-
Notifications
You must be signed in to change notification settings - Fork 112
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Integrate KICS for IaC #390
Comments
@kaplanlior, since checkmarx is a direct competitor to Qwiet.AI (ShiftLeft) it is very hard to get this project into this org. However, I understand the need for better IaC scanning so will look into some options such as moving sast-scan back to the AppThreat org (doable) or creating a separate IaC meta tool (time consuming) |
As KICS is 100% open source, I don't see a reason not to use it, same as GitLab did: Thanks for the fast response |
@kaplanlior Will definitely look into this. |
@kaplanlior My proposal is to create a new mirror of sast-scan into the Long term, however, this approach to merely invoking various tools has to change. With rosa, I am experimenting to make the analysis "Risk-oriented" which means lots of traditional findings would get triaged out and de-prioritized. Perhaps the data from kics might help but not sure. |
Good luck with the proposed changes. I support anything that would allow you in integrate KICS for IaC Security. Regarding rosa, sounds interesting. If you want to collaborate around KICS, I'm open to that. |
KICS is a IaC security tool, which supports many platforms.
https://github.com/checkmarx/kics
The text was updated successfully, but these errors were encountered: