security-review: scan CDK synthesized templates, skip only asset bundles (A2) #9
1 changed files with 6 additions and 1 deletions
|
|
@ -111,7 +111,12 @@ else note_missing gitleaks "brew install gitleaks"; fi
|
|||
if command -v checkov >/dev/null; then
|
||||
CKALL="$TMP/ck.json"; echo '[]' > "$CKALL"
|
||||
for p in $SCOPE_PATHS; do
|
||||
if [ -d "$p" ]; then RAW="$(checkov -d "$p" --skip-path cdk.out --skip-path node_modules --skip-path .venv --skip-path venv --skip-path .aws-sam --skip-path dist --skip-path build -o json --compact --quiet 2>/dev/null || true)"
|
||||
# --skip-path is a regex over the file path. Skip only the cdk.out asset.<hash>/
|
||||
# dependency bundles (the stall cause) + vendored/generated dirs — but KEEP
|
||||
# scanning cdk.out/<stack>.template.json, which is the real deploy artifact
|
||||
# (dropping it would silence genuine S3/IAM IaC findings). asset is anchored to
|
||||
# cdk.out so a source file literally named asset.* is not also excluded.
|
||||
if [ -d "$p" ]; then RAW="$(checkov -d "$p" --skip-path 'cdk\.out/asset\.' --skip-path node_modules --skip-path '\.venv' --skip-path venv --skip-path '\.aws-sam' --skip-path dist --skip-path build -o json --compact --quiet 2>/dev/null || true)"
|
||||
else RAW="$(checkov -f "$p" -o json --compact --quiet 2>/dev/null || true)"; fi
|
||||
[ -z "$RAW" ] && continue
|
||||
FC="$(echo "$RAW" | jq '[ (if type=="array" then .[] else . end).results.failed_checks // [] ] | add // []' 2>/dev/null || echo '[]')"
|
||||
|
|
|
|||
Reference in a new issue