security-review: scan CDK synthesized templates, skip only asset bundles (A2) #9

Merged
amoussa1229 merged 1 commit from fix/checkov-surgical-cdk-exclusions into main 2026-06-17 21:07:54 +00:00

1 commit

Author SHA1 Message Date
b0d8b842e5 security-review: surgically exclude only cdk.out asset bundles from checkov (A2)
The prior exclusion (--skip-path cdk.out) stopped the CDK-repo stall but also
silenced checkov on cdk.out/<stack>.template.json — the actual deploy artifact —
losing real S3/IAM IaC coverage (CKV_AWS_53-56, CKV_AWS_111). Switch to skipping
only the cdk.out asset.<hash>/ dependency bundles (the stall cause) so the
synthesized templates are still scanned.

- --skip-path 'cdk\.out/asset\.' anchors to cdk.out so a source file literally
  named asset.* is not also excluded; keeps cdk.out/*.template.json scanned.
- venv/dist/build kept as bare names (match anywhere); .venv/.aws-sam escaped.

cfn-lint + semgrep already prune these trees (prior commit). gitleaks runs in
git-mode and respects .gitignore, so cdk.out is already skipped there.

Verified: shellcheck clean; synthetic cdk.out test confirms the stack template is
scanned while asset.* is skipped; the orchestrator's own --scanners-only gate
still exits 0 with suppressions (inert on non-CDK repos: A1==A2 findings here).
2026-06-17 17:06:05 -04:00