opensecdevops/OSDO IaC Security Scan

Infrastructure as Code security scanning with Checkov, KICS, tfsec, Terrascan and Kubernetes validation

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Activelast commit May 21, 2026
License
None

Pinned Snippet

workflow.ymlSHA-pinned
uses: opensecdevops/osdo-iac-scan@28b2df4dd3d5b1d0f857cd202b5de8b13feb37c3 # v2.0.0

tags can be moved; commit SHAs can't. why a SHA?

namedescriptionrequireddefault
iac-directoryDirectory containing IaC filesno.
iac-typeType of IaC (terraform, cloudformation, kubernetes, helm, ansible, all)noall
scannersScanners to use (checkov, kics, tfsec, terrascan, all)noall
compliance-frameworksCompliance frameworks to check (cis, nist, pci-dss, hipaa)nocis
enable-kubernetes-validationEnable Kubernetes manifest validationnotrue
fail-on-highFail on high severity findingsnotrue
results-dirDirectory to store resultsno.osdo/results
namedescription
violations-foundTotal violations found
critical-countCritical violations count
high-countHigh violations count
frameworks-passedCompliance frameworks that passed