-
-
Notifications
You must be signed in to change notification settings - Fork 10
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Terraform projects: Transition from tfsec to trivy #3753
Comments
dduportal
changed the title
Terraform projects: Transition from trsec to tricy
Terraform projects: Transition from trsec to trivy
Sep 17, 2023
dduportal
changed the title
Terraform projects: Transition from trsec to trivy
Terraform projects: Transition from tfsec to trivy
Sep 21, 2023
dduportal
added a commit
to jenkins-infra/shared-tools
that referenced
this issue
Sep 23, 2023
Ref. jenkins-infra/helpdesk#3753 Signed-off-by: Damien Duportal <[email protected]>
dduportal
added a commit
to jenkins-infra/shared-tools
that referenced
this issue
Sep 23, 2023
Ref. jenkins-infra/helpdesk#3753 Signed-off-by: Damien Duportal <[email protected]>
dduportal
added a commit
to jenkins-infra/shared-tools
that referenced
this issue
Sep 23, 2023
* feat(terraform) use trivy for static validation or fallback to tfsec Ref. jenkins-infra/helpdesk#3753 Signed-off-by: Damien Duportal <[email protected]> * chore: Update Jenkinsfile in groovy code Made with ❤️️ by updatecli --------- Signed-off-by: Damien Duportal <[email protected]> Co-authored-by: Damien Duportal <[email protected]> Co-authored-by: Jenkins Infra Bot (updatecli) <[email protected]>
dduportal
added a commit
to jenkins-infra/shared-tools
that referenced
this issue
Sep 23, 2023
This was referenced Sep 23, 2023
dduportal
added a commit
to jenkins-infra/azure
that referenced
this issue
Sep 23, 2023
Related to jenkins-infra/helpdesk#3753 Signed-off-by: Damien Duportal <[email protected]>
This was referenced Sep 23, 2023
dduportal
modified the milestones:
infra-team-sync-2023-09-26,
infra-team-sync-2023-10-03
Sep 26, 2023
This was referenced Sep 28, 2023
dduportal
added a commit
to jenkins-infra/shared-tools
that referenced
this issue
Oct 3, 2023
Closing as |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
As per https://github.com/aquasecurity/tfsec, Aqua Security is transitioning their development effort from tfsec to trivy and recommend users to do the same.
recent 1.28.3 version of tfsec starts showing a message about this.
we should evaluate this change.
(edit)
Todo list:
trivy
by default if found, or fallback totfsec
(backwards compatibility)hashicorp-tools
docker image version to 1.0.12 shared-tools#120tfsec:ignore
inline commands totrivy:ignore
(ref. Support Inline Filtering aquasecurity/trivy#2961)oracle(gotta be deleted)0.45.1
packer-images#815tfsec
in jenkins-infraThe text was updated successfully, but these errors were encountered: