awesome-repositories.com
ब्लॉग
MCP
awesome-repositories.com

AI-संचालित खोज के साथ बेहतरीन ओपन-सोर्स रिपॉजिटरी खोजें।

एक्सप्लोर करेंक्यूरेटेड खोजेंओपन-सोर्स विकल्पसेल्फ-होस्टेड सॉफ्टवेयरब्लॉगसाइटमैप
प्रोजेक्टMCP सर्वरहमारे बारे मेंहम रैंकिंग कैसे करते हैंप्रेस
कानूनीगोपनीयताशर्तें
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
bridgecrewio avatar

bridgecrewio/checkov

0
View on GitHub↗
8,798 स्टार्स·1,354 फोर्क्स·Python·Apache-2.0·15 व्यूज़www.checkov.io↗

Checkov

Checkov is a static analysis tool and security scanner designed to identify misconfigurations in infrastructure as code, container images, and Kubernetes configurations. It functions as a cloud security posture tool, an SCA vulnerability scanner, and a secret scanning utility to prevent security breaches and version control leaks.

The project distinguishes itself through deep graph analysis and variable resolution, allowing it to map relationships between interconnected resources and evaluate the final state of infrastructure attributes. It provides extensibility for defining custom security policies using Python or YAML and includes a policy generation utility to create new static analysis checks.

The tool's capability surface covers a wide range of cloud templates, including Terraform plans, AWS SAM, CloudFormation, Azure ARM, and Bicep files. It also handles container security via Dockerfile and image auditing, and Kubernetes auditing through the analysis of manifests, Helm charts, and Kustomize files. Additionally, it performs software composition analysis to identify known CVEs in package dependencies and uses regex and entropy to detect hardcoded secrets.

Automation is supported via native integrations for CI/CD pipelines, git hooks, and IDEs, with results exportable in formats such as JSON, JUnit XML, SARIF, and Markdown.

