Secure Code Analysis #651
code-scanning.yml
on: schedule
trivy
3m 8s
checkov
7m 31s
Matrix: tflint
Annotations
11 errors and 3 warnings
trivy
Code Scanning could not process the submitted SARIF file:
locationFromSarifResult: expected artifact location, locationFromSarifResult: expected artifact location, locationFromSarifResult: expected artifact location
|
checkov:
terraform/environments/apex/backups.tf#L6
CKV_AWS_166: "Ensure Backup Vault is encrypted at rest using KMS CMK"
|
checkov:
terraform/environments/apex/backups.tf#L64
CKV_AWS_166: "Ensure Backup Vault is encrypted at rest using KMS CMK"
|
checkov:
terraform/environments/apex/cloudfront.tf#L157
CKV_AWS_300: "Ensure S3 lifecycle configuration sets period for aborting failed uploads"
|
checkov:
terraform/environments/apex/cloudfront.tf#L177
CKV_AWS_310: "Ensure CloudFront distributions should have origin failover configured"
|
checkov:
terraform/environments/apex/cloudfront.tf#L177
CKV_AWS_374: "Ensure AWS CloudFront web distribution has geo restriction enabled"
|
checkov:
terraform/environments/apex/cloudfront.tf#L177
CKV_AWS_305: "Ensure CloudFront distribution has a default root object configured"
|
checkov:
terraform/environments/apex/cloudfront.tf#L295
CKV_AWS_233: "Ensure Create before destroy for ACM certificates"
|
checkov:
terraform/environments/apex/ec2.tf#L6
CKV_AWS_79: "Ensure Instance Metadata Service Version 1 is not enabled"
|
checkov:
terraform/environments/apex/ec2.tf#L77
CKV_AWS_24: "Ensure no security groups allow ingress from 0.0.0.0:0 to port 22"
|
checkov:
terraform/environments/apex/ec2.tf#L105
CKV_AWS_23: "Ensure every security group and rule has a description"
|
tflint (ubuntu-latest)
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
|
trivy
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
|
checkov
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
|