Azure / Azure/Azure-Verified-Modules

[Question/Feedback]: Terraform Static Code Analysis

Open
#2,550 1 comment 0 reactions 0 assignees View on GitHub
Needs: Triage :mag: Type: Question/Feedback :raising_hand:
Dominant language
PowerShell
Stars
580
Forks
161
Avg merge
11h 3m
Merged PRs (30d)
15

Description

### Check for previous/existing GitHub issues

- [x] I have checked for previous/existing GitHub issues

### Description

On the last AVM community call, it mentioned that all TF modules will be moving to AzAPI for various benefits. Please can you recommend which tooling to use for static code analysis. I have tried checkov (which works well with AzureRM) but it doesn't scan AzAPI well.

Contributor guide

No contributing guide indexed for this repository

Research direction

Start with the issue's context about Terraform modules moving to AzAPI and the reported Checkov limitation. Compare available static-analysis tooling for AzAPI and document a recommendation that explains its coverage and how it applies to AVM Terraform modules.

Written by the indexing model from the issue text.

Assessment

Tech stack
terraform
Domain
infrastructure
Issue type
Documentation
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.