Ross ROSS = Recommend OSS · open-source software intelligence for agents

bridgecrewio/checkov

Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew. observed · 2026-08-28

github.com/bridgecrewio/checkov · homepage · Python · Apache-2.0 (permissive) observed · 2026-08-28

Health v2 · maintenance only

95/100

  • Activity 99
  • Release rhythm 87
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 2
  • age_days: 2471
  • days_rel: 7
  • days_push: 7
  • n_releases_24m: 190

Full methodology

Adoption not part of the score

8973 stars · 1399 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

Checkov is a static code analysis tool for infrastructure as code (Terraform, CloudFormation, Kubernetes, Helm, Dockerfile, and more) that detects misconfigurations before deployment. It also performs software composition analysis (SCA) on container images and open source packages, with a Python/YAML policy-as-code framework for custom checks.

Use cases

  • scan terraform files for security misconfigurations
  • find vulnerabilities in docker images and open source packages
  • enforce compliance policies on kubernetes manifests
  • run iac security checks in ci/cd pipeline
  • write custom policy-as-code checks for cloud resources
  • scan cloudformation and helm charts before deployment
  • prevent cloud misconfigurations at build time

When to choose

  • you need build-time scanning of IaC across many frameworks (Terraform, CloudFormation, Kubernetes, Helm, Bicep, ARM)
  • you want hundreds of built-in compliance and security checks plus custom Python/YAML policies
  • you need CI/CD integrations with GitHub Actions, GitLab, Jenkins, or Bitbucket
  • you want a single CLI covering both IaC misconfiguration and SCA scanning

When to avoid

  • you need runtime cloud posture management or live infrastructure scanning rather than static analysis
  • you only use a niche IaC tool not among the supported frameworks
  • you need dynamic application security testing or source code vulnerability analysis beyond IaC and dependencies

Facets

cli-tool · maturity stable

security vulnerability-scanning static-site-generator cli infrastructure-as-code developer-tools security infrastructure-as-code cloud-computing developer-tools python cli windows cloud iac-scanning policy-as-code sca terraform kubernetes cloudformation compliance misconfiguration-detection container-images cicd-integration devops containers docker linux macos

4 sources

Member repositories

RepositoryRoleHealth v2
bridgecrewio/checkovmain95

For agents

markdown · JSON · MCP: product_card(name="bridgecrewio/checkov")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem