last sync: 2025-Jul-08 17:23:11 UTC

[Deprecated]: API apps that use Python should use the latest 'Python version'

Azure BuiltIn Policy definition

Source Azure Portal
Display name [Deprecated]: API apps that use Python should use the latest 'Python version'
Id 74c3584d-afae-46f7-a20a-6f8adba71a16
Version 3.0.0-deprecated
Details on versioning
Versioning Versions supported for Versioning: 1
3.0.0 (3.0.0-deprecated)
Built-in Versioning [Preview]
Category App Service
Microsoft Learn
Description Periodically, newer versions are released for Python software either due to security flaws or to include additional functionality. Using the latest Python version for API apps is recommended in order to take advantage of security fixes, if any, and/or new functionalities of the latest version. We recommend all customers who are still using API apps to implement the built-in policy called 'App Service apps that use Python should use the latest 'Python version''.
Cloud environments AzureCloud = true
AzureUSGovernment = unknown
AzureChinaCloud = unknown
Available in AzUSGov Unknown, no evidence if Policy definition is/not available in AzureUSGovernment
Assessment(s) Assessments count: 1
Assessment Id: c2c90d64-38e2-e984-1457-7f4a98168c72
DisplayName: Python should be updated to the latest version for API apps
Description: It's important to regularly update the Python software used in API apps to the latest version.
Newer versions often include security fixes and additional functionalities.
If not updated, the API apps may be exposed to security vulnerabilities present in older versions, potentially leading to breaches.
Staying updated ensures the apps benefit from the latest security patches and features.

Remediation description: To set the Python version for your API app, follow the instructions to show and set the version using the Azure CLI outlined in this document: https://aka.ms/configure-python
Categories: AppServices
Severity: Medium
preview: True
Mode Indexed
Type BuiltIn
Preview False
Deprecated True
Effect Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
RBAC role(s) none
Rule aliases THEN-ExistenceCondition (1)
Alias Namespace ResourceType Path PathIsDefault DefaultPath Modifiable
Microsoft.Web/sites/config/web.linuxFxVersion Microsoft.Web sites/config properties.linuxFxVersion True False
Rule resource types IF (1)
Compliance
The following 3 compliance controls are associated with this Policy definition '[Deprecated]: API apps that use Python should use the latest 'Python version'' (74c3584d-afae-46f7-a20a-6f8adba71a16)
Control Domain Control Name MetadataId Category Title Owner Requirements Description Info Policy#
K_ISMS_P_2018 2.10.1 K_ISMS_P_2018_2.10.1 K ISMS P 2018 2.10.1 2.10 Establish Procedures for Managing the Security of System Operations Shared n/a Establish and implement operating procedures for managing the security of system operations such as designating system administrators, updating policies, changing rulesets, monitoring events, managing policy implementations or exceptions. 455
K_ISMS_P_2018 2.10.2 K_ISMS_P_2018_2.10.2 K ISMS P 2018 2.10.2 2.10 Establish Protective Measures for Administrator Privileges and Security Configurations Shared n/a Establish and implement protective measures with regard to administrator privileges and security configurations to ensure that important information and personal information are not exposed as a result of unauthorized access by service type or misconfigurations. 431
K_ISMS_P_2018 2.10.8 K_ISMS_P_2018_2.10.8 K ISMS P 2018 2.10.8 2.10 Apply the Latest Patches to Software and Hardware Shared n/a Apply the latest patches to software and hardware to prevent vulnerabilities in operating systems and security systems. If the latest patch cannot be applied, supplemental protective measures must be implemented such as exception approval. 10
Initiatives usage
Initiative DisplayName Initiative Id Initiative Category State Type polSet in AzUSGov
K ISMS P 2018 e0782c37-30da-4a78-9f92-50bfe7aa2553 Regulatory Compliance GA BuiltIn unknown
History
Date/Time (UTC ymd) (i) Change type Change detail
2022-07-01 16:32:34 change Version remains equal, new suffix: deprecated (3.0.0 > 3.0.0-deprecated)
2021-03-02 15:11:40 change Major (2.0.0 > 3.0.0)
2020-10-20 13:29:33 change Major (1.0.0 > 2.0.0)
2019-11-12 19:11:12 add 74c3584d-afae-46f7-a20a-6f8adba71a16
JSON compare
compare mode: version left: version right:
JSON
api-version=2021-06-01
EPAC