Features

  • Infrastructure as Code Scanners - Provides static analysis of infrastructure templates to detect security risks before deployment.
  • Infrastructure as Code Security - Provides automated security scanning for infrastructure configuration files across various cloud providers.
  • Static Code Analysis - Evaluates infrastructure code against Python and YAML rules to identify misconfigurations without executing the code.
  • Manifest Scanning - Evaluates Kubernetes configuration files against security best practices to identify non-compliant settings.
  • Dependency Graph Resolvers - Maps and traverses relationships between infrastructure resources to resolve complex variable connections.
  • Infrastructure Attribute Resolution - Resolves infrastructure variable references and default values to determine the final state of resource attributes.
  • Infrastructure Variable Resolution - Resolves infrastructure variable references and default values to accurately detect security misconfigurations.
  • Vulnerability Analysis - Analyzes Dockerfiles and container images to identify known vulnerabilities and insecure configurations.
  • Security Auditing - Inspects container images for known vulnerabilities and insecure settings to ensure security compliance.
  • Manifest Template Engines - Processes Helm and Kustomize files into final manifests to resolve dynamic values before security scanning.
  • Terraform Plan Analysis - Analyzes JSON-formatted Terraform plan files to identify security risks using execution context and dependencies.
  • Dependency Vulnerability Scanners - Analyzes project dependencies and container images to detect known security vulnerabilities (CVEs).
  • Dockerfile Security Scanning - Analyzes Dockerfiles and container image references to find security flaws and vulnerabilities.
  • Cloud Compliance Auditors - Evaluates cloud infrastructure templates and runtime resources against regulatory frameworks and security benchmarks.
  • Secret Detection - Identifies plaintext credentials and API keys using a combination of regex pattern matching and entropy analysis.
  • Secrets Scanning - Detects and alerts on hardcoded credentials in source code and configuration files.
  • Dependency Vulnerability Scanning - Analyzes package manager files and container images for known CVEs and vulnerability database matches.
  • Cloud Security Posture Scanners - Audits cloud templates and runtime resources to detect misconfigurations and security risks.
  • Software Composition Analysis Tools - Scans dependency trees and package files to identify known CVEs and license violations.
  • Static Analysis Security Testing - Analyzes source code to find security vulnerabilities and logic flaws before deployment.
  • Dependency Graph Resolution - Computes a graph of attribute references and parameters to analyze the final state of dependent infrastructure resources.
  • Vulnerability Mapping - Traverses package manager files and container images to identify known vulnerabilities in third-party libraries.
  • Relationship Analysis - Maps relationships between infrastructure components to detect complex security flaws spanning multiple resources.
  • CI/CD Security - Inspects pipeline definition files to detect security flaws within the automated deployment process.
  • Change Impact Analysis - Evaluates whether specific resource attributes have been modified in a plan to trigger conditional security checks.
  • Git Hooks - Runs security scans automatically during the pre-commit phase to block insecure changes from being merged.
  • IDE Integrations - Identifies misconfigurations and suggests fixes directly within the code editor during development.
  • Scan Configurations - Manages the scope of analysis by excluding specific files, directories, or checks via regex and flags.
  • Plan-to-Source Mapping - Combines plan file analysis with original source files to map security findings to specific code blocks.
  • CI/CD Pipeline Integrations - Integrates with automated build pipelines to prevent misconfigured infrastructure from being deployed to production.
  • Security Scanning - Provides security scanning for Helm charts by templating them into manifests to identify misconfigurations.
  • Security Scanning - Analyzes live Kubernetes cluster configurations to identify security misconfigurations in deployed resources.
  • Security Scanning - Templates Kustomize files into manifests and scans the resulting configuration against security policies.
  • Infrastructure Policy Definition - Allows defining tailored security checks using Python or YAML to enforce specific requirements across infrastructure.
  • Kubernetes Configuration Auditing - Evaluates Kubernetes manifests, Helm charts, and Kustomize files for security flaws and non-compliant settings.
  • Misconfiguration Scanning - Evaluates AWS SAM templates against security benchmarks to identify structural misconfigurations.
  • Scan Filtering Tools - Controls which policies execute during a run by including or excluding specific check IDs or severity levels.
  • Security Finding Management - Provides mechanisms to ignore specific security findings via inline comments to handle false positives.
  • Source Code Mapping - Merges JSON execution plans with source files to map security findings back to specific lines of code.
  • Template Scanning - Evaluates serverless infrastructure templates against security best practices to identify misconfigurations.
  • Sensitive Data Scanners - Scans code diffs for logging statements containing potentially sensitive variables to prevent accidental exposure.
  • Security Rule Development - Supports writing custom Python logic to define specific security rules for organizational requirements.
  • Rule Suppression Comments - Supports inline source code comments to disable specific security checks for intentional deviations.
  • IaC Security - Static analysis tool for infrastructure-as-code.
  • Infrastructure as Code Analysis - Scans Terraform, CloudFormation, and Kubernetes for insecure configurations.
  • Workflow Automation - Static analysis tool for security and compliance.
  • Workflow Utilities - Static analysis tool for security and compliance.
  • Application Security - Prevents cloud misconfigurations in infrastructure-as-code.
  • Application Security Testing - Static analysis tool for infrastructure as code security.
  • Infrastructure Security - Static analysis for Terraform, CloudFormation, and Kubernetes.
  • Security and Compliance - Static analysis for infrastructure-as-code security.
  • सिक्योरिटी और हार्डनिंग - Static analysis for infrastructure-as-code security.
  • Security Auditing - Static analysis tool for infrastructure-as-code security.
  • Testing Tools - Static analysis tool for infrastructure-as-code security.

स्टार हिस्ट्री

bridgecrewio/checkov के लिए स्टार हिस्ट्री चार्टbridgecrewio/checkov के लिए स्टार हिस्ट्री चार्ट

AI सर्च

और अधिक बेहतरीन रिपॉजिटरी खोजें

अपनी ज़रूरत को सरल भाषा में बताएं — AI हजारों क्यूरेटेड ओपन-सोर्स प्रोजेक्ट्स को प्रासंगिकता के आधार पर रैंक करता है।

Start searching with AI

अक्सर पूछे जाने वाले प्रश्न

bridgecrewio/checkov क्या करता है?

