OSS Tanbou

statically analyze Terraform, Kubernetes, and other infrastructure as code to catch cloud misconfigurations, policy violations, and dependency risks before deployment

About these scores

OSS scale score is an unbounded metric that log-compresses and weights Stars, Watchers, Forks, and Contributors. Discovery score is the current OSS scale score minus the score at discovery. Update pace is commits in the last 30 days, growth momentum is the OSS scale score difference within the recent observation window, and OSS health is a 0–100 rating based on available recency, Community Health, and release data.

Stars
9,054
Primary language
Python
License
Apache-2.0
Repository last updated
Oct 1, 2026
On this page

Overview

statically analyze Terraform, Kubernetes, and other infrastructure as code to catch cloud misconfigurations, policy violations, and dependency risks before deployment

Features and best fit

Based on official documentation; not hands-on tested · Content checked:

Key features

Key characteristics

statically analyze Terraform, Kubernetes, and other infrastructure as code to catch cloud misconfigurations, policy violations, and dependency risks before deployment

Sources: [1]

Best fit

Good fit for

A comparison candidate for Developer Tools, Infrastructure Automation, OSINT & Security, Infrastructure as code, Kubernetes, Misconfiguration scanning use cases. Check the official README and installation instructions for exact fit and requirements.

Before adoption

Check before adopting

The registered primary language is Python and the license is Apache-2.0. Verify version-specific runtime requirements, breaking changes, and additional dependencies in the official README and latest release notes.

Sources: [1]

Official sources

  1. [1]bridgecrewio/checkov — GitHub(2026-09-15)
Supplemental curator note

Checkov is useful when infrastructure policy should fail early in development rather than after cloud deployment. Treat the built-in policy set as a starting point and define organizational check selection, suppression review, and gating thresholds explicitly.

Try it in 3 steps

  1. 1

    Install Checkov 3.3.21 in a virtual environment

    Pin the stable release in an environment matching the README's Python 3.9 through 3.12 requirement.

    python3 -m venv .venv && . .venv/bin/activate && python -m pip install checkov==3.3.21
  2. 2

    Create a Terraform file to scan

    Create a small credential-free IaC file for a local static-analysis check.

    printf 'resource "aws_s3_bucket" "demo" {\n bucket = "example-checkov-demo"\n}\n' > main.tf
  3. 3

    Scan the Terraform file

    Run the built-in policies against the local file. A non-zero exit caused by findings is expected when using Checkov as a policy gate.

    checkov --file main.tf
Check the official README

Growth

Growth trends · Last 30 days

9,054 Stars

Trend data is still being collected.

Development activity

Last 90 days · weekly

Commits (last 30 days)
17
Open PRs
108

Development activity is still being collected.

Built with

Categories and tags

GitHub data

GitHub dataView detailed GitHub data

GitHub Topics

  • terraform
  • static-analysis
  • aws
  • gcp
  • azure
  • aws-security
  • cloudformation
  • scans
  • compliance
  • kubernetes
  • infrastructure-as-code
  • devops
Stars
9,054
Forks
1,424
Watchers
62
Open issues
75
Contributors
381
Owner type
Organization
Primary language
Python
License
Apache-2.0
Repository last updated
Oct 1, 2026
Write a related article

Share a guide or use case for this OSS in Markdown. Articles are published after administrator approval.

Report incorrect information

Tell us if any listing information is incorrect or outdated.

After reading this page, do you know what to do next?