This VS Code extension is for tfsec. A static analysis security scanner for your Terraform code that discovers problems with your infrastructure before hackers do.
The Findings Explorer displays an an organised view the issues that have been found in the current workspace.
The code runs tfsec in a VS Code integrated terminal so you can see the the output - when it is complete, press the refresh button to reload.
Right clicking on an tfsec code will let you view the associated page on https://aquasecurity.github.io/tfsec/latest
Issues can be ignored by right clicking the location in the explorer and selecting ignore this issue
.
Ignore codes will be automatically resolved and the description of the error will be displayed inline.
In the Explorer view, you can right click on a folder or .tf file and select Ignore path during tfsec runs
. This will pass the path to --exclude-path
when running tfsec and is only applicable to this workspace on this machine.
To remove ignores, edit the tfsec.excludedPath
in the .vscode/settings.json
file of the current workspace.
tfsec-check-file
in a yaml file to create custom checktfsec-custom-check
in the existing check file to add a new custom checkv1.0.0-rc.2