Repository navigation
chore: Upgrade c7n-left to 0.3.39 - #86
Merged
Merged
Conversation
Upgrades c7n-left from 0.3.38 to 0.3.39, which brings c7n 0.9.53, tfparse 0.6.22 and python-hcl2 8.1.4, and bumps the package version to 0.5.39. boto3/botocore move from 1.43.78 to 1.43.103 to match the pin in c7n 0.9.53. The lockfile refresh also pulls in transitive and development updates. tfparse 0.6.22 resolves `each.value.<attr>` when a `for_each` collection contains a module output reference (tfparse#283), and tracks references to `data` source attributes (tfparse#277). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Covers tfparse#283: when a for_each collection contains a module output reference, each.value.<attr> inside the resource body used to stay an unresolved reference marker and the for_each did not expand. The fixture mixes a module-sourced compliant entry with a static violating one, and the test asserts that only the violating instance is reported under its expanded address with its real tags. Fails on c7n-left 0.3.38 / tfparse 0.6.21, passes on 0.3.39 / 0.6.22. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
There was a problem hiding this comment.
No issues found across 6 files
Confidence score: 5/5
- Automated review surfaced no issues in the provided summaries.
- No files require special attention.
Architecture diagram
sequenceDiagram
participant User as CLI User
participant CLI as Sinistral CLI
participant C7N as c7n-left Scanner
participant TFP as tfparse Parser
participant HCL as python-hcl2
Note over User,HCL: Terraform Scanning Pipeline
User->>CLI: sinistral run --project foo -d <path>
CLI->>CLI: Load policies from API
CLI->>C7N: Submit terraform directory for scan
C7N->>TFP: Parse Terraform config
TFP->>HCL: Parse .tf files
HCL-->>TFP: AST representation
loop For each resource with for_each
TFP->>TFP: Resolve for_each collection
alt Collection contains module output reference
TFP->>TFP: Expand module output values
TFP->>TFP: Bind each.value.<attr> to real values
else Static collection
TFP->>TFP: Bind each.value.<attr> directly
end
alt Resource references data source attributes
TFP->>TFP: Track data source references
end
end
TFP-->>C7N: Expanded resource instances with resolved values
C7N->>C7N: Evaluate policies against each instance
alt Policy violated
C7N->>C7N: Generate violation finding
else Compliant
C7N->>C7N: Skip resource
end
C7N-->>CLI: Scan results
CLI->>CLI: Format results payload
alt Any violations found
CLI->>CLI: Set status to FAILED
else All compliant
CLI->>CLI: Set status to SUCCESS
end
CLI->>API: POST scan results
API-->>CLI: Ack
CLI-->>User: Exit code (non-zero if violations)
tvansteenburgh
approved these changes
Oct 2, 2026
tvansteenburgh
left a comment
Contributor
There was a problem hiding this comment.
Thanks @ajkerrigan !
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
ENG-8511
Release PR for 0.5.39. Picks up the c7n-left release that fixes unresolved
for_eachvalueswhen the collection contains a module output reference.
what
Upgrades c7n-left from 0.3.38 to 0.3.39, which brings c7n 0.9.53, tfparse 0.6.22 and
python-hcl2 8.1.4, and bumps the package version to 0.5.39.
The boto3/botocore pins move from 1.43.78 to 1.43.103. As with the last release, this is
required: c7n 0.9.53 pins
boto3==1.43.103. The lockfile refresh also pulls in minortransitive and development updates.
python-hcl2 jumps a major version (4.3.5 to 8.1.4). It's pinned by c7n-left and not
imported by sinistral directly.
why
tfparse 0.6.22 fixes
each.value.<attr>resolution when afor_eachcollection contains amodule output reference. Previously the
for_eachdidn't expand at all: the scan saw asingle bare
aws_sqs_queue.xwith attributes liketagsleft as an unresolvedeach.value.tagsmarker. Policies then evaluated the marker instead of the real value.That produced false positives on compliant resources and reported findings against the
wrong address.
It also tracks references from resources to
datasource attributes.Upstream: cloud-custodian/tfparse#283,
cloud-custodian/tfparse#277 and
cloud-custodian/tfparse#285
testing
Lint and the test suite pass.
Adds a regression test (
test_submit_run_foreach_module_output) with a fixture whosefor_eachmixes a compliant entry tagged via a module output and a static entry missingthe required tag. Only the static entry should be reported:
aws_sqs_queue.x, tags{"__attribute__": "each.value.tags", ...}(test fails)aws_sqs_queue.x["untagged"], tags{"Team": "platform"}(test passes)docs
Release notes updated.
Note for reviewers: merging this does not publish anything. The
v0.5.39tag push iswhat triggers the release workflow, and CI does not run on tag pushes, so this PR is the
only gate.