microsoft / security-devops-action

Microsoft Security DevOps for GitHub Actions.
MIT License
97 stars 44 forks source link

Specify IaC type when we use terrascan #82

Closed vidal777 closed 8 months ago

vidal777 commented 8 months ago

Basically, it's possible to specify iac types when we use terrascan tool? The thing is that terrascan automatically detects the diferents types based on the files. On a kustomize applying patch on diferents environments, terrascan detect k8s deployment and print some high vulnerability but in reality on the main deployment are resolved.

boAndron commented 8 months ago

Hello! Please check out our documentation on how to configure MSDO and the tools here You can set a build / environment variable called GDN_TERRASCAN_IACTYPE to configure the setting you asked about. Thanks!