{"repo":"bridgecrewio/checkov","free":true,"listed":false,"github":"https://github.com/bridgecrewio/checkov","clone":"git clone https://github.com/bridgecrewio/checkov.git","description":"Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.","language":"Python","stars":8949,"topics":["terraform","static-analysis","aws","gcp","azure","aws-security","cloudformation","scans","compliance","kubernetes"],"license":"Apache-2.0","category":"deployment-docker-iac","readme_excerpt":"Checkov is a static code analysis tool for infrastructure as code (IaC) and also a software composition analysis (SCA) tool for images and open source packages. It scans cloud infrastructure provisioned using Terraform, Terraform plan, Cloudformation, AWS SAM, Kubernetes, Helm charts, Kustomize, Dockerfile, Serverless, Bicep, OpenAPI, ARM Templates, or OpenTofu and detects security and compliance misconfigurations using graph-based scanning. It performs Software Composition Analysis (SCA) scanning which is a scan of open source packages and images for Common Vulnerabilities and Exposures (CVEs). Checkov also powers Prisma Cloud Application Security , the developer-first platform that codifies and streamlines cloud security throughout the development lifecycle. Prisma Cloud identifies, fixes, and prevents misconfigurations in cloud resources and infrastructure-as-code files. Table of contents - Features - Screenshots - Getting Started - Disclaimer - Support - Migration - v2 to v3 ## Features Over 1000 built-in policies cover security and compliance best practices for AWS, Azure and Google Cloud. Scans Terraform, Terraform Plan, Terraform JSON, CloudFormation, AWS SAM, Kubernetes, Helm, Kustomize, Dockerfile, Serverless framework, Ansible, Bicep, ARM, and OpenTofu template files. Scans Argo Workflows, Azure Pipelines, BitBucket Pipelines, Circle CI Pipelines, GitHub Actions and GitLab CI workflow files Supports Context-awareness policies based on in-memory graph-based scanning.","default_branch":null,"files":null,"tree":[],"storefront":"/r/bridgecrewio","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/bridgecrewio/checkov/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}