Skip to content

chore: synced file(s) with cds-snc/site-reliability-engineering #1821

chore: synced file(s) with cds-snc/site-reliability-engineering

chore: synced file(s) with cds-snc/site-reliability-engineering #1821

Workflow file for this run

name: "Terraform security scan"
on:
push:
branches:
- main
pull_request:
branches:
- main
jobs:
terraform-security-scan:
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
module:
- athena_access_logs
- ecs
- notify_slack
- user_login_alarm
- vpc
- rds_activity_stream
- resolver_dns
- S3
- S3_log_bucket
- S3_scan_object
- schedule_shutdown
- lambda
- lambda_response
steps:
- name: Checkout
uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.1.7
- name: Checkov security scan
id: checkov
uses: bridgecrewio/checkov-action@ffb0926e337a96499d5d11d4b83733672f2fe3c3 # latest as of Aug 10, 2021
with:
directory: ${{ matrix.module }}
framework: terraform
output_format: cli
download_external_modules: true