Update ci-checkov.sh (#30723)

This commit is contained in:
david-sandy 2022-02-06 05:30:06 -06:00 committed by GitHub
parent 5d3a028515
commit a13c81ec36
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -8,7 +8,7 @@ pip3 install checkov
# List of checks we do not want to run here
# This is a living list and will see additions and mostly removals over time.
# SKIP_CHECKS="CKV_GCP_22,CKV_GCP_66,CKV_GCP_13,CKV_GCP_71,CKV_GCP_61,CKV_GCP_21,CKV_GCP_65,CKV_GCP_67,CKV_GCP_20,CKV_GCP_69,CKV_GCP_12,CKV_GCP_24,CKV_GCP_25,CKV_GCP_64,CKV_GCP_68,CKV2_AWS_5,CKV2_GCP_3,CKV2_GCP_5,CKV_AWS_23,CKV_GCP_70,CKV_GCP_62,CKV_GCP_62,CKV_GCP_62,CKV_GCP_62,CKV_GCP_29,CKV_GCP_39"
SKIP_CHECKS="CKV_GCP_22,CKV_GCP_66,CKV_GCP_13,CKV_GCP_71,CKV_GCP_61,CKV_GCP_21,CKV_GCP_65,CKV_GCP_67,CKV_GCP_20,CKV_GCP_69,CKV_GCP_12,CKV_GCP_24,CKV_GCP_25,CKV_GCP_64,CKV_GCP_68,CKV2_AWS_5,CKV2_GCP_3,CKV2_GCP_5,CKV_AWS_23,CKV_GCP_70,CKV_GCP_62,CKV_GCP_62,CKV_GCP_62,CKV_GCP_62,CKV_GCP_29,CKV_GCP_39"
set +x
# In case no terraform code is present
@ -19,7 +19,7 @@ echo "==========================================================================
# Set not to fail on non-zero exit code
set +e
# Run checkov
python3 -m checkov.main --quiet --framework terraform --compact -d .
python3 -m checkov.main --skip-check $SKIP_CHECKS --quiet --framework terraform --compact -d .
# Options
# --quiet: Only show failing tests