Skip to content

Checkov

Policy scanning for Terraform, Kubernetes and cloud config

VerifiedCloud / DevSecOps· Infrastructure as CodeBeginnerApache-2.0Open sourceEntry revised 2 Jan 2026
  • Linux
  • macOS
  • Windows
  • Docker
  • Source
This entry is thinner than the rest of the directory — missing sections are shown as such rather than filled with filler.Improve this pageContribute

Overview

4 commands documented

Checkov parses infrastructure-as-code and run-time configuration against policy checks before anything reaches production. It runs in a repository hook, in CI, or against a plan file, and its findings are plain rules you can read in the project source.

Because the checks are declarative, it fits the same role as a linter: the value is in the pull-request signal, not in a quarterly report.

Supported platforms

5

Documented install or usage guidance

Learning curve

beginner

Difficulty of becoming productive, not of the underlying theory

Tags

iac, terraform, kubernetes, ci, policy

Dataset entry

checkov.ts

Reviewed 2026-01-02

Installation

Grouped by platform. Elevation requirements are marked per method.

Homebrew

RecommendedHomebrew
brew install checkov

Package availability follows your distribution and enabled repositories. Entry revised 2 Jan 2026 — confirm the current release on the project's own download page.

Commands

4 entries

Every command carries its purpose, an example where useful, and the limitations that change how you should read the output.

01Scan a repository

bash

Auto-detects frameworks and reports failing checks with file and line references.

checkov -d .

02Scan a Terraform plan instead of source

bash

Plan-file scanning sees defaults and module output that static source does not.

terraform plan -out=tf.plan && terraform show -json tf.plan > tf.json && checkov -f tf.json

03Accept existing debt, block new findings

bash

Writes a baseline of currently failing checks so CI fails only on regressions.

checkov -d . --create-baseline && checkov -d . --soft-fail false
  • A baseline hides accepted risk. Store it in the repository and review it quarterly, or it becomes a permanent mute button.

04Machine output for CI

bash

JUnit XML or JSON in the format your pipeline already publishes.

checkov -d . -o junitxml > checkov-results.xml

Notes

  • `--framework terraform,kubernetes` narrows a monorepo job; `--skip-check CKV2_AWS_6` documents an intentional exception in code review.

Common errors

Symptoms you will actually hit, with the cause and the legitimate fix.

Hundreds of findings on a mature repositoryCause 1/2

Possible causes

  • Every framework and severity enabled on a first run.

Usual fix

Start with `--framework terraform` and `--check HIGH`, triage the top block, then widen. A noisy first run is how policy tooling gets switched off.

Module-based resources reported as 'no checks applied'Cause 2/2

Possible causes

  • Nested modules and dynamic blocks are not fully resolvable statically.

Usual fix

Scan the rendered plan (`-f tf.json`) — that is what the framework actually provisions.

Tips

  • Add it as a pre-commit hook so the feedback arrives where the change is made.
  • Read the rule implementation for anything you plan to mark 'not applicable' — several rules are provider-version specific.

Alternatives & comparisons

Not documented yet: tfsec, terrascan. Request an entry and it will link up automatically.Request a tool

Side-by-side

References

Where to verify anything on this page. External links open in a new tab.

Found something wrong?Suggest an editMore in Cloud / DevSecOps

Looking for alternatives?

Trivy cover adjacent parts of the same job.

Compare side by side