Skip to content

plan-skeptic v0.1.0 - #1

Merged
bateller merged 1 commit into
mainfrom
feat/v0.1.0
Sep 29, 2026
Merged

bateller merged 1 commit into
mainfrom
feat/v0.1.0

Conversation

@bateller

Copy link
Copy Markdown
Member

First release of plan-skeptic: reads terraform show -json / tofu show -json output and reports what a change introduces that a reviewer must not skim.

  • Ten rules, PS001–PS010: stateful resource replaced, resource deleted, IAM wildcards, broad managed policy attached, trust policy open to any principal, ingress open to the world, public S3, publicly accessible database, encryption disabled, recovery guard removed. A delete paired with a create of the same type and name adds a "use a moved block" hint.
  • Text, JSON and SARIF 2.1.0 output; --fail-on high|medium|low|never; --disable; --list-rules. Exit codes: 0 clean, 1 findings at or above the threshold, 2 bad input.
  • Composite GitHub Action (action.yml) with a SARIF upload example in the README.
  • Eight fixtures: one captured from real tofu 1.12.5 output (credentials scrubbed), six hand-written flawed plans and one clean one.

CI runs the tests on Python 3.9 and 3.13 and self-tests the action against the fixtures.

After merge: tag v0.1.0 on main, which the README's uses: TellersTechOrg/plan-skeptic@v0.1.0 example depends on.

Reads Terraform/OpenTofu `show -json` output and reports what a change
introduces that a reviewer must not skim: ten rules (PS001-PS010), text/JSON/
SARIF 2.1.0 output, --fail-on thresholds, a composite GitHub Action, and
eight fixtures (one captured from real tofu 1.12.5 output).
@bateller
bateller merged commit bb2ce39 into main Sep 29, 2026
3 checks passed
@bateller
bateller deleted the feat/v0.1.0 branch September 29, 2026 16:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant