# Checkmarx/kics

Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.

Repository: https://github.com/Checkmarx/kics
Canonical: https://ross.abutalabs.com/products/kics
Homepage: https://kics.io
Language: Open Policy Agent
License: Apache-2.0
License Family: permissive
Topics: iac, infrastructure-as-code, security, appsec, cloudnative, hacktoberfest, devsecops, golang, security-tools, vulnerability-detection, vulnerability-scanners, open-policy-agent
Last push: 2026-08-25T21:02:29+00:00

## Health v2 (maintenance only)
Score: 98/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 99, release rhythm 95, longevity 100
- inputs: {"age_days": 2247, "days_push": 8, "days_rel": 34, "gap_med": 24, "n_releases_24m": 20}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 2695, forks 381 (observed 2026-08-28T04:07:11.160386+00:00)

## What it is
KICS (Keeping Infrastructure as Code Secure) is an open-source static analysis tool by Checkmarx that scans IaC files for security vulnerabilities, compliance issues, and misconfigurations. It supports Terraform, Kubernetes, Docker, CloudFormation, Ansible, Helm, ARM, Pulumi, and more, using 2400+ customizable OPA-based queries.

## Use cases
- scan terraform code for security misconfigurations
- find vulnerabilities in kubernetes manifests before deployment
- check dockerfiles for security best practices
- run iac security scanning in ci pipeline
- audit cloudformation templates for compliance issues
- detect misconfigurations in ansible playbooks and helm charts

## When to choose
- you need broad IaC platform coverage with thousands of built-in queries
- you want an open-source, CI-friendly scanner with Docker images
- you need customizable OPA-based security rules for infrastructure code

## When to avoid
- you need runtime or dynamic cloud posture scanning rather than static analysis
- you require SAST for application source code instead of IaC
- you need a managed commercial service with vendor support

## Facets
- artifact type: cli-tool
- maturity: active
- function: vulnerability-scanning, security, infrastructure-as-code, static-site-generator
- domain: security, infrastructure-as-code, cloud-computing
- platform: cli, cross-platform, go
- tags: iac-scanning, devsecops, open-policy-agent, sast, compliance, terraform, kubernetes, dockerfile, cloudformation, ansible, helm, devops, docker

## Member repositories
- Checkmarx/kics (main) score 98

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:07:11.160386+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T02:16:19.191710+00:00, confidence not recorded.
  - readme: https://github.com/Checkmarx/kics (fetched 2026-08-28T04:07:11.160386+00:00, sha f1edfc2f7bdd)
  - homepage: https://kics.io (fetched 2026-08-29T09:59:24.542120+00:00, sha 46b8b5bc47af)
  - site_page: https://docs.kics.io/latest/getting-started (fetched 2026-08-29T09:59:24.551127+00:00, sha e474e02a59b9)
  - site_page: https://docs.kics.io/ (fetched 2026-08-29T09:59:24.553051+00:00, sha 37b0d4ae981c)
  - site_page: http://kics.io/ (fetched 2026-08-29T09:59:24.554781+00:00, sha ee3a5ed8bb6e)
- Data as of 2026-08-30T08:39:29.467469+00:00.
