Security Center checks & other static analysis
- Dominant language
- Bicep
- Stars
- 3.6k
- Forks
- 830
- Avg merge
- 1d 21m
- Merged PRs (30d)
- 79
Description
**Describe the solution you'd like**
I would love to see something similar to [tfsec](https://github.com/aquasecurity/tfsec) for Bicep except linked up with Azure Security Center somehow. There are so many rules that could be running against our IoC instead of after a deployment. It would be super helpful to catch issues before a PR even gets merged.
Contributor guide
Research direction
Start by reviewing tfsec and Azure Security Center to understand the requested static-analysis scope for Bicep. Determine which Security Center checks could run against infrastructure as code before deployment and define how the checks would integrate into pull-request validation; done means an agreed, implementable design rather than a single-file change.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- azure
- Domain
- security, tooling
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100