bridgecrewio / checkov

Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.
https://www.checkov.io/
Apache License 2.0
7k stars 1.1k forks source link

Feature request: Integration with Reviewdog #510

Closed mdesmarest closed 3 years ago

mdesmarest commented 4 years ago

Please integrate Checkov Github action with Reviewdog below, they host a template to make it easy to build and host the action. Using a tool like this allows you to run checks against changes as the workflow action runs on pull requests and will allow issues to be address and resolved on the entirety of the repository separately. Without this pull requests may fail for errors not relates to changes that are being pushed.

https://github.com/reviewdog/reviewdog

https://github.com/reviewdog/action-template

also please allow these flags as this makes it easier to centralize rules within one repo and allows for deployment to workflows without having to update yaml files. It would great to reference a set folder of static rules via the --external-checks-dir and bypass the main scan all together.

--external-checks-git

--external-checks-dir

mlschindler commented 4 years ago

+1

stale[bot] commented 3 years ago

Thanks for contributing to Checkov! We've automatically marked this issue as stale to keep our issues list tidy, because it has not had any activity for 6 months. It will be closed in 14 days if no further activity occurs. Commenting on this issue will remove the stale tag. If you want to talk through the issue or help us understand the priority and context, feel free to add a comment or join us in the Checkov slack channel at https://slack.bridgecrew.io Thanks!

stale[bot] commented 3 years ago

Closing issue due to inactivity. If you feel this is in error, please re-open, or reach out to the community via slack: https://slack.bridgecrew.io Thanks!