constellation/.github/workflows/test-tfsec.yml
renovate[bot] 84fcf8d7f2
Update github actions dependencies (#294)
Co-authored-by: Paul Meyer <49727155+katexochen@users.noreply.github.com>
2022-10-18 13:00:41 +02:00

38 lines
821 B
YAML

name: Terraform security scanner
on:
workflow_dispatch:
push:
branches:
- main
paths:
- "**.tf"
pull_request:
paths:
- "**.tf"
permissions:
contents: read
pull-requests: write
jobs:
tfsec:
name: tfsec
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@1f9a0c22da41e6ebfa534300ef656657ea2c6707
with:
ref: ${{ github.event.pull_request.head.sha }}
- name: tfsec
uses: aquasecurity/tfsec-pr-commenter-action@d9fa64305ec243e19f9be1200dfc8e8154dc364f
with:
tfsec_formats: default,text
tfsec_args: --force-all-dirs
github_token: ${{ github.token }}
- name: tfsec summary
shell: bash
run: cat results.text | tail -n 27 >> $GITHUB_STEP_SUMMARY