Skip to content

chore: Upgrade c7n-left to 0.3.39 - #86

Merged
tvansteenburgh merged 2 commits into
mainfrom
ajk/chore/bump-c7n-left-0.3.39
Oct 5, 2026
Merged

tvansteenburgh merged 2 commits into
mainfrom
ajk/chore/bump-c7n-left-0.3.39

Conversation

@ajkerrigan

@ajkerrigan ajkerrigan commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

ENG-8511

Release PR for 0.5.39. Picks up the c7n-left release that fixes unresolved for_each values
when the collection contains a module output reference.

what

Upgrades c7n-left from 0.3.38 to 0.3.39, which brings c7n 0.9.53, tfparse 0.6.22 and
python-hcl2 8.1.4, and bumps the package version to 0.5.39.

The boto3/botocore pins move from 1.43.78 to 1.43.103. As with the last release, this is
required: c7n 0.9.53 pins boto3==1.43.103. The lockfile refresh also pulls in minor
transitive and development updates.

python-hcl2 jumps a major version (4.3.5 to 8.1.4). It's pinned by c7n-left and not
imported by sinistral directly.

why

tfparse 0.6.22 fixes each.value.<attr> resolution when a for_each collection contains a
module output reference. Previously the for_each didn't expand at all: the scan saw a
single bare aws_sqs_queue.x with attributes like tags left as an unresolved
each.value.tags marker. Policies then evaluated the marker instead of the real value.
That produced false positives on compliant resources and reported findings against the
wrong address.

It also tracks references from resources to data source attributes.

Upstream: cloud-custodian/tfparse#283,
cloud-custodian/tfparse#277 and
cloud-custodian/tfparse#285

testing

Lint and the test suite pass.

Adds a regression test (test_submit_run_foreach_module_output) with a fixture whose
for_each mixes a compliant entry tagged via a module output and a static entry missing
the required tag. Only the static entry should be reported:

c7n-left scan result
0.3.38 one finding on bare aws_sqs_queue.x, tags {"__attribute__": "each.value.tags", ...} (test fails)
0.3.39 one finding on aws_sqs_queue.x["untagged"], tags {"Team": "platform"} (test passes)

docs

Release notes updated.

Note for reviewers: merging this does not publish anything. The v0.5.39 tag push is
what triggers the release workflow, and CI does not run on tag pushes, so this PR is the
only gate.

ajkerrigan and others added 2 commits October 1, 2026 19:17
Upgrades c7n-left from 0.3.38 to 0.3.39, which brings c7n 0.9.53,
tfparse 0.6.22 and python-hcl2 8.1.4, and bumps the package version
to 0.5.39.

boto3/botocore move from 1.43.78 to 1.43.103 to match the pin in
c7n 0.9.53. The lockfile refresh also pulls in transitive and
development updates.

tfparse 0.6.22 resolves `each.value.<attr>` when a `for_each`
collection contains a module output reference (tfparse#283), and
tracks references to `data` source attributes (tfparse#277).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Covers tfparse#283: when a for_each collection contains a module output
reference, each.value.<attr> inside the resource body used to stay an
unresolved reference marker and the for_each did not expand. The
fixture mixes a module-sourced compliant entry with a static violating
one, and the test asserts that only the violating instance is reported
under its expanded address with its real tags.

Fails on c7n-left 0.3.38 / tfparse 0.6.21, passes on 0.3.39 / 0.6.22.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@ajkerrigan
ajkerrigan requested a review from a team as a code owner October 2, 2026 03:02

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 6 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.
Architecture diagram
sequenceDiagram
    participant User as CLI User
    participant CLI as Sinistral CLI
    participant C7N as c7n-left Scanner
    participant TFP as tfparse Parser
    participant HCL as python-hcl2

    Note over User,HCL: Terraform Scanning Pipeline

    User->>CLI: sinistral run --project foo -d <path>
    CLI->>CLI: Load policies from API
    CLI->>C7N: Submit terraform directory for scan

    C7N->>TFP: Parse Terraform config
    TFP->>HCL: Parse .tf files
    HCL-->>TFP: AST representation

    loop For each resource with for_each
        TFP->>TFP: Resolve for_each collection
        alt Collection contains module output reference
            TFP->>TFP: Expand module output values
            TFP->>TFP: Bind each.value.<attr> to real values
        else Static collection
            TFP->>TFP: Bind each.value.<attr> directly
        end

        alt Resource references data source attributes
            TFP->>TFP: Track data source references
        end
    end

    TFP-->>C7N: Expanded resource instances with resolved values
    C7N->>C7N: Evaluate policies against each instance
    alt Policy violated
        C7N->>C7N: Generate violation finding
    else Compliant
        C7N->>C7N: Skip resource
    end

    C7N-->>CLI: Scan results
    CLI->>CLI: Format results payload
    alt Any violations found
        CLI->>CLI: Set status to FAILED
    else All compliant
        CLI->>CLI: Set status to SUCCESS
    end

    CLI->>API: POST scan results
    API-->>CLI: Ack
    CLI-->>User: Exit code (non-zero if violations)
Loading

Re-trigger cubic

@tvansteenburgh tvansteenburgh left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @ajkerrigan !

@tvansteenburgh
tvansteenburgh merged commit 4f2cf75 into main Oct 5, 2026
10 checks passed
@tvansteenburgh
tvansteenburgh deleted the ajk/chore/bump-c7n-left-0.3.39 branch October 5, 2026 18:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants