bridgecrew
Infrastructure as code static analysis
Decision gist · record as of 2026-08-14
No. This package is explicitly deprecated and no longer supported. The maintainers recommend using checkov directly instead. There is no functional advantage to installing bridgecrew over checkov, and doing so ties you to unmaintained code that may become incompatible with future checkov releases.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- This package is deprecated and no longer supported; use checkov directly instead.
License · maintenance · safety
Apache License 2.0 (permissive) — Apache License 2.0 permits use, modification, and distribution with minimal restrictions, making it suitable for both commercial and open-source projects.
last release 2026-03-26 (141 days)
0 known vulnerabilities (OSV.dev, 2026-08-14) · 97,232 downloads/mo, #13,162 on PyPI
Alternatives
Verify before relying
pip install bridgecrew
from bridgecrew import cli
# Use checkov via bridgecrew CLI wrapper- Whether the package remains functional given its deprecation status and planned archival end of 2023
- Current maintenance state and whether checkov dependency receives active updates
What it is and what it does
Bridgecrew is a deprecated wrapper around checkov that provides infrastructure-as-code static analysis through a command-line interface. It scans IaC files for security misconfigurations and compliance violations. The package is no longer maintained and was planned for archival at the end of 2023; the maintainers explicitly recommend using checkov directly instead.
Since bridgecrew is simply a CLI wrapper for checkov with no additional functionality, installing it adds a layer of indirection without benefit. The single runtime dependency is checkov itself, which you can invoke directly without the deprecated wrapper.
Use it for
- Scan infrastructure-as-code files for security and compliance violations via a bridgecrew-branded CLI
- Analyze Terraform, CloudFormation, or other IaC configurations for misconfigurations
- Integrate IaC scanning into CI/CD pipelines using the bridgecrew command-line interface
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
No.
This package is explicitly deprecated and no longer supported. The maintainers recommend using checkov directly instead. There is no functional advantage to installing bridgecrew over checkov, and doing so ties you to unmaintained code that may become incompatible with future checkov releases.
Install
bridgecrew on PyPI
Before you install
This package is deprecated and no longer supported; use checkov directly instead.
License in practice
Apache License 2.0 permits use, modification, and distribution with minimal restrictions, making it suitable for both commercial and open-source projects.
Quickstart
pip install bridgecrew
from bridgecrew import cli
# Use checkov via bridgecrew CLI wrapper
Verify before relying
- Whether the package remains functional given its deprecation status and planned archival end of 2023
- Current maintenance state and whether checkov dependency receives active updates
Package facts
| License | Apache License 2.0 permissive |
| Python support | Not specified |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 1 packagecheckov |
| Maintenance | Actively maintained 141 days since the last release |
| First released | |
| Downloads | 97,232 / month, #13,162 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Environment :: ConsoleIntended Audience :: DevelopersIntended Audience :: System AdministratorsLicense :: OSI Approved :: Apache Software LicenseProgramming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.7Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9Topic :: SecurityTopic :: Software Development :: Build Tools |
Evidence: bridgecrew-3.2.511-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “infrastructure as code scanning”
- bridgecrewWraps checkov to provide infrastructure-as-code static analysis…
- checkovCheckov is a static code analysis tool that scans…
- cycodeCycode is a command-line security scanner that detects secrets,…
Give your agent the search over MCP, or paste the wish link into any chat.
More Build Tools packages
Provides reusable utilities for Python packaging interoperability, including version handling, specifiers, markers, requirements, tags, and metadata parsing according to standards like PEP 440 and PEP 425.
Wraps any iterable to display a real-time progress bar in the terminal or Jupyter notebook, showing iteration count, elapsed time, and estimated time remaining.
pip is the standard installer for Python packages, enabling you to download and install packages from the Python Package Index and other indexes into your Python environment.
Hatchling is a standards-compliant Python build backend that handles packaging, metadata, and distribution of Python projects when configured in a project's pyproject.toml file.
Generates Python gRPC service stubs and message classes from Protocol Buffer definitions, enabling developers to build gRPC clients and servers.
pre-commit is a framework for installing and running git hooks written in any language before commits are made, automating code quality and validation checks across multi-language projects.
Install it if your team needs consistent, automated validation at commit time.
See also checkov · cycode · socketsecurity · pulumi-github · terraform-compliance · uv-secure · awslabs.aws-iac-mcp-server · safety · pulumi-docker · pulumiverse-grafana