Checkov
softwareAbout
Policy-as-code static analysis tool that scans IaC configurations across Terraform, CloudFormation, and Kubernetes for security misconfigurations.
Pros
- +Broad IaC framework support in a single tool
- +Extensible with custom policies for org-specific rules
Cons
- -Requires technical knowledge to write custom policies
- -False positive rate needs tuning for complex configs
This may be an affiliate link — the creator and GuruStacks may earn a commission, at no extra cost to you. Learn more
Details
Pricing
Model
open source
Platforms
Related
Similar tools
View alternatives →Spacelift
4.9Infrastructure orchestration platform that adds policy, governance, and workflow automation on top of Terraform, OpenTofu, Pulumi, CloudFormation, and Kubernetes.
env0
4.2env0 is a cloud governance platform for self-service infrastructure deployment, providing IaC automation, policy-as-code guardrails, drift detection, and cost management across Terraform, OpenTofu, Pulumi, and Kubernetes workflows at enterprise scale.
AWS CloudFormation
4.6AWS infrastructure-as-code service for provisioning and managing cloud resources using JSON or YAML templates with automatic rollback on failure.
SonarQube
4.4Self-managed code quality and security analysis platform. Performs static analysis to detect bugs, vulnerabilities, and code smells across 30+ programming languages.
OpenTofu
4.4Open-source fork of Terraform maintained by the Linux Foundation, providing community-driven infrastructure-as-code with full Terraform compatibility.
Puppet
4.2Infrastructure automation platform for desired-state configuration management, compliance enforcement, and DevOps workflows across hybrid environments.