Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Checkov scanning Terraform plan needs to be updated. #6204

Open
junhu73 opened this issue Apr 24, 2024 · 1 comment
Open

Checkov scanning Terraform plan needs to be updated. #6204

junhu73 opened this issue Apr 24, 2024 · 1 comment
Labels
checks Check additions or changes

Comments

@junhu73
Copy link

junhu73 commented Apr 24, 2024

Describe the issue

Many issues related Checkov feature to scan terraform plan were closed prematurely without someone from Checkov making assessment whether this is bug or misuse of the tool. If Checkov does not support child module in the Terraform plan scanning when value is not known until after applying, the documentation needs to be updated. The same observation exists with Checkov connection and filter type policy not working with module resources while scanning Terraform plan.

Examples
#2762
#5387
#4638
#1116
there were more ...

Version (please complete the following information):

  • Checkov Version varies. most current versions still have the same issue.

Additional context

please update documentation to call out the limitation if scan Terraform plan is not fully supported. Or add as feature request so these issues can closed correctly.

@junhu73 junhu73 added the checks Check additions or changes label Apr 24, 2024
@sourava01
Copy link
Contributor

sourava01 commented Apr 24, 2024

Hi @junhu73
I have also raised a similar issue, ref - #6135
The issue seems to be with the graph builder in checkov, mainly not creating edges properly.

I raised a PR (#6145) to address some of the bugs, but not getting active responses in the PR :( .

Lets hope someone from checkov team looks into it on priority!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
checks Check additions or changes
Projects
None yet
Development

No branches or pull requests

2 participants