cdk-nag
Check CDK v2 applications for best practices using a combination on available rule packs.
Decision gist · record as of 2026-08-14
Yes. cdk-nag is actively maintained, has no known vulnerabilities, low install friction, and provides essential compliance and security scanning for CDK users. The permissive Apache-2.0 license poses no restrictions. Install it if you use CDK and need to enforce security or compliance standards.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.10 or later; aws-cdk-lib and constructs must be installed as runtime dependencies.
- Low install friction with a pure Python wheel distribution.
- Actively maintained with recent releases and 1032 repository stars.
License · maintenance · safety
Apache-2.0 (permissive) — Licensed under Apache-2.0 (permissive), allowing free use, modification, and distribution with minimal restrictions.
last release 2026-08-04 (10 days) · last repo commit 2026-08-10 · 1,032 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 3,690,555 downloads/mo, #2,528 on PyPI
Alternatives
Verify before relying
pip install cdk-nag
from cdk_nag import AwsSolutionsChecks
from constructs import Construct
Validations.of(app).add_plugins(AwsSolutionsChecks(app))- Whether all rule packs (AWS Solutions, HIPAA, NIST 800-53 rev 4/5, PCI DSS, Serverless) are equally mature or if some are experimental.
- Performance characteristics when scanning large CDK applications or complex CloudFormation templates.
- Specific use cases for the publication runtime dependency.
What it is and what it does
cdk-nag is a linting and compliance-checking tool for CDK applications and CloudFormation templates. It runs predefined rule packs—including AWS Solutions best practices, HIPAA security, NIST 800-53 revisions 4 and 5, PCI DSS 3.2.1, and Serverless patterns—to detect security misconfigurations and compliance gaps in infrastructure code. The tool integrates into validation frameworks, allowing you to suppress specific violations on individual constructs or stacks with inline acknowledgments and audit trails.
The package depends on aws-cdk-lib, constructs, jsii, and publication. It supports Python 3.10 through 3.14 and is actively maintained. Violations are reported in a policy-validation-report.json file in the cloud assembly, with optional CloudFormation metadata integration for compatibility with existing compliance tooling.
Use it for
- Enforce best practices across CDK applications before synthesis or deployment.
- Validate infrastructure code against regulatory frameworks during CI/CD pipelines.
- Suppress known violations on specific resources with documented reasons for audit compliance.
- Scan CloudFormation templates directly for security and compliance issues.
- Integrate compliance checking into synthesis pipelines to catch violations early.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
cdk-nag is actively maintained, has no known vulnerabilities, low install friction, and provides essential compliance and security scanning for CDK users. The permissive Apache-2.0 license poses no restrictions. Install it if you use CDK and need to enforce security or compliance standards.
Install
cdk-nag on PyPI
Before you install
Low install friction with a pure Python wheel distribution. Actively maintained with recent releases and 1032 repository stars.
Requires Python 3.10 or later; aws-cdk-lib and constructs must be installed as runtime dependencies.
License in practice
Licensed under Apache-2.0 (permissive), allowing free use, modification, and distribution with minimal restrictions.
Quickstart
pip install cdk-nag
from cdk_nag import AwsSolutionsChecks
from constructs import Construct
Validations.of(app).add_plugins(AwsSolutionsChecks(app))
Verify before relying
- Whether all rule packs (AWS Solutions, HIPAA, NIST 800-53 rev 4/5, PCI DSS, Serverless) are equally mature or if some are experimental.
- Performance characteristics when scanning large CDK applications or complex CloudFormation templates.
- Specific use cases for the publication runtime dependency.
Package facts
| License | Apache-2.0 permissive |
| Python support | Supports the current Python release >=3.10 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 4 packagesaws-cdk-libconstructsjsiipublication |
| Maintenance | Actively maintained 10 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 3,690,555 / month, #2,528 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 4 - BetaIntended Audience :: DevelopersLicense :: OSI ApprovedOperating System :: OS IndependentProgramming Language :: JavaScriptProgramming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Typing :: Typed |
Evidence: cdk_nag-3.0.2-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “cdk security scanning”
- cdk-nagScans AWS CDK applications and CloudFormation templates against…
- aws-cdk.aws-ecrProvides AWS CDK constructs for defining, configuring, and managing…
- cdk-events-notifyAn AWS CDK Construct Library that automatically sends Slack…
Give your agent the search over MCP, or paste the wish link into any chat.
More Quality Assurance packages
Coverage.py measures which lines of Python code are executed during test runs, reporting coverage percentages and identifying untested code paths.
Install it if you want to measure test completeness or enforce coverage thresholds in your project.
Ruff is a Python linter and code formatter written in Rust that combines linting, formatting, and code fixing into a single tool, replacing Flake8, Black, isort, and related utilities.
Pexpect spawns and controls interactive console applications by sending input and matching output patterns, automating tasks that would otherwise require manual interaction.
Black reformats Python source code to a consistent style by parsing entire files and rewriting them according to an opinionated, deterministic set of rules, eliminating manual formatting decisions.
pytest-xdist distributes pytest tests across multiple CPU cores or machines to speed up test execution, with the simplest usage being `pytest -n auto` to spawn workers equal to available CPUs.
Install it if your test suite takes long enough that parallelization would save meaningful time.
Validates AWS CloudFormation templates in YAML or JSON format against resource provider schemas and best practices, checking property values and configuration correctness.
Install it if you work with CloudFormation templates.
See also awslabs.aws-iac-mcp-server · ick · cloudsec-audit · aws-cdk.integ-tests-alpha · compliance-trestle · aws-cdk.aws-kms · aws-cdk.aws-cloudwatch · aws-cdk.aws-servicediscovery · abi3audit · prowler