 - Quick Actions now available for all Backup resources; Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-backup-v5-10-0</link>
            <description>_What&apos;s new?_
- Users can now perform quick actions on resources to remediate cloud configuration issues or skip Turbot alarms for issues that they want to come back to later. To get started, click on the `Actions` button, which will reveal a dropdown menu with available actions, and select one. See [Quick Actions](https://turbot.com/v5/docs/guides/quick-actions) for more information.
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

- Action Types:
  - AWS &gt; Backup &gt; Backup Plan &gt; Delete from AWS
  - AWS &gt; Backup &gt; Backup Plan &gt; Set Tags
  - AWS &gt; Backup &gt; Backup Plan &gt; Skip alarm for Active control
  - AWS &gt; Backup &gt; Backup Plan &gt; Skip alarm for Active control [90 days]
  - AWS &gt; Backup &gt; Backup Plan &gt; Skip alarm for Tags control
  - AWS &gt; Backup &gt; Backup Plan &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; Backup &gt; Backup Selection &gt; Delete from AWS
  - AWS &gt; Backup &gt; Backup Selection &gt; Skip alarm for Active control
  - AWS &gt; Backup &gt; Backup Selection &gt; Skip alarm for Active control [90 days]
  - AWS &gt; Backup &gt; Backup Vault &gt; Delete from AWS
  - AWS &gt; Backup &gt; Backup Vault &gt; Set Tags
  - AWS &gt; Backup &gt; Backup Vault &gt; Skip alarm for Active control
  - AWS &gt; Backup &gt; Backup Vault &gt; Skip alarm for Active control [90 days]
  - AWS &gt; Backup &gt; Backup Vault &gt; Skip alarm for Tags control
  - AWS &gt; Backup &gt; Backup Vault &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; Backup &gt; Recovery Point &gt; Delete from AWS
  - AWS &gt; Backup &gt; Recovery Point &gt; Set Tags
  - AWS &gt; Backup &gt; Recovery Point &gt; Skip alarm for Active control
  - AWS &gt; Backup &gt; Recovery Point &gt; Skip alarm for Active control [90 days]
  - AWS &gt; Backup &gt; Recovery Point &gt; Skip alarm for Tags control
  - AWS &gt; Backup &gt; Recovery Point &gt; Skip alarm for Tags control [90 days]</description>
            <pubDate>Fri, 27 Oct 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-workspaces-v5-3-0</guid>
            <title>aws-workspaces v5.3.0 - Quick Actions now available for WorkSpaces; Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-workspaces-v5-3-0</link>
            <description>_What&apos;s new?_

- Users can now perform quick actions on resources to remediate cloud configuration issues or skip Turbot alarms for issues that they want to come back to later. To get started, click on the `Actions` button, which will reveal a dropdown menu with available actions, and select one. See [Quick Actions](https://turbot.com/v5/docs/guides/quick-actions) for more information.
- Added support for `ap-south-1`, `af-south-1`, `cn-north-1` and `us-gov-east-1` regions in the `AWS &gt; WorkSpaces &gt; Regions` policy.
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Policy Types:
  - AWS &gt; WorkSpaces &gt; WorkSpace &gt; Approved &gt; Custom

- Action Types:
  - AWS &gt; WorkSpaces &gt; WorkSpace &gt; Delete from AWS
  - AWS &gt; WorkSpaces &gt; WorkSpace &gt; Set Tags
  - AWS &gt; WorkSpaces &gt; WorkSpace &gt; Skip alarm for Active control
  - AWS &gt; WorkSpaces &gt; WorkSpace &gt; Skip alarm for Active control [90 days]
  - AWS &gt; WorkSpaces &gt; WorkSpace &gt; Skip alarm for Approved control
  - AWS &gt; WorkSpaces &gt; WorkSpace &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; WorkSpaces &gt; WorkSpace &gt; Skip alarm for Tags control
  - AWS &gt; WorkSpaces &gt; WorkSpace &gt; Skip alarm for Tags control [90 days]</description>
            <pubDate>Thu, 26 Oct 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-s3-v5-23-0</guid>
            <title>aws-s3 v5.23.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-s3-v5-23-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.</description>
            <pubDate>Wed, 25 Oct 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-mq-v5-2-0</guid>
            <title>aws-mq v5.2.0 - Quick Actions now available for Brokers; Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-mq-v5-2-0</link>
            <description>_What&apos;s new?_

- Users can now perform quick actions on resources to remediate cloud configuration issues or skip Turbot alarms for issues that they want to come back to later. To get started, click on the `Actions` button, which will reveal a dropdown menu with available actions, and select one. See [Quick Actions](https://turbot.com/v5/docs/guides/quick-actions) for more information.
- Added support for `cn-north-1`, ` cn-northwest-1`, `us-gov-east-1` and `us-gov-west-1` regions in the `AWS &gt; MQ &gt; Regions` policy.
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Policy Types:
  - AWS &gt; Amazon MQ &gt; Broker &gt; Approved &gt; Custom

- Action Types:
  - AWS &gt; Amazon MQ &gt; Broker &gt; Delete from AWS
  - AWS &gt; Amazon MQ &gt; Broker &gt; Set Tags
  - AWS &gt; Amazon MQ &gt; Broker &gt; Skip alarm for Active control
  - AWS &gt; Amazon MQ &gt; Broker &gt; Skip alarm for Active control [90 days]
  - AWS &gt; Amazon MQ &gt; Broker &gt; Skip alarm for Approved control
  - AWS &gt; Amazon MQ &gt; Broker &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; Amazon MQ &gt; Broker &gt; Skip alarm for Tags control
  - AWS &gt; Amazon MQ &gt; Broker &gt; Skip alarm for Tags control [90 days]</description>
            <pubDate>Wed, 25 Oct 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-logs-v5-12-0</guid>
            <title>aws-logs v5.12.0 - Quick Actions now available for all Logs resources; Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-logs-v5-12-0</link>
            <description>_What&apos;s new?_

- Users can now perform quick actions on resources to remediate cloud configuration issues or skip Turbot alarms for issues that they want to come back to later. To get started, click on the `Actions` button, which will reveal a dropdown menu with available actions, and select one. See [Quick Actions](https://turbot.com/guardrails/docs/guides/quick-actions) for more information.
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Action Types:
  - AWS &gt; Logs &gt; Log Group &gt; Delete from AWS
  - AWS &gt; Logs &gt; Log Group &gt; Set Tags
  - AWS &gt; Logs &gt; Log Group &gt; Skip alarm for Active control
  - AWS &gt; Logs &gt; Log Group &gt; Skip alarm for Active control [90 days]
  - AWS &gt; Logs &gt; Log Group &gt; Skip alarm for Approved control
  - AWS &gt; Logs &gt; Log Group &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; Logs &gt; Log Group &gt; Skip alarm for Encryption at Rest control
  - AWS &gt; Logs &gt; Log Group &gt; Skip alarm for Encryption at Rest control [90 days]
  - AWS &gt; Logs &gt; Log Group &gt; Skip alarm for Tags control
  - AWS &gt; Logs &gt; Log Group &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; Logs &gt; Log Stream &gt; Delete from AWS
  - AWS &gt; Logs &gt; Log Stream &gt; Skip alarm for Active control
  - AWS &gt; Logs &gt; Log Stream &gt; Skip alarm for Active control [90 days]
  - AWS &gt; Logs &gt; Log Stream &gt; Skip alarm for Approved control
  - AWS &gt; Logs &gt; Log Stream &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; Logs &gt; Metric Filter &gt; Delete from AWS
  - AWS &gt; Logs &gt; Metric Filter &gt; Skip alarm for Active control
  - AWS &gt; Logs &gt; Metric Filter &gt; Skip alarm for Active control [90 days]
  - AWS &gt; Logs &gt; Metric Filter &gt; Skip alarm for Approved control
  - AWS &gt; Logs &gt; Metric Filter &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; Logs &gt; Resource Policy &gt; Delete from AWS
  - AWS &gt; Logs &gt; Resource Policy &gt; Skip alarm for Active control
  - AWS &gt; Logs &gt; Resource Policy &gt; Skip alarm for Active control [90 days]
  - AWS &gt; Logs &gt; Resource Policy &gt; Skip alarm for Approved control
  - AWS &gt; Logs &gt; Resource Policy &gt; Skip alarm for Approved control [90 days]</description>
            <pubDate>Wed, 25 Oct 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-fsx-v5-3-0</guid>
            <title>aws-fsx v5.3.0 - Quick Actions now available for Backups and File Systems; Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-fsx-v5-3-0</link>
            <description>_What&apos;s new?_

- Users can now perform quick actions on resources to remediate cloud configuration issues or skip Turbot alarms for issues that they want to come back to later. To get started, click on the `Actions` button, which will reveal a dropdown menu with available actions, and select one. See [Quick Actions](https://turbot.com/v5/docs/guides/quick-actions) for more information.
- Added support for `cn-north-1`, ` cn-northwest-1`, `us-gov-east-1` and `us-gov-west-1` regions in the `AWS &gt; FSx &gt; Regions` policy.
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Policy Types:
  - AWS &gt; FSx &gt; Backup &gt; Approved &gt; Custom
  - AWS &gt; FSx &gt; File System &gt; Approved &gt; Custom

- Action Types:
  - AWS &gt; FSx &gt; Backup &gt; Delete from AWS
  - AWS &gt; FSx &gt; Backup &gt; Set Tags
  - AWS &gt; FSx &gt; Backup &gt; Skip alarm for Active control
  - AWS &gt; FSx &gt; Backup &gt; Skip alarm for Active control [90 days]
  - AWS &gt; FSx &gt; Backup &gt; Skip alarm for Approved control
  - AWS &gt; FSx &gt; Backup &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; FSx &gt; Backup &gt; Skip alarm for Tags control
  - AWS &gt; FSx &gt; Backup &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; FSx &gt; File System &gt; Delete from AWS
  - AWS &gt; FSx &gt; File System &gt; Set Tags
  - AWS &gt; FSx &gt; File System &gt; Skip alarm for Active control
  - AWS &gt; FSx &gt; File System &gt; Skip alarm for Active control [90 days]
  - AWS &gt; FSx &gt; File System &gt; Skip alarm for Approved control
  - AWS &gt; FSx &gt; File System &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; FSx &gt; File System &gt; Skip alarm for Tags control
  - AWS &gt; FSx &gt; File System &gt; Skip alarm for Tags control [90 days]</description>
            <pubDate>Wed, 25 Oct 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-cloudwatch-v5-7-0</guid>
            <title>aws-cloudwatch v5.7.0 - Quick Actions now available for Alarms; Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-cloudwatch-v5-7-0</link>
            <description>_What&apos;s new?_

- Users can now perform quick actions on resources to remediate cloud configuration issues or skip Turbot alarms for issues that they want to come back to later. To get started, click on the `Actions` button, which will reveal a dropdown menu with available actions, and select one. See [Quick Actions](https://turbot.com/guardrails/docs/guides/quick-actions) for more information.
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

- Action Types:
  - AWS &gt; CloudWatch &gt; Alarm &gt; Delete from AWS
  - AWS &gt; CloudWatch &gt; Alarm &gt; Set Tags
  - AWS &gt; CloudWatch &gt; Alarm &gt; Skip alarm for Active control
  - AWS &gt; CloudWatch &gt; Alarm &gt; Skip alarm for Active control [90 days]
  - AWS &gt; CloudWatch &gt; Alarm &gt; Skip alarm for Approved control
  - AWS &gt; CloudWatch &gt; Alarm &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; CloudWatch &gt; Alarm &gt; Skip alarm for Tags control
  - AWS &gt; CloudWatch &gt; Alarm &gt; Skip alarm for Tags control [90 days]</description>
            <pubDate>Wed, 25 Oct 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-appstream-v5-3-0</guid>
            <title>aws-appstream v5.3.0 - Quick Actions now available for all AppStream resources; Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-appstream-v5-3-0</link>
            <description>_What&apos;s new?_

- Users can now perform quick actions on resources to remediate cloud configuration issues or skip Turbot alarms for issues that they want to come back to later. To get started, click on the `Actions` button, which will reveal a dropdown menu with available actions, and select one. See [Quick Actions](https://turbot.com/v5/docs/guides/quick-actions) for more information.
- Added support for `ca-central-1`, `eu-west-2`, ` sa-east-1`, `us-east-2` and `us-gov-east-1` regions in the `AWS &gt; AppStream &gt; Regions` policy.
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Policy Types:
  - AWS &gt; AppStream &gt; Fleet &gt; Approved &gt; Custom
  - AWS &gt; AppStream &gt; Image &gt; Approved &gt; Custom
  - AWS &gt; AppStream &gt; Image Builder &gt; Approved &gt; Custom
  - AWS &gt; AppStream &gt; User &gt; Approved &gt; Custom

- Action Types:
  - AWS &gt; AppStream &gt; Fleet &gt; Delete from AWS
  - AWS &gt; AppStream &gt; Fleet &gt; Set Tags
  - AWS &gt; AppStream &gt; Fleet &gt; Skip alarm for Active control
  - AWS &gt; AppStream &gt; Fleet &gt; Skip alarm for Active control [90 days]
  - AWS &gt; AppStream &gt; Fleet &gt; Skip alarm for Approved control
  - AWS &gt; AppStream &gt; Fleet &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; AppStream &gt; Fleet &gt; Skip alarm for Tags control
  - AWS &gt; AppStream &gt; Fleet &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; AppStream &gt; Image &gt; Delete from AWS
  - AWS &gt; AppStream &gt; Image &gt; Set Tags
  - AWS &gt; AppStream &gt; Image &gt; Skip alarm for Active control
  - AWS &gt; AppStream &gt; Image &gt; Skip alarm for Active control [90 days]
  - AWS &gt; AppStream &gt; Image &gt; Skip alarm for Approved control
  - AWS &gt; AppStream &gt; Image &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; AppStream &gt; Image &gt; Skip alarm for Tags control
  - AWS &gt; AppStream &gt; Image &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; AppStream &gt; Image Builder &gt; Delete from AWS
  - AWS &gt; AppStream &gt; Image Builder &gt; Set Tags
  - AWS &gt; AppStream &gt; Image Builder &gt; Skip alarm for Active control
  - AWS &gt; AppStream &gt; Image Builder &gt; Skip alarm for Active control [90 days]
  - AWS &gt; AppStream &gt; Image Builder &gt; Skip alarm for Approved control
  - AWS &gt; AppStream &gt; Image Builder &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; AppStream &gt; Image Builder &gt; Skip alarm for Tags control
  - AWS &gt; AppStream &gt; Image Builder &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; AppStream &gt; User &gt; Delete from AWS
  - AWS &gt; AppStream &gt; User &gt; Skip alarm for Active control
  - AWS &gt; AppStream &gt; User &gt; Skip alarm for Active control [90 days]
  - AWS &gt; AppStream &gt; User &gt; Skip alarm for Approved control
  - AWS &gt; AppStream &gt; User &gt; Skip alarm for Approved control [90 days]</description>
            <pubDate>Wed, 25 Oct 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-42-4</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.42.4 - passport-saml Node package downgraded to 1.3.5.</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-42-4</link>
            <description>_What&apos;s new?_

- Server:
  - Updated: Downgrade passport-saml Node package to 1.3.5.</description>
            <pubDate>Tue, 24 Oct 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ec2-v5-36-1</guid>
            <title>aws-ec2 v5.36.1 - Bug Squashed - Volume Discovery control would go into an error state due to bad GraphQL queries</title>
            <link>https://turbot.com/guardrails/changelog/aws-ec2-v5-36-1</link>
            <description>_Bug fixes_

- The `AWS &gt; EC2 &gt; Volume &gt; Discovery` control would go into an error state because of an unintended GraphQL query bug. This is fixed and the control will now work correctly as expected.</description>
            <pubDate>Tue, 17 Oct 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-53-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.53.0 - Hive manager Updated to Manage New RDS Certificate</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-53-0</link>
            <description>_What&apos;s new?_

- Updated: Hive manager code to include the new certificate.</description>
            <pubDate>Wed, 11 Oct 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/ted-v1-38-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.38.0 - New Parameter for RDS Certificate for Commercial Cloud</title>
            <link>https://turbot.com/guardrails/changelog/ted-v1-38-0</link>
            <description>_What&apos;s new?_

- Added: parameter for RDS certificate for commercial cloud.</description>
            <pubDate>Wed, 11 Oct 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-42-3</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.42.3 - Bugs Squashed - Stack Control Execution Issue with Large number of Resources; RDS CA Certificate to use the latest bundled certificate</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-42-3</link>
            <description>_What&apos;s new?_

- Server:
  - Updated: RDS CA Certificate to use the latest bundled certificate.
  - Updated: Updated the package passport-saml to @node-saml/passport-saml: 4.0.4
  - Updated: Steampipe query in developer section now points to the correct table.

- UI:
  - Added: Option to view Changelogs in the Help dropdown menu.

_Bug fixes_

- Server:
  - Fixed: Stack control failed to run when a large number of resources were being managed by a stack control.</description>
            <pubDate>Wed, 11 Oct 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-guardduty-v5-7-0</guid>
            <title>aws-guardduty v5.7.0 - Quick Actions now available for all GuardDuty resources; Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-guardduty-v5-7-0</link>
            <description>_What&apos;s new?_

- Users can now perform quick actions on resources to remediate cloud configuration issues or skip Turbot alarms for issues that they want to come back to later. To get started, click on the `Actions` button, which will reveal a dropdown menu with available actions, and select one. See [Quick Actions](https://turbot.com/guardrails/docs/guides/quick-actions) for more information.
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Action Types:
  - AWS &gt; GuardDuty &gt; Detector &gt; Delete from AWS
  - AWS &gt; GuardDuty &gt; Detector &gt; Set Tags
  - AWS &gt; GuardDuty &gt; Detector &gt; Skip alarm for Active control
  - AWS &gt; GuardDuty &gt; Detector &gt; Skip alarm for Active control [90 days]
  - AWS &gt; GuardDuty &gt; Detector &gt; Skip alarm for Approved control
  - AWS &gt; GuardDuty &gt; Detector &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; GuardDuty &gt; Detector &gt; Skip alarm for Tags control
  - AWS &gt; GuardDuty &gt; Detector &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; GuardDuty &gt; IPSet &gt; Delete from AWS
  - AWS &gt; GuardDuty &gt; IPSet &gt; Set Tags
  - AWS &gt; GuardDuty &gt; IPSet &gt; Skip alarm for Active control
  - AWS &gt; GuardDuty &gt; IPSet &gt; Skip alarm for Active control [90 days]
  - AWS &gt; GuardDuty &gt; IPSet &gt; Skip alarm for Approved control
  - AWS &gt; GuardDuty &gt; IPSet &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; GuardDuty &gt; IPSet &gt; Skip alarm for Tags control
  - AWS &gt; GuardDuty &gt; IPSet &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; GuardDuty &gt; ThreatIntelSet &gt; Delete from AWS
  - AWS &gt; GuardDuty &gt; ThreatIntelSet &gt; Set Tags
  - AWS &gt; GuardDuty &gt; ThreatIntelSet &gt; Skip alarm for Active control
  - AWS &gt; GuardDuty &gt; ThreatIntelSet &gt; Skip alarm for Active control [90 days]
  - AWS &gt; GuardDuty &gt; ThreatIntelSet &gt; Skip alarm for Approved control
  - AWS &gt; GuardDuty &gt; ThreatIntelSet &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; GuardDuty &gt; ThreatIntelSet &gt; Skip alarm for Tags control
  - AWS &gt; GuardDuty &gt; ThreatIntelSet &gt; Skip alarm for Tags control [90 days]</description>
            <pubDate>Mon, 09 Oct 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-emr-v5-7-0</guid>
            <title>aws-emr v5.7.0 - Quick Actions now available for Clusters and Security Configurations; Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-emr-v5-7-0</link>
            <description>_What&apos;s new?_

- Users can now perform quick actions on resources to remediate cloud configuration issues or skip Turbot alarms for issues that they want to come back to later. To get started, click on the `Actions` button, which will reveal a dropdown menu with available actions, and select one. See [Quick Actions](https://turbot.com/guardrails/docs/guides/quick-actions) for more information.
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Action Types:
  - AWS &gt; EMR &gt; Cluster &gt; Delete from AWS
  - AWS &gt; EMR &gt; Cluster &gt; Set Tags
  - AWS &gt; EMR &gt; Cluster &gt; Skip alarm for Active control
  - AWS &gt; EMR &gt; Cluster &gt; Skip alarm for Active control [90 days]
  - AWS &gt; EMR &gt; Cluster &gt; Skip alarm for Approved control
  - AWS &gt; EMR &gt; Cluster &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; EMR &gt; Cluster &gt; Skip alarm for Tags control
  - AWS &gt; EMR &gt; Cluster &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; EMR &gt; Security Configuration &gt; Delete from AWS
  - AWS &gt; EMR &gt; Security Configuration &gt; Skip alarm for Active control
  - AWS &gt; EMR &gt; Security Configuration &gt; Skip alarm for Active control [90 days]
  - AWS &gt; EMR &gt; Security Configuration &gt; Skip alarm for Approved control
  - AWS &gt; EMR &gt; Security Configuration &gt; Skip alarm for Approved control [90 days]</description>
            <pubDate>Mon, 09 Oct 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ecs-v5-6-0</guid>
            <title>aws-ecs v5.6.0 - Quick Actions now available for all ECS resources; Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-ecs-v5-6-0</link>
            <description>_What&apos;s new?_

