Terraform Scanning to Detect Risky or Sensitive Modules
We’d like to see native support in Spacelift for scanning Terraform code to ensure compliance with security policies. Specifically, this would help identify misconfigurations or potentially malicious modules before they are applied. While we currently use SonarCloud, its Terraform scanning capabilities are quite limited, and a more integrated solution in Spacelift would streamline our workflows and reduce risk exposure.
- Problem
Log in to comment and vote
Comments1
Black Breeze
May 8, 2025
Normally you’d run something like Trivy as one of the “before” hooks - presumably before_init:
https://github.com/aquasecurity/trivy
It can be enforced by adding putting that hook in a context and then auto-attaching it to everything.