Skip to content

Config Mod Updates

Config Mod Updates #2

Workflow file for this run

name: checkov-scan
on: [pull_request]
jobs:
#build:
checkov:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v2
- name: Python 3.8
uses: actions/setup-python@v1
with:
python-version: 3.8
- name: Checkov Github Action
id: checkov
uses: bridgecrewio/checkov-action@master
with:
directory: /
soft_fail: true
quiet: true
skip_check:
'CKV_AZURE_41,CKV_AWS*'
#CKV_AZURE_41 "Ensure that the expiration date is set on all secrets"
framework: terraform
output_format: github_failed_only
#add comment
- name: add-checkov-comment
id: comment
uses: actions/github-script@v5
if: github.event_name == 'pull_request'
with:
github-token: ${{ secrets.GITHUB_TOKEN }}
script: |
const output = `#### Checkov Scan 📖: ${{ steps.checkov.outcome }}
Checkov
${{env.CHECKOV_RESULTS}}
*Pusher: @${{ github.actor }}, Action: ${{ github.event_name }}, Working Directory: ${{ github.workspace }}, Workflow: ${{ github.workflow }}*`
github.rest.issues.createComment({
issue_number: context.issue.number,
owner: context.repo.owner,
repo: context.repo.repo,
body: output
})