Skip to main content

Terraform Scanning to Detect Risky or Sensitive Modules

We’d like to see native support in Spacelift for scanning Terraform code to ensure compliance with security policies. Specifically, this would help identify misconfigurations or potentially malicious modules before they are applied. While we currently use SonarCloud, its Terraform scanning capabilities are quite limited, and a more integrated solution in Spacelift would streamline our workflows and reduce risk exposure.

Problem
Status: 🗑️ Archived1 comment

Log in to comment and vote

Comments1

  • Black Breeze

    •

    May 8, 2025

    Normally you’d run something like Trivy as one of the “before” hooks - presumably before_init:

    https://github.com/aquasecurity/trivy
    It can be enforced by adding putting that hook in a context and then auto-attaching it to everything.