Ross ROSS = Recommend OSS · open-source software intelligence for agents

Checkmarx/kics

Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx. observed · 2026-08-28

github.com/Checkmarx/kics · homepage · Open Policy Agent · Apache-2.0 (permissive) observed · 2026-08-28

Health v2 · maintenance only

98/100

  • Activity 99
  • Release rhythm 95
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 24
  • age_days: 2247
  • days_rel: 34
  • days_push: 8
  • n_releases_24m: 20

Full methodology

Adoption not part of the score

2695 stars · 381 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

KICS (Keeping Infrastructure as Code Secure) is an open-source static analysis tool by Checkmarx that scans IaC files for security vulnerabilities, compliance issues, and misconfigurations. It supports Terraform, Kubernetes, Docker, CloudFormation, Ansible, Helm, ARM, Pulumi, and more, using 2400+ customizable OPA-based queries.

Use cases

  • scan terraform code for security misconfigurations
  • find vulnerabilities in kubernetes manifests before deployment
  • check dockerfiles for security best practices
  • run iac security scanning in ci pipeline
  • audit cloudformation templates for compliance issues
  • detect misconfigurations in ansible playbooks and helm charts

When to choose

  • you need broad IaC platform coverage with thousands of built-in queries
  • you want an open-source, CI-friendly scanner with Docker images
  • you need customizable OPA-based security rules for infrastructure code

When to avoid

  • you need runtime or dynamic cloud posture scanning rather than static analysis
  • you require SAST for application source code instead of IaC
  • you need a managed commercial service with vendor support

Facets

cli-tool · maturity active

vulnerability-scanning security infrastructure-as-code static-site-generator security infrastructure-as-code cloud-computing cli cross-platform go iac-scanning devsecops open-policy-agent sast compliance terraform kubernetes dockerfile cloudformation ansible helm devops docker

5 sources

Member repositories

RepositoryRoleHealth v2
Checkmarx/kicsmain98

For agents

markdown · JSON · MCP: product_card(name="Checkmarx/kics")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem