fix: remove checkov from CI (runs in Atlantis instead), avoid pip dependency conflicts
Some checks failed
PR Checks / OpenTofu Validate & Policy (pull_request) Failing after 8s
Security Scan / Security Scan (pull_request) Successful in 9s

This commit is contained in:
Claude AI 2026-02-14 17:34:49 +01:00
parent de3401645f
commit bc79f11276

View File

@ -45,18 +45,5 @@ jobs:
--exit-code 0 \
--format table 2>&1
echo "Trivy IaC scan complete (advisory mode)"
- name: Install checkov
run: pip3 install --break-system-packages -q checkov 2>&1 | tail -3
- name: Checkov IaC Security Scan
run: |
echo "=== Checkov IaC Security Scan ==="
checkov -d environments/ \
--framework terraform \
--soft-fail \
--compact \
--skip-check CKV_TF_1,CKV_TF_2 \
--output cli 2>&1 || true
echo "Checkov scan complete (soft-fail mode)"
echo ""
echo "Note: Checkov IaC scanning runs during Atlantis plan (integrated in Atlantis Dockerfile)"