Skip to content

feat(lab6): Checkov + KICS scans + custom policy#1273

Open
ratteperk wants to merge 3 commits into
inno-devops-labs:mainfrom
ratteperk:feature/lab6
Open

feat(lab6): Checkov + KICS scans + custom policy#1273
ratteperk wants to merge 3 commits into
inno-devops-labs:mainfrom
ratteperk:feature/lab6

Conversation

@ratteperk

@ratteperk ratteperk commented Jun 26, 2026

Copy link
Copy Markdown

Goal

Scan vulnerable Terraform + Pulumi with Checkov, scan vulnerable Ansible with KICS, then (bonus) write a custom Checkov policy for a project-specific rule.


Changes

  • submissions/lab6.md - file with answers
  • labs/lab6/policies/my-custom-policy.yaml - custom Checkov's policy file

Testing


Artifacts & Screenshots


  • Task 1 — Checkov on Terraform + Pulumi with top-5 rules and module-leverage analysis
  • Task 2 — KICS on Ansible with Checkov-vs-KICS comparison
  • Bonus — Custom Checkov policy demonstrably firing on the vulnerable sample

@ratteperk ratteperk changed the title Feature/lab6 feat(lab6): Checkov + KICS scans + custom policy Jun 26, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant