efterlev/Efterlev compliance scan

Run the Efterlev FedRAMP 20x compliance scanner against your Terraform and post findings as a sticky PR comment.

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
target-dirDirectory to scan, relative to the workspace.no.
baselineFRMR baseline name (fedramp-20x-moderate is the v1 default).nofedramp-20x-moderate
efterlev-versionEfterlev version to install. "latest" pulls the newest stable PyPI release.nolatest
run-gap-agentRun the Gap Agent after scanning. Requires ANTHROPIC_API_KEY in env.nofalse
fail-on-findingExit non-zero if any scan finding is detected.nofalse
comment-on-prPost or update a sticky PR comment with scan results. Only applies to pull_request events.notrue
install-methodHow to install Efterlev: "pipx" or "container".nopipx
namedescription
findings-countTotal number of detector findings produced by the scan.
report-pathFilesystem path to the HTML report produced by the scan.
store-dirFilesystem path to the .efterlev/ provenance store.
has-regressionsWhether drift/regressions were detected. Always false at v1.0.0; reserved for the future Drift Agent integration.