Skip to content

Secure Code Analysis #659

Secure Code Analysis

Secure Code Analysis #659

Triggered via schedule December 11, 2024 02:10
Status Failure
Total duration 7m 59s
Artifacts

code-scanning.yml

on: schedule
Matrix: tflint
Fit to window
Zoom out
Zoom in

Annotations

11 errors and 3 warnings
trivy
Code Scanning could not process the submitted SARIF file: locationFromSarifResult: expected artifact location, locationFromSarifResult: expected artifact location, locationFromSarifResult: expected artifact location
checkov: terraform/environments/apex/backups.tf#L6
CKV_AWS_166: "Ensure Backup Vault is encrypted at rest using KMS CMK"
checkov: terraform/environments/apex/backups.tf#L64
CKV_AWS_166: "Ensure Backup Vault is encrypted at rest using KMS CMK"
checkov: terraform/environments/apex/cloudfront.tf#L157
CKV_AWS_300: "Ensure S3 lifecycle configuration sets period for aborting failed uploads"
checkov: terraform/environments/apex/cloudfront.tf#L177
CKV_AWS_310: "Ensure CloudFront distributions should have origin failover configured"
checkov: terraform/environments/apex/cloudfront.tf#L177
CKV_AWS_374: "Ensure AWS CloudFront web distribution has geo restriction enabled"
checkov: terraform/environments/apex/cloudfront.tf#L177
CKV_AWS_305: "Ensure CloudFront distribution has a default root object configured"
checkov: terraform/environments/apex/cloudfront.tf#L295
CKV_AWS_233: "Ensure Create before destroy for ACM certificates"
checkov: terraform/environments/apex/ec2.tf#L6
CKV_AWS_79: "Ensure Instance Metadata Service Version 1 is not enabled"
checkov: terraform/environments/apex/ec2.tf#L80
CKV_AWS_24: "Ensure no security groups allow ingress from 0.0.0.0:0 to port 22"
checkov: terraform/environments/apex/ec2.tf#L108
CKV_AWS_23: "Ensure every security group and rule has a description"
tflint (ubuntu-latest)
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
trivy
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
checkov
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636