Checkov
Vulnerability ScanningStatic code analysis tool for infrastructure-as-code (IaC) that scans Terraform, CloudFormation, Kubernetes, Dockerfiles and other formats to detect security and compliance misconfigurations, plus software‑composition analysis for CVEs.
Features
- Over 1000 built‑in policies covering AWS, Azure, GCP security & compliance
- Scans Terraform, CloudFormation, Kubernetes, Helm, Dockerfile, Serverless and many other IaC formats
- Performs software composition analysis (SCA) to detect CVEs in packages and images
Security Response History
2 CVEs| CVE | Severity | Disclosed | Patched (this tool) | vs Ecosystem Median |
|---|---|---|---|---|
| CVE-2020-11023 KEV |
medium
CVSS 6.9
|
2025-01-23 | 2026-01-25 | 1y / median 1y 1mo |
| CVE-2023-44487 KEV |
medium
CVSS 7.5
|
2023-10-10 | 2026-01-25 | 2y 4mo / median 2y 3mo |
Recent releases
View all 34 releases →Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Install & Platforms
Install via
pip
Platforms
linux
macos
windows