Azure / Azure/Azure-Verified-Modules
[Feedback]: Security reports based on Bicep template security scans
- Dominant language
- PowerShell
- Stars
- 580
- Forks
- 161
- Avg merge
- 11h 3m
- Merged PRs (30d)
- 15
Description
### Check for previous/existing GitHub issues
- [X] I have checked for previous/existing GitHub issues
### Description
Hi AVM team,
Currently, I am working within an organisation that has some high-security standards and I am trying to let them adopt Azure Verified Modules from the container registry (mcr.microsoft.com). The problem I am running into is that there are security concerns regarding using externally loaded modules on runtime to deploy their critical infrastructure. There is no control, or any security overview regarding this. The external source, in this case, a domain from *.microsoft.com is trusted and allowed to be used.
I know I am not the only one not being able to use AVM via the MCR due to security concerns, and this can cause other problems like using outdated AVM modules or having to clone AVM and having to figure out security scans and update mechanisms.
A solution could be automated security scans of the Bicep modules, which in the end will result in a security report. It might be a "simple" page on which the security status can be seen or a SARIF-formatted file... This can help answer security-based questions and elevate trust in using AVM using the container registry, and it will help with the adoption of AVM for larger organisations.
Is this something that's already on the radar?
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.