Checkov is a static analysis tool and security scanner designed to identify misconfigurations in infrastructure as code, container images, and Kubernetes configurations. It functions as a cloud security posture tool, an SCA vulnerability scanner, and a secret scanning utility to prevent security breaches and version control leaks. The project distinguishes itself through deep graph analysis and variable resolution, allowing it to map relationships between interconnected resources and evaluate the final state of infrastructure attributes. It provides extensibility for defining custom security
Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.
Regula checks infrastructure as code templates (Terraform, CloudFormation, k8s manifests) for AWS, Azure, Google Cloud, and Kubernetes security and compliance using Open Policy Agent/Rego
Extensible auto-tagger for your IaC files. The ultimate way to link entities in the cloud back to the codified resource which created it.
الميزات الرئيسية لـ bridgecrewio/yor هي: AWS Security, Workflow Automation, Workflow Utilities, Infrastructure Security.
تشمل البدائل مفتوحة المصدر لـ bridgecrewio/yor: checkmarx/kics — Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle… gebalamariusz/cloud-audit — Fast, opinionated AWS security scanner. Curated checks. Zero noise. Copy-paste fixes. bridgecrewio/airiam — Least privilege AWS IAM Terraformer. bridgecrewio/checkov — Checkov is a static analysis tool and security scanner designed to identify misconfigurations in infrastructure as… fugue/regula — Regula checks infrastructure as code templates (Terraform, CloudFormation, k8s manifests) for AWS, Azure, Google… 0xdones/tfgen — Terraform code generator for consistent codebase and DRY.