An experiment to see what an alternative Snyk IaC experience could look like
$ snyky test -s <filename>
will test the current directory of files against all of the policy packs in the packs
folder
$ snyky test -s <filename> -p snyk,user
will only use the Snyk & User provided policies found in packs/snyk
and packs/user
respectively
First make sure you have conftest installed, following the instructions here
Next run go get github.com/benlaplanche/snyky
to instlal this onto your path
Run $ snyky test --help
to check it's all working correctly.
- ability to specify multiple packs as a flag. should this be
-p terraform -p user
or-p terraform,user
packs
output in the JSON should really be subdirectory e.g.terraform
oruser
- can we show details of the successful policies aswell? looks like a change is needed to conftest to output allow rules?