Ross ROSS = Recommend OSS · open-source software intelligence for agents

tenable/terrascan

Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure. observed · 2026-08-28

github.com/tenable/terrascan · homepage · Go · Apache-2.0 (permissive) · archived observed · 2026-08-28

Health v2 · maintenance only

10/100

  • Activity 53
  • Release rhythm 40
  • Longevity 100

Flags: archived

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 7
  • age_days: 3278
  • days_rel: 714
  • days_push: 286
  • n_releases_24m: 2

Full methodology

Adoption not part of the score

5211 stars · 556 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

Terrascan is a static code analyzer for Infrastructure as Code that detects compliance and security violations across Terraform, CloudFormation, ARM, Kubernetes, and Helm configurations. It offers 500+ policies for security best practices and can run locally or integrate into CI/CD pipelines.

Use cases

  • scan terraform code for security misconfigurations
  • detect compliance violations in infrastructure as code
  • scan kubernetes yaml for security violations
  • integrate iac security scanning into ci/cd pipeline
  • check aws cloudformation templates for security issues
  • audit helm charts for misconfigurations
  • prevent insecure cloud infrastructure before provisioning

When to choose

  • you need a mature, policy-rich IaC scanner with 500+ built-in policies
  • you want to scan multiple IaC formats (Terraform, CFT, ARM, Kubernetes, Helm) with one tool
  • you need a CLI tool that fits easily into CI/CD pipelines

When to avoid

  • you need active maintenance, updates, or support - the repository is archived and no longer maintained
  • you want ongoing policy updates for new cloud services
  • you prefer an actively developed alternative like Checkov, tfsec, or Trivy

Facets

cli-tool · maturity abandoned

security vulnerability-scanning infrastructure-as-code cli ci-cd security cloud-computing infrastructure-as-code developer-tools windows cli go iac-scanning terraform kubernetes cloudformation helm policy-as-code devsecops compliance archived devops linux macos docker

9 sources

Member repositories

RepositoryRoleHealth v2
tenable/terrascanmain10

For agents

markdown · JSON · MCP: product_card(name="tenable/terrascan")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem