awslabs / awslabs/simple-code-scanning-pipeline
Add OPA Scan
- Dominant language
- TypeScript
- Stars
- 19
- Forks
- 3
- PR merge metrics
- No merged PRs in 30d
Description
The DevOps Quickstart tool uses Open Policy Agent (https://www.openpolicyagent.org/) to "define and enforce policies on infrastructure resources at development time."
We should look at adding this tool to the Golden Pipeline.
https://github.com/aws-samples/devsecops-quickstart/blob/main/devsecops_quickstart/opa_scan/opascan.py
Contributor guide
Research direction
Start by reading the linked devsecops-quickstart/devsecops_quickstart/opa_scan/opascan.py implementation and then inspect this repository's Golden Pipeline entry points. Identify how a new scan is integrated and what existing pipeline tests cover. Done means OPA scanning is integrated into the Golden Pipeline with appropriate coverage and documented behavior.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- python
- Domain
- devops, security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100