Azure / Azure/Azure-Verified-Modules

[Feedback]: Security reports based on Bicep template security scans

Open
#1,041 9 comments 3 reactions 1 assignee Claimed by @jtracey93 View on GitHub
Language: Bicep :muscle: Needs: Core Team :genie: Status: Long Term :hourglass_flowing_sand: Type: Question/Feedback :raising_hand:
Dominant language
PowerShell
Stars
580
Forks
161
Avg merge
11h 3m
Merged PRs (30d)
15

Description

### Check for previous/existing GitHub issues

- [X] I have checked for previous/existing GitHub issues

### Description

Hi AVM team,

Currently, I am working within an organisation that has some high-security standards and I am trying to let them adopt Azure Verified Modules from the container registry (mcr.microsoft.com). The problem I am running into is that there are security concerns regarding using externally loaded modules on runtime to deploy their critical infrastructure. There is no control, or any security overview regarding this. The external source, in this case, a domain from *.microsoft.com is trusted and allowed to be used.

I know I am not the only one not being able to use AVM via the MCR due to security concerns, and this can cause other problems like using outdated AVM modules or having to clone AVM and having to figure out security scans and update mechanisms.

A solution could be automated security scans of the Bicep modules, which in the end will result in a security report. It might be a "simple" page on which the security status can be seen or a SARIF-formatted file... This can help answer security-based questions and elevate trust in using AVM using the container registry, and it will help with the adoption of AVM for larger organisations.

Is this something that's already on the radar?

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.