Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure.
翻译 - 在配置云原生基础架构之前,将整个基础架构中的合规性和安全违规行为作为代码进行检测,以降低风险。
Visual Studio Code extension for writing Terrascan Rego policies
Use it to play with Terraform using AZ CLI, AWS CLI, and other tools.
Ansible role for 'terrascan'. Available on Ansible Galaxy.
Run terrascan with reviewdog on pull requests to enforce security best practices
Microsoft Security DevOps (MSDO) Lab for testing Defender for DevOps integration on Azure.
Implementation of https://devopsroadmap.io/projects/hivebox/
Let's play with the pre-commit framework and several Static Code Analysis tools!
A git repository that I use to try terraform.