Skip to content

Commit

Permalink
Sync with plan
Browse files Browse the repository at this point in the history
  • Loading branch information
jit-ci[bot] committed Aug 30, 2023
1 parent 16c0c38 commit bfd1ced
Showing 1 changed file with 33 additions and 0 deletions.
33 changes: 33 additions & 0 deletions .github/workflows/jit-security.yml
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,39 @@ jobs:
with:
security_control: registry.jit.io/control-enrichment-slim:latest

iac-misconfig-detection-cloudformation:
if: fromJSON(github.event.inputs.client_payload).payload.workflow_job_name == 'iac-misconfig-detection-cloudformation' && fromJSON(github.event.inputs.client_payload).payload.workflow_slug == 'workflow-iac-misconfiguration-detection'
runs-on: ubuntu-20.04
timeout-minutes: 20
steps:
- name: kics
uses: jitsecurity-controls/jit-github-action@v4.0.1
with:
security_control: registry.jit.io/control-kics-alpine:latest
security_control_output_file: /code/jit-report/results.json

iac-misconfig-detection-pulumi:
if: fromJSON(github.event.inputs.client_payload).payload.workflow_job_name == 'iac-misconfig-detection-pulumi' && fromJSON(github.event.inputs.client_payload).payload.workflow_slug == 'workflow-iac-misconfiguration-detection'
runs-on: ubuntu-20.04
timeout-minutes: 20
steps:
- name: kics
uses: jitsecurity-controls/jit-github-action@v4.0.1
with:
security_control: registry.jit.io/control-kics-alpine:latest
security_control_output_file: /code/jit-report/results.json

iac-misconfig-detection-terraform:
if: fromJSON(github.event.inputs.client_payload).payload.workflow_job_name == 'iac-misconfig-detection-terraform' && fromJSON(github.event.inputs.client_payload).payload.workflow_slug == 'workflow-iac-misconfiguration-detection'
runs-on: ubuntu-20.04
timeout-minutes: 20
steps:
- name: kics
uses: jitsecurity-controls/jit-github-action@v4.0.1
with:
security_control: registry.jit.io/control-kics-alpine:latest
security_control_output_file: /code/jit-report/results.json

remediation-pr:
if: fromJSON(github.event.inputs.client_payload).payload.workflow_job_name == 'remediation-pr' && fromJSON(github.event.inputs.client_payload).payload.workflow_slug == 'workflow-remediation-pr'
runs-on: ubuntu-20.04
Expand Down

0 comments on commit bfd1ced

Please sign in to comment.