Fix Wiz Defend Passthrough severity function - #2068
Conversation
Map INFORMATIONAL to INFO and fall back to DEFAULT for unknown values, so severity() always returns a value Panther accepts (fixes #2057).
PR SummaryMedium Risk Overview Updates Reviewed by Cursor Bugbot for commit 78b20f7. Bugbot is set up for automated code reviews on this repo. Configure here. |
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 3660bfb. Configure here.

Summary
severity()function inWiz.Defend.Alert.Passthroughwas returningINFORMATIONAL, which is not in Panther's allowed set (INFO,LOW,MEDIUM,HIGH,CRITICAL).INFORMATIONAL→INFO, passes through allowed values, and falls back toDEFAULTotherwise — mirroring the recent FDR Passthrough fix in Fix FDR Passthrough Severity Function #2056.Test plan
pipenv run panther_analysis_tool test --filter RuleID=Wiz.Defend.Alert.Passthroughpasses (High/Low/Informational test cases)make fmt && make lintpass via pre-commit🤖 Generated with Claude Code