- Users can now perform quick actions on resources to remediate cloud configuration issues or skip Turbot alarms for issues that they want to come back to later. To get started, click on the `Actions` button, which will reveal a dropdown menu with available actions, and select one. See [Quick Actions](https://turbot.com/guardrails/docs/guides/quick-actions) for more information.
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Action Types:
  - AWS &gt; ECS &gt; Cluster &gt; Delete from AWS
  - AWS &gt; ECS &gt; Cluster &gt; Set Tags
  - AWS &gt; ECS &gt; Cluster &gt; Skip alarm for Active control
  - AWS &gt; ECS &gt; Cluster &gt; Skip alarm for Active control [90 days]
  - AWS &gt; ECS &gt; Cluster &gt; Skip alarm for Approved control
  - AWS &gt; ECS &gt; Cluster &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; ECS &gt; Cluster &gt; Skip alarm for Tags control
  - AWS &gt; ECS &gt; Cluster &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; ECS &gt; Container Instance &gt; Delete from AWS
  - AWS &gt; ECS &gt; Container Instance &gt; Skip alarm for Active control
  - AWS &gt; ECS &gt; Container Instance &gt; Skip alarm for Active control [90 days]
  - AWS &gt; ECS &gt; Container Instance &gt; Skip alarm for Approved control
  - AWS &gt; ECS &gt; Container Instance &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; ECS &gt; Service &gt; Delete from AWS
  - AWS &gt; ECS &gt; Service &gt; Set Tags
  - AWS &gt; ECS &gt; Service &gt; Skip alarm for Active control
  - AWS &gt; ECS &gt; Service &gt; Skip alarm for Active control [90 days]
  - AWS &gt; ECS &gt; Service &gt; Skip alarm for Approved control
  - AWS &gt; ECS &gt; Service &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; ECS &gt; Service &gt; Skip alarm for Tags control
  - AWS &gt; ECS &gt; Service &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; ECS &gt; Task Definition &gt; Delete from AWS
  - AWS &gt; ECS &gt; Task Definition &gt; Set Tags
  - AWS &gt; ECS &gt; Task Definition &gt; Skip alarm for Active control
  - AWS &gt; ECS &gt; Task Definition &gt; Skip alarm for Active control [90 days]
  - AWS &gt; ECS &gt; Task Definition &gt; Skip alarm for Approved control
  - AWS &gt; ECS &gt; Task Definition &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; ECS &gt; Task Definition &gt; Skip alarm for Tags control
  - AWS &gt; ECS &gt; Task Definition &gt; Skip alarm for Tags control [90 days]</description>
            <pubDate>Mon, 09 Oct 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ec2-v5-36-0</guid>
            <title>aws-ec2 v5.36.0 - You can now Block Public Access for AMIs; Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-ec2-v5-36-0</link>
            <description>_What&apos;s new?_

- You can now configure Block Public Access for AMIs. To get started, set the `AWS &gt; EC2 &gt; Account Attributes &gt; Block Public Access for AMIs` policy to `Enforce: Enable Block Public Access for AMIs`.
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

- Control Types:
  - AWS &gt; EC2 &gt; Account Attributes &gt; Block Public Access for AMIs

- Policy Types:
  - AWS &gt; EC2 &gt; Account Attributes &gt; Block Public Access for AMIs

- Action Types:
  - AWS &gt; EC2 &gt; Account Attributes &gt; Update Block Public Access for AMIs</description>
            <pubDate>Mon, 09 Oct 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-dms-v5-5-0</guid>
            <title>aws-dms v5.5.0 - Quick Actions now available for Endpoints and Replication Instances; Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-dms-v5-5-0</link>
            <description>_What&apos;s new?_

- Users can now perform quick actions on resources to remediate cloud configuration issues or skip Turbot alarms for issues that they want to come back to later. To get started, click on the `Actions` button, which will reveal a dropdown menu with available actions, and select one. See [Quick Actions](https://turbot.com/guardrails/docs/guides/quick-actions) for more information.
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Policy Types:
  - AWS &gt; DMS &gt; Endpoint &gt; Approved &gt; Custom
  - AWS &gt; DMS &gt; Replication Instance &gt; Approved &gt; Custom

- Action Types:
  - AWS &gt; DMS &gt; Endpoint &gt; Delete from AWS
  - AWS &gt; DMS &gt; Endpoint &gt; Set Tags
  - AWS &gt; DMS &gt; Endpoint &gt; Skip alarm for Active control
  - AWS &gt; DMS &gt; Endpoint &gt; Skip alarm for Active control [90 days]
  - AWS &gt; DMS &gt; Endpoint &gt; Skip alarm for Approved control
  - AWS &gt; DMS &gt; Endpoint &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; DMS &gt; Endpoint &gt; Skip alarm for Tags control
  - AWS &gt; DMS &gt; Endpoint &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; DMS &gt; Replication Instance &gt; Delete from AWS
  - AWS &gt; DMS &gt; Replication Instance &gt; Set Tags
  - AWS &gt; DMS &gt; Replication Instance &gt; Skip alarm for Active control
  - AWS &gt; DMS &gt; Replication Instance &gt; Skip alarm for Active control [90 days]
  - AWS &gt; DMS &gt; Replication Instance &gt; Skip alarm for Approved control
  - AWS &gt; DMS &gt; Replication Instance &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; DMS &gt; Replication Instance &gt; Skip alarm for Tags control
  - AWS &gt; DMS &gt; Replication Instance &gt; Skip alarm for Tags control [90 days]</description>
            <pubDate>Mon, 09 Oct 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ses-v5-4-0</guid>
            <title>aws-ses v5.4.0 - Quick Actions now available for Identities; Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-ses-v5-4-0</link>
            <description>_What&apos;s new?_

- Users can now perform quick actions on resources to remediate cloud configuration issues or skip Turbot alarms for issues that they want to come back to later. To get started, click on the `Actions` button, which will reveal a dropdown menu with available actions, and select one. See [Quick Actions](https://turbot.com/guardrails/docs/guides/quick-actions) for more information.
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Action Types:
  - AWS &gt; SES &gt; Identity &gt; Delete from AWS
  - AWS &gt; SES &gt; Identity &gt; Skip alarm for Active control
  - AWS &gt; SES &gt; Identity &gt; Skip alarm for Active control [90 days]
  - AWS &gt; SES &gt; Identity &gt; Skip alarm for Approved control
  - AWS &gt; SES &gt; Identity &gt; Skip alarm for Approved control [90 days]</description>
            <pubDate>Fri, 06 Oct 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-securityhub-v5-3-0</guid>
            <title>aws-securityhub v5.3.0 - Quick Actions now available for Security Hub; Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-securityhub-v5-3-0</link>
            <description>_What&apos;s new?_

- Users can now perform quick actions on resources to remediate cloud configuration issues or skip Turbot alarms for issues that they want to come back to later. To get started, click on the `Actions` button, which will reveal a dropdown menu with available actions, and select one. See [Quick Actions](https://turbot.com/guardrails/docs/guides/quick-actions) for more information.
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Policy Types:
  - AWS &gt; Security Hub &gt; Hub &gt; Approved &gt; Custom

- Action Types:
  - AWS &gt; Security Hub &gt; Hub &gt; Delete from AWS
  - AWS &gt; Security Hub &gt; Hub &gt; Set Tags
  - AWS &gt; Security Hub &gt; Hub &gt; Skip alarm for Approved control
  - AWS &gt; Security Hub &gt; Hub &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; Security Hub &gt; Hub &gt; Skip alarm for Tags control
  - AWS &gt; Security Hub &gt; Hub &gt; Skip alarm for Tags control [90 days]</description>
            <pubDate>Fri, 06 Oct 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-kinesis-v5-8-0</guid>
            <title>aws-kinesis v5.8.0 - Quick Actions now available for Consumers and Streams; Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-kinesis-v5-8-0</link>
            <description>_What&apos;s new?_

- Users can now perform quick actions on resources to remediate cloud configuration issues or skip Turbot alarms for issues that they want to come back to later. To get started, click on the `Actions` button, which will reveal a dropdown menu with available actions, and select one. See [Quick Actions](https://turbot.com/guardrails/docs/guides/quick-actions) for more information.
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Action Types:
  - AWS &gt; Kinesis &gt; Consumer &gt; Delete from AWS
  - AWS &gt; Kinesis &gt; Consumer &gt; Skip alarm for Active control
  - AWS &gt; Kinesis &gt; Consumer &gt; Skip alarm for Active control [90 days]
  - AWS &gt; Kinesis &gt; Consumer &gt; Skip alarm for Approved control
  - AWS &gt; Kinesis &gt; Consumer &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; Kinesis &gt; Stream &gt; Delete from AWS
  - AWS &gt; Kinesis &gt; Stream &gt; Set Tags
  - AWS &gt; Kinesis &gt; Stream &gt; Skip alarm for Active control
  - AWS &gt; Kinesis &gt; Stream &gt; Skip alarm for Active control [90 days]
  - AWS &gt; Kinesis &gt; Stream &gt; Skip alarm for Approved control
  - AWS &gt; Kinesis &gt; Stream &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; Kinesis &gt; Stream &gt; Skip alarm for Encryption at Rest control
  - AWS &gt; Kinesis &gt; Stream &gt; Skip alarm for Encryption at Rest control [90 days]
  - AWS &gt; Kinesis &gt; Stream &gt; Skip alarm for Tags control
  - AWS &gt; Kinesis &gt; Stream &gt; Skip alarm for Tags control [90 days]</description>
            <pubDate>Fri, 06 Oct 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-dynamodb-v5-10-0</guid>
            <title>aws-dynamodb v5.10.0 - Quick Actions now available for Backups, Global Tables and Tables; Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-dynamodb-v5-10-0</link>
            <description>_What&apos;s new?_

- Users can now perform quick actions on resources to remediate cloud configuration issues or skip Turbot alarms for issues that they want to come back to later. To get started, click on the `Actions` button, which will reveal a dropdown menu with available actions, and select one. See [Quick Actions](https://turbot.com/guardrails/docs/guides/quick-actions) for more information.
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Action Types:
  - AWS &gt; DynamoDB &gt; Backup &gt; Delete from AWS
  - AWS &gt; DynamoDB &gt; Backup &gt; Skip alarm for Active control
  - AWS &gt; DynamoDB &gt; Backup &gt; Skip alarm for Active control [90 days]
  - AWS &gt; DynamoDB &gt; Backup &gt; Skip alarm for Approved control
  - AWS &gt; DynamoDB &gt; Backup &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; DynamoDB &gt; Global Table &gt; Delete from AWS
  - AWS &gt; DynamoDB &gt; Global Table &gt; Skip alarm for Active control
  - AWS &gt; DynamoDB &gt; Global Table &gt; Skip alarm for Active control [90 days]
  - AWS &gt; DynamoDB &gt; Global Table &gt; Skip alarm for Approved control
  - AWS &gt; DynamoDB &gt; Global Table &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; DynamoDB &gt; Table &gt; Delete from AWS
  - AWS &gt; DynamoDB &gt; Table &gt; Set Tags
  - AWS &gt; DynamoDB &gt; Table &gt; Skip alarm for Active control
  - AWS &gt; DynamoDB &gt; Table &gt; Skip alarm for Active control [90 days]
  - AWS &gt; DynamoDB &gt; Table &gt; Skip alarm for Approved control
  - AWS &gt; DynamoDB &gt; Table &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; DynamoDB &gt; Table &gt; Skip alarm for Encryption at Rest control
  - AWS &gt; DynamoDB &gt; Table &gt; Skip alarm for Encryption at Rest control [90 days]
  - AWS &gt; DynamoDB &gt; Table &gt; Skip alarm for Tags control
  - AWS &gt; DynamoDB &gt; Table &gt; Skip alarm for Tags control [90 days]</description>
            <pubDate>Fri, 06 Oct 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-stepfunctions-v5-6-0</guid>
            <title>aws-stepfunctions v5.6.0 - Quick Actions now available for State Machines; Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-stepfunctions-v5-6-0</link>
            <description>_What&apos;s new?_

- Users can now perform quick actions on resources to remediate cloud configuration issues or skip Turbot alarms for issues that they want to come back to later. To get started, click on the `Actions` button, which will reveal a dropdown menu with available actions, and select one. See [Quick Actions](https://turbot.com/guardrails/docs/guides/quick-actions) for more information.
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Policy Types:
  - AWS &gt; Step Functions &gt; State Machine &gt; Approved &gt; Custom

- Action Types:
  - AWS &gt; Step Functions &gt; State Machine &gt; Delete from AWS
  - AWS &gt; Step Functions &gt; State Machine &gt; Set Tags
  - AWS &gt; Step Functions &gt; State Machine &gt; Skip alarm for Active control
  - AWS &gt; Step Functions &gt; State Machine &gt; Skip alarm for Active control [90 days]
  - AWS &gt; Step Functions &gt; State Machine &gt; Skip alarm for Approved control
  - AWS &gt; Step Functions &gt; State Machine &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; Step Functions &gt; State Machine &gt; Skip alarm for Tags control
  - AWS &gt; Step Functions &gt; State Machine &gt; Skip alarm for Tags control [90 days]</description>
            <pubDate>Thu, 05 Oct 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-shield-v5-2-0</guid>
            <title>aws-shield v5.2.0 - Quick Actions now available for Shield Protection; Lambda runtimes now powered by Node 18; and more</title>
            <link>https://turbot.com/guardrails/changelog/aws-shield-v5-2-0</link>
            <description>_What&apos;s new?_

- Users can now perform quick actions on resources to remediate cloud configuration issues or skip Turbot alarms for issues that they want to come back to later. To get started, click on the `Actions` button, which will reveal a dropdown menu with available actions, and select one. See [Quick Actions](https://turbot.com/guardrails/docs/guides/quick-actions) for more information.
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Policy Types:
  - AWS &gt; Shield &gt; Protection &gt; Approved &gt; Custom

- Action Types:
  - AWS &gt; Shield &gt; Protection &gt; Delete from AWS
  - AWS &gt; Shield &gt; Protection &gt; Skip alarm for Active control
  - AWS &gt; Shield &gt; Protection &gt; Skip alarm for Active control [90 days]
  - AWS &gt; Shield &gt; Protection &gt; Skip alarm for Approved control
  - AWS &gt; Shield &gt; Protection &gt; Skip alarm for Approved control [90 days]</description>
            <pubDate>Thu, 05 Oct 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-directoryservice-v5-4-0</guid>
            <title>aws-directoryservice v5.4.0 - Quick Actions now available for Directories; Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-directoryservice-v5-4-0</link>
            <description>_What&apos;s new?_

- Users can now perform quick actions on resources to remediate cloud configuration issues or skip Turbot alarms for issues that they want to come back to later. To get started, click on the `Actions` button, which will reveal a dropdown menu with available actions, and select one. See [Quick Actions](https://turbot.com/guardrails/docs/guides/quick-actions) for more information.
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Policy Types:
  - AWS &gt; Directory Service &gt; Directory &gt; Approved &gt; Custom

- Action Types:
  - AWS &gt; Directory Service &gt; Directory &gt; Delete from AWS
  - AWS &gt; Directory Service &gt; Directory &gt; Skip alarm for Active control
  - AWS &gt; Directory Service &gt; Directory &gt; Skip alarm for Active control [90 days]
  - AWS &gt; Directory Service &gt; Directory &gt; Skip alarm for Approved control
  - AWS &gt; Directory Service &gt; Directory &gt; Skip alarm for Approved control [90 days]</description>
            <pubDate>Thu, 05 Oct 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-codebuild-v5-5-0</guid>
            <title>aws-codebuild v5.5.0 - Quick Actions now available for all CodeBuild resources; Lambda runtimes now powered by Node 18; and more</title>
            <link>https://turbot.com/guardrails/changelog/aws-codebuild-v5-5-0</link>
            <description>_What&apos;s new?_

- Users can now perform quick actions on resources to remediate cloud configuration issues or skip Turbot alarms for issues that they want to come back to later. To get started, click on the `Actions` button, which will reveal a dropdown menu with available actions, and select one. See [Quick Actions](https://turbot.com/guardrails/docs/guides/quick-actions) for more information.
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Action Types:
  - AWS &gt; CodeBuild &gt; Build &gt; Delete from AWS
  - AWS &gt; CodeBuild &gt; Build &gt; Skip alarm for Active control
  - AWS &gt; CodeBuild &gt; Build &gt; Skip alarm for Active control [90 days]
  - AWS &gt; CodeBuild &gt; Build &gt; Skip alarm for Approved control
  - AWS &gt; CodeBuild &gt; Build &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; CodeBuild &gt; Project &gt; Delete from AWS
  - AWS &gt; CodeBuild &gt; Project &gt; Set Tags
  - AWS &gt; CodeBuild &gt; Project &gt; Skip alarm for Active control
  - AWS &gt; CodeBuild &gt; Project &gt; Skip alarm for Active control [90 days]
  - AWS &gt; CodeBuild &gt; Project &gt; Skip alarm for Approved control
  - AWS &gt; CodeBuild &gt; Project &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; CodeBuild &gt; Project &gt; Skip alarm for Tags control
  - AWS &gt; CodeBuild &gt; Project &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; CodeBuild &gt; Source Credential &gt; Delete from AWS
  - AWS &gt; CodeBuild &gt; Source Credential &gt; Skip alarm for Active control
  - AWS &gt; CodeBuild &gt; Source Credential &gt; Skip alarm for Active control [90 days]
  - AWS &gt; CodeBuild &gt; Source Credential &gt; Skip alarm for Approved control
  - AWS &gt; CodeBuild &gt; Source Credential &gt; Skip alarm for Approved control [90 days]</description>
            <pubDate>Thu, 05 Oct 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-cloudformation-v5-11-0</guid>
            <title>aws-cloudformation v5.11.0 - Quick Actions now available for Stacks and Stack Sets; Lambda runtimes now powered by Node 18; and more</title>
            <link>https://turbot.com/guardrails/changelog/aws-cloudformation-v5-11-0</link>
            <description>_What&apos;s new?_

- Users can now perform quick actions on resources to remediate cloud configuration issues or skip Turbot alarms for issues that they want to come back to later. To get started, click on the `Actions` button, which will reveal a dropdown menu with available actions, and select one. See [Quick Actions](https://turbot.com/guardrails/docs/guides/quick-actions) for more information.
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Policy Types:
  - AWS &gt; CloudFormation &gt; Stack &gt; Approved &gt; Custom
  - AWS &gt; CloudFormation &gt; StackSet &gt; Approved &gt; Custom

- Action Types:
  - AWS &gt; CloudFormation &gt; Stack &gt; Delete from AWS
  - AWS &gt; CloudFormation &gt; Stack &gt; Set Tags
  - AWS &gt; CloudFormation &gt; Stack &gt; Skip alarm for Active control
  - AWS &gt; CloudFormation &gt; Stack &gt; Skip alarm for Active control [90 days]
  - AWS &gt; CloudFormation &gt; Stack &gt; Skip alarm for Approved control
  - AWS &gt; CloudFormation &gt; Stack &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; CloudFormation &gt; Stack &gt; Skip alarm for Tags control
  - AWS &gt; CloudFormation &gt; Stack &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; CloudFormation &gt; StackSet &gt; Delete from AWS
  - AWS &gt; CloudFormation &gt; StackSet &gt; Set Tags
  - AWS &gt; CloudFormation &gt; StackSet &gt; Skip alarm for Active control
  - AWS &gt; CloudFormation &gt; StackSet &gt; Skip alarm for Active control [90 days]
  - AWS &gt; CloudFormation &gt; StackSet &gt; Skip alarm for Approved control
  - AWS &gt; CloudFormation &gt; StackSet &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; CloudFormation &gt; StackSet &gt; Skip alarm for Tags control
  - AWS &gt; CloudFormation &gt; StackSet &gt; Skip alarm for Tags control [90 days]</description>
            <pubDate>Thu, 05 Oct 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-athena-v5-4-0</guid>
            <title>aws-athena v5.4.0 - Quick Actions now available for NamedQuery and Workgroups; Lambda runtimes now powered by Node 18; and more</title>
            <link>https://turbot.com/guardrails/changelog/aws-athena-v5-4-0</link>
            <description>_What&apos;s new?_

- Users can now perform quick actions on resources to remediate cloud configuration issues or skip Turbot alarms for issues that they want to come back to later. To get started, click on the `Actions` button, which will reveal a dropdown menu with available actions, and select one. See [Quick Actions](https://turbot.com/guardrails/docs/guides/quick-actions) for more information.
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Policy Types:
  - AWS &gt; Athena &gt; NamedQuery &gt; Approved &gt; Custom
  - AWS &gt; Athena &gt; Workgroup &gt; Approved &gt; Custom

- Action Types:
  - AWS &gt; Athena &gt; NamedQuery &gt; Delete from AWS
  - AWS &gt; Athena &gt; NamedQuery &gt; Set Tags
  - AWS &gt; Athena &gt; NamedQuery &gt; Skip alarm for Active control
  - AWS &gt; Athena &gt; NamedQuery &gt; Skip alarm for Active control [90 days]
  - AWS &gt; Athena &gt; NamedQuery &gt; Skip alarm for Approved control
  - AWS &gt; Athena &gt; NamedQuery &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; Athena &gt; NamedQuery &gt; Skip alarm for Tags control
  - AWS &gt; Athena &gt; NamedQuery &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; Athena &gt; Workgroup &gt; Delete from AWS
  - AWS &gt; Athena &gt; Workgroup &gt; Set Tags
  - AWS &gt; Athena &gt; Workgroup &gt; Skip alarm for Active control
  - AWS &gt; Athena &gt; Workgroup &gt; Skip alarm for Active control [90 days]
  - AWS &gt; Athena &gt; Workgroup &gt; Skip alarm for Approved control
  - AWS &gt; Athena &gt; Workgroup &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; Athena &gt; Workgroup &gt; Skip alarm for Tags control
  - AWS &gt; Athena &gt; Workgroup &gt; Skip alarm for Tags control [90 days]</description>
            <pubDate>Thu, 05 Oct 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-cloudsearch-v5-4-0</guid>
            <title>aws-cloudsearch v5.4.0 - Quick Actions now available for Domains; Lambda runtimes now powered by Node 18; and more</title>
            <link>https://turbot.com/guardrails/changelog/aws-cloudsearch-v5-4-0</link>
            <description>_What&apos;s new?_

- Users can now perform quick actions on resources to remediate cloud configuration issues or skip Turbot alarms for issues that they want to come back to later. To get started, click on the `Actions` button, which will reveal a dropdown menu with available actions, and select one. See [Quick Actions](https://turbot.com/guardrails/docs/guides/quick-actions) for more information.
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Action Types:
  - AWS &gt; CloudSearch &gt; Domain &gt; Skip alarm for Active control
  - AWS &gt; CloudSearch &gt; Domain &gt; Skip alarm for Active control [90 days]
  - AWS &gt; CloudSearch &gt; Domain &gt; Skip alarm for Approved control
  - AWS &gt; CloudSearch &gt; Domain &gt; Skip alarm for Approved control [90 days]</description>
            <pubDate>Wed, 04 Oct 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-cloudfront-v5-4-0</guid>
            <title>aws-cloudfront v5.4.0 - Quick Actions now available for all CloudFront resources; Lambda runtimes now powered by Node 18; and more</title>
            <link>https://turbot.com/guardrails/changelog/aws-cloudfront-v5-4-0</link>
            <description>_What&apos;s new?_

- Users can now perform quick actions on resources to remediate cloud configuration issues or skip Turbot alarms for issues that they want to come back to later. To get started, click on the `Actions` button, which will reveal a dropdown menu with available actions, and select one. See [Quick Actions](https://turbot.com/guardrails/docs/guides/quick-actions) for more information.
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Policy Types:
  - AWS &gt; CloudFront &gt; CloudFront Origin Access Identity &gt; Approved &gt; Custom
  - AWS &gt; CloudFront &gt; Distribution &gt; Approved &gt; Custom
  - AWS &gt; CloudFront &gt; Streaming Distribution &gt; Approved &gt; Custom

- Action Types:
  - AWS &gt; CloudFront &gt; CloudFront Origin Access Identity &gt; Skip alarm for Active control
  - AWS &gt; CloudFront &gt; CloudFront Origin Access Identity &gt; Skip alarm for Active control [90 days]
  - AWS &gt; CloudFront &gt; CloudFront Origin Access Identity &gt; Skip alarm for Approved control
  - AWS &gt; CloudFront &gt; CloudFront Origin Access Identity &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; CloudFront &gt; Distribution &gt; Set Tags
  - AWS &gt; CloudFront &gt; Distribution &gt; Skip alarm for Active control
  - AWS &gt; CloudFront &gt; Distribution &gt; Skip alarm for Active control [90 days]
  - AWS &gt; CloudFront &gt; Distribution &gt; Skip alarm for Approved control
  - AWS &gt; CloudFront &gt; Distribution &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; CloudFront &gt; Distribution &gt; Skip alarm for Tags control
  - AWS &gt; CloudFront &gt; Distribution &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; CloudFront &gt; Streaming Distribution &gt; Set Tags
  - AWS &gt; CloudFront &gt; Streaming Distribution &gt; Skip alarm for Active control
  - AWS &gt; CloudFront &gt; Streaming Distribution &gt; Skip alarm for Active control [90 days]
  - AWS &gt; CloudFront &gt; Streaming Distribution &gt; Skip alarm for Approved control
  - AWS &gt; CloudFront &gt; Streaming Distribution &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; CloudFront &gt; Streaming Distribution &gt; Skip alarm for Tags control
  - AWS &gt; CloudFront &gt; Streaming Distribution &gt; Skip alarm for Tags control [90 days]</description>
            <pubDate>Wed, 04 Oct 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-apigateway-v5-8-0</guid>
            <title>aws-apigateway v5.8.0 - Quick Actions now available for all API Gateway resources; Lambda runtimes now powered by Node 18; and more</title>
            <link>https://turbot.com/guardrails/changelog/aws-apigateway-v5-8-0</link>
            <description>_What&apos;s new?_

- Users can now perform quick actions on resources to remediate cloud configuration issues or skip Turbot alarms for issues that they want to come back to later. To get started, click on the `Actions` button, which will reveal a dropdown menu with available actions, and select one. See [Quick Actions](https://turbot.com/guardrails/docs/guides/quick-actions) for more information.
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Action Types:
  - AWS &gt; API Gateway &gt; API &gt; Delete from AWS
  - AWS &gt; API Gateway &gt; API &gt; Set Tags
  - AWS &gt; API Gateway &gt; API &gt; Skip alarm for Active control
  - AWS &gt; API Gateway &gt; API &gt; Skip alarm for Active control [90 days]
  - AWS &gt; API Gateway &gt; API &gt; Skip alarm for Approved control
  - AWS &gt; API Gateway &gt; API &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; API Gateway &gt; API &gt; Skip alarm for Tags control
  - AWS &gt; API Gateway &gt; API &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; API Gateway &gt; API Key &gt; Delete from AWS
  - AWS &gt; API Gateway &gt; API Key &gt; Set Tags
  - AWS &gt; API Gateway &gt; API Key &gt; Skip alarm for Active control
  - AWS &gt; API Gateway &gt; API Key &gt; Skip alarm for Active control [90 days]
  - AWS &gt; API Gateway &gt; API Key &gt; Skip alarm for Approved control
  - AWS &gt; API Gateway &gt; API Key &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; API Gateway &gt; API Key &gt; Skip alarm for Tags control
  - AWS &gt; API Gateway &gt; API Key &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; API Gateway &gt; API V2 &gt; Delete from AWS
  - AWS &gt; API Gateway &gt; API V2 &gt; Set Tags
  - AWS &gt; API Gateway &gt; API V2 &gt; Skip alarm for Active control
  - AWS &gt; API Gateway &gt; API V2 &gt; Skip alarm for Active control [90 days]
  - AWS &gt; API Gateway &gt; API V2 &gt; Skip alarm for Approved control
  - AWS &gt; API Gateway &gt; API V2 &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; API Gateway &gt; API V2 &gt; Skip alarm for Tags control
  - AWS &gt; API Gateway &gt; API V2 &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; API Gateway &gt; Authorizer &gt; Delete from AWS
  - AWS &gt; API Gateway &gt; Authorizer &gt; Skip alarm for Active control
  - AWS &gt; API Gateway &gt; Authorizer &gt; Skip alarm for Active control [90 days]
  - AWS &gt; API Gateway &gt; Authorizer &gt; Skip alarm for Approved control
  - AWS &gt; API Gateway &gt; Authorizer &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; API Gateway &gt; Authorizer V2 &gt; Delete from AWS
  - AWS &gt; API Gateway &gt; Authorizer V2 &gt; Skip alarm for Active control
  - AWS &gt; API Gateway &gt; Authorizer V2 &gt; Skip alarm for Active control [90 days]
  - AWS &gt; API Gateway &gt; Authorizer V2 &gt; Skip alarm for Approved control
  - AWS &gt; API Gateway &gt; Authorizer V2 &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; API Gateway &gt; Domain Name V2 &gt; Delete from AWS
  - AWS &gt; API Gateway &gt; Domain Name V2 &gt; Set Tags
  - AWS &gt; API Gateway &gt; Domain Name V2 &gt; Skip alarm for Active control
  - AWS &gt; API Gateway &gt; Domain Name V2 &gt; Skip alarm for Active control [90 days]
  - AWS &gt; API Gateway &gt; Domain Name V2 &gt; Skip alarm for Approved control
  - AWS &gt; API Gateway &gt; Domain Name V2 &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; API Gateway &gt; Domain Name V2 &gt; Skip alarm for Tags control
  - AWS &gt; API Gateway &gt; Domain Name V2 &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; API Gateway &gt; Integration V2 &gt; Delete from AWS
  - AWS &gt; API Gateway &gt; Integration V2 &gt; Skip alarm for Active control
  - AWS &gt; API Gateway &gt; Integration V2 &gt; Skip alarm for Active control [90 days]
  - AWS &gt; API Gateway &gt; Integration V2 &gt; Skip alarm for Approved control
  - AWS &gt; API Gateway &gt; Integration V2 &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; API Gateway &gt; Resource &gt; Delete from AWS
  - AWS &gt; API Gateway &gt; Resource &gt; Skip alarm for Active control
  - AWS &gt; API Gateway &gt; Resource &gt; Skip alarm for Active control [90 days]
  - AWS &gt; API Gateway &gt; Resource &gt; Skip alarm for Approved control
  - AWS &gt; API Gateway &gt; Resource &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; API Gateway &gt; Stage &gt; Delete from AWS
  - AWS &gt; API Gateway &gt; Stage &gt; Set Tags
  - AWS &gt; API Gateway &gt; Stage &gt; Skip alarm for Active control
  - AWS &gt; API Gateway &gt; Stage &gt; Skip alarm for Active control [90 days]
  - AWS &gt; API Gateway &gt; Stage &gt; Skip alarm for Approved control
  - AWS &gt; API Gateway &gt; Stage &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; API Gateway &gt; Stage &gt; Skip alarm for Tags control
  - AWS &gt; API Gateway &gt; Stage &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; API Gateway &gt; Stage v2 &gt; Delete from AWS
  - AWS &gt; API Gateway &gt; Stage v2 &gt; Set Tags
  - AWS &gt; API Gateway &gt; Stage v2 &gt; Skip alarm for Active control
  - AWS &gt; API Gateway &gt; Stage v2 &gt; Skip alarm for Active control [90 days]
  - AWS &gt; API Gateway &gt; Stage v2 &gt; Skip alarm for Approved control
  - AWS &gt; API Gateway &gt; Stage v2 &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; API Gateway &gt; Stage v2 &gt; Skip alarm for Tags control
  - AWS &gt; API Gateway &gt; Stage v2 &gt; Skip alarm for Tags control [90 days]
  - AWS &gt; API Gateway &gt; Usage Plan &gt; Delete from AWS
  - AWS &gt; API Gateway &gt; Usage Plan &gt; Set Tags
  - AWS &gt; API Gateway &gt; Usage Plan &gt; Skip alarm for Active control
  - AWS &gt; API Gateway &gt; Usage Plan &gt; Skip alarm for Active control [90 days]
  - AWS &gt; API Gateway &gt; Usage Plan &gt; Skip alarm for Approved control
  - AWS &gt; API Gateway &gt; Usage Plan &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; API Gateway &gt; Usage Plan &gt; Skip alarm for Tags control
  - AWS &gt; API Gateway &gt; Usage Plan &gt; Skip alarm for Tags control [90 days]</description>
            <pubDate>Wed, 04 Oct 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-amplify-v5-4-0</guid>
            <title>aws-amplify v5.4.0 - New permissions for Deployment, WebHook and Artifacts; Quick Actions for Amplify Apps; Lambda runtimes now powered by Node 18; and more</title>
            <link>https://turbot.com/guardrails/changelog/aws-amplify-v5-4-0</link>
            <description>_What&apos;s new?_

- `AWS/Amplify/Admin` and `AWS/Amplify/Metadata` now also include permissions for Deployment, WebHook and Artifacts.
- Users can now perform quick actions on resources to remediate cloud configuration issues or skip Turbot alarms for issues that they want to come back to later. To get started, click on the `Actions` button, which will reveal a dropdown menu with available actions, and select one. See [Quick Actions](https://turbot.com/guardrails/docs/guides/quick-actions) for more information.
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Policy Types:
  - AWS &gt; Amplify &gt; App &gt; Approved &gt; Custom

- Action Types:
  - AWS &gt; Amplify &gt; App &gt; Delete from AWS
  - AWS &gt; Amplify &gt; App &gt; Set Tags
  - AWS &gt; Amplify &gt; App &gt; Skip alarm for Active control
  - AWS &gt; Amplify &gt; App &gt; Skip alarm for Active control [90 days]
  - AWS &gt; Amplify &gt; App &gt; Skip alarm for Approved control
  - AWS &gt; Amplify &gt; App &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; Amplify &gt; App &gt; Skip alarm for Tags control
  - AWS &gt; Amplify &gt; App &gt; Skip alarm for Tags control [90 days]</description>
            <pubDate>Wed, 04 Oct 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-acm-v5-8-0</guid>
            <title>aws-acm v5.8.0 - Quick Actions now available for Certificates; Lambda runtimes now powered by Node 18; and more</title>
            <link>https://turbot.com/guardrails/changelog/aws-acm-v5-8-0</link>
            <description>_What&apos;s new?_

- Users can now perform quick actions on resources to remediate cloud configuration issues or skip Turbot alarms for issues that they want to come back to later. To get started, click on the `Actions` button, which will reveal a dropdown menu with available actions, and select one. See [Quick Actions](https://turbot.com/guardrails/docs/guides/quick-actions) for more information.
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.

- Policy Types:
  - AWS &gt; ACM &gt; Certificate &gt; Approved &gt; Custom

- Action Types:
  - AWS &gt; ACM &gt; Certificate &gt; Delete from AWS
  - AWS &gt; ACM &gt; Certificate &gt; Set Tags
  - AWS &gt; ACM &gt; Certificate &gt; Skip alarm for Active control
  - AWS &gt; ACM &gt; Certificate &gt; Skip alarm for Active control [90 days]
  - AWS &gt; ACM &gt; Certificate &gt; Skip alarm for Approved control
  - AWS &gt; ACM &gt; Certificate &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; ACM &gt; Certificate &gt; Skip alarm for Tags control
  - AWS &gt; ACM &gt; Certificate &gt; Skip alarm for Tags control [90 days]</description>
            <pubDate>Wed, 04 Oct 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/ted-v1-37-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.37.0 - Added support for t4g, m7g, m6gd, r7g, r6gd, c6g and c6gd instance types for RDS; and more</title>
            <link>https://turbot.com/guardrails/changelog/ted-v1-37-0</link>
            <description>_What&apos;s new?_

- Added: t4g, m7g, m6gd, r7g, r6gd, c6g and c6gd to instance type parameter for RDS.
- Added: new hive parameter group for Postgres 14 and 15.</description>
            <pubDate>Fri, 29 Sep 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-eks-v5-6-0</guid>
            <title>aws-eks v5.6.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-eks-v5-6-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Rebranded to a Turbot Guardrails Mod. To maintain compatibility, none of the existing resource types, control types or policy types have changed, your existing configurations and settings will continue to work as before.</description>
            <pubDate>Fri, 29 Sep 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-route53-v6-5-0</guid>
            <title>aws-route53 v6.5.0 - Added new Resource Type for Route53 Records</title>
            <link>https://turbot.com/guardrails/changelog/aws-route53-v6-5-0</link>
            <description>_What&apos;s new?_

- Resource Types:
  - AWS &gt; Route 53 &gt; Record

- Control Types:
  - AWS &gt; Route 53 &gt; Record &gt; Active
  - AWS &gt; Route 53 &gt; Record &gt; Approved
  - AWS &gt; Route 53 &gt; Record &gt; CMDB
  - AWS &gt; Route 53 &gt; Record &gt; Discovery

- Policy Types:
  - AWS &gt; Route 53 &gt; Record &gt; Active
  - AWS &gt; Route 53 &gt; Record &gt; Active &gt; Age
  - AWS &gt; Route 53 &gt; Record &gt; Active &gt; Budget
  - AWS &gt; Route 53 &gt; Record &gt; Active &gt; Last Modified
  - AWS &gt; Route 53 &gt; Record &gt; Approved
  - AWS &gt; Route 53 &gt; Record &gt; Approved &gt; Budget
  - AWS &gt; Route 53 &gt; Record &gt; Approved &gt; Custom
  - AWS &gt; Route 53 &gt; Record &gt; Approved &gt; Usage
  - AWS &gt; Route 53 &gt; Record &gt; CMDB

- Action Types:
  - AWS &gt; Route 53 &gt; Record &gt; Delete
  - AWS &gt; Route 53 &gt; Record &gt; Delete from AWS
  - AWS &gt; Route 53 &gt; Record &gt; Router
  - AWS &gt; Route 53 &gt; Record &gt; Skip alarm for Active control
  - AWS &gt; Route 53 &gt; Record &gt; Skip alarm for Active control [90 days]
  - AWS &gt; Route 53 &gt; Record &gt; Skip alarm for Approved control
  - AWS &gt; Route 53 &gt; Record &gt; Skip alarm for Approved control [90 days]</description>
            <pubDate>Thu, 28 Sep 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-organizations-v5-2-0</guid>
            <title>aws-organizations v5.2.0 - New Active and Approved controls and policies for Organizational Root and Organizational Account resource types</title>
            <link>https://turbot.com/guardrails/changelog/aws-organizations-v5-2-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

- Control Types:
  - AWS &gt; Organizations &gt; Organization Root &gt; Active
  - AWS &gt; Organizations &gt; Organization Root &gt; Approved
  - AWS &gt; Organizations &gt; Organizational Account &gt; Active
  - AWS &gt; Organizations &gt; Organizational Account &gt; Approved

- Policy Types:
  - AWS &gt; Organizations &gt; Organization Root &gt; Active
  - AWS &gt; Organizations &gt; Organization Root &gt; Active &gt; Age
  - AWS &gt; Organizations &gt; Organization Root &gt; Active &gt; Last Modified
  - AWS &gt; Organizations &gt; Organization Root &gt; Approved
  - AWS &gt; Organizations &gt; Organization Root &gt; Approved &gt; Custom
  - AWS &gt; Organizations &gt; Organization Root &gt; Approved &gt; Usage
  - AWS &gt; Organizations &gt; Organizational Account &gt; Active
  - AWS &gt; Organizations &gt; Organizational Account &gt; Active &gt; Age
  - AWS &gt; Organizations &gt; Organizational Account &gt; Active &gt; Last Modified
  - AWS &gt; Organizations &gt; Organizational Account &gt; Approved
  - AWS &gt; Organizations &gt; Organizational Account &gt; Approved &gt; Custom
  - AWS &gt; Organizations &gt; Organizational Account &gt; Approved &gt; Usage

- Action Types:
  - AWS &gt; Organizations &gt; Organization Root &gt; Skip alarm for Active control
  - AWS &gt; Organizations &gt; Organization Root &gt; Skip alarm for Active control [90 days]
  - AWS &gt; Organizations &gt; Organization Root &gt; Skip alarm for Approved control
  - AWS &gt; Organizations &gt; Organization Root &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; Organizations &gt; Organizational Account &gt; Skip alarm for Active control
  - AWS &gt; Organizations &gt; Organizational Account &gt; Skip alarm for Active control [90 days]
  - AWS &gt; Organizations &gt; Organizational Account &gt; Skip alarm for Approved control
  - AWS &gt; Organizations &gt; Organizational Account &gt; Skip alarm for Approved control [90 days]</description>
            <pubDate>Tue, 26 Sep 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-msk-v5-4-0</guid>
            <title>aws-msk v5.4.0 - Added new permissions for Cluster V2, Scram Secrets and Kafka VPC Connections; and more</title>
            <link>https://turbot.com/guardrails/changelog/aws-msk-v5-4-0</link>
            <description>_What&apos;s new?_

- `AWS/MSK/Admin`, `AWS/MSK/Metadata` and `AWS/MSK/Operator` now also include permissions for Cluster V2, Scram Secrets and Kafka VPC Connections.
- We&apos;ve updated the runtime of the lambda functions to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Resource&apos;s metadata will now also include `createdBy` details in Turbot CMDB.
- Rebranded to a Turbot Guardrails Mod. To maintain compatibility, none of the existing resource types, control types or policy types have changed, your existing configurations and settings will continue to work as before.

- Policy Types:
  - AWS &gt; MSK &gt; Cluster &gt; Approved &gt; Custom
  - AWS &gt; MSK &gt; Cluster &gt; Approved &gt; Instance Types

- Action Types:
  - AWS &gt; MSK &gt; Cluster &gt; Delete from AWS
  - AWS &gt; MSK &gt; Cluster &gt; Set Tags
  - AWS &gt; MSK &gt; Cluster &gt; Skip alarm for Active control
  - AWS &gt; MSK &gt; Cluster &gt; Skip alarm for Active control [90 days]
  - AWS &gt; MSK &gt; Cluster &gt; Skip alarm for Approved control
  - AWS &gt; MSK &gt; Cluster &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; MSK &gt; Cluster &gt; Skip alarm for Tags control
  - AWS &gt; MSK &gt; Cluster &gt; Skip alarm for Tags control [90 days]

_Bug fixes_

- Guardrails would sometimes fail to upsert clusters correctly in CMDB. This is now fixed.</description>
            <pubDate>Tue, 26 Sep 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-elasticache-v5-8-0</guid>
            <title>aws-elasticache v5.8.0 - You can now configure Backups for your Elasticache Replication Groups</title>
            <link>https://turbot.com/guardrails/changelog/aws-elasticache-v5-8-0</link>
            <description>_What&apos;s new?_

- Control Types:
  - AWS &gt; ElastiCache &gt; Replication Group &gt; Backup

- Policy Types:
  - AWS &gt; ElastiCache &gt; Replication Group &gt; Backup
  - AWS &gt; ElastiCache &gt; Replication Group &gt; Backup &gt; Retention Period
  - AWS &gt; ElastiCache &gt; Replication Group &gt; Backup &gt; Window

- Action Types:
  - AWS &gt; ElastiCache &gt; Cache Cluster &gt; Skip alarm for approved control
  - AWS &gt; ElastiCache &gt; Cache Cluster &gt; Skip alarm for approved control [90 days]
  - AWS &gt; ElastiCache &gt; Cache Parameter Group &gt; Skip alarm for approved control
  - AWS &gt; ElastiCache &gt; Cache Parameter Group &gt; Skip alarm for approved control [90 days]
  - AWS &gt; ElastiCache &gt; Replication Group &gt; Skip alarm for approved control
  - AWS &gt; ElastiCache &gt; Replication Group &gt; Skip alarm for approved control [90 days]
  - AWS &gt; ElastiCache &gt; Replication Group &gt; Update Backup
  - AWS &gt; ElastiCache &gt; Snapshot &gt; Skip alarm for approved control
  - AWS &gt; ElastiCache &gt; Snapshot &gt; Skip alarm for approved control [90 days]</description>
            <pubDate>Tue, 26 Sep 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-v5-28-0</guid>
            <title>aws v5.28.0 - Added support for Global Event Handlers</title>
            <link>https://turbot.com/guardrails/changelog/aws-v5-28-0</link>
            <description>_What&apos;s new?_

- Added support for Global Event Handlers. This release contains new Guardrails policies and controls to support deployment of Global Event Handlers for AWS.

