Skip to content

Checkov

Vulnerability Scanning

Static code analysis tool for infrastructure-as-code (IaC) that scans Terraform, CloudFormation, Kubernetes, Dockerfiles and other formats to detect security and compliance misconfigurations, plus software‑composition analysis for CVEs.

Python Latest 3.3.8 · 17d ago Security brief →

Features

  • Over 1000 built‑in policies covering AWS, Azure, GCP security & compliance
  • Scans Terraform, CloudFormation, Kubernetes, Helm, Dockerfile, Serverless and many other IaC formats
  • Performs software composition analysis (SCA) to detect CVEs in packages and images

Security Response History

2 CVEs
CVE Severity Disclosed Patched (this tool) vs Ecosystem Median
CVE-2020-11023 KEV medium
CVSS 6.9
2025-01-23 2026-01-25 1y / median 1y 1mo
CVE-2023-44487 KEV medium
CVSS 7.5
2023-10-10 2026-01-25 2y 4mo / median 2y 3mo

Recent releases

View all 34 releases →
No immediate action
3.3.8 Bug fix

CKV_K8S_40 fix

No immediate action
3.3.7 Bug fix

SCA GitHub output fix

No immediate action
3.3.6 Bug fix

Fixes S3 crash

No immediate action
3.3.5 Bug fix

Retry kustomize/helm installs

No immediate action
3.3.2 Bug fix

log_bucket handling + GCP check

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

About

Stars
8,875
Forks
1,367
Languages
Python HCL TypeScript

Install & Platforms

Install via
pip
Platforms
linux macos windows

Community & Support

Beta — feedback welcome: [email protected]