Using tfsec to scan Terraform Code || tfsec with GitHub Actions

preview_player
Показать описание
Topic: Avoiding misconfiguration using TFSEC for Terraform Code

Agenda of the talk
* Terraform Introduction
* What & Why of TFSEC
* [DEMO] Scanning your code
* TFSEC advanced features
- Custom checks
- Ignoring checks
- expiry, workspace filtering
* When to use tfsec: Shift left Approach
* Using it on CI
* VSCode extension

Link to download TFSEC
=======================

Description:
Security misconfiguration is a vulnerability that has been there on the OWASP top 10 for a while. As we move towards cloud and using Infrastructure as code it becomes inevitable for us to make sure we test our code for any mis-configurations that exist before the code is used in production. The session will talk about TFSEC, a SAST tool used to test terraform code to help build secure infrastructure code.

Speakers: Nalinikanth (Nal) & Sudhamsh K

#tfsec #terraform #thoughtworks
Рекомендации по теме
Комментарии
Автор

tfsec is being rolled into Trivey within Aqua

WilsonMar