Files
Checkov will run on files with the following files and extensions:.tf.yml.yaml.json.template.bicep.hclbower.jsonbuild.gradlebuild.gradle.ktsgo.sumgradle.propertiesMETADATAnpm-shrinkwrap.jsonpackage.jsonpackage-lock.jsonpom.xmlrequirements.txtDockerfile.dockerfileDockerfile.*.csprojyarn.lockGemfileGemfile.lockgo.modpaket.dependenciespaket.lockpackages.configcomposer.jsoncomposer.lock
Configuration
CodeRabbit will include on the following severity levels based on the profile selected:Chill
HIGHCRITICAL
Assertive
MEDIUMHIGHCRITICAL
When we skip Checkov
CodeRabbit will skip running Checkov when:- Checkov is already running in GitHub workflows.