checkov

Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.

APACHE-2.0 License

Downloads
4.3M
Stars
6.8K
Committers
400

Bot releases are visible (Hide)

checkov - 3.2.98

Published by github-actions[bot] 5 months ago

Bug Fix

  • terraform: Remove invalid CIDRs in CKV2_AWS_44 - #6301
checkov - 3.2.97

Published by github-actions[bot] 5 months ago

Feature

  • arm: add CKV_AZURE_73 to ensure that Automation account variables are encrypted - #6271
  • arm: add CKV_AZURE_76 to ensure that Azure Batch account uses key vault to encrypt data - #6280
  • arm: add FunctionAppDisallowCORS - password correctness check - #6248
  • arm: ARM FunctionAppHttpVersionLatest policy - #6244
  • arm: CKV_AZURE_74 to Ensure that Azure Data Explorer (Kusto) uses disk encryption - #6273
  • arm: MSSQLServerMinTLSVersion - #6245
checkov - 3.2.95

Published by github-actions[bot] 5 months ago

Bug Fix

  • terraform: handle module source tag ref when it is not the first parameter - #6314
checkov - 3.2.94

Published by github-actions[bot] 5 months ago

Bug Fix

  • sast: fix random test sast js - #6315

Platform

  • general: Double-Encode URI for RelayState Parameter - #6302
checkov - 3.2.92

Published by github-actions[bot] 5 months ago

Feature

  • sast: CDK TypeScript policies - #6161
  • terraform: add check for tf module versioned tag - #6213

Bug Fix

  • secrets: secret_filter_block_list filter by file name and suffixes - #6285
  • secrets: secret_filter_block_list filter by file name and suffixes 2 - #6306

Platform

  • general: Fix policy.name to use the spaces as specified on CLI. - #6296
checkov - 3.2.91

Published by github-actions[bot] 5 months ago

Feature

  • secrets: bump bc-detect-secrets to 1.5.10 - #6297
checkov - 3.2.90

Published by github-actions[bot] 5 months ago

Feature

  • general: Add deep-analysis to GHA - #6288
  • terraform: Add more hype policies - #6239

Bug Fix

  • ansible: fix ansible definitions raw type - #6292

Platform

  • ansible: add set definitions raw to ansible runner - #6286
  • general: Handle SAST suppressions (suppressions V2) - #6109

Documentation

  • general: add RENDER_EDGES_DUPLICATE_ITER_COUNT to docs - #6291
  • general: Update README links for PyPi - #6231
checkov - 3.2.85

Published by github-actions[bot] 6 months ago

Platform

  • ansible: add missing arg to ansible runner - #6276
checkov - 3.2.84

Published by github-actions[bot] 6 months ago

Feature

  • sast: Enable cdk ts integraion test - #6158

Bug Fix

  • secrets: add files for secret to skip - #6275
  • terraform: Update CKV_AWS_31 for RBAC - #6224
checkov - 3.2.82

Published by github-actions[bot] 6 months ago

Feature

  • github: add summary message in github_failed_only output - #6131
  • sast: add ts checks to python pack - #6261
  • sast: run all cdk integration test - #6256

Bug Fix

  • general: fix changed serif path - #6251
checkov - 3.2.79

Published by github-actions[bot] 6 months ago

Feature

  • sast: Add 10 TS CDK - #6194
  • sast: add typescript - DONT MERGE - #6193
  • sast: Filter js files generate by ts - #6220
  • secrets: bump bc-detect-secrets 1.5.9 - #6205
  • terraform: Add GCP policy - #6177
  • terraform: Add resource attributes to jsonify - #6203
  • terraform: Ensure dedicated data endpoints are enabled - #6188
  • terraform: support provider in tf_plan graph - #6195
  • terraform: Update CloudArmorWAFACLCVE202144228.py - #6217

Bug Fix

  • general: add print to random test - #6229
  • general: fix integration test in build - #6227
  • general: fix integration tests - #6207
  • kubernetes: Update checkov-job.yaml - #5985
  • sca: remove old test for the depracated workflow github-action - #6232
  • terraform_plan: Edges not created because of indexing in resource["address"] when resources in modules use count - #6145
  • terraform: CKV_AWS_23 rule description fixed for clarity - #5993
  • terraform: Fix CKV_AWS_358 to handle plan files - #6202

Platform

  • ansible: add create_definitions function for ansible framework - #6225

Documentation

  • general: Fix docs html brackets - #6051
  • general: Remove Python 3.7 - #6200
checkov - 3.2.74

Published by github-actions[bot] 6 months ago

Feature

  • general: Update range includes to handle lists of ranges and lists of values - #6192
checkov - 3.2.73

Published by github-actions[bot] 6 months ago

Feature

  • sast: TypeScript cdk policies p7 - #6186
checkov - 3.2.72

Published by github-actions[bot] 6 months ago

Feature

  • bicep: Add bicep version of policy - #6191
checkov - 3.2.71

Published by github-actions[bot] 6 months ago

Feature

  • sca: support licenses custom policies enforcement rules - #6173
checkov - 3.2.70

Published by github-actions[bot] 6 months ago

Feature

  • sast: Add 5 cdk for TS - #6179

Bug Fix

  • sast: fix skipped_checks paths before upload to the platform - #6183
checkov - 3.2.68

Published by github-actions[bot] 6 months ago

Feature

  • sast: adding extended code block - #6178
  • sca: using the new api license/get-licenses-violations instead of packages/get-licenses-violations (which is deprecated) - #6174

Bug Fix

  • sca: Revert "feat(sca): using the new api license/get-licenses-violations … - #6176
checkov - 3.2.65

Published by github-actions[bot] 6 months ago

Bug Fix

  • sast: save suppress_comment for sast inline suppressions - #6171
  • secrets: Azure Storage Key detector updates in bc-detect-secrets 1.5.7 - #6168
checkov - 3.2.63

Published by github-actions[bot] 6 months ago

Feature

  • sast: CDK TS policies p2 - #6165
checkov - 3.2.60

Published by github-actions[bot] 6 months ago

Feature

  • sast: Add TS CDK policies 1 - #6151
  • sast: CDK TS policies p3 - #6157

Bug Fix

  • terraform: Fix conditional expression evaluation logic with compare - #6160
  • terraform: Fixed flaky test for CKV_AWS_356 - #6162
Package Rankings
Top 9.86% on Proxy.golang.org
Top 0.86% on Pypi.org
Badges
Extracted from project README
checkov Maintained by Prisma Cloud build status security status code_coverage docs PyPI Python Version Terraform Version Downloads Docker Pulls slack-community Open in Gitpod