awesome-repositories.com
Blog
awesome-repositories.com

Descubre los mejores repositorios open-source con nuestra búsqueda potenciada por IA.

ExplorarBúsquedas curadasAlternativas open-sourceSoftware autohospedableBlogMapa del sitio
ProyectoAcerca deCómo clasificamosPrensaServidor MCP
Aviso legalPrivacidadTérminos
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
tfsec avatar

tfsec/tfsec

0
View on GitHub↗
7,013 estrellas·555 forks·Go·MIT·11 vistasaquasecurity.github.io/trivy↗

Tfsec

tfsec is a static analysis tool and security scanner for infrastructure as code, specifically designed to detect misconfigurations and compliance violations in Terraform and cloud infrastructure definitions before deployment. It functions as a cloud security policy engine that identifies vulnerabilities across multiple cloud platforms.

The tool provides capabilities for cloud compliance auditing and scanning of Cloud Development Kit code. It supports custom security policy enforcement and allows for the definition of organization-specific security requirements.

The scanner includes features for automating analysis within DevSecOps pipelines and exporting results to security dashboards. It manages analysis noise through check filtering and the suppression of security warnings via inline comments with expiration dates.

Features

  • Static Configuration Analysis - Scans Terraform and cloud configuration files to identify security vulnerabilities and compliance issues before deployment.
  • Static Analysis Engines - Implements a static analysis engine to identify security misconfigurations in infrastructure code without executing it.
  • Infrastructure Variable Resolution - Resolves external variable files to determine the final attribute state of cloud resources for accurate analysis.
  • Infrastructure Configuration Analysis - Analyzes Terraform configuration files to detect misconfigurations and compliance violations before deployment.
  • Policy Engines - Enforces security best practices and operational standards across multiple cloud-native environments using a policy engine.
  • Cloud Compliance Auditors - Automates the evaluation of cloud infrastructure against regulatory frameworks and security compliance benchmarks.
  • Infrastructure as Code Scanners - Identifies security risks and vulnerabilities in cloud infrastructure definitions via static analysis.
  • Infrastructure as Code Security - Scans Terraform and cloud configuration files to identify security misconfigurations before deployment.
  • Infrastructure Policy Enforcers - Provides the ability to define and apply organization-specific security requirements through a flexible policy language.
  • Security Pattern Matching - Evaluates infrastructure code structures against known signatures of security vulnerabilities and misconfigurations.
  • Relationship Analysis - Analyzes dependencies between cloud resources to detect security vulnerabilities that span multiple configuration blocks.
  • DevSecOps and Automation - Automates the integration of security analysis and alert uploads within DevSecOps pipelines.
  • CI/CD Pipeline Integrations - Provides native integration for automating security quality checks within CI/CD deployment workflows.
  • CI Pipeline Integrations - Integrates static security analysis and optimized logging directly into automated CI pipeline environments.
  • Infrastructure Development Kit Scanning - Analyzes Cloud Development Kit code and resource relationships to identify security flaws in programmatic infrastructure.
  • Custom Security Scan Extensions - Supports the definition of custom security policies and tailored checks to meet organizational requirements.
  • Infrastructure and Configuration - Static analysis for Terraform to prevent cloud misconfigurations.
  • Infrastructure as Code - Static analysis tool for identifying security issues in Terraform.
  • Application Security Testing - Static analysis tool for identifying infrastructure misconfigurations.

Historial de estrellas

Gráfico del historial de estrellas de tfsec/tfsecGráfico del historial de estrellas de tfsec/tfsec

Búsqueda con IA

Explora más repositorios increíbles

Describe lo que necesitas en lenguaje sencillo: la IA clasifica miles de proyectos open-source curados por relevancia.

