Open tschechniker opened 1 year ago
this has made many engineers at my org very unhappy with me, would love to see some development on this one.
+1 for this. Can't modify the external modules.
+1 for this please :pray:
+1 on this
Also +1 for this one please - thanks
+1 wasn't that already implemented in https://github.com/bridgecrewio/checkov/issues/777 and https://github.com/bridgecrewio/checkov/pull/1629 ? Does this mean there's a regression?
We have the same problems
module "gitlab_project" {
source = "gitlab.com/my-org/project/gitlab"
version = "16.6.0"
#checkov:skip=CKV_GLB_4: "Ensure GitLab commits are signed"
reject_unsigned_commits = false
}
We are using --download-external-modules true
and CHECKOV_EXPERIMENTAL_TERRAFORM_MANAGED_MODULES=True
Error:
Check: CKV_GLB_4: "Ensure GitLab commits are signed"
+1
+1
+1
+1
Can someone please add a full example that doesn't work? thx.
When tested with this test - https://github.com/bridgecrewio/checkov/blob/0197bfc9d5a26c30ff7e2d3186e7866774c1bb1c/tests/terraform/runner/test_runner.py#L618
And added suppression to this module - https://github.com/bridgecrewio/checkov/blob/0197bfc9d5a26c30ff7e2d3186e7866774c1bb1c/tests/terraform/runner/resources/multiple_module_versions/main.tf#L1
(+ changed the source to be "git::https://github.com...." and not "terraform-aws-modules/ec2-instance/aws")
And everything works as expected, the resources with violations are now in the the skipped resources list.
@tsmithv11 FYI
Describe the issue As this issue describes Feature request: Support checkov:skip in modules skipping findings inside modules should work now. But when we use external modules it does not work. Checkov seems to test the external modules without any context from the "calling" reference.
Examples Please share an example code sample (in the IaC of your choice) + the expected outcomes.
Version (please complete the following information):
Additional context We set download-external-modules: true