- Control Types:
  - AWS &gt; Turbot &gt; Event Handlers [Global]

- Policy Types:
  - AWS &gt; Turbot &gt; Event Handlers [Global]
  - AWS &gt; Turbot &gt; Event Handlers [Global] &gt; Events
  - AWS &gt; Turbot &gt; Event Handlers [Global] &gt; Events &gt; Rules
  - AWS &gt; Turbot &gt; Event Handlers [Global] &gt; Events &gt; Rules &gt; Name Prefix
  - AWS &gt; Turbot &gt; Event Handlers [Global] &gt; Events &gt; Rules &gt; Tags
  - AWS &gt; Turbot &gt; Event Handlers [Global] &gt; Events &gt; Target
  - AWS &gt; Turbot &gt; Event Handlers [Global] &gt; Events &gt; Target &gt; IAM Role ARN
  - AWS &gt; Turbot &gt; Event Handlers [Global] &gt; Primary Region
  - AWS &gt; Turbot &gt; Event Handlers [Global] &gt; SNS
  - AWS &gt; Turbot &gt; Event Handlers [Global] &gt; SNS &gt; Topic
  - AWS &gt; Turbot &gt; Event Handlers [Global] &gt; SNS &gt; Topic &gt; Customer Managed Key
  - AWS &gt; Turbot &gt; Event Handlers [Global] &gt; SNS &gt; Topic &gt; Name Prefix
  - AWS &gt; Turbot &gt; Event Handlers [Global] &gt; SNS &gt; Topic &gt; Tags
  - AWS &gt; Turbot &gt; Event Handlers [Global] &gt; Source
  - AWS &gt; Turbot &gt; Event Handlers [Global] &gt; Terraform Version
  - AWS &gt; Turbot &gt; Service Roles &gt; Event Handlers [Global]
  - AWS &gt; Turbot &gt; Service Roles &gt; Event Handlers [Global] &gt; Name</description>
            <pubDate>Fri, 22 Sep 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-rds-v5-25-0</guid>
            <title>aws-rds v5.25.0 - New Performance Insights permissions</title>
            <link>https://turbot.com/guardrails/changelog/aws-rds-v5-25-0</link>
            <description>_What&apos;s new?_

- `AWS/RDS/Admin`, `AWS/RDS/Metadata` and `AWS/RDS/Operator` now include permissions for Performance Insights.
- Rebranded to a Turbot Guardrails Mod. To maintain compatibility, none of the existing resource types, control types or policy types have changed, your existing configurations and settings will continue to work as before.</description>
            <pubDate>Thu, 21 Sep 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-v5-22-0</guid>
            <title>gcp v5.22.0 - Added support for newly supported multi-regions in GCP</title>
            <link>https://turbot.com/guardrails/changelog/gcp-v5-22-0</link>
            <description>_What&apos;s new?_

- Added support for new multi-regions `NAM8`, `NAM9`, `NAM10`, `NAM11`, `NAM12`, `NAM13`, `NAM14`, `NAM15`, `NAM-EUR-ASIA1`, `NAM-EUR-ASIA3`, `IN`, `EUR5`, `EUR6`, `EUROPE` and `EMEA` in the `GCP &gt; Project &gt; Regions` policy.

- Policy Types Removed:
  - GCP &gt; Project &gt; Multi-Regions [Deprecated]</description>
            <pubDate>Wed, 20 Sep 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-vpc-security-v5-9-3</guid>
            <title>aws-vpc-security v5.9.3 - Fixed issues for Security Group CMDB control on TE v 5.42.1 or lower</title>
            <link>https://turbot.com/guardrails/changelog/aws-vpc-security-v5-9-3</link>
            <description>_Bug fixes_

- The `AWS &gt; VPC &gt; Security Group &gt; CMDB` control would sometimes go into an error state if the TE version installed on the workspace was 5.42.1 or lower. This is fixed and the control will now work as expected.</description>
            <pubDate>Mon, 18 Sep 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/ted-v1-36-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.36.0 - Added support for m7g instance types for Elasticache; and more</title>
            <link>https://turbot.com/guardrails/changelog/ted-v1-36-0</link>
            <description>_What&apos;s new?_

- Added: m7g instance types for Elasticache.

_Bug fixes_

- User group name for hive names with _ in it.
- Hive manager code to add access grant to public schema for postgres 15.

_Requirements_

- TEF: 1.52.0</description>
            <pubDate>Fri, 15 Sep 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-v5-21-0</guid>
            <title>gcp v5.21.0 - Added support for new `europe-west10` region</title>
            <link>https://turbot.com/guardrails/changelog/gcp-v5-21-0</link>
            <description>_What&apos;s new?_

- Added support for new `europe-west10` region in the `GCP &gt; Project &gt; Regions` policy.
- Rebranded to a Turbot Guardrails Mod. To maintain compatibility, none of the existing resource types, control types or policy types have changed, your existing configurations and settings will continue to work as before.</description>
            <pubDate>Fri, 15 Sep 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-computeengine-v5-16-0</guid>
            <title>gcp-computeengine v5.16.0 - Added support for newly supported regions in GCP Compute Engine Service, and fixed a bug to upsert data disks correctly in Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/gcp-computeengine-v5-16-0</link>
            <description>_What&apos;s new?_

- Added support for new `asia-northeast3`, `asia-south2`, `asia-southeast2`, `australia-southeast2`, `europe-central2`, `europe-southwest1`, `europe-west10`, `europe-west12`, `europe-west8`, `europe-west9`, `me-central1`, `me-west1`, `northamerica-northeast2`, `southamerica-west1`, `us-east5`, `us-south1`, `us-west3` and `us-west4` regions in the `GCP &gt; Compute Engine &gt; Regions` policy.
- Rebranded to a Turbot Guardrails Mod. To maintain compatibility, none of the existing resource types, control types or policy types have changed, your existing configurations and settings will continue to work as before.

_Bug fixes_

- The real-time Event Handlers would sometimes fail to upsert data disks attached to instances in Guardrails CMDB. This is now fixed.</description>
            <pubDate>Fri, 15 Sep 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-vpc-security-v5-9-2</guid>
            <title>aws-vpc-security v5.9.2 - Fixed issues for Security Groups and Security Group Rules created/claimed via Guardrails stacks</title>
            <link>https://turbot.com/guardrails/changelog/aws-vpc-security-v5-9-2</link>
            <description>_Bug fixes_

- Guardrails stack controls would fail to claim any existing Security Group if the Security Group was available in Guardrails CMDB and the stack&apos;s Source policy included the Terraform plan for the Security Group. This is fixed and stack control will now be able to claim existing Security Groups correctly. Please note that this fix will only work for workspaces on TE v5.42.2 or higher.
- Guardrails stack controls would sometimes fail to update Security Groups and Security Group Rules if the Terraform plan in the stack&apos;s source policy included changes to attributes which force replaced the resource. This is fixed and the stack controls will now update such resources correctly, as expected. Please note that this fix will only work for workspaces on TE v5.42.2 or higher.</description>
            <pubDate>Fri, 15 Sep 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-ec2-v5-35-0</guid>
            <title>aws-ec2 v5.35.0 - Fixed Schedule control behavior to not start/stop an instance if it were stopped/started manually outside of the control</title>
            <link>https://turbot.com/guardrails/changelog/aws-ec2-v5-35-0</link>
            <description>_What&apos;s new?_

- Policy Types:
  - AWS &gt; EC2 &gt; Instance &gt; Schedule Tag &gt; Name

_Bug fixes_

- After starting/stopping an instance successfully, the `AWS &gt; EC2 &gt; Instance &gt; Schedule` control would try and perform the same start/stop action again if the state of the instance was changed outside of the control within 1 hour of the successful start/stop run. This is fixed and the control will now not trigger a start/stop action again for a minimum of 1 hour of the previous successful run.</description>
            <pubDate>Fri, 15 Sep 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-52-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.52.0 - Hive manager now includes access grant for public schema for Postgres 15</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-52-0</link>
            <description>_What&apos;s new?_

- Updated: Hive manager code to include access grant for public schema for postgres 15.</description>
            <pubDate>Thu, 14 Sep 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-42-2</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.42.2 - Bugs Squashed - Create workspaces on fresh PostgreSQL 15 installations, removed support for vm2 node package; and more</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-42-2</link>
            <description>_What&apos;s new?_

- Server:
  - Updated: Now supports creating multiple AKAs starting with arn, azure, and gcp via APIs.
  - Updated: Add mod version check for workspace upgrade.

_Bug fixes_

- Server:
  - Fixed: Ensure successful workspace creation on fresh PostgreSQL 15 installations.
  - Fixed: The stack should claim the Security Group (SG) or Security Group Rule (SGR) if the resource already exists.
  - Removed: vm2 node package.</description>
            <pubDate>Thu, 14 Sep 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-network-v5-15-0</guid>
            <title>azure-network v5.15.0 - Added new Resource Types for Express Route Circuits</title>
            <link>https://turbot.com/guardrails/changelog/azure-network-v5-15-0</link>
            <description>_What&apos;s new?_

- Resource Types:
  - Azure &gt; Network &gt; Express Route Circuits

- Control Types:
  - Azure &gt; Network &gt; Express Route Circuits &gt; Active
  - Azure &gt; Network &gt; Express Route Circuits &gt; Approved
  - Azure &gt; Network &gt; Express Route Circuits &gt; CMDB
  - Azure &gt; Network &gt; Express Route Circuits &gt; Discovery
  - Azure &gt; Network &gt; Express Route Circuits &gt; Tags

- Policy Types:
  - Azure &gt; Network &gt; Express Route Circuits &gt; Active
  - Azure &gt; Network &gt; Express Route Circuits &gt; Active &gt; Age
  - Azure &gt; Network &gt; Express Route Circuits &gt; Active &gt; Last Modified
  - Azure &gt; Network &gt; Express Route Circuits &gt; Approved
  - Azure &gt; Network &gt; Express Route Circuits &gt; Approved &gt; Custom
  - Azure &gt; Network &gt; Express Route Circuits &gt; Approved &gt; Regions
  - Azure &gt; Network &gt; Express Route Circuits &gt; Approved &gt; Usage
  - Azure &gt; Network &gt; Express Route Circuits &gt; CMDB
  - Azure &gt; Network &gt; Express Route Circuits &gt; Regions
  - Azure &gt; Network &gt; Express Route Circuits &gt; Tags
  - Azure &gt; Network &gt; Express Route Circuits &gt; Tags &gt; Template

- Action Types:
  - Azure &gt; Network &gt; Express Route Circuits &gt; Delete
  - Azure &gt; Network &gt; Express Route Circuits &gt; Router
  - Azure &gt; Network &gt; Express Route Circuits &gt; Set Tags</description>
            <pubDate>Thu, 14 Sep 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-iam-v5-32-0</guid>
            <title>aws-iam v5.32.0 - Added support to delete Login Profiles for IAM Users</title>
            <link>https://turbot.com/guardrails/changelog/aws-iam-v5-32-0</link>
            <description>_What&apos;s new?_

Users can now delete Login Profiles for IAM Users.

- Control Types:
  - AWS &gt; IAM &gt; User &gt; Login Profile

- Policy Types:
  - AWS &gt; IAM &gt; User &gt; Login Profile

- Action Types:
  - AWS &gt; IAM &gt; User &gt; Delete Login Profile</description>
            <pubDate>Mon, 11 Sep 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/azure-network-v5-14-0</guid>
            <title>azure-network v5.14.0 - Added new Resource Types for Private DNS Zones and Private Endpoints</title>
            <link>https://turbot.com/guardrails/changelog/azure-network-v5-14-0</link>
            <description>_What&apos;s new?_

- Resource Types:
  - Azure &gt; Network &gt; Private DNS Zones
  - Azure &gt; Network &gt; Private Endpoints

- Control Types:
  - Azure &gt; Network &gt; Private DNS Zones &gt; Active
  - Azure &gt; Network &gt; Private DNS Zones &gt; Approved
  - Azure &gt; Network &gt; Private DNS Zones &gt; CMDB
  - Azure &gt; Network &gt; Private DNS Zones &gt; Discovery
  - Azure &gt; Network &gt; Private DNS Zones &gt; Tags
  - Azure &gt; Network &gt; Private Endpoints &gt; Active
  - Azure &gt; Network &gt; Private Endpoints &gt; Approved
  - Azure &gt; Network &gt; Private Endpoints &gt; CMDB
  - Azure &gt; Network &gt; Private Endpoints &gt; Discovery
  - Azure &gt; Network &gt; Private Endpoints &gt; Tags

- Policy Types:
  - Azure &gt; Network &gt; Private DNS Zones &gt; Active
  - Azure &gt; Network &gt; Private DNS Zones &gt; Active &gt; Age
  - Azure &gt; Network &gt; Private DNS Zones &gt; Active &gt; Last Modified
  - Azure &gt; Network &gt; Private DNS Zones &gt; Approved
  - Azure &gt; Network &gt; Private DNS Zones &gt; Approved &gt; Custom
  - Azure &gt; Network &gt; Private DNS Zones &gt; Approved &gt; Usage
  - Azure &gt; Network &gt; Private DNS Zones &gt; CMDB
  - Azure &gt; Network &gt; Private DNS Zones &gt; Tags
  - Azure &gt; Network &gt; Private DNS Zones &gt; Tags &gt; Template
  - Azure &gt; Network &gt; Private Endpoints &gt; Active
  - Azure &gt; Network &gt; Private Endpoints &gt; Active &gt; Age
  - Azure &gt; Network &gt; Private Endpoints &gt; Active &gt; Last Modified
  - Azure &gt; Network &gt; Private Endpoints &gt; Approved
  - Azure &gt; Network &gt; Private Endpoints &gt; Approved &gt; Custom
  - Azure &gt; Network &gt; Private Endpoints &gt; Approved &gt; Regions
  - Azure &gt; Network &gt; Private Endpoints &gt; Approved &gt; Usage
  - Azure &gt; Network &gt; Private Endpoints &gt; CMDB
  - Azure &gt; Network &gt; Private Endpoints &gt; Regions
  - Azure &gt; Network &gt; Private Endpoints &gt; Tags
  - Azure &gt; Network &gt; Private Endpoints &gt; Tags &gt; Template

- Action Types:
  - Azure &gt; Network &gt; Private DNS Zones &gt; Delete
  - Azure &gt; Network &gt; Private DNS Zones &gt; Router
  - Azure &gt; Network &gt; Private DNS Zones &gt; Set Tags
  - Azure &gt; Network &gt; Private Endpoints &gt; Delete
  - Azure &gt; Network &gt; Private Endpoints &gt; Router
  - Azure &gt; Network &gt; Private Endpoints &gt; Set Tags</description>
            <pubDate>Wed, 06 Sep 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-v5-27-2</guid>
            <title>aws v5.27.2 - Fine-tuned the internals and smoothed out some wrinkles</title>
            <link>https://turbot.com/guardrails/changelog/aws-v5-27-2</link>
            <description>_Bug fixes_

- A few policy values would sometimes fail to evaluate correctly if the mod was installed on TE v5.42.1. We&apos;ve fixed this issue and such policy values will now be evaluated correctly.</description>
            <pubDate>Wed, 06 Sep 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-v5-27-1</guid>
            <title>aws v5.27.1 - Added support for AWS S3 Multi-Region Access Poin real-time events</title>
            <link>https://turbot.com/guardrails/changelog/aws-v5-27-1</link>
            <description>_Bug fixes_

- The `AWS &gt; Turbot &gt; Event Handlers` now support real-time events for AWS S3 Multi-Region Access Point.</description>
            <pubDate>Wed, 06 Sep 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-multiregionaccesspoint-v5-0-0</guid>
            <title>aws-multiregionaccesspoint v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/aws-multiregionaccesspoint-v5-0-0</link>
            <description>_What&apos;s new?_

- Resource Types:
  - AWS &gt; S3 &gt; Multi-Region Access Point

- Control Types:
  - AWS &gt; S3 &gt; Multi-Region Access Point &gt; Active
  - AWS &gt; S3 &gt; Multi-Region Access Point &gt; Approved
  - AWS &gt; S3 &gt; Multi-Region Access Point &gt; CMDB
  - AWS &gt; S3 &gt; Multi-Region Access Point &gt; Discovery
  - AWS &gt; S3 &gt; Multi-Region Access Point &gt; Usage

- Policy Types:
  - AWS &gt; S3 &gt; Multi-Region Access Point &gt; Active
  - AWS &gt; S3 &gt; Multi-Region Access Point &gt; Active &gt; Age
  - AWS &gt; S3 &gt; Multi-Region Access Point &gt; Active &gt; Budget
  - AWS &gt; S3 &gt; Multi-Region Access Point &gt; Active &gt; Last Modified
  - AWS &gt; S3 &gt; Multi-Region Access Point &gt; Approved
  - AWS &gt; S3 &gt; Multi-Region Access Point &gt; Approved &gt; Budget
  - AWS &gt; S3 &gt; Multi-Region Access Point &gt; Approved &gt; Custom
  - AWS &gt; S3 &gt; Multi-Region Access Point &gt; Approved &gt; Usage
  - AWS &gt; S3 &gt; Multi-Region Access Point &gt; CMDB
  - AWS &gt; S3 &gt; Multi-Region Access Point &gt; Usage
  - AWS &gt; S3 &gt; Multi-Region Access Point &gt; Usage &gt; Limit
  - AWS &gt; Turbot &gt; Event Handlers &gt; Events &gt; Rules &gt; Custom Event Patterns &gt; @turbot/aws-s3multiregionaccesspoint

- Action Types:
  - AWS &gt; S3 &gt; Multi-Region Access Point &gt; Delete
  - AWS &gt; S3 &gt; Multi-Region Access Point &gt; Delete from AWS
  - AWS &gt; S3 &gt; Multi-Region Access Point &gt; Router
  - AWS &gt; S3 &gt; Multi-Region Access Point &gt; Skip alarm for Active control
  - AWS &gt; S3 &gt; Multi-Region Access Point &gt; Skip alarm for Active control [90 days]
  - AWS &gt; S3 &gt; Multi-Region Access Point &gt; Skip alarm for Approved control
  - AWS &gt; S3 &gt; Multi-Region Access Point &gt; Skip alarm for Approved control [90 days]</description>
            <pubDate>Wed, 06 Sep 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-s3-v5-22-0</guid>
            <title>aws-s3 v5.22.0 - New Multi Region Access Point Routes permissions</title>
            <link>https://turbot.com/guardrails/changelog/aws-s3-v5-22-0</link>
            <description>_What&apos;s new?_

- `AWS/S3/Admin` and `AWS/S3/Metadata` now include permissions for Multi-Region Access Point Routes.</description>
            <pubDate>Wed, 06 Sep 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-efs-v5-7-0</guid>
            <title>aws-efs v5.7.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-efs-v5-7-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime for lambda functions in the aws-efs mod to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.
- Rebranded to a Turbot Guardrails Mod. To maintain compatibility, none of the existing resource types, control types or policy types have changed, your existing configurations and settings will continue to work as before.</description>
            <pubDate>Fri, 01 Sep 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-config-v5-8-0</guid>
            <title>aws-config v5.8.0 - New Approved &gt; Custom policies and Quick Actions for Cofigurations Recorder, Delivery Channel and Rule</title>
            <link>https://turbot.com/guardrails/changelog/aws-config-v5-8-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime for lambda functions in the aws-config mod to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.

- Policy Types:
  - AWS &gt; Config &gt; Configuration Recorder &gt; Approved &gt; Custom
  - AWS &gt; Config &gt; Delivery Channel &gt; Approved &gt; Custom
  - AWS &gt; Config &gt; Rule &gt; Approved &gt; Custom

- Action Types
  - AWS &gt; Config &gt; Configuration Recorder &gt; Skip alarm for Active control
  - AWS &gt; Config &gt; Configuration Recorder &gt; Skip alarm for Active control [90 days]
  - AWS &gt; Config &gt; Configuration Recorder &gt; Skip alarm for Approved control
  - AWS &gt; Config &gt; Configuration Recorder &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; Config &gt; Delivery Channel &gt; Skip alarm for Active control
  - AWS &gt; Config &gt; Delivery Channel &gt; Skip alarm for Active control [90 days]
  - AWS &gt; Config &gt; Delivery Channel &gt; Skip alarm for Approved control
  - AWS &gt; Config &gt; Delivery Channel &gt; Skip alarm for Approved control [90 days]
  - AWS &gt; Config &gt; Rule &gt; Skip alarm for Active control
  - AWS &gt; Config &gt; Rule &gt; Skip alarm for Active control [90 days]
  - AWS &gt; Config &gt; Rule &gt; Skip alarm for Approved control
  - AWS &gt; Config &gt; Rule &gt; Skip alarm for Approved control [90 days]</description>
            <pubDate>Fri, 01 Sep 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-cloudtrail-v5-10-0</guid>
            <title>aws-cloudtrail v5.10.0 - Lambda runtimes now powered by Node 18</title>
            <link>https://turbot.com/guardrails/changelog/aws-cloudtrail-v5-10-0</link>
            <description>_What&apos;s new?_

- We&apos;ve updated the runtime for lambda functions in the [aws-cloudtrail](https://turbot.com/guardrails/docs/mods/aws/aws-cloudtrail#5100-2023-08-31) mod to Node 18. You wouldn&apos;t notice any difference and things will continue to work smoothly and consistently as before.</description>
            <pubDate>Thu, 31 Aug 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/aws-elasticinference-v5-0-0</guid>
            <title>aws-elasticinference v5.0.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/aws-elasticinference-v5-0-0</link>
            <description>_What&apos;s new?_

- Resource Types:
  - AWS &gt; Elastic Inference

- Policy Types:
  - AWS &gt; Elastic Inference &gt; API Enabled
  - AWS &gt; Elastic Inference &gt; Approved Regions [Default]
  - AWS &gt; Elastic Inference &gt; Enabled
  - AWS &gt; Elastic Inference &gt; Permissions
  - AWS &gt; Elastic Inference &gt; Permissions &gt; Levels
  - AWS &gt; Elastic Inference &gt; Permissions &gt; Levels &gt; Modifiers
  - AWS &gt; Elastic Inference &gt; Permissions &gt; Lockdown
  - AWS &gt; Elastic Inference &gt; Permissions &gt; Lockdown &gt; API Boundary
  - AWS &gt; Elastic Inference &gt; Regions
  - AWS &gt; Elastic Inference &gt; Tags Template [Default]
  - AWS &gt; Turbot &gt; Event Handlers &gt; Events &gt; Rules &gt; Event Sources &gt; @turbot/aws-elasticinference
  - AWS &gt; Turbot &gt; Permissions &gt; Compiled &gt; API Boundary &gt; @turbot/aws-elasticinference
  - AWS &gt; Turbot &gt; Permissions &gt; Compiled &gt; Levels &gt; @turbot/aws-elasticinference
  - AWS &gt; Turbot &gt; Permissions &gt; Compiled &gt; Service Permissions &gt; @turbot/aws-elasticinference</description>
            <pubDate>Fri, 25 Aug 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-42-1</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.42.1 - Replaced vm2 with eval for inline and trustedInline execution of policies, controls, and actions; and more</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-42-1</link>
            <description>_What&apos;s new?_

- Server:
  - Cloudwatch dashboard query for View AWS External Messages by AWS Account ID and Events to exclude restriction on AWS.
  - Allow sending notifications for same state change.
  - Replaced vm2 with eval for inline and trustedInline execution of policies, controls, and actions.</description>
            <pubDate>Thu, 24 Aug 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/gcp-oauth-v5-1-0</guid>
            <title>gcp-oauth v5.1.0 - New oauthconfig:* permissions</title>
            <link>https://turbot.com/guardrails/changelog/gcp-oauth-v5-1-0</link>
            <description>_What&apos;s new?_

- `GCP/OAuth/Admin` and `GCP/OAuth/Metadata` now also include `oauthconfig:*` permissions. Click [here](https://turbot.com/guardrails/docs/mods/gcp/gcp-oauth#510-2023-08-24) for more details.</description>
            <pubDate>Thu, 24 Aug 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-51-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.51.0 - Restrict untrusted code upload to Guardrails</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-51-0</link>
            <description>_What&apos;s new?_

- Added: Parameter for restricting untrusted code upload to Turbot Guardrails.
- Removed: Alb Waf support.</description>
            <pubDate>Mon, 14 Aug 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-42-0</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.42.0 - Revamping Workflow - Introducing Workers, SQS and SNS for Stack Efficiency</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-42-0</link>
            <description>_What&apos;s new?_

- Server:
  - Added: worker, sqs queue, sns topic for factory.
  - Updated: Allow upload of mod based on the value of TURBOT_CUSTOM_MOD_UPLOAD.
  - Added: Environment variable for custom mod upload.
  - Removed: Support for ALB WAF.

