Skip to content

Containment plan fix#44089

Open
OmriItzhak wants to merge 32 commits into
masterfrom
containment_plan_fix
Open

Containment plan fix#44089
OmriItzhak wants to merge 32 commits into
masterfrom
containment_plan_fix

Conversation

@OmriItzhak
Copy link
Copy Markdown
Contributor

Status

  • In Progress
  • Ready
  • In Hold - (Reason for hold)

Related Issues

fixes:https://jira-dc.paloaltonetworks.com/browse/XSUP-65857

Description

T1059 - Command and Scripting Interpreter:

  • Fixed the default value of the AutoContainment input passed to the Containment Plan sub-playbook from true to false, preventing unintended automatic containment actions.

T1036 - Masquerading

  • Fixed the default value of the AutoContainment input passed to the Containment Plan sub-playbook from true to false, preventing unintended automatic containment actions.

Containment Plan

  • Added case-insensitive comparison for the AutoContainment input condition checks, ensuring the playbook correctly handles True/False values regardless of casing.

Containment Plan - Isolate Device

  • Fixed endpoint isolation condition logic: isolation now triggers when either an Endpoint ID or an Endpoint Hostname is provided, instead of requiring both simultaneously.

Must have

  • Tests
  • Documentation

@content-bot
Copy link
Copy Markdown
Contributor

🤖 AI-Powered Code Review Available

You can leverage AI-powered code review to assist with this PR!

Available Commands:

  • @marketplace-ai-reviewer start review - Initiate a full AI code review
  • @marketplace-ai-reviewer re-review - Incremental review for new commits

@OmriItzhak OmriItzhak added docs-approved ready-for-pipeline-running Whether the pr is ready for running the whole pipeline, including testing on SAAS machines skip-ai-review and removed skip-ai-review labels Apr 29, 2026
@OmriItzhak OmriItzhak added the ready-for-ai-review The PR is ready for reviewing the PR with the AI Reviewer. label Apr 29, 2026
@marketplace-ai-reviewer marketplace-ai-reviewer removed the ready-for-ai-review The PR is ready for reviewing the PR with the AI Reviewer. label Apr 29, 2026
@marketplace-ai-reviewer
Copy link
Copy Markdown
Contributor

🤖 Analysis started. Please wait for results...

@marketplace-ai-reviewer
Copy link
Copy Markdown
Contributor

🤖 AI Review Disclaimer

This review was generated by an AI-powered tool and may contain inaccuracies. Please be advised, and we extend our sincere apologies for any inconvenience this may cause.

Copy link
Copy Markdown
Contributor

@marketplace-ai-reviewer marketplace-ai-reviewer left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for your contribution! I've reviewed the updates and just have a quick suggestion regarding the metadata. Please ensure the vendor name is added to the keywords in the pack_metadata.json files to help improve searchability. Let me know if you have any questions!

Additionally, please address the following file-level notes:

  • Packs/CommonPlaybooks/pack_metadata.json: Add vendor name to keywords
  • Packs/Core/pack_metadata.json: Add vendor name to keywords

@melamedbn, @OmriItzhak please review and approve the results generated by the AI Reviewer by responding 👍 on this comment.

@content-bot

This comment has been minimized.

@content-bot

This comment has been minimized.

@content-bot
Copy link
Copy Markdown
Contributor

This PR was automatically updated by a GitHub Action

  • CommonPlaybooks pack version was bumped to 2.7.35.

To stop automatic version bumps, add the ignore-auto-bump-version label to the github PR.

@content-bot

This comment has been minimized.

@content-bot
Copy link
Copy Markdown
Contributor

This PR was automatically updated by a GitHub Action

  • Core pack version was bumped to 3.5.43.

To stop automatic version bumps, add the ignore-auto-bump-version label to the github PR.

@content-bot

This comment has been minimized.

@content-bot
Copy link
Copy Markdown
Contributor

This PR was automatically updated by a GitHub Action

  • Core pack version was bumped to 3.5.44.

To stop automatic version bumps, add the ignore-auto-bump-version label to the github PR.

@content-bot
Copy link
Copy Markdown
Contributor

This PR was automatically updated by a GitHub Action

  • Core pack version was bumped to 3.5.45.

To stop automatic version bumps, add the ignore-auto-bump-version label to the github PR.

@content-bot

This comment has been minimized.

@content-bot
Copy link
Copy Markdown
Contributor

This PR was automatically updated by a GitHub Action

  • Core pack version was bumped to 3.5.46.

To stop automatic version bumps, add the ignore-auto-bump-version label to the github PR.

@content-bot

This comment has been minimized.

@content-bot
Copy link
Copy Markdown
Contributor

This PR was automatically updated by a GitHub Action

  • Core pack version was bumped to 3.5.47.
  • CommonPlaybooks pack version was bumped to 2.7.36.

To stop automatic version bumps, add the ignore-auto-bump-version label to the github PR.

@content-bot
Copy link
Copy Markdown
Contributor

This PR was automatically updated by a GitHub Action

  • Core pack version was bumped to 3.5.48.

To stop automatic version bumps, add the ignore-auto-bump-version label to the github PR.

@content-bot
Copy link
Copy Markdown
Contributor

This PR was automatically updated by a GitHub Action

  • Core pack version was bumped to 3.5.49.

To stop automatic version bumps, add the ignore-auto-bump-version label to the github PR.

@content-bot
Copy link
Copy Markdown
Contributor

Validate summary
The following errors were thrown as a part of this pr: .
If the AG100 validation in the pre-commit GitHub Action fails, the pull request cannot be force-merged.

Verdict: PR can be force merged from validate perspective? ✅

@content-bot
Copy link
Copy Markdown
Contributor

🔍 AI Triage Report Available

An automated triage report has been generated for this pipeline.

Status: failed
Report ID: 63c0f14cb94a7f5e

📋 Triage Report
💡 Resolutions are available in the full report.

⚠️ AI-generated triage. Validate before acting.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

docs-approved ready-for-pipeline-running Whether the pr is ready for running the whole pipeline, including testing on SAAS machines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants