Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Unable to create Issue from Security Checks #9

Open
djdta opened this issue May 21, 2021 · 2 comments
Open

Unable to create Issue from Security Checks #9

djdta opened this issue May 21, 2021 · 2 comments

Comments

@djdta
Copy link

djdta commented May 21, 2021

Is your feature request related to a problem? Please describe.
A clear and concise description of what the problem is. Ex. I'm always frustrated when [...]

The one thing that tfsec does not have is the ability to raise security issues on the repo once they have been found.

Describe the solution you'd like
A clear and concise description of what you want to happen.

When a security check has found some issue, I would like to right-click on that issue and create an issue on the repo

Describe alternatives you've considered
A clear and concise description of any alternative solutions or features you've considered.

Nope.

Additional context
Add any other context or screenshots about the feature request here.

@owenrumney
Copy link
Member

Hey @djdta - this sounds a little intrusive on the part of tfsec. We'd have to dig into the .git folder to get the org and repo details. Then assuming there is a GITHUB_TOKEN on the environment of the executing machine we can create an issue on your behalf. I don't think that is something I would welcome a command-line tool doing.

One option you could consider, assuming you use GitHub Actions is to make use of the tfsec-pr-commenter-action which will comment on PRs when it sees issues (specifically created within the PRs commits)

Another possible option, the VSCode TFSEC Plugin could be updated to have a check generated from the explorer view of identified issues? Does that sound like something that would work for you?

@djdta
Copy link
Author

djdta commented May 22, 2021

@owenrumney Thanks for your reply.

For the cli i understand this will not be possible, but for the vs code plugin I think it would be a great feature to have.

djdta

@owenrumney owenrumney transferred this issue from aquasecurity/tfsec Jul 5, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants