Skip to main content

Private Module Registry via SHA

We want to ensure our terraform scans are coming back secure, without pointing to SHA, we get violations

CKV_TF_1: "Ensure Terraform module sources use a commit hash"

Using a git commit SHA in your private module registry with Terraform ensures the security and integrity of our modules

By providing a SHA checksum, we can ensure that the module downloaded from the registry matches the original version intended by the author. This prevents tampering or corruption during download.

The concern is if the module author simply deletes a module version in the Registry and re-publishes it after moving the version to a malicious one

This is what we are required to do to ensure the commit id SHA

https://developer.hashicorp.com/terraform/language/modules/sources#selecting-a-revision

Workaround
Problem
Status: ❌ Rejected1 comment

Log in to comment and vote

Comments1

  • Black Breeze

    •

    May 10, 2025

    Thanks for the suggestion! To help us understand better—what job are you hiring the registry to do in this case?

    The Terraform Module Registry Protocol supports semantic versions (e.g. 1.2.3), but not commit SHAs—that’s something specific to Git sources. Are you looking for:

    • A way to pin modules immutably by commit?

    • A simpler or more standardized way to reference modules from Git?

    • Guarantees that published versions can’t change under the hood?

    We’d love to understand what problem you’re trying to solve, so we can see if the registry is the right layer for it—or if there’s a simpler solution.