From d94c65bcb214a9fff6d24f0ae29e1de85ce30247 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Wed, 8 Jul 2026 16:30:42 -0400 Subject: [PATCH] fix(scanner): skip gitignored cdk.out synth output in checkov scan (INFRA-144) checkov scanned cdk.out/.template.json, which is gitignored generated synth output. A dev with a stale cdk.out lying around would false-block unrelated pushes on CKV_AWS_111 raised against CDK-generated roles (LogRetention, asset publishing) that are not authored source. Broaden the checkov --skip-path from cdk.out/asset. to the whole cdk.out/ tree so it treats synth output the same as semgrep (--exclude cdk.out) and cfn-lint (cdk.out prune) already do. Authored IaC checkov parses (SAM/CFN template.yaml, Terraform) is tracked source and is still fully scanned; verified a planted wildcard IAM policy in tracked source still trips CKV_AWS_111 and blocks. --- review.sh | 17 +++++++++++------ 1 file changed, 11 insertions(+), 6 deletions(-) diff --git a/review.sh b/review.sh index 73d294a..2314db5 100755 --- a/review.sh +++ b/review.sh @@ -121,12 +121,17 @@ else note_missing gitleaks "brew install gitleaks"; fi if command -v checkov >/dev/null; then CKALL="$TMP/ck.json"; echo '[]' > "$CKALL" for p in $SCOPE_PATHS; do - # --skip-path is a regex over the file path. Skip only the cdk.out asset./ - # dependency bundles (the stall cause) + vendored/generated dirs — but KEEP - # scanning cdk.out/.template.json, which is the real deploy artifact - # (dropping it would silence genuine S3/IAM IaC findings). asset is anchored to - # cdk.out so a source file literally named asset.* is not also excluded. - if [ -d "$p" ]; then RAW="$(checkov -d "$p" --skip-path 'cdk\.out/asset\.' --skip-path node_modules --skip-path '\.claude' --skip-path '\.venv' --skip-path venv --skip-path '\.aws-sam' --skip-path dist --skip-path build -o json --compact --quiet 2>/dev/null || true)" + # --skip-path is a regex over the file path. Skip the ENTIRE cdk.out/ synth tree + # plus other generated/vendored dirs. cdk.out/ is gitignored generated output, not + # source — gating pushes on it false-blocks unrelated work (INFRA-144): checkov + # raises CKV_AWS_111 (and similar) on CDK-generated roles (LogRetention, asset + # publishing, bootstrap) that only exist post-synth and that a dev may have lying + # around from a stale `cdk synth`. Authored IaC that checkov actually parses + # (SAM/CFN template.yaml, Terraform) is TRACKED source and is still fully scanned; + # CDK synth output is covered by the agentic /sh-security-review pass, not this + # deterministic gate. Matches semgrep's `--exclude cdk.out` and cfn-lint's cdk.out + # prune, so all three scanners now treat synth output consistently. + if [ -d "$p" ]; then RAW="$(checkov -d "$p" --skip-path 'cdk\.out/' --skip-path node_modules --skip-path '\.claude' --skip-path '\.venv' --skip-path venv --skip-path '\.aws-sam' --skip-path dist --skip-path build -o json --compact --quiet 2>/dev/null || true)" else RAW="$(checkov -f "$p" -o json --compact --quiet 2>/dev/null || true)"; fi [ -z "$RAW" ] && continue FC="$(echo "$RAW" | jq '[ (if type=="array" then .[] else . end).results.failed_checks // [] ] | add // []' 2>/dev/null || echo '[]')"