You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Using v 0.4.6. Configuration of digger action - upload-plan-destination: github.
Issue: Plan artifact in Github is accessible to everyone who has read access on the repository (this is not configurable on GitHub). Terraform plan binary file can contain sensitive values and shouldn't be accessible to all users.
Suggestion for solution: Implement encryption of the file before storing it to artifacts. It can be either password protected zip file (that the plan is currently in) or file encryption on top of it.
The text was updated successfully, but these errors were encountered:
chvima
changed the title
Plan artifact in GitHub security issue - implement encryption
TF Plan security: Plan artifact in GitHub is unencrypted- implement encryption
Mar 8, 2024
chvima
changed the title
TF Plan security: Plan artifact in GitHub is unencrypted- implement encryption
TF Plan security: Plan artifact in GitHub is not encrypted
Mar 8, 2024
Using v 0.4.6. Configuration of digger action - upload-plan-destination: github.
Issue: Plan artifact in Github is accessible to everyone who has read access on the repository (this is not configurable on GitHub). Terraform plan binary file can contain sensitive values and shouldn't be accessible to all users.
Suggestion for solution: Implement encryption of the file before storing it to artifacts. It can be either password protected zip file (that the plan is currently in) or file encryption on top of it.
The text was updated successfully, but these errors were encountered: