/plushcap/analysis/spacelift/integrating-security-tools-with-spacelift

Integrating Security Tools With Spacelift Using the Custom Inputs

What's this blog post about?

Spacelift, a CI/CD automation tool, offers Custom Inputs feature to integrate security tools in workflows. The integration involves three steps: installing the security tool, running it as part of a hook and saving its output to a json file, and accessing the data in a plan policy. Spacelift supports integrating with various security tools like Tfsec, Checkov, Terrascan, and Kics. These tools can be integrated using runner images or before_init hooks. Custom inputs provide flexibility as they can integrate with any JSON file, allowing users to create powerful policies based on their use case.

Company
Spacelift

Date published
March 17, 2023

Author(s)
Flavius Dinu

Word count
2140

Hacker News points
None found.

Language
English


By Matt Makai. 2021-2024.