microsoft / microsoft/security-devops-azdevops

Terrascan

Open
#21 1 comment 1 reaction 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
TypeScript
Stars
86
Forks
22
PR merge metrics
No merged PRs in 30d

Description

Hi
I have been testing MSDO with Azure DevOps and looking specifically into terrascan, which I like a lot. I have noticed that terrascan is lacking in basic functionality and there seem not to be that great throughput in the project at the moment.

According to the version change log here https://runterrascan.io/docs/reference/ there has not been any new releases of terrascan for over a year.

My question is, will MSDO rely on terrascan as it continues or do you consider other options (like checkov or a like).

As an example, you can take a look at this issue: https://github.com/tenable/terrascan/issues/1453 that I have worked on lately.

The reason I ask is that it seems to be hard to get in touch with the maintainers of the terrascan project as well.

Kind Regards
Jakub

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Review the Terrascan documentation and the linked Terrascan issue first, then inspect how this extension currently depends on or invokes Terrascan. Done means documenting a maintainer decision about continuing with Terrascan or evaluating alternatives such as Checkov; the issue does not name a repository file or test.

Written by the indexing model from the issue text.

Assessment

Tech stack
azure
Domain
devops, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
15/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.