"S6497: Pulling an image based on its digest is security-sensitive" is harmful to security

Hello Craig,

Thank you for your message. We removed this rule from the default quality profile, SonarWay as a first step.

It should be effective in the next release of the sonar-iac plugin (containing our Docker, Kubernetes, Terraform, Cloudformation and ARM rules), which should appear in the next product releases.

Cheers,

Loris