_Bug fixes_

- Server:
  - Stack will not fail to delete and recreate resources.

_Requirements_

- TEF: 1.51.0</description>
            <pubDate>Mon, 14 Aug 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/ted-v1-35-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.35.0 - Added support for multiple Postgres versions</title>
            <link>https://turbot.com/guardrails/changelog/ted-v1-35-0</link>
            <description>_What&apos;s new?_

- Added: Postgres version 11.19, 11.20, 12.14, 12.15, 13.10, 13.11, 14.8, 15.2 and 15.3.</description>
            <pubDate>Thu, 10 Aug 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-41-1</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.41.1 - Bugs Squashed - Attach/Detach Actor Info &amp; Redis Dependent Notifications Fix; and more</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-41-1</link>
            <description>_What&apos;s new?_

- UI
  - Added: Inactive Users report.

_Bug fixes_

- Server:
  - The actor information for attach and detach smart folder.
  - Disable notification feature if Redis is not being used.</description>
            <pubDate>Wed, 02 Aug 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-50-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.50.0 - Added support for Factory worker</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-50-0</link>
            <description>_What&apos;s new?_

- Added: Support for Factory worker.
- Updated: Descriptions and names to Turbot Guardrails Enterprise Foundation from Turbot Enterprise Foundation.</description>
            <pubDate>Thu, 27 Jul 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-34-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.34.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-34-0</link>
            <description>_What&apos;s new?_

- Updated: descriptions and names from Turbot Enterprise Database to Turbot Guardrails Enterprise Database.</description>
            <pubDate>Thu, 27 Jul 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-41-0</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.41.0 - Notifying Made Easy - Control/Action Updates via Slack, Teams, and Email</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-41-0</link>
            <description>_What&apos;s new?_

- Server:
  - Added: Added support for control/action update notifications.
  - Added: Support for interface in control types.
  - Added: Turbot Installation Type environment variable.
  - Added: SES SendEmail permission to Worker Lambda Role.
  - Added: Add notification index to improve performance of notifications.
  - Updated: Improve policy value create/update with a more efficient database design.
  - Updated: Description of TE stack from Turbot Enterprise to Turbot Guardrails Enterprise.
  - Updated: @slack/web-api to 6.8.1. @wry/equality to 0.5.6. anymatch to 3.1.3. archiver to 5.3.1. body-parser to 1.20.2. chai to 4.3.7. chokidar to 3.5.3. classnames to 2.3.2. cli-progress to 3.12.0. copy-to-clipboard to 3.3.3. dataloader to 2.2.2. diff to 5.1.0. express to 4.18.2. generate-password to 1.7.0. graphql-2-json-schema to 0.10.0. http-status-codes to 2.2.0. lodash-match-pattern to 2.3.1. micromatch to 4.0.5. mockserver-client to 5.15.0. moment-timezone to 0.5.43. nconf to 0.12.0. nodemailer to 6.9.2. nunjucks to 3.2.4. passport to 0.6.0. pg to 8.10.0. performant-array-to-tree to 1.11.0. prismjs to 1.29.0. prompt to 1.3.0. prompts to 2.4.2. recursive-readdir to 2.2.3. redux to 4.2.1. resolve to 1.22.2. semver to 7.5.1. simple-git to 3.18.0. unzipper to 0.10.14. uri-js to 4.4.1. vm2 to 3.9.19 and other dev dependencies. Removed aws-appsync and aws-xray-sdk. ioredis to 5.3.1.

- UI
  - Updated: Updated new login logo and home page logo.
  - Updated: Turbot directory should be created in guardrails.turbot.com.
  - Updated: Turbot directory SSO login should be redirected to there respective guardrails domain.

_Note_

IAM change in this release:

- Updated worker lambda to include SES SendEmail permissions.</description>
            <pubDate>Thu, 27 Jul 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-29-0</guid>
            <title>Turbot Guardrails CLI v1.29.0</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-29-0</link>
            <description>_What&apos;s new?_

- Rebrand to Turbot Guardrails CLI. We recommend using the new guardrails registries `guardrails.turbot.com`, `guardrails.turbot-stg.com` or `guardrails.turbot-dev.com` to publish a guardrails mod. To maintain compatibility, none of the existing commands have changed, your existing configuration and commands will continue to work as before.</description>
            <pubDate>Thu, 27 Jul 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/turbot-v5-45-0</guid>
            <title>turbot v5.45.0 - Added Policy to set process retention in cache</title>
            <link>https://turbot.com/guardrails/changelog/turbot-v5-45-0</link>
            <description>_What&apos;s new?_

- Policy Types:
  - Turbot &gt; Workspace &gt; Retention &gt; Process Cache Retention.

- Resource Types:
  - `Smart Folders` are now called `Policy Packs`.

_Requirements_

- TE: 5.35.4</description>
            <pubDate>Sat, 22 Jul 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/terraform-provider-v1-10-0</guid>
            <title>Terraform Provider v1.10.0 is now available</title>
            <link>https://turbot.com/guardrails/changelog/terraform-provider-v1-10-0</link>
            <description>v1.10.0 of the [Terraform Provider for Guardrails](https://registry.terraform.io/providers/turbot/turbot/1.10.0) is now available.

_Documentation_

Rebrand to Turbot Guardrails provider. Resource and data source names in this provider have not changed to maintain compatibility. Existing templates will continue to work as-is without need to change anything.</description>
            <pubDate>Fri, 07 Jul 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-40-11</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.40.11 </title>
            <link>https://turbot.com/guardrails/changelog/te-v5-40-11</link>
            <description>_What&apos;s new?_
- Fixed: Resource details are now correctly included when doing a csv download of the `Resources Deleted by Turbot` report.

_Requires_
- [TEF v1.49.0](https://turbot.com/v5/docs/releases/tef#v1490-2023-03-30)

_Container Info_
- Ubuntu: [`22.04`, `jammy-20230425`](https://hub.docker.com/layers/library/ubuntu/22.04/images/sha256-ca5534a51dd04bbcebe9b23ba05f389466cf0c190f1f8f182d7eea92a9671d00)
- Alpine: [`3.17.3`](https://hub.docker.com/layers/library/alpine/3.17.3/images/sha256-b6ca290b6b4cdcca5b3db3ffa338ee0285c11744b4a6abaa9627746ee3291d8d)</description>
            <pubDate>Wed, 05 Jul 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/turbot-v5-44-1</guid>
            <title>turbot v5.44.1 - Improved pattern validation for Slack webhook URL in Rule-Based Routing policy for notifications</title>
            <link>https://turbot.com/guardrails/changelog/turbot-v5-44-1</link>
            <description>_Bug fixes_

- Policy Types:
  - Improved pattern validation for `slackWebhookUrl` in `Turbot &gt; Notifications &gt; Rule-Based Routing` policy.

_Requirements_

- TE: 5.35.4</description>
            <pubDate>Sat, 24 Jun 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-40-8</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.40.8 </title>
            <link>https://turbot.com/guardrails/changelog/te-v5-40-8</link>
            <description>_What&apos;s new?_
- Added: Tagging details now included in CSV download for GCP Compute Engine VM Instances, Azure Compute Virtual Machines, Azure Compute Disks and EBS Volumes report.
- Added: New filters for Turbot Files and Smart Folders in the resource browser.
- Updated: Editing a Turbot File via the UI no longer requires the resource AKA to be specified.
- Fixed: Resource deletion will no longer trigger an increase the count of active controls.

_Requires_
- TEF v1.49.0

_Container Info_
- Ubuntu: [`22.04`, `jammy-20230425`](https://hub.docker.com/layers/library/ubuntu/22.04/images/sha256-ca5534a51dd04bbcebe9b23ba05f389466cf0c190f1f8f182d7eea92a9671d00)
- Alpine: [`3.17.3`](https://hub.docker.com/layers/library/alpine/3.17.3/images/sha256-b6ca290b6b4cdcca5b3db3ffa338ee0285c11744b4a6abaa9627746ee3291d8d)</description>
            <pubDate>Fri, 23 Jun 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-40-10</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.40.10 </title>
            <link>https://turbot.com/guardrails/changelog/te-v5-40-10</link>
            <description>_What&apos;s new?_
- Added: Quick actions are now available for users that only have permission at the account level.
- Fixed: The resource import page will now function correctly if the AWS mod is not installed.
- Fixed: Resource deletion will no longer trigger an increase the count of active controls.

_Requires_
- TEF v1.49.0

_Container Info_
- Ubuntu: [`22.04`, `jammy-20230425`](https://hub.docker.com/layers/library/ubuntu/22.04/images/sha256-ca5534a51dd04bbcebe9b23ba05f389466cf0c190f1f8f182d7eea92a9671d00)
- Alpine: [`3.17.3`](https://hub.docker.com/layers/library/alpine/3.17.3/images/sha256-b6ca290b6b4cdcca5b3db3ffa338ee0285c11744b4a6abaa9627746ee3291d8d)</description>
            <pubDate>Fri, 23 Jun 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/ted-v1-33-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.33.0</title>
            <link>https://turbot.com/guardrails/changelog/ted-v1-33-0</link>
            <description>_What&apos;s new?_

- Added: Postgres version 14.6 and 14.7.</description>
            <pubDate>Fri, 16 Jun 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/turbot-v5-44-0</guid>
            <title>turbot v5.44.0 - Added Policy to store and manage outbound CIDR ranges for Lambda functions, ensuring secure connectivity with external applications</title>
            <link>https://turbot.com/guardrails/changelog/turbot-v5-44-0</link>
            <description>_What&apos;s new?_

- Policy Types:
  - Turbot &gt; Workspace &gt; Outbound CIDR Ranges

_Requirements_

- TE: 5.35.4</description>
            <pubDate>Sat, 10 Jun 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-40-7</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.40.7 </title>
            <link>https://turbot.com/guardrails/changelog/te-v5-40-7</link>
            <description>_What&apos;s new?_

- Added: Ability to specify AKA when creating Turbot File.
- Updated: Turbot explorer search will show results for Smart Folders and Turbot
  Files.
- Fixed: Terraform stack control should not end in error if the data size for
  command is too large.
- Fixed: Turbot actions will now be visible for users with grants at the cloud
  account level.

_Enterprise_

- Updated: Added debug statements for createGrant mutations.

_Requires_

- TEF v1.49.0

_Container Info_

- Ubuntu:
  [`22.04`, `jammy-20230425`](https://hub.docker.com/layers/library/ubuntu/22.04/images/sha256-ca5534a51dd04bbcebe9b23ba05f389466cf0c190f1f8f182d7eea92a9671d00)
- Alpine:
  [`3.17.3`](https://hub.docker.com/layers/library/alpine/3.17.3/images/sha256-b6ca290b6b4cdcca5b3db3ffa338ee0285c11744b4a6abaa9627746ee3291d8d)</description>
            <pubDate>Mon, 15 May 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-40-6</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.40.6 </title>
            <link>https://turbot.com/guardrails/changelog/te-v5-40-6</link>
            <description>_Enterprise_

- Changed: Removed long debug statements from stack controls to improve
  performance of large stacks.
- Added: Additional logging information emmited while preparing stack container.

_Requires_

- TEF v1.49.0

_Container Info_

- Ubuntu:
  [`22.04`, `jammy-20230425`](https://hub.docker.com/layers/library/ubuntu/22.04/images/sha256-ca5534a51dd04bbcebe9b23ba05f389466cf0c190f1f8f182d7eea92a9671d00?context=explore)
- Alpine:
  [`3.17.3`](https://hub.docker.com/layers/library/alpine/3.17.3/images/sha256-b6ca290b6b4cdcca5b3db3ffa338ee0285c11744b4a6abaa9627746ee3291d8d?context=explore)</description>
            <pubDate>Mon, 15 May 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-40-5</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.40.5 </title>
            <link>https://turbot.com/guardrails/changelog/te-v5-40-5</link>
            <description>_What&apos;s new?_

- Fixed: Smart retention controls are now a bit smarter.

_Enterprise_

- Updated: Resource policy of Events SQS queues now require encryption in
  transit.
- Updated: Resource policy of Events SNS topics now require encryption in
  transit.

_Requires_

- TEF v1.49.0

_Container Info_

- Ubuntu `22.04`, `jammy-20230425`
- Alpine: `3.18.0`
-</description>
            <pubDate>Tue, 09 May 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-40-4</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.40.4 </title>
            <link>https://turbot.com/guardrails/changelog/te-v5-40-4</link>
            <description>_What&apos;s new?_

- Added: debug statement for Smart Retention control.

_Requires_

- TEF v1.49.0</description>
            <pubDate>Thu, 04 May 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-40-3</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.40.3 </title>
            <link>https://turbot.com/guardrails/changelog/te-v5-40-3</link>
            <description># Server

_What&apos;s new?_

- Added support for version `v5.10.0` of the Turbot IAM mod.
- Fixed: Adding grants to group profile now works as expected.

_Requires_

- TEF v1.49.0</description>
            <pubDate>Thu, 13 Apr 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-49-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.49.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-49-0</link>
            <description>_What&apos;s new?_
- Added: New parameter that allows selection of the TLS policy for application load balancers.</description>
            <pubDate>Thu, 30 Mar 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-32-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.32.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-32-0</link>
            <description>_What&apos;s new?_

- Added: Parameter to manage KMS Key for RDS Performance Insights.</description>
            <pubDate>Thu, 30 Mar 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-40-2</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.40.2 </title>
            <link>https://turbot.com/guardrails/changelog/te-v5-40-2</link>
            <description>_What&apos;s new?_

- Updated: Accounts Summary Report now includes resource AKA(s) in the CSV
  output.
- Updated: The Turbot auth token cookie `SameSite` configuration to `strict`.
- Updated: The policy setting page to now render HTML content as string.

_Enterprise_

- Added: Parameter for TLS Policy for ALB HTTPS Listener.
- Added: Rate limits to the login directories APIs.

_Requires_

- TEF v1.49.0</description>
            <pubDate>Thu, 30 Mar 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-31-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.31.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-31-0</link>
            <description>_What&apos;s new?_

- Updated: Moved management of the Elasticache user group to CloudFormation
  instead of the Hive Manager lambda. It is no longer necessary to update the
  Redis access control groups after making changes to the Redis cluster.</description>
            <pubDate>Wed, 22 Mar 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-40-1</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.40.1 </title>
            <link>https://turbot.com/guardrails/changelog/te-v5-40-1</link>
            <description>_What&apos;s new?_

- Added: AWS Lambda Functions report.
- Updated: Turbot will now use AWS Terraform provider version `3.75.0` when
  `Turbot &gt; Stack Terraform Version [Default]` is set to `0.15.*`

_Bug fixes_

- Fixed: Timestamp display in the console now updates correctly for recently
  deleted mods.
- Fixed: When an `Action` fails due to cloud provider throttling, Turbot will
  now reschedule the control that triggered the action, those actions should now
  be more consistently applied under heavy loads.

_Note_ AWS IAM permissions change in this release:

- Updated: Worker Lambda to include Elasticache permissions to support the
  `Turbot &gt; Cache &gt; Health Check` control.
- Updated: Hive Manager no longer manages the authentication configuration for
  ElastiCache. This responsibility has shifted to Turbot Guardrails Enterprise Database.
-</description>
            <pubDate>Wed, 22 Mar 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-48-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.48.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-48-0</link>
            <description>_What&apos;s new?_
- Added: Parameter to modify Lambda trigger concurrency.</description>
            <pubDate>Tue, 21 Mar 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/turbot-v5-43-0</guid>
            <title>turbot v5.43.0 - Unused `Turbot &gt; Type Installed &gt; Background Tasks` is now removed</title>
            <link>https://turbot.com/guardrails/changelog/turbot-v5-43-0</link>
            <description>_What&apos;s new?_

- Control Types:
  - Unused `Turbot &gt; Type Installed &gt; Background Tasks` is now removed

_Requirements_

- TE: 5.35.4</description>
            <pubDate>Sun, 05 Mar 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-47-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.47.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-47-0</link>
            <description>_What&apos;s new?_
- Added: New parameter for attaching a custom security group to each ECS host.
- Added: New parameter for attaching a custom security group to the TE ALB. Requires TE &gt; `v5.40.0`. 
- Added: Option added to enable IMDSv2 for ECS hosts.
- Added: New parameters to specify the size and type of EBS volumes attached to ECS Hosts. 
- Added: New parameter to specify a port for outbound SMTP (if needed).
- Updated: The `db_pair` security group now includes Elasticache rules, when Elasticache is enabled.

_Deprecation_
- As a result of this change to the `db_pair` security group, the Elasticache `cache_pair` security group is no longer required.  It will be removed in a future release.</description>
            <pubDate>Wed, 01 Mar 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-40-0</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.40.0 </title>
            <link>https://turbot.com/guardrails/changelog/te-v5-40-0</link>
            <description>_Bug fixes_

- Fixed: Improved handling of HTTP &quot;Too Many Requests&quot; (429) errors.

_Enterprise_

- Updated: TE Management Lambdas, and ECS Containers will be deployed with the
  NodeJS 16.x runtime. This change is independent of Mod Lambda runtime
  versions.
- Added: If specified in TEF, a custom security group may be assigned to the TE
  ALB.

_Requires_

- TEF v1.47.0</description>
            <pubDate>Wed, 01 Mar 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-46-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.46.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-46-0</link>
            <description>_What&apos;s new?_
- Added: Parameter to modify Lambda trigger concurrency</description>
            <pubDate>Thu, 09 Feb 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-39-12</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.39.12 </title>
            <link>https://turbot.com/guardrails/changelog/te-v5-39-12</link>
            <description>_Enterprise_

- Added: Parameter for Lambda trigger concurrency.

_Requires_ TEF: v1.46.0 TED: v1.9.1</description>
            <pubDate>Thu, 09 Feb 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-45-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.45.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-45-0</link>
            <description>_What&apos;s new?_
- Added: SSM parameter for events DLQ and worker retry reserved concurrency.</description>
            <pubDate>Thu, 02 Feb 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-39-11</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.39.11 </title>
            <link>https://turbot.com/guardrails/changelog/te-v5-39-11</link>
            <description>_Bug fixes_

- Fixed: Issue that could prevent indexes from being recreated after being
  dropped.
- Fixed: Issue with safeGet() function that could prevent reports from rendering
  in the UI.
- Fixed: Ansible task and service now created correctly created for Ansible
  version `2.10.7`.

_Enterprise_

- Added: Support for trigger concurrency in worker and events lamda functions.

_Requires_ TEF: v1.45.0 TED: v1.9.1</description>
            <pubDate>Thu, 02 Feb 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-44-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.44.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-44-0</link>
            <description>_What&apos;s new?_
- New: Turbot&apos;s autoscale group configuration has switched from `launch templates` to `launch configurations`.
- Added: Parameter to select Lambda function runtime version.
- Added: Encryption in transit policy for SNS topics and SQS queues.
- Updated: Changed EBS volume storage type to `gp3`.
-</description>
            <pubDate>Thu, 19 Jan 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-39-10</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.39.10</title>
            <link>https://turbot.com/guardrails/changelog/te-v5-39-10</link>
            <description>_What&apos;s new?_

- Fixed: Activity page should display `alternatePersona` in the actor field if
  available.

_Bug fixes_

- Fixed: AWS EC2 Instance report now runs more reliably.
- Updated: Improved the performance of the Activity page.

_Enterprise_

- Added: Encryption in transit policy for SNS topics and SQS queues in the
  Turbot Master account.
- Updated: Removed the deleted control historical records from control_usage
  table.
- Updated: `vm2` package to 3.9.11 in the ECS containers.
-</description>
            <pubDate>Tue, 17 Jan 2023 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-39-9</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.39.9 </title>
            <link>https://turbot.com/guardrails/changelog/te-v5-39-9</link>
            <description>_What&apos;s new?_

- Added: Support to import Azure China Cloud subscriptions.
- Added: Support for Azure China Cloud endpoints.

_Bug fixes_

- Updated: Increased reliability of policy value application when attaching a
  smartfolder.

_Enterprise_

- Updated: Removed Xray configuration from Postgres pool, as it was not being
  used.
- Updated: vm2 in main package.json updated to 3.9.11.
- Updated: Maintenance container base image to node:14-alpine3.17.

_Requires_ TEF: v1.42.1 TED: v1.9.1</description>
            <pubDate>Mon, 19 Dec 2022 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-28-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.28.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-28-0</link>
            <description>_What&apos;s new?_

- Added: Support for Postgres versions: 13.8, 14.1, 14.2, 14.3, 14.4, 14.5.
- Added: Support for Redis 7.0.
- Added: Support for RDS gp3 disk types.</description>
            <pubDate>Fri, 09 Dec 2022 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-28-6</guid>
            <title>Turbot Guardrails CLI v1.28.6</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-28-6</link>
            <description>_Bug fixes_

- Add role as a valid level to generate temporary credentials for roles.</description>
            <pubDate>Tue, 29 Nov 2022 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-39-8</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.39.8 </title>
            <link>https://turbot.com/guardrails/changelog/te-v5-39-8</link>
            <description>_Bug fixes_

- Updated: Query for resource notifications to improve performance when using
  the `Activity` sub-tab on the resource page.
- Updated: Improved logic used to determine when to run maintenance control for
  stale policy values.
- Updated: Mod install controlls will now use the standard worker queue instead
  of worker_priority queue to allow other actions to take priority during mod
  installs.

_Enterprise_

- Updated: Updated Ubuntu vm2 package to version 3.9.11. to resolve
  CVE-2022-36067.
- Updated: Message retetion period of events priority queue changed to 96 hours.

_Requires_ TEF: v1.42.1 TED: v1.9.1</description>
            <pubDate>Wed, 23 Nov 2022 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-43-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.43.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-43-0</link>
            <description>_What&apos;s new?_
- Added: support for TLS 1.2 for API Gateway</description>
            <pubDate>Wed, 16 Nov 2022 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-39-7</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.39.7 </title>
            <link>https://turbot.com/guardrails/changelog/te-v5-39-7</link>
            <description>_Bug fixes_

- Added: Btree aka index for akas_history and akas table. The Activity Tab
  should show improved performance.

_Requires_ TEF: v1.42.1 TED: v1.9.1</description>
            <pubDate>Tue, 08 Nov 2022 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-39-6</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.39.6 </title>
            <link>https://turbot.com/guardrails/changelog/te-v5-39-6</link>
            <description>_Bug fixes_

- Fixed: Downloading the csv for EC2 &gt; Instance &gt; Report should not fail.

_Enterprise_

- Added: ability to run async/callback in control&apos;s `inline`.
- Added: Ability to move control to priority queue.
- Updated: mute noisy log if unable to get process log data from S3.

_Requires_ TEF: v1.42.1 TED: v1.9.1</description>
            <pubDate>Tue, 25 Oct 2022 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-27-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.27.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-27-0</link>
            <description>_What&apos;s new?_

- Added: Postgres version 13.7 to RDS engine parameter.
- Added: Tags to elasticache resources.</description>
            <pubDate>Thu, 06 Oct 2022 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-39-5</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.39.5 </title>
            <link>https://turbot.com/guardrails/changelog/te-v5-39-5</link>
            <description>_Bug fixes_

- Updated: Local Profiles and Group Profiles filter now use free text search
  instead of akas matches.
- Updated: Installing a mod using the CLI now runs faster, reducing the
  likelyhood of a timeout.
- Fixed: Quick actions menu will no longer show actions from child resources.

_Enterprise_

- Added: Support for workspace URL in Turbot &gt; Workspace &gt; Workspace URL policy.

_Requires_ TEF: v1.42.1 TED: v1.9.1</description>
            <pubDate>Tue, 06 Sep 2022 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-42-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.42.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-42-0</link>
            <description>_What&apos;s new?_
- Added: SSM parameter for Process Log Fallback Bucket.</description>
            <pubDate>Thu, 25 Aug 2022 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-39-4</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.39.4 </title>
            <link>https://turbot.com/guardrails/changelog/te-v5-39-4</link>
            <description>_Bug fixes_

- Fixed: Resolved issue where EC2 instance report would fail to run.
- Fixed: Permissions summary report now works for users without permissions at
  the root level.

_Enterprise_

- Added: allow an alternative process log bucket to be provided to read from an
  older bucket.
- Updated: Ansible container base image to Ubuntu 22.10 (Kinetic Kudu)
- Updated: Ansible version to 2.10.7
- Updated: Docker base images of API and Factory to ubuntu 22.

_Requires_ TEF: v1.42.1 TED: v1.9.1</description>
            <pubDate>Thu, 25 Aug 2022 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-39-3</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.39.3 </title>
            <link>https://turbot.com/guardrails/changelog/te-v5-39-3</link>
            <description>_Bug fixes_

- Fixed: Apollo UI behaves properly when setting backoff interval of an action.
- Fixed: Actor display information will now fallback to `unidentified` if
  persona and identity are not available.
- Updated: UI will now use the actor information of the process (if supplied)
  for Policy Setting CRUD operations.
- Updated: Action runs now carry the identity of its launcher. This changes the
  way notifications are presented. Previously notifications from an action
  showed as `Unidentified`, now they will carry the identity of the launcher,
  most of the time this will be the Turbot identity unless the action is
  launched by a user from Turbot UI.

_Enterprise_

- Updated: Linux Environment control to support version 3 of SELinux Python
  bindings</description>
            <pubDate>Mon, 08 Aug 2022 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-39-2</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.39.2 </title>
            <link>https://turbot.com/guardrails/changelog/te-v5-39-2</link>
            <description>_Enterprise_

- Updated: Improved Ansible container error handling

_UI_

- Added: Mutation resolver for quick action and steampipe query in the developer
  tab.
- Added: Add support to execute quick action via URL.</description>
            <pubDate>Wed, 27 Jul 2022 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-39-1</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.39.1 </title>
            <link>https://turbot.com/guardrails/changelog/te-v5-39-1</link>
            <description>_Enterprise_

- Fixed: Control type should only trigger the control if there is a change in
  graphql/inline/function.</description>
            <pubDate>Wed, 13 Jul 2022 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/te-v5-39-0</guid>
            <title>Turbot Guardrails Enterprise (TE) v5.39.0 </title>
            <link>https://turbot.com/guardrails/changelog/te-v5-39-0</link>
            <description>_What&apos;s new?_

- New Feature: Quick Actions
- Updated: graphiql to 1.4.5

_Quick Actions_ Quick Actions is a new feature that allows Turbot users to
initaite specific (one time) control enforcements on their cloud environment via
the Turbot UI. Cloud operations teams can use Quick Actions to remediate cloud
configuration issues (e.g. enable encryption on a resource) or snooze Turbot
alarms for issues that we want to come back to later. More
[details in the documentation](#). Quick actions will be rolling out across all
supported cloud services in the coming months (based on your feedback); this
initial release covers resources in the following AWS mods:

- cloudtrail
- ec2
- kms
- lambda
- rds
- s3
- sns
- sqs
- vpc

_Disabling the Quick Actions feature_

- Quick Actions use the permissions granted to the Turbot service user or
  cross-account role used to import your cloud service account into Turbot.
  Execution of quick actions will fail if the underlying role prevents those
  actions from occuring.

- The Quick Actions feature is disabled by default, but can easily be enabled
  via the `Turbot &gt; Quick Actions &gt; Enabled` policy. If you would like to
  prevent lower level Turbot administrators from enabling Quick Actions for
  their cloud service accounts, then make sure you set
  `Turbot &gt; Quick Actions &gt; Enabled` to `Disabled` at the Turbot level using the
  `Required` option.

- The policy `Turbot &gt; Quick Actions &gt; Permission Levels` offers fine-grained
  control over which Turbot permission levels are required to execute specific
  quick actions. These permission limits can be set globally and specific
  exceptions can be managed down to the individual cloud service account level.

_Enterprise_

- Split package dependencies between Server and UI so they can use independent
  versions of GraphQL.</description>
            <pubDate>Tue, 05 Jul 2022 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-28-5</guid>
            <title>Turbot Guardrails CLI v1.28.5</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-28-5</link>
            <description>_Bug fixes_

- CLI failed to download latest mod versions automatically for mods with version
  &lt; 5.0.0.
- `turbot completion` command was displayed twice on running `turbot help`.</description>
            <pubDate>Thu, 30 Jun 2022 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-28-4</guid>
            <title>Turbot Guardrails CLI v1.28.4</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-28-4</link>
            <description>_Bug fixes_

- CLI failed to install dependencies for a mod with more than 26 dependencies.</description>
            <pubDate>Tue, 07 Jun 2022 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-41-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.41.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-41-0</link>
            <description>_What&apos;s new?_
- Added: new IAM permissions for Mod Lambda to publish messages to the Priority Events queue.
- Added: parameter for Worker Priority and Events Tick Lambda Reserved Concurrency.
- Added: EC2 ECS host recycling using parameter.

_Bug fixes_
- Fixed: ECS Rolling update.
- Fixed: Condition of Foundation Key to prevent its creation if TEFKmsKey parameter value is specified.

### There are IAM changes in this release:
- New IAM permissions for Mod Lambda to publish messages to the Priority Events queue.
- New IAM roles for ECS Rolling Update.</description>
            <pubDate>Mon, 06 Jun 2022 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-26-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.26.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-26-0</link>
            <description>_What&apos;s new?_

- Updated: GovCloud certificate to rds-ca-rsa4096-g1.</description>
            <pubDate>Wed, 18 May 2022 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-40-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.40.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-40-0</link>
            <description>_What&apos;s new?_
- Added: Parameter to limit the URL where the API Gateway Lambda can forward to. This should be a regular expression of valid workspace URLs.
- Updated: `TEF KMS Key` parameter name changed to `TEF KMS Key Arn`.
- Updated: Enforce HTTPS access for S3 buckets created by TEF.</description>
            <pubDate>Fri, 29 Apr 2022 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-25-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.25.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-25-0</link>
            <description>_What&apos;s new?_

- Updated: Enforce HTTPS access for S3 buckets created by TED.
- Added: Postgres versions 11.12, 11.13, 11.14, 11.15, 12.7, 12.8, 12.9, 12.10,
  13.3, 13.4, 13.5 and 13.6.</description>
            <pubDate>Fri, 29 Apr 2022 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-39-1</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.39.1</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-39-1</link>
            <description>_What&apos;s new?_
- Added: Parameter for Alb WAF option. (Default is disabled)
- Added: Parameter for Mods Cleanup.</description>
            <pubDate>Fri, 08 Apr 2022 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-30-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.30.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-30-0</link>
            <description>_What&apos;s new?_

- Updated: Moved management of the Elasticache user group to CloudFormation
  instead of the Hive Manager lambda. It is no longer necessary to update the
  Redis access control groups after making changes to the Redis cluster.

## 1.30.0 [2022-03-01]

_What&apos;s new?_

- Updated: Elasticache now uses the `db_pair` security group from TEF 1.47.0.
- Fixed: The Cloudformation Hive custom resource used to depend on Elasticache
  when it shouldn&apos;t have in environments without Elasticache deployed.

_Deprecation_

- As a result of this change to the `db_pair` security group, the Elasticache
  `cache_pair` security group is no longer required. It will be removed in a
  future release.

_Requirements_

- TEF v1.47.0</description>
            <pubDate>Tue, 01 Mar 2022 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-38-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.38.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-38-0</link>
            <description>_What&apos;s new?_
- Added: Parameters for Api and Events Container Scaling metrics, and threshold values for CPU Utilization.
- Added: Parameter to allow import of Foundation KMS Key.
- Updated: Set DeletionPolicy of FoundationKey to Retain.</description>
            <pubDate>Mon, 28 Feb 2022 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-37-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.37.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-37-0</link>
            <description>_What&apos;s new?_
- Added: Parameters for ECS Factory Task hard limit and soft limit on memory.</description>
            <pubDate>Fri, 11 Feb 2022 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-36-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.36.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-36-0</link>
            <description>_Warning_
- There are IAM changes in this release.

_What&apos;s new?_
- Updated: Condition for HiveManagerExecutionRole.
- Updated: TurbotParameters and TurbotSnsSqsPolicyParameterLambda to include variables for Proxy setting.
- Removed: MskManagerExecutionRole role from custom iam role template.</description>
            <pubDate>Mon, 07 Feb 2022 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-24-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.24.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-24-0</link>
            <description>_What&apos;s new?_

- Added: Postgres version 13.5 to RDS engine parameter.
- Fixed: Replication group setting to enable Data Tiering for r6gd node type.</description>
            <pubDate>Mon, 07 Feb 2022 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-29-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.29.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-29-0</link>
            <description>_What&apos;s new?_

- Added: Postgres version 12.11 and 12.12.
- Updated: PerformanceInsights description.
- Updated: Default storage type to `gp3`.
  [More info on using gp3](enterprise/FAQ/general-purpose-gp3)
- Updated: Hive custom resource depends on to include Elasticache cluster and
  parameter group and add ParameterDeploymentTrigger.</description>
            <pubDate>Wed, 02 Feb 2022 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-23-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.23.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-23-0</link>
            <description>_What&apos;s new?_

- Added: r6gd node type option for Elasticache.</description>
            <pubDate>Tue, 04 Jan 2022 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-22-2</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.22.2</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-22-2</link>
            <description>_What&apos;s new?_

- Updated: Backup Service Role to include kms Grant permissions for
  CopyDBSnapshot operation.</description>
            <pubDate>Thu, 25 Nov 2021 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-22-1</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.22.1</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-22-1</link>
            <description>_What&apos;s new?_

- Updated: Backup Service Role to include kms permissions.</description>
            <pubDate>Wed, 03 Nov 2021 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-35-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.35.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-35-0</link>
            <description>_What&apos;s new?_
- Added: VPC Endpoint for s3 to reduce NAT Gateway cost.
- Updated: API and Events container scaling by replacing hardcoded values with parameters.
- Updated: Outbound, Api and Database security groups so that they are created for Predefined VPC if custom security groups are not mentioned.
- Updated: default value of LogRetentionDays parameter changed to 180.</description>
            <pubDate>Fri, 22 Oct 2021 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-22-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.22.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-22-0</link>
            <description>_What&apos;s new?_

- Added: Postgres version 13.3, 13.4 to RDS engine parameter.
- Fixed: Cloudwatch alarms to use correct db identifier when hive name has \_ in
  it.
- Updated: Default database system backup to 7 days.
- Updated: AWS Backup Service role to allow copying of RDS snapshots.
- Updated: Cloudwatch alarms for ElastiCache SwapUsage and
  DatabaseMemoryUsagePercentage for multi-node architectures.
- Updated: Dashboard to move read-replica stats to right axis and that of
  primary to the left.
- Updated: Dashboard to add Total IOPS metrics.</description>
            <pubDate>Fri, 22 Oct 2021 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-34-1</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.34.1</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-34-1</link>
            <description>_Warning_
- There are IAM changes in this release for the `turbot_policy_parameter`.

_Bug fixes_
- TE Build ID was misconfigured causing TEF to build unsuccessfully, this has now been corrected and TEF builds as expected.</description>
            <pubDate>Fri, 02 Jul 2021 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-21-1</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.21.1</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-21-1</link>
            <description>_What&apos;s new?_

- Minimum DB size is now 50GB, default size is 200GB.

_Requirements_

- TEF v1.31.2</description>
            <pubDate>Fri, 25 Jun 2021 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-34-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.34.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-34-0</link>
            <description>_Warning_
- There are IAM changes in this release for the `turbot_policy_parameter`.

_What&apos;s new?_
- Turbot Security Group is added and includes rules for Ansible and LDAP.  The security group is intended for additional rules to be added under feature flags.  Note: the existing LDAP and Ansible security groups will remain for older TE versions.
- Dashboard for ECS Cluster metrics is now added.
- Autoscaling parameters were added for the Events Service.
- ElastiCache Security Groups and Subnet Groups are now added to the overrides template.
- TEF Workspace Manager now prevents users from changing the workspace name.
- OSGuardrail parameter location from Advanced - OS Guardrails to Advanced - Deployment Group.
- `turbot_parameters` and `turbot_policy_parameter` lambda functions now include VPC config.
- `turbot_policy_parameter` IAM Role now includes EC2 network interfaces policy. 
- Improved input validation to not allow blank values.</description>
            <pubDate>Wed, 16 Jun 2021 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-21-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.21.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-21-0</link>
            <description>_What&apos;s new?_

- CloudWatch Alarms and Dashboards are added for ElastiCache SwapUsage and
  DatabaseMemoryUsagePercentage.
- ElastiCache Instance Type can now be specified in the template.
- Read replica parameter default is now set to false.

_Requirements_

- TEF v1.31.2</description>
            <pubDate>Wed, 16 Jun 2021 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-20-1</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.20.1</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-20-1</link>
            <description>_What&apos;s new?_

- DB parameter group support for 11.10, 11.11, 12.6 and 13.2.
- Postgres version 13.2 is now the default selection.

_Requirements_

- TEF v1.31.2</description>
            <pubDate>Thu, 06 May 2021 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-20-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.20.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-20-0</link>
            <description>_What&apos;s new?_

- Shared_buffers parameter added for DB parameter group.
- Postgres version 13.1 is now the default selection.
- Postgres wal_keep_size default size is now 2048 (RDS Postgres default).
- Turbot database default size is now 250GB.
- Storage autoscale threshold default is now 1TB. For new TED installations
  only!

_Requirements_

- TEF v1.31.2</description>
            <pubDate>Wed, 28 Apr 2021 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-28-3</guid>
            <title>Turbot Guardrails CLI v1.28.3</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-28-3</link>
            <description>_Bug fixes_

- Invalid module reference fixed - this was causing `turbot template build` to
  fail.</description>
            <pubDate>Thu, 15 Apr 2021 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-28-2</guid>
            <title>Turbot Guardrails CLI v1.28.2</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-28-2</link>
            <description>_Bug fixes_

- `template build` was loading the lock-file from the base branch to determine
  the current template version. When using a work-in-progress (wip) branch, this
  could lead to identifying an incorrect current version, leading to rebasing
  errors. Fix by loading the lock file from the wip branch.</description>
            <pubDate>Tue, 13 Apr 2021 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-33-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.33.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-33-0</link>
            <description>_What&apos;s new?_

- S3 bucket lifecycle rule added to the mods processing log bucket. 
- Optional AWS Security Group added to be used for connecting to LDAP server.
- S3 inventory reports will no longer generate in the TEF Process Logs bucket.
- Updated process log bucket lifecycle configurations to remove /debug/ rules.
- Runtime has been updated to Node 14 for all Turbot Core deployed Lambda functions.</description>
            <pubDate>Fri, 02 Apr 2021 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-19-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.19.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-19-0</link>
            <description>_What&apos;s new?_

- Postgres version 13.1. For new TED installations only!
- ElastiCache replication groups now support multi nodes.cluster mode.

_Bug fixes_

- Hive Log Bucket lifecycle configurations now delete all objects.

_Requirements_

- TEF v1.31.2</description>
            <pubDate>Fri, 02 Apr 2021 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-18-1</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.18.1</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-18-1</link>
            <description>_Bug fixes_

- Dependency issue with the HiveKey.

_Requirements_

- TEF v1.31.2</description>
            <pubDate>Mon, 08 Mar 2021 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-32-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.32.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-32-0</link>
            <description>_What&apos;s new?_

* OSGuardrails feature flag, adding security groups and SSM parameters as required.
* HealthCheckProxyLambda runtime updated from 2.7 to 3.8.</description>
            <pubDate>Thu, 04 Mar 2021 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-18-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.18.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-18-0</link>
            <description>_What&apos;s new?_

- Postgres version 12.5. **For new TED installations only!**
- Parameter Group support for both 11.x and 12.x.

_Bug fixes_

- Cache cluster parameter passed to Hive Manager should also convert underscore
  to hyphen.
- Allow default encryption for ElastiCache for use in GovCloud (which does not
  support CMK).

_Requirements_

- TEF v1.31.2</description>
            <pubDate>Thu, 04 Mar 2021 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-28-1</guid>
            <title>Turbot Guardrails CLI v1.28.1</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-28-1</link>
            <description>_Bug fixes_

- Fixed CLI packaging error required for proper v1.28.0 installation.</description>
            <pubDate>Thu, 04 Mar 2021 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-28-0</guid>
            <title>Turbot Guardrails CLI v1.28.0</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-28-0</link>
            <description>_Bug fixes_

- `turbot template build` now cleans up branches after a rebase failure.</description>
            <pubDate>Wed, 03 Mar 2021 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-31-3</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.31.3</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-31-3</link>
            <description>_Warning_

* IAM permissions updated in v1.31.0.

_Bug fixes_

* Fix and republish a corrupt portfolio build artifact.</description>
            <pubDate>Thu, 28 Jan 2021 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-17-2</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.17.2</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-17-2</link>
            <description>_Bug fixes_

- AWS Backup Vault name format issue.

_Requirements_

- TEF v1.31.2</description>
            <pubDate>Thu, 28 Jan 2021 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-31-2</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.31.2</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-31-2</link>
            <description>_Warning_

* IAM permissions updated in v1.31.0.

_Bug fixes_

* Hive Manager should convert underscore to hyphen when creating Redis group (from TE).</description>
            <pubDate>Wed, 27 Jan 2021 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-31-1</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.31.1</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-31-1</link>
            <description>_Warning_

* IAM permissions updated in v1.31.0.

_Bug fixes_

* Hive Manager should convert underscore to hyphen when creating Redis user (from TE).</description>
            <pubDate>Mon, 25 Jan 2021 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-17-1</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.17.1</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-17-1</link>
            <description>_Bug fixes_

- ElastiCache Redis cluster name should convert underscores to hyphens.

_Requirements_

- TEF v1.31.2</description>
            <pubDate>Mon, 25 Jan 2021 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-31-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.31.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-31-0</link>
            <description>_Warning_

* IAM permissions updated.

_What&apos;s new?_

* ElastiCache Redis is now enabled by default.
* Parameters - Mod Lambda function limits.
* Parameters - Worker Lambda configuration, allowing reuse across TE versions.
* CloudWatch Alarms for SQS ApproximateAgeOfOldestMessage.</description>
            <pubDate>Fri, 22 Jan 2021 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-17-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.17.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-17-0</link>
            <description>_What&apos;s new?_

- ElastiCache Redis is now enabled by default.

_Bug fixes_

- Postgres 11.9 is now available for the read replica as well.
- ElastiCache Redis cluster should be created with the hive name rather than
  just resource name prefix.
- AWS Backup Vault deletion policy is now set to retain.

_Requirements_

- TEF v1.31.2</description>
            <pubDate>Fri, 22 Jan 2021 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-27-0</guid>
            <title>Turbot Guardrails CLI v1.27.0</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-27-0</link>
            <description>_What&apos;s new?_

- `turbot template build --rebase` command now cleans up the work in progress
  branch if the template render fails.

_Bug fixes_

- `turbot template build --rebase` command was failing to re-apply manual
  changes.
- `turbot template build --fleet-mode` would stop building all branches if a
  single one failed.</description>
            <pubDate>Mon, 07 Dec 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-30-1</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.30.1</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-30-1</link>
            <description>_Bug fixes_

- Fixed: Code of s3BucketArnLambda to fix s3 permission.</description>
            <pubDate>Thu, 26 Nov 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-30-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.30.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-30-0</link>
            <description>_What&apos;s new?_

* Hive Manager and Workspace Manager runtime updated to node 12.

_Bug fixes_

* Install Hive Manager in all regions, not just the Alpha region.</description>
            <pubDate>Fri, 20 Nov 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-15-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.15.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-15-0</link>
            <description>_What&apos;s new?_

- Added latest RDS DB instance types.
- Experimental ElastiCache: Configure use of Redis 6.x Access Control Lists.
- Experimental ElastiCache: Also install Hive Manager in the replica region, for
  Redis management.

