Skip to content

tfsec issues with 9.2.2 #1311

@stevepatter

Description

@stevepatter

Describe the bug

Current (9.2.2) codebase does not fully pass security scans from aquasecurity tfsec (version 1.28.14), with 6 high risk issues identified, 1 medium & 3 low.

These should be resolved, as much as possible, with priority for the high risk issues, I think there'd be a mix of hardcoded parameters & user supplied enable/disable flags to address them

To Reproduce

Steps to reproduce the behavior:

  • clone terraform-aws-gitlab-runner repository
  • install tfsec
  • run tfsec with no additional parameters, it'll generate an output summary

Expected behavior

There should be no high risks reported by tfsec, and ideally no medium or low risk issues.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions