# tenable/terrascan

Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure.

Repository: https://github.com/tenable/terrascan
Canonical: https://ross.abutalabs.com/products/terrascan
Homepage: https://runterrascan.io
Language: Go
License: Apache-2.0
License Family: permissive
Topics: security-tools, infrastructure-as-code, devsecops, devops, security, terraform, aws, cloudsecurity, cloud-security, terrascan, infrastructure, security-violations, architecture, kubernetes, iac, sast, azure-security, aws-security, gcp-security, scans
Archived: true
Last push: 2025-11-20T19:37:10+00:00

## Health v2 (maintenance only)
Score: 10/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 53, release rhythm 40, longevity 100
- inputs: {"age_days": 3278, "days_push": 286, "days_rel": 714, "gap_med": 7, "n_releases_24m": 2}
- flags: archived
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 5211, forks 556 (observed 2026-08-28T04:09:13.043621+00:00)

## What it is
Terrascan is a static code analyzer for Infrastructure as Code that detects compliance and security violations across Terraform, CloudFormation, ARM, Kubernetes, and Helm configurations. It offers 500+ policies for security best practices and can run locally or integrate into CI/CD pipelines.

## Use cases
- scan terraform code for security misconfigurations
- detect compliance violations in infrastructure as code
- scan kubernetes yaml for security violations
- integrate iac security scanning into ci/cd pipeline
- check aws cloudformation templates for security issues
- audit helm charts for misconfigurations
- prevent insecure cloud infrastructure before provisioning

## When to choose
- you need a mature, policy-rich IaC scanner with 500+ built-in policies
- you want to scan multiple IaC formats (Terraform, CFT, ARM, Kubernetes, Helm) with one tool
- you need a CLI tool that fits easily into CI/CD pipelines

## When to avoid
- you need active maintenance, updates, or support - the repository is archived and no longer maintained
- you want ongoing policy updates for new cloud services
- you prefer an actively developed alternative like Checkov, tfsec, or Trivy

## Facets
- artifact type: cli-tool
- maturity: abandoned
- function: security, vulnerability-scanning, infrastructure-as-code, cli, ci-cd
- domain: security, cloud-computing, infrastructure-as-code, developer-tools
- platform: windows, cli, go
- tags: iac-scanning, terraform, kubernetes, cloudformation, helm, policy-as-code, devsecops, compliance, archived, devops, linux, macos, docker

## Member repositories
- tenable/terrascan (main) score 10

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:09:13.043621+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T18:00:12.088673+00:00, confidence not recorded.
  - readme: https://github.com/tenable/terrascan (fetched 2026-08-28T04:09:13.043621+00:00, sha 78e68edaabd5)
  - homepage: https://runterrascan.io (fetched 2026-08-29T08:55:25.484078+00:00, sha bb536fdd966a)
  - site_page: https://www.tenable.com/about-tenable/contact-tenable (fetched 2026-08-29T08:55:25.489434+00:00, sha 2882b0d13846)
  - site_page: https://www.tenable.com/about-tenable/about-us (fetched 2026-08-29T08:55:25.491459+00:00, sha f481a257faa5)
  - site_page: https://www.tenable.com/about-tenable/leadership (fetched 2026-08-29T08:55:25.494203+00:00, sha 16dc7728e915)
  - site_page: https://www.tenable.com/about-tenable/awards-and-recognitions (fetched 2026-08-29T08:55:25.497062+00:00, sha 1a6a63707f68)
  - site_page: https://www.tenable.com/about-tenable/engagement-and-inclusion (fetched 2026-08-29T08:55:25.499225+00:00, sha 6b9dd00c1fd4)
  - site_page: https://docs.tenable.com/ (fetched 2026-08-29T08:55:25.501547+00:00, sha 72c3d3ef60de)
  - site_page: https://www.tenable.com/products/tenable-one/pricing (fetched 2026-08-29T08:55:25.487131+00:00, sha 31ad9ac3a20e)
- Data as of 2026-08-30T08:39:29.467469+00:00.
