Guard offers a policy-as-code domain-specific language (DSL) to write rules and validate JSON- and YAML-formatted data such as CloudFormation Templates, K8s configurations, and Terraform JSON plans/configurations against those rules. Take this survey to provide feedback about cfn-guard: https://amazonmr.au1.qualtrics.com/jfe/form/SV_bpyzpfoYGGuuUl0
tfsec is a static analysis tool and security scanner for infrastructure as code, specifically designed to detect misconfigurations and compliance violations in Terraform and cloud infrastructure definitions before deployment. It functions as a cloud security policy engine that identifies vulnerabilities across multiple cloud platforms. The tool provides capabilities for cloud compliance auditing and scanning of Cloud Development Kit code. It supports custom security policy enforcement and allows for the definition of organization-specific security requirements. The scanner includes features
Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure.
cesar-rodriguez/terrascan की मुख्य विशेषताएं हैं: Infrastructure and Configuration, Infrastructure as Code, Infrastructure Security।
cesar-rodriguez/terrascan के ओपन-सोर्स विकल्पों में शामिल हैं: aws-cloudformation/cloudformation-guard — Guard offers a policy-as-code domain-specific language (DSL) to write rules and validate JSON- and YAML-formatted data… wata727/tflint — A Pluggable Terraform Linter. tfsec/tfsec — tfsec is a static analysis tool and security scanner for infrastructure as code, specifically designed to detect… awslabs/cfn-python-lint — CloudFormation Linter. awslabs/git-secrets — Git-secrets is a security utility designed to prevent the accidental exposure of sensitive credentials by integrating… aws-samples/automated-security-helper — ASH is an extensible, open source SAST, SCA, and IaC security scanner orchestration engine.