Private Module Registry via SHA
We want to ensure our terraform scans are coming back secure, without pointing to SHA, we get violations
CKV_TF_1: "Ensure Terraform module sources use a commit hash"
Using a git commit SHA in your private module registry with Terraform ensures the security and integrity of our modules
By providing a SHA checksum, we can ensure that the module downloaded from the registry matches the original version intended by the author. This prevents tampering or corruption during download.
The concern is if the module author simply deletes a module version in the Registry and re-publishes it after moving the version to a malicious one
This is what we are required to do to ensure the commit id SHA
https://developer.hashicorp.com/terraform/language/modules/sources#selecting-a-revision
- Workaround
- Problem
Log in to comment and vote
Comments1
Black Breeze
May 10, 2025
Thanks for the suggestion! To help us understand better—what job are you hiring the registry to do in this case?
The Terraform Module Registry Protocol supports semantic versions (e.g. 1.2.3), but not commit SHAs—that’s something specific to Git sources. Are you looking for:
A way to pin modules immutably by commit?
A simpler or more standardized way to reference modules from Git?
Guarantees that published versions can’t change under the hood?
We’d love to understand what problem you’re trying to solve, so we can see if the registry is the right layer for it—or if there’s a simpler solution.