_Requirements_

- TEF v1.30.0</description>
            <pubDate>Fri, 20 Nov 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-29-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.29.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-29-0</link>
            <description>_Warning_

* IAM permissions updated.

_What&apos;s new?_

* New `turbot_transient` KMS key specifically used for encryption of transient data (e.g. SNS, SQS).
* Tightened IAM access policies to Turbot&apos;s own S3 buckets.
* Hive Manager is now permitted IAM access to manage ElastiCache.
* Added ListBucket permission to WorkspaceManager role so head object calls will return 404 instead of 403.

_Bug fixes_

* Event Proxy Lambda must be installed in the subnet where Load Balancers are installed (by TE).</description>
            <pubDate>Thu, 12 Nov 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-26-0</guid>
            <title>Turbot Guardrails CLI v1.26.0</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-26-0</link>
            <description>_What&apos;s new?_

- `turbot compose` (used by all CLI commands that compose mods) now omits the
  `releaseNotes` field from `turbot.head.json`. It is still included in
  `turbot.dist.json`.
- `turbot template` has a new `--unchanged-issue &lt;issue_id&gt;` argument. When a
  template build operation commits changes to git, if no files have actually
  changed then the commit message will use this issue instead of the normal
  `--issue &lt;issue_id&gt;` field. The commit message will also specify &quot;no changes&quot;.</description>
            <pubDate>Thu, 12 Nov 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-25-0</guid>
            <title>Turbot Guardrails CLI v1.25.0</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-25-0</link>
            <description>_What&apos;s new?_

- `turbot publish` has a new `--timeout &lt;secs&gt;` argument to customize the
  publish timeout. The default has been increased to 2 minutes.
- Use `turbot template build --issue 1234 --close-issue` will set the commit
  message to close the issue.

_Bug fixes_

- `turbot test` should not fail with the the error
  `TypeError: tmod.parse is not a function`.</description>
            <pubDate>Mon, 02 Nov 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-28-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.28.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-28-0</link>
            <description>_Warning_

* IAM permissions updated.

_What&apos;s new?_

* Further refined our IAM permissions for S3 bucket access, with a focus on
  removing more wildcards. It was already good, but now it&apos;s better.

_Bug fixes_

* Made the ElastiCache network infrastructure optional through `Development
  Mode`. It was harmless, but not necessary unless ElastiCache is enabled in
  TED.
* Moved policy parameter role into the IAM stacks, where it belongs.</description>
            <pubDate>Mon, 26 Oct 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-14-2</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.14.2</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-14-2</link>
            <description>_Bug fixes_

- Databases should never automatically upgrade their minor or major versions.
  Doing so takes the database out of sync with the CloudFormation stack, leading
  to upgrade rollbacks. We&apos;ve deliberately removed these options and set the
  auto-update to false.

_Requirements_

- TEF v1.25.0</description>
            <pubDate>Fri, 23 Oct 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-24-3</guid>
            <title>Turbot Guardrails CLI v1.24.3</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-24-3</link>
            <description>_Bug fixes_

- `turbot template build --patch --push-instance-root` command failed to push
  changes to the wip branch.</description>
            <pubDate>Fri, 23 Oct 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-14-1</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.14.1</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-14-1</link>
            <description>_What&apos;s new?_

- Changes to the Turbot audit trail log group in v1.14.0 forced a name change,
  which is difficult for customers with integrations. This version removes that
  requirement, so existing installs keep their original log group name.

_Bug fixes_

- Required TEF version dropped back down to TEF v1.25.0. v1.27.0 is only
  required if you are setting up the experimental ElastiCache features.

_Requirements_

- TEF v1.25.0</description>
            <pubDate>Wed, 21 Oct 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-27-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.27.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-27-0</link>
            <description>_What&apos;s new?_

* Reclaimed the `ECSDesiredInstanceCount` parameter, which now defaults to
  using `ECSMinInstanceCount` instead. This frees up a precious parameter slot
  for other options.
* Added the `DevelopmentMode` parameter for internal use, which groups options
  like using the latest container image (instead of cached).
* For environments with ElastiCache enabled in TED, cache subnet group and
  security groups have been added.</description>
            <pubDate>Wed, 14 Oct 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-14-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.14.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-14-0</link>
            <description>_What&apos;s new?_

- The deletion policy for the DB Parameter Group is now set to Retain.
- New installations will now add the stack ID to the audit trail log group,
  making it easier to re-install TED multiple times in testing / setup.
- New `ExperimentalFeatures` flag, allowing gradual introduction of new
  capabilities. The first one is installation of ElastiCache preparing for
  future use in TE.

_Requirements_

- TEF v1.27.0</description>
            <pubDate>Wed, 14 Oct 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-24-2</guid>
            <title>Turbot Guardrails CLI v1.24.2</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-24-2</link>
            <description>_Bug fixes_

- `turbot pack` and `turbot publish` were failing to run pre-pack script when
  `--dir` arg is used.</description>
            <pubDate>Wed, 07 Oct 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-24-1</guid>
            <title>Turbot Guardrails CLI v1.24.1</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-24-1</link>
            <description>_Bug fixes_

- `turbot inspect` should give a clear error message for invalid templates.</description>
            <pubDate>Tue, 06 Oct 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-24-0</guid>
            <title>Turbot Guardrails CLI v1.24.0</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-24-0</link>
            <description>_Bug fixes_

- `turbot inspect --format changelog` should properly escape CSV fields with
  commas.</description>
            <pubDate>Mon, 05 Oct 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-26-3</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.26.3</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-26-3</link>
            <description>_Bug fixes_

* Error handling in workspace pre-install checker.</description>
            <pubDate>Thu, 01 Oct 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-26-2</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.26.2</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-26-2</link>
            <description>_Bug fixes_

* Error handling in workspace pre-install checker.</description>
            <pubDate>Thu, 01 Oct 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-26-1</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.26.1</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-26-1</link>
            <description>_Bug fixes_

* ECS Agent should attempt to use the locally cached image, which dramatically
  reduces disk IO and download bandwidth.
* Upgrade via CloudFormation had a race condition in our custom resource Lambda
  functions that could be triggered when doing a large number of upgrades or
  rollbacks in parallel.</description>
            <pubDate>Wed, 30 Sep 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-26-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.26.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-26-0</link>
            <description>_Bug fixes_

* When a custom outbound access security group is specified in the TEF template
  do not create the {prefix}\_outbound\_internet\_security\_group or the
  {prefix}\_{version}\_outbound\_internet\_security\_group.</description>
            <pubDate>Thu, 24 Sep 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-25-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.25.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-25-0</link>
            <description>_What&apos;s new?_

* Ability to restrict SNS topic and SQS queue access based on Organization Id.</description>
            <pubDate>Tue, 22 Sep 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-13-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.13.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-13-0</link>
            <description>- Added: support to restrict access to SNS topic and SQS queue based on the
  Organization Id.

_Requirements_

- TEF v1.25.0</description>
            <pubDate>Tue, 22 Sep 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-12-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.12.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-12-0</link>
            <description>_What&apos;s new?_

- Added: Encryption to SNS Topic for Dashboard.
- Updated: TED Stack - changed R/W IOPS metrics from line to stacked area,
  changed Transaction ID Wraparound Monitor threshold to 2 billion.
- Fixed: Description and Typo (Duraction to Duration, Actiond to Action).

_Requirements_

- TEF v1.22.1</description>
            <pubDate>Mon, 21 Sep 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-23-0</guid>
            <title>Turbot Guardrails CLI v1.23.0</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-23-0</link>
            <description>_What&apos;s new?_

- `turbot install` - checks if a compatible version of each dependency is
  already installed. If so, it is does not install from the registry unless
  there is a newer version available.
- `turbot template build --rebase` rebuilds templates while using rebase to
  better merge and preserve custom changes to the rendered files since the last
  build.</description>
            <pubDate>Fri, 18 Sep 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-22-0</guid>
            <title>Turbot Guardrails CLI v1.22.0</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-22-0</link>
            <description>_What&apos;s new?_

- Show a progress bar during long running operations.</description>
            <pubDate>Mon, 07 Sep 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-24-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.24.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-24-0</link>
            <description>_Warning_

* IAM permissions updated.

_Bug fixes_

* The (optional) API Gateway to proxy external events to the internal Turbot
  load balancer was returning error codes (5xx) all queries even though it
  worked successfully. This could lead to retries of the message (which were
  not processed due to our duplicate detection). Errors in both the event
  handler and the health check have been cleared.</description>
            <pubDate>Fri, 21 Aug 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-21-0</guid>
            <title>Turbot Guardrails CLI v1.21.0</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-21-0</link>
            <description>_What&apos;s new?_

- Improved error messages for failed queries like authentication, network
  connectivity, etc.
- Update credentials precedence to prioritise specific credentials (key,
  secretKey and workspace) over profile.

_Bug fixes_

- `turbot configure` fails when no command line credentials arguments are given
  but they set in environment
- `turbot workspace list` should ignore `TURBOT_PROFILE` env var and only filter
  profiles if one is given in command line.
- `turbot download` should fall back to use the production registry if the user
  is not logged in.</description>
            <pubDate>Thu, 20 Aug 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-20-1</guid>
            <title>Turbot Guardrails CLI v1.20.1</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-20-1</link>
            <description>_Bug fixes_

- Exceptions from the pre-pack script in `turbot pack` were not caught and
  reported correctly.</description>
            <pubDate>Fri, 31 Jul 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-20-0</guid>
            <title>Turbot Guardrails CLI v1.20.0</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-20-0</link>
            <description>_What&apos;s new?_

- Improved error messages for `turbot pack`, `turbot up` and `turbot publish`
  for faster troubleshooting.

_Bug fixes_

- `turbot graphql` queries for `control`, `policy-value`, etc were not properly
  handling the `--resource-id` and `--resource-aka` arguments.</description>
            <pubDate>Thu, 30 Jul 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-19-3</guid>
            <title>Turbot Guardrails CLI v1.19.3</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-19-3</link>
            <description>_Bug fixes_

- `turbot configure` was failing for some Windows users when used in interactive
  mode.</description>
            <pubDate>Thu, 30 Jul 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-23-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.23.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-23-0</link>
            <description>_What&apos;s new?_

* Updated Workspace Manager permissions for SSM policy lookups and reading S3
  data for access to the TE workspace manager Lambda results.</description>
            <pubDate>Wed, 22 Jul 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-19-2</guid>
            <title>Turbot Guardrails CLI v1.19.2</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-19-2</link>
            <description>_Bug fixes_

- `turbot configure` was always failing validation when using interactive mode
  to enter credentials.</description>
            <pubDate>Mon, 20 Jul 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-19-1</guid>
            <title>Turbot Guardrails CLI v1.19.1</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-19-1</link>
            <description>_Bug fixes_

- `turbot install [mod]` was not working. You can now install specific mods as
  expected.</description>
            <pubDate>Mon, 20 Jul 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-19-0</guid>
            <title>Turbot Guardrails CLI v1.19.0</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-19-0</link>
            <description>_What&apos;s new?_

- Use `turbot install [mod[@version]]` to
  install a specific mod as a local dependency.
- Credentials passed to `turbot workspace configure` are now validated before
  saving, so you can be confident they are good to go.</description>
            <pubDate>Thu, 16 Jul 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-18-1</guid>
            <title>Turbot Guardrails CLI v1.18.1</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-18-1</link>
            <description>_What&apos;s new?_

- Use `turbot workspace list` to see a list of your currently configured
  workspaces.
- `turbot workspace configure` added, with the same behavior as
  `turbot configure`.

_Bug fixes_

- `turbot test` was failing for some GCP controls due to an update in the GCP
  auth library package. This has been fixed.</description>
            <pubDate>Fri, 10 Jul 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-18-0</guid>
            <title>Turbot Guardrails CLI v1.18.0</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-18-0</link>
            <description>_See v1.18.1_</description>
            <pubDate>Fri, 10 Jul 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-22-1</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.22.1</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-22-1</link>
            <description>_Bug fixes_

* As part of preparing for connection pooling, the hive manager included steps
  to initialize multiple database roles. These are not yet in use so have been
  removed.</description>
            <pubDate>Tue, 07 Jul 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-11-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.11.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-11-0</link>
            <description>_What&apos;s new?_

- As part of preparing for connection pooling, the hive manager included steps
  to initialize multiple database roles. These are not yet in use so have been
  removed.

_Requirements_

- TEF v1.22.1</description>
            <pubDate>Tue, 07 Jul 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-22-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.22.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-22-0</link>
            <description>_What&apos;s new?_

* The default browser facing security group (used by the load balancer) is now
  open on port 80, so HTTP traffic can be automatically redirected to HTTPS at
  the load balancer level.
* Expanded EC2 instance type options, and changed the default to `t3.medium`.
* Changed the default maximum limit for ECS hosts from 64 to a more sensible,
  but still generous, 8.
* Further restricted permissions to EC2 hosts, limiting the accessible resources
  as much as possible.</description>
            <pubDate>Mon, 06 Jul 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-21-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.21.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-21-0</link>
            <description>_What&apos;s new?_

* Introducing a new parameter model in TEF, allowing parameter &quot;overrides&quot; to
  be optionally set in SSM. Turbot creates default parameters, but will
  automatically detect any overrides you create during the stack run. This
  allows us to expand beyond the 60 parameter limit of CloudFormation.
* Each Turbot version installs minimal IAM policies and roles specific to its
  requirements. Some customers prefer more control over IAM management, so we
  now support BYO-IAM with parameters for all IAM entities required in the
  Turbot primary account.
* Added parameters to optionally set the `ALB Log Prefix` and `ALB Idle Timeout`.
* TEF will now perform a rolling update of the EC2 hosts if required due to
  launch configuration changes, ensuring no downtime during upgrades.
* Allow preinstall check Lambda function to use VPC from non-VPC setting.</description>
            <pubDate>Fri, 19 Jun 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-10-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.10.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-10-0</link>
            <description>_What&apos;s new?_

- Parameter groups created in GovCloud do not support newer parameters, unless a
  new parameter group is created (Note: AWS Commerical accounts were not
  affected by this). This blocks some existing customers from upgrading their
  TED stack. Because parameter group changes require a reboot (downtime), and
  most customers do not require this change, we&apos;ve made it an optional parameter
  in the stack to force the change as required.
- Default storage allocation for new installs is now 1TB (up from 100GB).

_Requirements_

- TEF v1.19.1</description>
            <pubDate>Fri, 19 Jun 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-20-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.20.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-20-0</link>
            <description>_What&apos;s new?_

* Added `169.254.170.2` to the default `NO_PROXY` parameter. This is required for stack containers to execute in some proxy environments.</description>
            <pubDate>Fri, 29 May 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-17-3</guid>
            <title>Turbot Guardrails CLI v1.17.3</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-17-3</link>
            <description>_Bug fixes_

- `turbot install` was attempting to install the latest version, which would
  fail if that version was not available or recommended. It will now install the
  latest recommended version, or if none are recommended, the latest available
  version.</description>
            <pubDate>Thu, 21 May 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-19-1</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.19.1</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-19-1</link>
            <description>_Bug fixes_

* Network Interface permissions added in v1.19.0 are low risk, but have
  been tightened further to only be granted in environments running Lambda
  inside the VPC.</description>
            <pubDate>Wed, 20 May 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-9-1</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.9.1</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-9-1</link>
            <description>_Bug fixes_

- v1.9.0 introduced a mix of names between `preinstall` and `preinstallation`
  which felt messy. This patch release brought to you by our clean up crew.

_Requirements_

- TEF v1.19.1</description>
            <pubDate>Tue, 19 May 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-19-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.19.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-19-0</link>
            <description>_What&apos;s new?_

* TED and TE are being enhanced to automatically check that their required
  versions of TEF and TED are installed. The Lambda function they use for
  that check (custom resource during the CloudFormation stack run) is
  deployed in TEF, and added in this release.
* Turbot Guardrails Enterprise uses a lot of Lambda functions to execute mod code. For
  organizations who prefer more visibility into network traffic, we&apos;re adding
  support to run these functions inside the VPC. This version of TEF expands
  the IAM permissions granted to Lambda functions with the minimum required
  to attach Network Interface cards.</description>
            <pubDate>Mon, 18 May 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-9-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.9.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-9-0</link>
            <description>_What&apos;s new?_

- TED now automatically checks the required TEF version is installed. If not,
  the TED stack will automatically rollback allowing you to upgrade TEF first.

_Requirements_

- TEF v1.19.1</description>
            <pubDate>Mon, 18 May 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-18-1</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.18.1</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-18-1</link>
            <description>_What&apos;s new?_

* `Flags` parameter now has validation rules and defaults to `NONE` (CloudFormation does not like empty string defaults for SSM parameters).</description>
            <pubDate>Thu, 14 May 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-18-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.18.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-18-0</link>
            <description>_What&apos;s new?_

* `Flags` parameter will allow features to be enabled or disabled at the
  installation level giving us more flexibility to innovate and gradually
  deploy features.</description>
            <pubDate>Thu, 14 May 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-8-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.8.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-8-0</link>
            <description>_Warning_

- The default for `TrackFunctions` in v1.7.0 was `pl`. Consider changing this to
  `none` (the new, more common, default in v1.8.0) if you don&apos;t require that
  tracking.

_What&apos;s new?_

- Process log data collected by Turbot is being moved into TED level management.
  This better aligns with our model of data separation and encryption. This
  version adds S3 buckets with encryption and lifecycle rules to start accepting
  that (and other future) data.
- If the master password is an empty string then Turbot will reset it
  automatically when required. The default was previously blank, requiring the
  parameter to be set (even if to empty string). This was difficult to
  understand and implement for those automating TED configuration. We now
  default to the empty string.
- Added new DB instance size option of `m5.8xlarge`.

_Bug fixes_

- Resource names related to metric collection, alarms and dashboards have been
  updated to use the ResourceName prefix. This aligns them with all other TED
  resources and makes it easier to track or target them with local rules.</description>
            <pubDate>Thu, 14 May 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-17-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.17.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-17-0</link>
            <description>_What&apos;s new?_

* Moved to ECS optimized Amazon Linux 2 as our host OS for containers.
  (Previously we used ECS optimized Amazon Linux 1.)
* Expanded proxy server support, particularly through the ECS bootstrap sequence.
  We now support HTTP and HTTPS requests being routed to a `http://` proxy for
  all traffic - no need for endpoints or similar in any case. (We do not yet
  support custom certificates and `https://` proxies.)
* TEF now publishes an SSM parameter with the currently installed version,
  which will be used in the future to check version compatibility during TED
  and TE upgrades.</description>
            <pubDate>Tue, 12 May 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-17-2</guid>
            <title>Turbot Guardrails CLI v1.17.2</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-17-2</link>
            <description>_Bug fixes_

- The build of v1.17.1 was not properly published, leading to confusion and
  mixed installs. This release is identical, but properly distributed.</description>
            <pubDate>Mon, 11 May 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-17-1</guid>
            <title>Turbot Guardrails CLI v1.17.1</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-17-1</link>
            <description>_Bug fixes_

- Remove the explicit default value for `force-recommended` as this causes
  issues when using the yargs `conflicts` parameter.</description>
            <pubDate>Thu, 07 May 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-17-0</guid>
            <title>Turbot Guardrails CLI v1.17.0</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-17-0</link>
            <description>_What&apos;s new?_

- Mod authors often want to set their new version as `RECOMMENDED` in the
  registry, telling users it&apos;s the best choice. Use
  `turbot publish --force-recommended` and `turbot modify --force-recommended`
  to mark this version as `RECOMMENDED` and set all currently recommended
  versions to `AVAILABLE`.

_Bug fixes_

- `turbot test` was showing incorrect test data validation errors, due to a
  graphql schema change that had not been handled by the CLI.</description>
            <pubDate>Thu, 07 May 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-16-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.16.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-16-0</link>
            <description>_What&apos;s new?_

* `Allow Self-Signed Certificate` parameter, instructing Turbot to ignore
  certificate errors when connecting to external services - for example -
  enterprise environments with an outbound internet proxy.
* S3 bucket inventory has been enabled, setting us up for future batch
  operations on collections of log files.
* Updated lifecycle rules to clean deleted versions of debug logs and
  match changes to the prefix of log files.</description>
            <pubDate>Tue, 05 May 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-15-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.15.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-15-0</link>
            <description>_What&apos;s new?_

* Added a &quot;connectivity test&quot; lambda function, making it easier to verify that
  an environment has the necessary network setup. Run
  `${ResourceNamePrefix}_connectivity_checker` manually to test.
* Improved descriptions for the Installation Domain and Turbot Certificate ARN
  parameters.</description>
            <pubDate>Fri, 01 May 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-16-0</guid>
            <title>Turbot Guardrails CLI v1.16.0</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-16-0</link>
            <description>_What&apos;s new?_

- `turbot inspect` now enforces valid semantic versions in mod version numbers.
  We admire your creativity, but encourage you to express it elsewhere.

_Bug fixes_

- Fixed `turbot up --zip`, which broke during a dependency update.</description>
            <pubDate>Thu, 30 Apr 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-14-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.14.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-14-0</link>
            <description>_What&apos;s new?_

* Turbot License Key has been added as a (currently optional) parameter.</description>
            <pubDate>Fri, 24 Apr 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-15-1</guid>
            <title>Turbot Guardrails CLI v1.15.1</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-15-1</link>
            <description>_Bug fixes_

- `turbot login` was failing if the `~/.config` folder did not exist.
- `turbot template build` was always expecting a `wip-*` instance branch to
  exist. It&apos;s now correctly limited to runs where `--use-instance-root-branch`
  is passed.</description>
            <pubDate>Fri, 24 Apr 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-15-0</guid>
            <title>Turbot Guardrails CLI v1.15.0</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-15-0</link>
            <description>_What&apos;s new?_

- Proxy support via the `HTTPS_PROXY` environment variable. Login, install mods
  and publish to our registry all via your favorite proxy. (Provided it&apos;s a
  `http://` proxy, we don&apos;t support `https://` yet.)</description>
            <pubDate>Wed, 22 Apr 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-13-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.13.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-13-0</link>
            <description>_What&apos;s new?_

* Updates Hive Manager, which includes the ability to convert ownership of
  database schemas. This is part of a longer term effort to move database
  ownership to specific turbot roles, reducing our use of the master account.</description>
            <pubDate>Fri, 17 Apr 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-7-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.7.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-7-0</link>
            <description>_What&apos;s new?_

- Parameters to set `rds.force_admin_logging_level` and `track_functions`,
- Add CloudWatch alarms for DB connections, CPU utilization and free storage
  alerts.
- Added t2.medium and t2.large instance class options, useful in test or dev
  environments.</description>
            <pubDate>Fri, 17 Apr 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-14-0</guid>
            <title>Turbot Guardrails CLI v1.14.0</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-14-0</link>
            <description>_What&apos;s new?_

- Manage published mods in the registry from the CLI, including their status and
  description. For example
  `turbot registry modify --mod &quot;@turbot/aws&quot; --mod-version &quot;5.0.0&quot; --status RECOMMENDED --description &quot;updated description&quot;`.
- Usually a newly published version should be the recommended one. So now you
  can do that automatically during `turbot publish` using the
  `--status RECOMMENDED` flag.
- `turbot template build` now supports instance root branch names with a random
  suffix, following the naming convention: `wip/&lt;instance root name&gt;/*`. We&apos;ve
  found scheme much more effective at scale.
- We now automatically include `RELEASE_NOTES.md` as well as `CHANGELOG.md` when
  building a mod. Release notes are intended for users while a changelog is
  intended for developers or others obsessed over details.
- `turbot test` validates input query, but only works for a single query (not
  for the more advanced array of queries syntax). Previously the test would
  always fail for an array of queries, so we&apos;re now skipping the test in these
  cases until it can be fully supported.

