Repository navigation
docs: Explain optional repair verification - #1031
lokesh0186 wants to merge 1 commit into
Conversation
Assisted-by: Codex:GPT-6
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (1)
Included review availability: This review used your included allowance. Your plan provides up to 8 included reviews per hour; 7 remain after this review. 📝 SummarySummary by CodeRabbit
WalkthroughThe README adds an optional workflow that compares Checkov JSON reports before and after a scan to verify one declared repair. It documents setup, inconclusive results, failure conditions, and scope limits. The workflow is external and is not included in the project’s hook manifest. ChangesRepair Verification Documentation
Priority: ⬇️ Low Estimated code review effort: 1 (Trivial) | ~4 minutes Change: Other Suggested reviewers: Merge Risk: ⚪ Minimal · up to The optional recipe’s documented behavior and external status are supported. No actionable merge risk remains. Architecture SummaryArchitecture risk: 🔵 Low · up to The change affects 1 system. Changed systems: Architecture concerns Review detailsSystems and components
Before / after behavior
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches 💡 1🛠️ Fix failing CI checks 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Description of your changes
What
Add an optional README example beside
terraform_checkovfor repositories that keep a trusted before/after Terraform repair pair. It explains how a team can compare full Checkov JSON reports itself, then links the released IaC-Guard-V 1.0 recipe for teams that prefer a packaged check for one declared target. Trivy's passing results and custom checks are acknowledged as other building blocks. This PR changes documentation only; it does not add a hook or dependency to pre-commit-terraform.Closes #1029.
Why
Checkov's baseline is useful for finding new failures, but a zero baseline exit does not show that a particular existing finding was repaired. A reviewer needs to see the selected check fail before and pass afterward on the same resource, and an inconclusive scan must not count as success. A small project-owned script over full Checkov reports can do this for a controlled case. Teams taking that route also need to handle missing or duplicate targets, skips, parsing errors, and failed scans. For supported Checkov evidence, the linked IaC-Guard-V recipe packages those checks, binds the declared target to the before and after snapshots, and retains a report with the result. Keeping it optional gives teams a concrete choice without changing this project's default hooks.
How can we test changes
pre-commit run --files README.mdandgit diff --checkpassed locally. The local pre-commit setup neededSSL_CERT_FILE=/etc/ssl/cert.pemto install its Node environment.For the linked recipe, I ran the released IaC-Guard-V 1.0.0 wheel with Checkov 3.3.0 in separate environments. The synthetic EBS repair returned
VERIFIED/0; unchanged, deleted, suppressed, malformed, and wrong-resource candidates did not pass. The recipe records the author-run checks. These are author-run results, not a pre-commit-terraform maintainer run.