Checkov is a static analysis tool and security scanner designed to identify misconfigurations in infrastructure as code, container images, and Kubernetes configurations. It functions as a cloud security posture tool, an SCA vulnerability scanner, and a secret scanning utility to prevent security breaches and version control leaks.

bridgecrewio/checkov की मुख्य विशेषताएं क्या हैं?

bridgecrewio/checkov की मुख्य विशेषताएं हैं: Infrastructure as Code Scanners, Infrastructure as Code Security, Static Code Analysis, Manifest Scanning, Dependency Graph Resolvers, Infrastructure Attribute Resolution, Infrastructure Variable Resolution, Vulnerability Analysis।

bridgecrewio/checkov के कुछ ओपन-सोर्स विकल्प क्या हैं?

bridgecrewio/checkov के ओपन-सोर्स विकल्पों में शामिल हैं: snyk/snyk — Snyk is an application security testing platform designed to identify and remediate vulnerabilities across source… tfsec/tfsec — tfsec is a static analysis tool and security scanner for infrastructure as code, specifically designed to detect… liamg/tfsec — tfsec is a static analysis tool and security scanner for Terraform configuration files. It functions as an… aquasecurity/tfsec — tfsec is a static analysis tool and infrastructure as code linter designed to detect security misconfigurations and… securego/gosec — gosec is a static analysis security tool designed to scan Go source code for vulnerabilities and common coding flaws.… snyk/cli — The Snyk CLI is a command-line security scanner that detects known vulnerabilities across open-source dependencies,…

Checkov के ओपन-सोर्स विकल्प

समान ओपन-सोर्स प्रोजेक्ट्स, जो Checkov के साथ साझा की गई सुविधाओं के आधार पर रैंक किए गए हैं।
  • snyk/snyksnyk का अवतार

    snyk/snyk

    5,586GitHub पर देखें↗

    Snyk is an application security testing platform designed to identify and remediate vulnerabilities across source code, open-source dependencies, container images, and infrastructure-as-code configurations. It functions as a comprehensive security workflow automation tool, utilizing a static analysis engine and dependency graph mapping to detect security flaws and license compliance issues throughout the software development lifecycle. The platform distinguishes itself through agentic workflow orchestration and an automated remediation pipeline that generates and submits pull requests to patc

    TypeScript
    GitHub पर देखें↗5,586
  • tfsec/tfsectfsec का अवतार

    tfsec/tfsec

    7,013GitHub पर देखें↗

    tfsec is a static analysis tool and security scanner for infrastructure as code, specifically designed to detect misconfigurations and compliance violations in Terraform and cloud infrastructure definitions before deployment. It functions as a cloud security policy engine that identifies vulnerabilities across multiple cloud platforms. The tool provides capabilities for cloud compliance auditing and scanning of Cloud Development Kit code. It supports custom security policy enforcement and allows for the definition of organization-specific security requirements. The scanner includes features

    Go
    GitHub पर देखें↗7,013
  • liamg/tfsecliamg का अवतार

    liamg/tfsec

    7,013GitHub पर देखें↗

    tfsec is a static analysis tool and security scanner for Terraform configuration files. It functions as an infrastructure as code security scanner and compliance linter designed to detect misconfigurations and vulnerabilities across multiple cloud providers before resources are deployed. The tool identifies security risks by analyzing infrastructure code and variable files to evaluate the final state of the environment. It supports custom policy enforcement and allows for the suppression of specific security warnings through inline comments. Its capabilities cover cloud security posture mana

    Go
    GitHub पर देखें↗7,013
  • aquasecurity/tfsecaquasecurity का अवतार

    aquasecurity/tfsec

    7,013GitHub पर देखें↗

    tfsec is a static analysis tool and infrastructure as code linter designed to detect security misconfigurations and compliance violations in Terraform infrastructure code. It functions as a cloud security posture tool and policy enforcement engine that evaluates configurations against established security benchmarks. The tool provides multi-cloud security auditing for providers including AWS, Azure, Google Cloud, and Kubernetes, as well as specialized scanning for DigitalOcean, OpenStack, CloudStack, and GitHub configurations. It identifies insecure settings such as public access or unencrypt

    Go
    GitHub पर देखें↗7,013
Checkov के सभी 30 विकल्प देखें→