trivy does not report AVD-AZU-0011 where tfsec does #4433
Closed
tbutler-qontigo
started this conversation in
Bugs
Replies: 2 comments 1 reply
-
Hi there, shared this issue under defsec which provides the default policies for the Terraform scanning in Trivy https://github.com/aquasecurity/defsec/issues/1328 |
Beta Was this translation helpful? Give feedback.
1 reply
-
Thanks for reporting. I've opened #4461 to track it. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Description
Hi
Given that
tfsec
is deprecated in favour oftrivy
, I would expect that it will detect all the same issues.Trivy does not seem to detect
AVD-AZU-0011
-azure-storage-use-secure-tls-policy
in terraform files.Desired Behavior
Trivy should detect and report
AVD-AZU-0011
issuesActual Behavior
These issues are ignored
Reproduction Steps
and trivy and tflint installed in the
bin
folder./bin/trivy.exe fs --list-all-pkgs --scanners config,secret,vuln --format json --debug .\main.tf
./bin/tfsec-windows-amd64.exe . --force-all-dirs --soft-fail --format json
You will observe that tfsec reports the issue but trivy reports no issues.
Checklist
trivy --reset
Beta Was this translation helpful? Give feedback.
All reactions