Checkov IaC scanning
Scan Infrastructure as Code repositories with Checkov. Orchestration and Ingestion modes supported.
You can easily set up a Checkov step to run automated scans in your Harness pipeline. This step scans the IaC repository you specify using the Checkov CLI. Then it correlates, deduplicates, and ingests the scan results into Harness. You can see your scan results in the Vulnerabilities tab of the pipeline execution.
Important notes for running Checkov scans in STO
You can utilize custom STO scan images and pipelines to run scans as a non-root user. For more details, refer Configure your pipeline to use STO images from private registry.
Set-up workflows
Checkov step settings reference
Scan
Scan Mode
Target
Type
Target and Variant Detection
Name
The identifier for the target such codebaseAlpha. Descriptive target names make it much easier to navigate your scan data in the STO UI.
It is good practice to specify a baseline for every target.
Variant
Workspace
Ingestion File
The path to your scan results when running an Ingestion scan, for example /shared/scan_results/checkov.sarif.
The data file must be in a supported format for the scanner.
The data file must be accessible to the scan step. It's good practice to save your results files to a shared path in your stage. In the visual editor, go to the stage where you're running the scan. Then go to Overview > Shared Paths. You can also add the path to the YAML stage definition like this:
Log Level
Additional CLI flags
Passing CLI flags is an advanced feature. Some flags might not work in the context of STO. You should test your flags and arguments thoroughly before you use them in your production environment.
Fail on Severity
Settings
You can add more settings to the scan step as needed.
Additional Configuration
Advanced settings
Configure Checkov as a Built-in Scanner
The Checkov scanner is available as a built-in scanner in STO. Configuring it as a built-in scanner enables the step to automatically perform scans using the free version without requiring any licenses. Follow these steps to set it up:
Search for IaC in the step palette or navigate to the Built-in Scanners section and select the IaC step.
Expand the Additional CLI Flags section if you want to configure optional CLI flags.
Click Add Scanner to save the configuration.
The scanner will automatically use the free version, detect scan targets, and can be further configured by clicking on the step whenever needed.
Proxy settings
Last updated
Was this helpful?