Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Migratie to Trivy #112

Open
yu-iskw opened this issue Oct 25, 2023 · 11 comments
Open

Migratie to Trivy #112

yu-iskw opened this issue Oct 25, 2023 · 11 comments

Comments

@yu-iskw
Copy link

yu-iskw commented Oct 25, 2023

Overview

Thank you for the great Action. It enables us to keep good quality of terraform at scale. As you may know, tfsec was merged to Trivy. It would be great to use Trivy instead of tfsec. For instance,tfsec doesn't support new features in terraform 1.5+ any more.

Proposal

We may want to archive the repository and create a new repository copes with Trivy by reusing the great knowledge in the repository. Please let me know, if there is anything I can help.

@shogo82148
Copy link
Contributor

Your pull request is welcome!

@nayuta
Copy link

nayuta commented Nov 21, 2023

@shogo82148 Hi, I'm working on the issue and almost fixed other than README.md. Can I create a PR for this repository by fixing README.md?

nayuta#1

@shogo82148
Copy link
Contributor

@nayuta of course, you can. however I think nayuta#1 would be better to publish it as a new GitHub Action.

@shogo82148
Copy link
Contributor

I created a new repository https://github.com/reviewdog/action-trivy based on nayuta#1

@nayuta
Copy link

nayuta commented Nov 23, 2023

@shogo82148 Thank you! However, there are some bugs in the trivy for Terraform. We may need to wait for the next update to use...

@nayuta
Copy link

nayuta commented Dec 6, 2023

@shogo82148 I completed the test with the newest version of trivy, and it's worked. And I also created two PRs for supporting trivy commands and fixing build indicators on README.md.

reviewdog/action-trivy#5
reviewdog/action-trivy#4

Please inform me of some requirements to release the action-trivy.

@shogo82148
Copy link
Contributor

@nayuta Thanks! @review-dog invites you to the reviewdog organization; you can now create the v1.0.0 tag on https://github.com/reviewdog/action-trivy

@nayuta
Copy link

nayuta commented Dec 6, 2023

@shogo82148 Thank you for inviting me.

Could you check the other PR: reviewdog/action-trivy#5? This PR will change behavior from the original action-tfsec, so it's ok to merge into the next upcoming release.
(I'm so sorry for splitting the PR from the first one...)

I'll create a tag after hearing your answer.

@nayuta
Copy link

nayuta commented Dec 9, 2023

@shogo82148 Thank you for checking the PR.

And, I'm sorry for replying again. But I don't have permission to create a tag at action-trivy, but I have permission for this repo.

Could you fix this?

@shogo82148
Copy link
Contributor

@nayuta I've updated the repository permission. could you try again?

@nayuta
Copy link

nayuta commented Dec 10, 2023

@shogo82148 Thank you! I've done!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants