Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add misconfiguration scans #1

Open
lancehampton opened this issue Jun 18, 2024 · 0 comments
Open

Add misconfiguration scans #1

lancehampton opened this issue Jun 18, 2024 · 0 comments
Assignees
Labels
enhancement New feature or request

Comments

@lancehampton
Copy link
Collaborator

lancehampton commented Jun 18, 2024

Goal

Provide a quick and easy source of evidence which shows the configuration of the modules in this repo enforce the security settings defined in the CIS Software Supply Chain Security Guide v1.0.

Requirements

  1. Use Trivy and custom misconfiguration checks to run against the GitHub resources defined in these Terraform modules. Some basic examples are shown in the trivy-checks repo.
  2. Configure the trivy-action to run the checks on a regular basis (e.g. daily, weekly).
@lancehampton lancehampton added the enhancement New feature or request label Jun 18, 2024
@lancehampton lancehampton self-assigned this Jun 18, 2024
@lancehampton lancehampton changed the title Configure misconfiguration scans Add misconfiguration scans Jun 24, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

1 participant