Table of contents

Cloud One Github Template Scanner App

Currently in Preview

Location

https://github.com/apps/cloud-one-template-scanner-preview

The Cloud One Template Scanner enables you to run Trend Micro Cloud One™ – Template Scanner Rules in the infrastructure-as-code templates present in your git repositories. You can select repositories within your organization to be automatically scanned when code is pushed to Github.

We currently do not support the Github Enterprise organizations.

What is Cloud One Template Scanner app?

The Cloud One Template Scanner app is a Github application that can be installed in your Github Organization to enforce scanning infrastructure-as-code templates present in your git repositories.

Implementing Template Security scanning within Github is the earliest point in the software development lifecycle where compliance with security requirements can reasonably be enforced at a team/organisation level. Detecting security risks while developers are in the process of implementing changes in the code means not only flagging issues earlier, but also makes it easier to have the necessary context to apply the fixes.

How to install Cloud One Template Scanner app?

You can install the Cloud One Template Scanner from Github following this link.

  1. Click on Install.

  2. Choose if you want "All repositories" or "Only select repositories" to be scanned.

  3. Click on Install and you will be taken to Trend Micro Cloud One™ to link your account.

  4. Select the account you would like to link and click Go.

    Please make sure that your selected account belongs to the region us-1.

  5. Click Integrate Template Scanner.

  6. Success! You've now linked your account and finished the installation.

How to trigger a scan?

Supported Templates Supported Resource Types
Terraform S3
SNS
  • To trigger a scan, create a pull request in Github for the repository where you installed the Cloud One Template Scanner app.
  • You should now see the status of the scan at the bottom of your pull request in Github.