On this page
Overview
statically analyze Terraform, Kubernetes, and other infrastructure as code to catch cloud misconfigurations, policy violations, and dependency risks before deployment
Features and best fit
Based on official documentation; not hands-on tested · Content checked:
Key features
Key characteristics
statically analyze Terraform, Kubernetes, and other infrastructure as code to catch cloud misconfigurations, policy violations, and dependency risks before deployment
Sources: [1]
Best fit
Good fit for
A comparison candidate for Developer Tools, Infrastructure Automation, OSINT & Security, Infrastructure as code, Kubernetes, Misconfiguration scanning use cases. Check the official README and installation instructions for exact fit and requirements.
Before adoption
Check before adopting
The registered primary language is Python and the license is Apache-2.0. Verify version-specific runtime requirements, breaking changes, and additional dependencies in the official README and latest release notes.
Sources: [1]
Official sources
- [1]bridgecrewio/checkov — GitHub(2026-09-15)
Supplemental curator note
Checkov is useful when infrastructure policy should fail early in development rather than after cloud deployment. Treat the built-in policy set as a starting point and define organizational check selection, suppression review, and gating thresholds explicitly.
Try it in 3 steps
- 1
Install Checkov 3.3.21 in a virtual environment
Pin the stable release in an environment matching the README's Python 3.9 through 3.12 requirement.
python3 -m venv .venv && . .venv/bin/activate && python -m pip install checkov==3.3.21 - 2
Create a Terraform file to scan
Create a small credential-free IaC file for a local static-analysis check.
printf 'resource "aws_s3_bucket" "demo" {\n bucket = "example-checkov-demo"\n}\n' > main.tf - 3
Scan the Terraform file
Run the built-in policies against the local file. A non-zero exit caused by findings is expected when using Checkov as a policy gate.
checkov --file main.tf
Growth
Growth trends · Last 30 days
9,054 Stars
Trend data is still being collected.
Development activity
Last 90 days · weekly
- Commits (last 30 days)
- 17
- Open PRs
- 108
Development activity is still being collected.
Built with
Categories and tags
GitHub data
GitHub dataView detailed GitHub data
GitHub Topics
- terraform
- static-analysis
- aws
- gcp
- azure
- aws-security
- cloudformation
- scans
- compliance
- kubernetes
- infrastructure-as-code
- devops
- Stars
- 9,054
- Forks
- 1,424
- Watchers
- 62
- Open issues
- 75
- Contributors
- 381
- Owner type
- Organization
- Primary language
- Python
- License
- Apache-2.0
- Repository last updated
- Oct 1, 2026
Related information
Write a related articleShare a guide or use case for this OSS in Markdown. Articles are published after administrator approval.
Explore next
- JumpServer31,706 Stars
2 shared tag(s) · 1 shared category(s) · Same language
centralize privileged access to SSH, RDP, Kubernetes, and databases in one PAM platform
Python - MasterHttpRelayVPN3,935 Stars
2 shared tag(s) · 1 shared category(s) · Same language
Understand it as an experimental HTTP/SOCKS relay stack where a local proxy forwards traffic through services such as Google Apps Script
Python - Ruff49,889 Stars
2 shared tag(s) · 1 shared category(s)
combine Python linting and formatting in one Rust-based CLI with 900+ rules, caching, and automatic fixes
Rust - Terraform49,817 Stars
2 shared tag(s) · 1 shared category(s)
Manage infrastructure changes through declarative configuration, plans, and dependency graphs
Go - Coder16,825 Stars
2 shared tag(s) · 1 shared category(s)
provision secure Terraform-defined environments for developers and coding agents
Go - cert-manager14,104 Stars
2 shared tag(s) · 1 shared category(s)
automate TLS certificate issuance and renewal inside Kubernetes while using ACME, Vault, and other issuers through shared resources
Go
Report incorrect information
Tell us if any listing information is incorrect or outdated.