checkov
Infrastructure as code static analysis
Decision gist · record as of 2026-08-14
Yes. Checkov is actively maintained, widely adopted (top 5000 PyPI packages), has no known vulnerabilities, and low install friction. It is essential for teams managing infrastructure-as-code who want to catch security and compliance issues early. The permissive Apache 2.0 license and broad IaC format support make it suitable for most environments. Install it if you use Terraform, CloudFormation, Kubernetes, or Dockerfile in your infrastructure pipeline.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python >= 3.9 and <= 3.12; Terraform >= 0.12 for Terraform scanning.
- Low install friction with a pure-wheel distribution.
- Actively maintained with a release just 1 day old and 8936 repository stars.
License · maintenance · safety
Apache License 2.0 (permissive) — Licensed under Apache License 2.0 (permissive), allowing free use, modification, and distribution with minimal restrictions—suitable for both open-source and commercial projects.
last release 2026-08-13 (1 days) · last repo commit 2026-08-13 · 8,936 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 21,179,540 downloads/mo, #1,008 on PyPI
Alternatives
Verify before relying
pip install checkov
checkov --directory /path/to/iac/code
# or scan a specific file:
checkov --file /path/to/terraform.tf- Whether the 46 runtime dependencies introduce supply-chain risk or maintenance burden in your environment.
- Performance characteristics when scanning large IaC repositories or many files in parallel.
What it is and what it does
Checkov is a static analysis and software composition analysis (SCA) tool designed to catch security and compliance misconfigurations in infrastructure-as-code before deployment. It scans Terraform, CloudFormation, Kubernetes manifests, Dockerfiles, Helm charts, and several other IaC formats using graph-based analysis to understand context and relationships between resources. The tool also performs SCA scanning to detect known vulnerabilities (CVEs) in container images and open-source packages.
You run it as a command-line tool pointing to a directory or file, and it reports failures and passes against built-in policies covering AWS, Azure, and Google Cloud security best practices. Results can be output in multiple formats (CLI, JSON, JUnit XML, SARIF, CycloneDX) for integration into CI/CD pipelines or security dashboards. It supports policy suppression, variable evaluation, and secret detection using regex and entropy analysis.
Use it for
- Scan Terraform configurations in CI/CD to block deployments with security misconfigurations before they reach cloud infrastructure.
- Validate Kubernetes manifests and Helm charts for compliance with security policies (e.g., pod security standards, RBAC rules).
- Detect hardcoded AWS credentials and secrets in infrastructure code and Lambda environment variables.
- Perform SCA scanning of container images and open-source dependencies to identify known CVEs.
- Generate compliance reports (SARIF, JUnit XML, CycloneDX) for security audits and regulatory requirements.
- Enforce organization-specific policies using custom YAML or Python policy definitions across all IaC files.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
Checkov is actively maintained, widely adopted (top 5000 PyPI packages), has no known vulnerabilities, and low install friction. It is essential for teams managing infrastructure-as-code who want to catch security and compliance issues early. The permissive Apache 2.0 license and broad IaC format support make it suitable for most environments. Install it if you use Terraform, CloudFormation, Kubernetes, or Dockerfile in your infrastructure pipeline.
Install
checkov on PyPI
Before you install
Low install friction with a pure-wheel distribution. Actively maintained with a release just 1 day old and 8936 repository stars. Requires Python 3.9–3.12; some environments (e.g., Debian 12) may need a virtual environment for installation.
Requires Python >= 3.9 and <= 3.12; Terraform >= 0.12 for Terraform scanning.
License in practice
Licensed under Apache License 2.0 (permissive), allowing free use, modification, and distribution with minimal restrictions—suitable for both open-source and commercial projects.
Quickstart
pip install checkov
checkov --directory /path/to/iac/code
# or scan a specific file:
checkov --file /path/to/terraform.tf
Verify before relying
- Whether the 46 runtime dependencies introduce supply-chain risk or maintenance burden in your environment.
- Performance characteristics when scanning large IaC repositories or many files in parallel.
Package facts
| License | Apache License 2.0 permissive |
| Python support | Supports the current Python release >=3.9 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 46 packagesbc-jsonpath-ngpycep-parsertabulatecoloramatermcolorjunit-xmldpathpyyamlboto3gitpythonjmespathtqdmpackagingcloudsplainingnetworkxdockerfile-parsedockerconfigargparseargcompletetyping-extensionsimportlib-metadatacachetoolscyclonedx-python-libpackageurl-pythonclickaiohttpaiodnsaiomultiprocessschemajsonschema |
| Maintenance | Actively maintained 1 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 21,179,540 / month, #1,008 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Environment :: ConsoleIntended Audience :: DevelopersIntended Audience :: System AdministratorsLicense :: OSI Approved :: Apache Software LicenseProgramming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.9Topic :: SecurityTopic :: Software Development :: Build ToolsTyping :: Typed |
Evidence: checkov-3.3.11-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “infrastructure as code security scanning”
- checkovCheckov is a static code analysis tool that scans…
- bridgecrewWraps checkov to provide infrastructure-as-code static analysis…
- cycodeCycode is a command-line security scanner that detects secrets,…
Give your agent the search over MCP, or paste the wish link into any chat.
More Build Tools packages
Provides reusable utilities for Python packaging interoperability, including version handling, specifiers, markers, requirements, tags, and metadata parsing according to standards like PEP 440 and PEP 425.
Wraps any iterable to display a real-time progress bar in the terminal or Jupyter notebook, showing iteration count, elapsed time, and estimated time remaining.
pip is the standard installer for Python packages, enabling you to download and install packages from the Python Package Index and other indexes into your Python environment.
Hatchling is a standards-compliant Python build backend that handles packaging, metadata, and distribution of Python projects when configured in a project's pyproject.toml file.
Generates Python gRPC service stubs and message classes from Protocol Buffer definitions, enabling developers to build gRPC clients and servers.
pre-commit is a framework for installing and running git hooks written in any language before commits are made, automating code quality and validation checks across multi-language projects.
Install it if your team needs consistent, automated validation at commit time.
See also bridgecrew · terraform-compliance · cycode · guarddog · kingfisher-bin · cloudsec-audit · flawfinder · awslabs.aws-iac-mcp-server · skylos · flux-local