Context
tfsec was archived by aquasecurity. We've pinned to v1.28.14 as a workaround (see CHANGELOG [Unreleased] and .github/workflows/validate-templates.yml).
The official successor is trivy config, which is already used for container scanning in the template.
Acceptance Criteria
References
Priority
Medium — current workaround is stable, but tfsec will receive no further updates.
Context
tfsec was archived by aquasecurity. We've pinned to v1.28.14 as a workaround (see CHANGELOG [Unreleased] and
.github/workflows/validate-templates.yml).The official successor is
trivy config, which is already used for container scanning in the template.Acceptance Criteria
.github/workflows/validate-templates.ymlwithtrivy config.security-baselines/tfsec.ymlto trivy config format (or consolidate with existing trivy baseline)templates/cicd/ci-infra.yml(scaffolder template) to use trivy config instead of tfsecReferences
Priority
Medium — current workaround is stable, but tfsec will receive no further updates.