Tfsec
This plugin allows you to scan the Terraform code with tfsec and provide output.
tfsec is a static analysis security scanner for your Terraform code.

Configuration options
- Name: This is Brainboard field to describe what this task is about.
- Version: always points to the latest version to give you the latest security checks released.
- Extra environment variables: variables that you can define here that will be used as environment variables in the execution shell.
- Disable grouping: disable grouping of similar results.
- Ignore failure: this will put the task in a non-blocking failure, which means, the execution of the following stage will be triggered even if the task fails.
- Include ignored: include ignored checks in the result output.
- Include passed: include passed checks in the result output.
- Require approval: means that this task will not be executed until approved by people added in the approvers' list.
-
The task remains blocked until all approvers added in the list approve it.
-
When enabled, it allows you to add approvers to the list
.png)
-
The approver has to be Brainboard user
-
- Minimum severity: you can specify the minimum severity of result that should be reported. By default, every severity is reported. You must use one of
CRITICAL,HIGH,MEDIUM,LOW. - Disabled checks: comma separated list of checks to exclude during the execution.
- This list has to be in this format:
rule1,rule2,rule3... - No space is added after the comma in the list
- This list has to be in this format:
Sample output

The output includes clickable links that open the relevant documentation pages listed in the 'More Information' section.