Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Integrate KICS for IaC #390

Open
kaplanlior opened this issue Apr 24, 2023 · 5 comments
Open

Integrate KICS for IaC #390

kaplanlior opened this issue Apr 24, 2023 · 5 comments

Comments

@kaplanlior
Copy link

kaplanlior commented Apr 24, 2023

KICS is a IaC security tool, which supports many platforms.

https://github.com/checkmarx/kics

@prabhu
Copy link
Contributor

prabhu commented Apr 24, 2023

@kaplanlior, since checkmarx is a direct competitor to Qwiet.AI (ShiftLeft) it is very hard to get this project into this org. However, I understand the need for better IaC scanning so will look into some options such as moving sast-scan back to the AppThreat org (doable) or creating a separate IaC meta tool (time consuming)

@kaplanlior
Copy link
Author

As KICS is 100% open source, I don't see a reason not to use it, same as GitLab did:
https://docs.gitlab.com/ee/user/application_security/iac_scanning/#supported-languages-and-frameworks

Thanks for the fast response

@prabhu
Copy link
Contributor

prabhu commented Apr 24, 2023

@kaplanlior Will definitely look into this.

@prabhu
Copy link
Contributor

prabhu commented May 5, 2023

@kaplanlior My proposal is to create a new mirror of sast-scan into the AppThreat org. It will be uncreatively called scan. I will add some enhancements such as integrating kics and upgrading versions of python, go etc to keep the project going a bit more. WDYT?

Long term, however, this approach to merely invoking various tools has to change. With rosa, I am experimenting to make the analysis "Risk-oriented" which means lots of traditional findings would get triaged out and de-prioritized. Perhaps the data from kics might help but not sure.

@kaplanlior
Copy link
Author

Good luck with the proposed changes. I support anything that would allow you in integrate KICS for IaC Security.

Regarding rosa, sounds interesting. If you want to collaborate around KICS, I'm open to that.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants