modernisation-platform icon indicating copy to clipboard operation
modernisation-platform copied to clipboard

Move from tfsec to trivy

Open davidkelliott opened this issue 1 year ago • 2 comments

User Story

As a Modernisation Platform Engineer I want to migrate from tfsec to trivy So that we continue to benefit from up-to-date secure code analysis

trivy is now being favoured over tfsec, they are still using the same base rules so this isn't urgent but we should still change at some point. https://github.com/aquasecurity/tfsec/blob/master/docs/guides/trivy.md

User Type(s)

Modernisation Platform Engineer

Value

The migration from tfsec to trivy is discussed here. Trivy is now being favoured over tfsec. While they are still using the same base rules this isn't urgent but we should change to ensure we stay in line with the most up-to-date tooling, and prevent the need to urgently change should tfsec be fully deprecated.

Assumptions / Hypothesis / Questions / Unknowns

Definition of done

  • [ ] references to tfsec actions in Modernisation Platform repositories updated
  • [ ] ministryofjustice/github-actions/terraform-static-analysis tool updated
  • [ ] another team member has reviewed
  • [ ] tests are green

Reference

How to write good user stories Moving towards configuration scanning with Trivy

davidkelliott avatar Mar 08 '23 14:03 davidkelliott

This issue is stale because it has been open 90 days with no activity.

github-actions[bot] avatar Jun 07 '23 01:06 github-actions[bot]

currently not urgent, but this might change. Though only for code formatting

SimonPPledger avatar Jul 06 '23 14:07 SimonPPledger

created code for trivy and tested it on a personl repo and found to be working going to add code to the modernisation platform repo via a pr shortly

markgov avatar Jan 09 '24 12:01 markgov

https://github.com/ministryofjustice/modernisation-platform/pull/5938

markgov avatar Jan 15 '24 14:01 markgov

https://github.com/ministryofjustice/modernisation-platform/pull/5978

markgov avatar Jan 15 '24 14:01 markgov

This is now complete new issue raised to do all other mod platform repos

markgov avatar Jan 15 '24 14:01 markgov