constellation/.github/workflows/test-tfsec.yml

42 lines
1001 B
YAML
Raw Normal View History

2022-09-20 07:38:37 -04:00
name: Terraform security scanner
on:
workflow_dispatch:
push:
branches:
- main
- "release/**"
2022-09-20 07:38:37 -04:00
paths:
- "**.tf"
- "./github/workflows/test-tfsec.yml"
2022-09-20 07:38:37 -04:00
pull_request:
paths:
- "**.tf"
- "./github/workflows/test-tfsec.yml"
2022-09-20 07:38:37 -04:00
permissions:
contents: read
pull-requests: write
jobs:
tfsec:
name: tfsec
runs-on: ubuntu-22.04
2022-09-20 07:38:37 -04:00
steps:
- name: Checkout
uses: actions/checkout@ac593985615ec2ede58e132d2e21d2b1cbd6127c # v3.3.0
2022-09-20 07:38:37 -04:00
with:
ref: ${{ !github.event.pull_request.head.repo.fork && github.head_ref || '' }}
2022-09-20 07:38:37 -04:00
- name: tfsec
uses: aquasecurity/tfsec-pr-commenter-action@7a44c5dcde5dfab737363e391800629e27b6376b
2022-09-20 07:38:37 -04:00
with:
soft_fail_commenter: true
2022-09-20 07:38:37 -04:00
tfsec_formats: default,text
tfsec_args: --force-all-dirs
github_token: ${{ github.token }}
- name: tfsec summary
shell: bash
run: tail -n 27 results.text >> "$GITHUB_STEP_SUMMARY"