
Checkov
Checkov is a free static analysis tool used to find misconfigurations in infrastructure as code and open source packages for cloud and DevSecOps teams.
0 upvotes · 0 downvotes
No ratings yet
- Categories
- Cloud SecurityApplication Security
- Pricing
- Free
- Platforms
- LinuxmacOS
- License
- Open source
- Reviewed
- Last reviewed 6 October 2026
What it is
A policy as code scanner that reads Terraform, CloudFormation, Kubernetes, and other definition files to flag insecure settings before anything is deployed.
What it helps with
- Catching insecure defaults in infrastructure as code across many frameworks
- Scanning open source packages and images for known vulnerabilities
- Running inside a pipeline with output formats for CI systems and review
Who it's for
Cloud, platform, and DevSecOps engineers who want to catch misconfigurations early in the build.
Worth knowing
It ships with over a thousand built-in checks and supports custom policies written in Python or YAML. Deeper package scanning connects to the Prisma Cloud platform with an access key.
How is it installed?
With pip, or through Homebrew on macOS and Linux.
Can I ignore specific findings?
Yes. Individual checks can be suppressed inline or skipped from the command line.
What result formats does it produce?
Among others, JSON, JUnit XML, CSV, SARIF, and CycloneDX.
Discussion & reviews
0 comments
No contributions yet. Be the first to review or comment.