_Bug fixes_

- `turbot publish --dir &lt;mod folder&gt;` did not work if run outside the mod
  folder - the function zips were not correctly created.</description>
            <pubDate>Fri, 17 Apr 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-13-0</guid>
            <title>Turbot Guardrails CLI v1.13.0</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-13-0</link>
            <description>What&apos;s new?_

- Registry login using `turbot login` (and similar) now requires both
  `--username` and `--password` or neither. They just can&apos;t live without each
  other.

_Bug fixes_

- `turbot template build --patch` command was failing without running the git
  command.</description>
            <pubDate>Mon, 06 Apr 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-12-1</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.12.1</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-12-1</link>
            <description>_Bug fixes_

* EC2 instances used for ECS should have AssociatePublicIpAddress set to false.
  This is a defence improvement since our EC2 instances are run in a private VPC
  so were not publically accessible anyway.</description>
            <pubDate>Thu, 02 Apr 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-12-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.12.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-12-0</link>
            <description>_What&apos;s new?_

* Cleanup IAM roles to use `_` consistently in names (instead of mixing `_` and
  `-` together).</description>
            <pubDate>Wed, 01 Apr 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-11-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.11.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-11-0</link>
            <description>_What&apos;s new?_

* Some organizations need to use a self-signed certificate for their ALB. This would
  fail a certificate check when also using our API Gateway proxy. Use the `Self
  Signed Certificate In ALB` parameter to ignore these certificate errors.

_Bug fixes_

* The IAM role used for ECS EC2 instances is now named consistently with our
  other IAM roles.</description>
            <pubDate>Tue, 31 Mar 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-10-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.10.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-10-0</link>
            <description>_Warning_

* Existing TEF installations must install v1.9.0 before upgrading to
  v1.10.0. This sequence will automatically preserve and transition parameter
  settings for S3 bucket names as we move from fixed names to randomized names
  by default for new installations.

_What&apos;s new?_

* Log and process buckets now use a partly random name by default, making new
  installations smoother and easier to troubleshoot.</description>
            <pubDate>Fri, 27 Mar 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-9-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.9.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-9-0</link>
            <description>_What&apos;s new?_

* Optionally use a random name for log and process log buckets, making repeated
  install and uninstall easier.
* Log buckets will now be retained on deletion of the TEF stack.</description>
            <pubDate>Thu, 26 Mar 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-6-1</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.6.1</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-6-1</link>
            <description>_Bug fixes_

- The SNS topic name for CPU alarms was not consistent with our other resources.
  Now it is.</description>
            <pubDate>Tue, 24 Mar 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-8-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.8.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-8-0</link>
            <description>_What&apos;s new?_

* Setup an S3 bucket to store process logs, including lifecycle rules to
  cleanup debug logs.</description>
            <pubDate>Mon, 23 Mar 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-6-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.6.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-6-0</link>
            <description>_What&apos;s new?_

- Alarm levels defined in the dashboard for CPU utilization and free storage,
  making problem levels clearer.
- Dashboard charts are now zero based, as any statistician will tell you they
  should be.
- SNS topic publishing CPU alarms, making it easy to subscribe for alerts.</description>
            <pubDate>Mon, 23 Mar 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-12-0</guid>
            <title>Turbot Guardrails CLI v1.12.0</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-12-0</link>
            <description>_What&apos;s new?_

- In `turbot compose` the `+schema` directive can now map from openApi format
  schema to valid JSON schema.

_Bug fixes_

- `turbot template build` fleet operations were failing due to an error
  displaying the summary. This has been fixed.</description>
            <pubDate>Thu, 19 Mar 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-7-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.7.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-7-0</link>
            <description>_What&apos;s new?_

* Turbot Hive Manager lambda now has permission to create encrypted SSM
  parameters, required by TED v1.5.0.</description>
            <pubDate>Tue, 17 Mar 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-5-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.5.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-5-0</link>
            <description>_Warning_

- Requires TEF v1.7.0 or later.

_What&apos;s new?_

- Parameter to set the maintenance window.
- Parameter to set a Customer Managed Key for encryption.
- Parameter to set the turbot master password. If blank, the master password is
  automatically reset.

_Bug fixes_

- Auto scaling of storage for the read replicas outside the primary region.</description>
            <pubDate>Tue, 17 Mar 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-11-0</guid>
            <title>Turbot Guardrails CLI v1.11.0</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-11-0</link>
            <description>_What&apos;s new?_

- Use `turbot test` to check GraphQL mutations (e.g. `updatePolicySetting`) are
  called as expected from controls.
- `turbot compose` no longer errors when a glob matches no source files.</description>
            <pubDate>Thu, 12 Mar 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-6-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.6.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-6-0</link>
            <description>_Warning_

* Security access from the load balancer to ECS has changed from requiring
  port 8443 to requiring the full high port range of 32768-65535. This
  allows us to run ECS in bridge mode and efficiently reuse IP addresses across
  Turbot core containers. 
  
* The outbound security group now allows port 80 outbound by default. This
  makes cloud-init in the ECS optimized image run much faster than only
  providing port 443 outbound.

* If you are upgrading from a previous TEF version, you will
  need to make the modifications listed below:

  *  Add ports 32768-65535 to the `Load Balancer Security Group` OUTBOUND to the `API Security Group`

  *  Add ports 32768-65535 to the `API Security Group` INBOUND from the `Load Balancer Security Group`

  *  Add port 80 to the `Outbound Internet Security Group` OUTBOUND to `0.0.0.0/0`


_What&apos;s new?_

* Use ECS on EC2 (instead of Fargate) to accelerate container startup
  time (particularly for stacks), increase cost efficiency at scale,
  and prepare for wider container use at the core level.</description>
            <pubDate>Mon, 09 Mar 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-5-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.5.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-5-0</link>
            <description>_What&apos;s new?_

* Workspace manager creation of turbot.com directories updated to use
  a server name (instead of a phase).</description>
            <pubDate>Thu, 05 Mar 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-10-0</guid>
            <title>Turbot Guardrails CLI v1.10.0</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-10-0</link>
            <description>_What&apos;s new?_

- Use `turbot test` to check GraphQL mutations (e.g. `updatePolicySetting`) are
  called as expected from controls.
- `turbot compose` no longer errors when a glob matches no source files.</description>
            <pubDate>Wed, 04 Mar 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-9-0</guid>
            <title>Turbot Guardrails CLI v1.9.0</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-9-0</link>
            <description>_What&apos;s new?_

- A new directive, `+schema` has been added for `turbot compose`. This allows
  you to include a specific item from a schema file, including all definitions
  which are referenced.
- `turbot template build` will now run even if there are changes on the local
  branch, if neither the `--use-fleet-branch` or `--use-instance-root-branch`
  arguments are set. This is useful when running building templates for the
  first time with local config updated but not committed.</description>
            <pubDate>Wed, 26 Feb 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-8-0</guid>
            <title>Turbot Guardrails CLI v1.8.0</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-8-0</link>
            <description>_What&apos;s new?_

- `turbot inspect --format changelog` now includes the uri of each control,
  policy, resource and action item.

_Bug fixes_

- `turbot up` was broken in 1.7.0. This has been fixed.
- `turbot pack` and `turbot publish` had to be run out of the target mod
  directory. They can now be run out of any directory by passing the `--dir`
  flag.</description>
            <pubDate>Mon, 24 Feb 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-7-0</guid>
            <title>Turbot Guardrails CLI v1.7.0</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-7-0</link>
            <description>_What&apos;s new?_

- `turbot aws credentials` now supports `--aws-profile &lt;aws_profile&gt;`,
  `--profile &lt;turbot_profile&gt;` and
  `--access-key &lt;turbot_access_key&gt; --secret-key &lt;turbot_secret_key&gt;`
  combinations.

_Bug fixes_

- `turbot test` was doing type coercion of input data before validation. It now
  expects correct types to be passed, matching the behavior of the Turbot
  server.</description>
            <pubDate>Sun, 23 Feb 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-4-1</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.4.1</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-4-1</link>
            <description>_Bug fixes_

- Auto scaling of storage for the primary read replica.</description>
            <pubDate>Fri, 21 Feb 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-6-0</guid>
            <title>Turbot Guardrails CLI v1.6.0</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-6-0</link>
            <description>_What&apos;s new?_

- Use `--no-color` to simplify the output of any command. Sometimes less is
  more.
- `turbot template build --git --branch &lt;branch-name&gt;` allows you to specify the
  branch the build operations will be committed onto.
- `turbot template build` no longer supports the `--config` flag. Use
  `template.yml` files instead.

_Bug fixes_

- `turbot install` was not downloading files. Now it does.
- `turbot template build` was creating `template.yml` files for every template
  instance. This is noisy and defeats the value of template inheritence, so has
  been stopped.</description>
            <pubDate>Wed, 12 Feb 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-5-1</guid>
            <title>Turbot Guardrails CLI v1.5.1</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-5-1</link>
            <description>_Bug fixes_

- `turbot template build --git` should checkout the original git branch at the
  end of the build. Broken in v1.5.0</description>
            <pubDate>Mon, 10 Feb 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-5-0</guid>
            <title>Turbot Guardrails CLI v1.5.0</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-5-0</link>
            <description>_What&apos;s new?_

- `turbot template build --git` now skips instances without a template-lock
  file, which cannot be resolved anyway.

_Bug fixes_

- `turbot up` and `turbot publish` were stalling for large mods.</description>
            <pubDate>Mon, 10 Feb 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-4-1</guid>
            <title>Turbot Guardrails CLI v1.4.1</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-4-1</link>
            <description>_Bug fixes_

- `turbot template build --git` should checkout the original git branch at the
  end of the build. Broken in v1.4.0.</description>
            <pubDate>Fri, 07 Feb 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-4-0</guid>
            <title>Turbot Guardrails CLI v1.4.0</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-4-0</link>
            <description>_What’s new?_

- Clearer reporting of errors when running `turbot template build`.
- `turbot template build --fleet-mode` now defaults to `update`, which is almost
  always the right choice.
- When running `turbot template build --git` it is no longer necessary to
  specify a base git branch, it sensibly assumes you want to use the current
  branch.
- Use `turbot pack --zip-file awesome.zip` to output mods with any name you
  prefer.</description>
            <pubDate>Thu, 06 Feb 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-3-1</guid>
            <title>Turbot Guardrails CLI v1.3.1</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-3-1</link>
            <description>_Bug fixes_

- `turbot template outdated` fixed to work with specific template definition
  directories.
- Only save successful template operations to the branch when using
  `turbot template build --git`. Previously we were polluting that goodness with
  failures as well.
- Limit `template-lock.yml` to data that is absolutely necessary, removing noise
  from change logs.
- Disabled `turbot template update`. Please use `turbot template build` instead,
  as you probably already were.</description>
            <pubDate>Wed, 05 Feb 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-3-0</guid>
            <title>Turbot Guardrails CLI v1.3.0</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-3-0</link>
            <description>_What&apos;s new?_

- `turbot inspect --output-format` will now accept either a file path to the template or the template string directly.
- Clearer output of the actions taken when running `turbot template build`.
- Automatic code merging when doing updates with `turbot template build` will now merge successful changes onto a single branch and write failed patches to the filesystem for easier review.</description>
            <pubDate>Tue, 04 Feb 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-4-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.4.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-4-0</link>
            <description>_What&apos;s new?_

- Support customization of parameters for `max_connections`, `deadlock_timeout`,
  `idle_in_transaction_session_timeout` and `statement_timeout`.</description>
            <pubDate>Mon, 03 Feb 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-4-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.4.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-4-0</link>
            <description>_What&apos;s new?_

* Added a lifecycle rule to automatically delete temporary data from S3.</description>
            <pubDate>Wed, 22 Jan 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-3-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.3.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-3-0</link>
            <description>_What&apos;s new?_

* Reduced scope of permissions granted to custom mod Lambda functions. These
  add extra levels of protection and take effect as mods are installed or
  updated in Turbot v5.5.0 or later.</description>
            <pubDate>Mon, 20 Jan 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-2-1</guid>
            <title>Turbot Guardrails CLI v1.2.1</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-2-1</link>
            <description>_Bug fixes_

- `turbot template build` has a special case &quot;provider&quot; field in the render
  context. Long term it will be removed. Short term, it should not break for
  vendor level mods like @turbot/aws or @turbot/linux.</description>
            <pubDate>Mon, 20 Jan 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-3-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.3.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-3-0</link>
            <description>_What&apos;s new?_

- `Instance Type for Replica DB` will now default to `Same as Primary DB`, which
  is a lot easier than having to set and maintain it manually when most of the
  time they are the same anyway.
- Choose a custom master username during install.</description>
            <pubDate>Thu, 16 Jan 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-2-0</guid>
            <title>Turbot Guardrails CLI v1.2.0</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-2-0</link>
            <description>_What&apos;s new?_

- View and confirm `turbot template build` actions before they happen. (Add
  `--yes` to keep the previous behavior.)
- Easily review success and failure after running `turbot template build` across
  many instances.

_Bug fixes_

- `turbot download` will now give up gracefully on failed downloads, relieving it of an eternity of failed retries.</description>
            <pubDate>Thu, 16 Jan 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-16-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.16.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-16-0</link>
            <description>_What&apos;s new?_

- Option to configure AWS Backup with daily, weekly and/or monthly snapshots of
  the primary database.
- Add Postgres v11.9 to supported versions list.
- CloudWatch Alarms added for freeable memory, read replica CPU and queue depth.
- RDS disk burst balance metrics added to TED dashboard.
- Elasticache metrics added to TED dashboard.
- Improve text and limit for Transaction ID Wraparound in TED dashboard.

_Requirements_

- TEF v1.30.0</description>
            <pubDate>Tue, 14 Jan 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-2-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.2.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-2-0</link>
            <description>_What&apos;s new?_

* Publish the alpha region as an SSM parameter so it can be used as a default
  in other areas - like TED&apos;s default location for the primary DB.</description>
            <pubDate>Tue, 14 Jan 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-2-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.2.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-2-0</link>
            <description>_Warning_

- Requires TEF v1.2.0 or later.
- The parameter `Instance Type for Replica DB` is new and must be set during
  upgrade. (Note: Fixed in v1.3.0 to use `Same as Primary DB` by default.)

_What&apos;s new?_

- The Turbot Audit Trail is stored in a CloudWatch Log group managed in TED. It
  will now be retained if the TED stack is deleted, avoiding loss of audit trail
  data in that rare scenario.
- Easily configure auto-scaling of the database storage up to a maximum value.
- Read replicas can now have a different instance class to the primary.
  Typically they have a lower load level, so we&apos;ve added flexibility to optimize
  costs.
- Default to using the alpha region (as defined in TEF) for primary DB install.</description>
            <pubDate>Tue, 14 Jan 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-1-1</guid>
            <title>Turbot Guardrails CLI v1.1.1</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-1-1</link>
            <description>_Bug fixes_

- Fix `turbot template build` crash added by v1.1.0.</description>
            <pubDate>Mon, 13 Jan 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-1-0</guid>
            <title>Turbot Guardrails CLI v1.1.0</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-1-0</link>
            <description>_What’s new?_

- Use `turbot aws credentials --account 123456789012 --profile my-account` to
  generate and save temporary AWS credentials into your local AWS profile.
  Easily work across many AWS accounts using your single Turbot profile.
- Filter `turbot template build` to target all instances of a specific template,
  which is great when you are in the process of converting code to use the
  template (some code in template management, some still custom).

_Bug fixes_

- `turbot test` was broken in v1.0.4 due to a missing dependency. Life is better with friends.</description>
            <pubDate>Mon, 13 Jan 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-1-1</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.1.1</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-1-1</link>
            <description>_Bug fixes_

* The Hive Manager and Workspace Manager lambda functions used during the
  workspace upgrade process were not properly connecting to the database using
  SSL during initial workspace creation (they were during upgrades). Our change
  to force SSL on the database in TED revealed this issue, which is now fixed.</description>
            <pubDate>Wed, 08 Jan 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/ted-v1-1-1</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.1.1</title>
            <link>https://turbot.com/guardrails/changelog/ted-v1-1-1</link>
            <description>_Bug fixes_

- Expanded the list of database instance classes available during install to
  include older generations (e.g. m3) which are required for AWS us-gov-west-1.
- Added the AWS RDS 2017 certificate as an option, since it&apos;s uniquely used and
  required in Gov Cloud installs.</description>
            <pubDate>Wed, 08 Jan 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-1-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.1.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-1-0</link>
            <description>_What&apos;s new?_

* TEF version is now published as an output parameter in CloudFormation. (We&apos;d
  rather that Service Catalog showed this automatically, but there is an AWS
  quirk that breaks that feature when Service Catalog versions are published
  using CloudFormation.)
* Workspace upgrades may now take up to 15 minutes before timing out. This
  allows us to run larger data migration jobs during the upgrade process.
  (Don&apos;t worry, we design these to be background tasks that don&apos;t affect
  availability during the upgrade.)
* Custom security groups are published as SSM parameters allowing them to be
  leveraged by the Turbot Guardrails Enterprise CloudFormation stacks to override
  per-version default security groups.

_Bug fixes_

* GovCloud installations require conditions in IAM to match the correct
  partition `arn:aws-us-gov:`.</description>
            <pubDate>Tue, 07 Jan 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-1-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.1.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-1-0</link>
            <description>_Warning_

- The AWS RDS certificate change requires a database reboot. This may cause a
  brief impact on availability. Please schedule this change for a suitable
  window.

_What&apos;s new?_

- SSL is now required by default for all connections to the database. We used
  SSL anyway, but now we enforce it at the DB level as an extra precaution.
- Upgrade database instances to the AWS RDS 2019 root certificate (their 2015
  certificate is expiring soon).</description>
            <pubDate>Tue, 07 Jan 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-0-4</guid>
            <title>Turbot Guardrails CLI v1.0.4</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-0-4</link>
            <description>_Bug fixes_

- `turbot template` should allow rendering of the filename as well as folder
  names, e.g. `src/{{instance}}/resource/types/{{instance}}.yml`.</description>
            <pubDate>Tue, 07 Jan 2020 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-0-3</guid>
            <title>Turbot Guardrails CLI v1.0.3</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-0-3</link>
            <description>_Bug fixes_

- `test.options` are useful, but not required, so `turbot test` should not crash if they are not set for a test.</description>
            <pubDate>Thu, 19 Dec 2019 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-0-2</guid>
            <title>Turbot Guardrails CLI v1.0.2</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-0-2</link>
            <description>_Bug fixes_

- Registry name validation should work for valid registries like turbot.com.
- `turbot test` has a `test.awsProfile` field to set the AWS profile to use when
  running tests locally. This has been moved into the generic, customizable
  `test.options.awsProile` location since it&apos;s relevant to AWS mods specifically
  rather than a core feature of Turbot.</description>
            <pubDate>Thu, 19 Dec 2019 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-0-0</guid>
            <title>Turbot Guardrails Enterprise Foundation (TEF) v1.0.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-0-0</link>
            <description>_What&apos;s new?_

* Initial version.
* CloudFormation design for deployment via Service Catalog.
* Foundation components: KMS keys, IAM roles, Log groups &amp; buckets.
* Network configuration with up to 3 tiers (public, turbot, database) across 3 availability zones in 3 regions.
* Automated VPC peering setup across regions.
* Subnet Groups and Security Groups for database and cache services.
* Optional gateway proxy for external event handling with an internal installation.
* Optional BYO network parameters for complex or pre-existing environments.</description>
            <pubDate>Wed, 18 Dec 2019 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-0-1</guid>
            <title>Turbot Guardrails CLI v1.0.1</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-0-1</link>
            <description>_Bug fixes_

- The default registry is now turbot.com. Other development registries have been
  cleaned up to reduce noise.
- Cleaned up available commands and their descriptions.</description>
            <pubDate>Wed, 18 Dec 2019 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/cli-v1-0-0</guid>
            <title>Turbot Guardrails CLI v1.0.0</title>
            <link>https://turbot.com/guardrails/changelog/cli-v1-0-0</link>
            <description>_What&apos;s new?_

- Easily manage Turbot credentials and profiles.
- Run graphql commands in scripts.
- Install and inspect mods.
- Build, compose &amp; test Turbot mods.
- Upload mods to Turbot for internal testing or use.
- Publish mods to the Turbot registry for public sharing.
- Use templates to accelerate the development of mods.</description>
            <pubDate>Wed, 18 Dec 2019 09:00:00 GMT</pubDate>
        </item>
        <item>
            <guid>https://turbot.com/guardrails/changelog/tef-v1-0-0</guid>
            <title>Turbot Guardrails Enterprise Database (TED) v1.0.0</title>
            <link>https://turbot.com/guardrails/changelog/tef-v1-0-0</link>
            <description>_What&apos;s new?_

- Initial version.
- CloudFormation design for deployment via Service Catalog.
- CloudFormation stack per hive (physical shard).
- Postgres design with primary, failover and regional read replicas.
- Encryption at rest for all data.
- Custom Resource for automatic database hive configuration.</description>
            <pubDate>Wed, 11 Dec 2019 09:00:00 GMT</pubDate>
        </item>
    </channel>
</rss>