bridgecrewio / checkov

Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.
https://www.checkov.io/
Apache License 2.0
6.75k stars 1.08k forks source link

docs: GitLab CI Component for Checkov, SAST JSON Results First When Feature is present, do not fail build for single scanner new findings #6278

Open DarwinJS opened 2 months ago

DarwinJS commented 2 months ago

Updating docs for Checkov GitLab CI Component and advising not doing build failures to prevent new vulnerabilities from being accepted into production bound code.

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

[//]: # "

PR Title

Be aware that we use the title to create changelog automatically and therefore only allow specific prefixes
- break:    to indicate a breaking change, this supersedes any of the types
- feat:     to indicate new features or checks
- fix:      to indicate a bugfix or handling of edge cases of existing checks
- docs:     to indicate an update to our documentation
- chore:    to indicate adjustments to workflow files or dependency updates
- platform: to indicate a change needed for the platform
Additionally a scope is needs to be added to the prefix, which indicates the targeted framework, in doubt choose 'general'.
#    
Allowed prefixs:
ansible|argo|arm|azure|bicep|bitbucket|circleci|cloudformation|dockerfile|github|gha|gitlab|helm|kubernetes|kustomize|openapi|sast|sca|secrets|serverless|terraform|general|graph|terraform_plan|terraform_json
#
ex.
feat(terraform): add CKV_AWS_123 to ensure that VPC Endpoint Service is configured for Manual Acceptance

"

Description

I had previous created the GitLab CI include that I believe some of your code on this page was from (I may have even submitted a PR). I have updated my original code to create a fairly capable GitLab CI Component and bumped those improvements on to your page here.

This code also detects if the CI is running under a context where Security Dashboards are licensed (currently GitLab Ultimate) and outputs json sast automatically as this creates maximum value for your customers. Checkov findings then appear in the MR Widget, Security Dashboard and can be part of Security Policy Merge Approvals. (See the attachment that shows this in action for Amazon CodeGuru SAST Scanning findings.

image

Most notable

Fixes # (issue)

New

Description

Include a description of what makes it a violation and any relevant external links.

Fix

How does someone fix the issue in code and/or in runtime?

Checklist: