Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Feature Request: file-by-file checks for Pull Requests #16

Open
libertyy opened this issue Aug 31, 2020 · 3 comments · May be fixed by #31
Open

Feature Request: file-by-file checks for Pull Requests #16

libertyy opened this issue Aug 31, 2020 · 3 comments · May be fixed by #31
Labels
enhancement New feature or request

Comments

@libertyy
Copy link
Contributor

Feature request:
Support out of the box the ability to report only on files modified within a Pull Request.

In the event of a Pull Request, do not scan the entire target directory. Instead, invoke checkov only against those files modified within the PR.

@metahertz metahertz added the enhancement New feature or request label Feb 9, 2021
@metahertz
Copy link
Contributor

Thanks for raising this @libertyy
Sorry for the review delay!

I think reviewdog as in #14 makes more sense that writing logic specific to the action. OK to collapse these issues in favour of #14?

Also just as an FYI if interested, our Bridgecrew Github app supports automated PR scanning and issue annotation/comments:

info:
https://bridgecrew.io/blog/keeping-infrastructure-secure-on-every-commit-with-bridgecrew-and-github/

@mbainter
Copy link

mbainter commented Feb 9, 2021

I am not familiar with reviewdog, so I don't know what that implementation would look like. I think more generic support would be better so that anyone using it can integrate it with their existing tools. If the reviewdog suggestion gets us to that point anyway then I'm for it.

@libertyy libertyy linked a pull request Mar 9, 2021 that will close this issue
@danekantner
Copy link

the reviewdog request doesn't seem related to this request

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

Successfully merging a pull request may close this issue.

4 participants