-
-
Notifications
You must be signed in to change notification settings - Fork 90
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
feat: add bridgecrewio/checkov #20226
feat: add bridgecrewio/checkov #20226
Conversation
[bridgecrewio/checkov](https://github.com/bridgecrewio/checkov): Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew
Did you run e.g. aqua-registry/pkgs/1xyz/pryrite/registry.yaml Lines 6 to 10 in 61b4a5e
Ah, I see. This repository has a lot of GitHub Releases. 1,823 e.g. cmdx s -limit 200 bridgecrewio/checkov |
I did run it and it created rules for old releases. Since this is a new package I thought it is ok if we start by only supporting the latest version and future versions. I removed the rules and old versions. |
I don't think so. |
👍 I will try to update the PR to include the version_constraint |
Created the config again with version constraints for older versions |
LGTM. Thank you! BTW, I'm not familiar with checkov, but checkov seems to be very slow. And $ time /opt/homebrew/bin/checkov -v
3.2.20
/opt/homebrew/bin/checkov -v 2.67s user 0.59s system 36% cpu 9.015 total $ time /Users/shunsukesuzuki/.local/share/aquaproj-aqua/pkgs/github_release/github.com/bridgecrewio/checkov/3.2.23/checkov_darwin_X86_64_3.2.23.zip/dist/checkov -v
3.2.23
-v 3.00s user 2.81s system 19% cpu 29.465 total This has nothing to do with aqua, so I don't care about it but this is a little interesting. |
v4.140.0 is out 🎉 |
bridgecrewio/checkov: Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew
$ aqua g -i bridgecrewio/checkov
How to confirm if this package works well
Reviewers aren't necessarily familiar with this package, so please describe how to confirm if this package works well.
Please confirm if this package works well yourself as much as possible.
Command and output
Reference