Skip to main content
☑️

Checkov

Open-source IaC security scanner for Terraform, CloudFormation, and Kubernetes

Security
Checkov logo

Checkov

Open-source IaC security scanner for Terraform, CloudFormation, and Kubernetes

Checkov is an open-source static analysis tool from Bridgecrew (Palo Alto Networks) that scans infrastructure-as-code files for security and compliance misconfigurations before deployment. It supports Terraform, CloudFormation, Kubernetes manifests, Dockerfile, and ARM templates, checking against 1000+ built-in policies covering CIS Benchmarks, HIPAA, GDPR, and PCI-DSS. Checkov integrates into CI pipelines to catch misconfigured S3 buckets, overly permissive IAM roles, and unencrypted databases at commit time.

Key Features

  • 1000+ security policies
  • Terraform/CloudFormation/K8s
  • CIS/HIPAA/PCI compliance
  • CI/CD integration
  • Custom policies
  • Open source
#iac-security#terraform#cloudformation#kubernetes#devsecops

Get Started

Visit Checkov
🟢
Free
Completely free to use

Quick Info

Category
Security
Pricing
Free

More Security Tools