Start searching with AI

Alternativas open-source a Tfsec

Proyectos open-source similares, clasificados según cuántas características comparten con Tfsec.
  • bridgecrewio/checkovAvatar de bridgecrewio

    bridgecrewio/checkov

    8,798Ver en GitHub↗

    Checkov is a static analysis tool and security scanner designed to identify misconfigurations in infrastructure as code, container images, and Kubernetes configurations. It functions as a cloud security posture tool, an SCA vulnerability scanner, and a secret scanning utility to prevent security breaches and version control leaks. The project distinguishes itself through deep graph analysis and variable resolution, allowing it to map relationships between interconnected resources and evaluate the final state of infrastructure attributes. It provides extensibility for defining custom security

    Python
    Ver en GitHub↗8,798
  • liamg/tfsecAvatar de liamg

    liamg/tfsec

    7,013Ver en GitHub↗

    tfsec is a static analysis tool and security scanner for Terraform configuration files. It functions as an infrastructure as code security scanner and compliance linter designed to detect misconfigurations and vulnerabilities across multiple cloud providers before resources are deployed. The tool identifies security risks by analyzing infrastructure code and variable files to evaluate the final state of the environment. It supports custom policy enforcement and allows for the suppression of specific security warnings through inline comments. Its capabilities cover cloud security posture mana

    Go
    Ver en GitHub↗7,013
  • tenable/terrascanAvatar de tenable

    tenable/terrascan

    5,210Ver en GitHub↗

    Terrascan is a static analysis tool designed to evaluate infrastructure-as-code configuration files for security vulnerabilities and compliance violations. By parsing these files into an intermediate representation, it identifies risks before cloud resources are provisioned, serving as a compliance auditor for cloud-native environments. The tool functions as a policy-as-code engine, allowing users to define and enforce custom security rules and industry benchmarks using a specialized query language. It distinguishes itself through its ability to integrate directly into development and deploym

    Go
    Ver en GitHub↗5,210
  • aquasecurity/tfsecAvatar de aquasecurity

    aquasecurity/tfsec

    7,013Ver en GitHub↗

    tfsec is a static analysis tool and infrastructure as code linter designed to detect security misconfigurations and compliance violations in Terraform infrastructure code. It functions as a cloud security posture tool and policy enforcement engine that evaluates configurations against established security benchmarks. The tool provides multi-cloud security auditing for providers including AWS, Azure, Google Cloud, and Kubernetes, as well as specialized scanning for DigitalOcean, OpenStack, CloudStack, and GitHub configurations. It identifies insecure settings such as public access or unencrypt

    Go
    Ver en GitHub↗7,013
Ver las 30 alternativas a Tfsec→

Preguntas frecuentes

¿Qué hace tfsec/tfsec?

tfsec is a static analysis tool and security scanner for infrastructure as code, specifically designed to detect misconfigurations and compliance violations in Terraform and cloud infrastructure definitions before deployment. It functions as a cloud security policy engine that identifies vulnerabilities across multiple cloud platforms.

¿Cuáles son las características principales de tfsec/tfsec?

Las características principales de tfsec/tfsec son: Static Configuration Analysis, Static Analysis Engines, Infrastructure Variable Resolution, Infrastructure Configuration Analysis, Policy Engines, Cloud Compliance Auditors, Infrastructure as Code Scanners, Infrastructure as Code Security.

¿Qué alternativas de código abierto existen para tfsec/tfsec?

Las alternativas de código abierto para tfsec/tfsec incluyen: bridgecrewio/checkov — Checkov is a static analysis tool and security scanner designed to identify misconfigurations in infrastructure as… liamg/tfsec — tfsec is a static analysis tool and security scanner for Terraform configuration files. It functions as an… tenable/terrascan — Terrascan is a static analysis tool designed to evaluate infrastructure-as-code configuration files for security… aquasecurity/tfsec — tfsec is a static analysis tool and infrastructure as code linter designed to detect security misconfigurations and… snyk/cli — The Snyk CLI is a command-line security scanner that detects known vulnerabilities across open-source dependencies,… toniblyx/prowler — Prowler is a multi-cloud security scanner and security posture management tool. It automates security and compliance…