checkov

Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.

APACHE-2.0 License

Downloads
4.3M
Stars
6.8K
Committers
400

Bot releases are visible (Hide)

checkov - 3.1.26

Published by github-actions[bot] 11 months ago

Bug Fix

  • general: check both path types for suppression - #5834
  • terraform: Fix range issue in OCI RDP check - #5832
checkov - 3.1.24

Published by github-actions[bot] 11 months ago

Bug Fix

  • sca: Update the log level of specific logs - #5828
  • terraform: CKV_GCP_26 Added additional google_compute_subnetwork purposes that do not support flow logs - #5812
  • terraform: Fix CKV_GCP_30 for unknown service account - #5818
  • terraform: Fixed to_dict of terraform block regarding source_module_object - #5822
checkov - 3.1.21

Published by github-actions[bot] 11 months ago

Feature

  • ansible: add CKV_PAN_17 - Check for src and dst zone any - #5803
  • sast: sast enabled from integration - #5780
  • terraform: Adding Python based build time policies for corresponding PC runtime policies - #5762
  • terraform: Adding YAML based build time policies for corresponding PC runtime policies - #5810
checkov - 3.1.20

Published by github-actions[bot] 11 months ago

Platform

  • general: handle the updated on prem response from the platform - #5809
checkov - 3.1.19

Published by github-actions[bot] 11 months ago

Feature

  • sca: Using alias data from assets.json for giving Package Used indication for aliased packages - #5808
checkov - 3.1.18

Published by github-actions[bot] 11 months ago

Bug Fix

  • terraform: Add source_module_object to blocks from_dict func - #5806
checkov - 3.1.17

Published by github-actions[bot] 11 months ago

Feature

  • ansible: PAN-OS IPsec checks - #5802
checkov - 3.1.15

Published by github-actions[bot] 11 months ago

Feature

  • ansible: add CKV_PAN_16 PAN-OS BPA Check for session log at start - #5794
  • sast: Add alias data to imports assets - #5788

Bug Fix

  • bicep: Update AppServiceHttps20Enabled to consider newer ApiVersion - #5795
checkov - 3.1.11

Published by github-actions[bot] 11 months ago

Bug Fix

  • general: Policy metadata API fixes - #5761
checkov - 3.1.9

Published by github-actions[bot] 11 months ago

Bug Fix

  • gha: Update GitHub Actions Workflow Schema #5742 - #5759
  • terraform_plan: load terraform registry checks when using terraform plan - #5778
  • terraform: Ensure HTTPS in Azure Function App and App Slots - #5766

Platform

  • general: do not display an auth error when the runconfig endpoint returns a 500 - #5779
checkov - 3.1.4

Published by github-actions[bot] 11 months ago

Breaking Change

  • general: set default parallelization type to spawn and leverage Terraform downloaded module by default - #5760

Feature

  • terraform: Ensure ACR is zone-redundant - #5748

Bug Fix

  • general: Revert parallelization commit - #5777
  • sast: remove SAST frameworks for OSS users - #5773
  • secrets: don't reinitialize the upload client without API key usage - #5771

Documentation

  • general: properly escape CLI flags in the CLI command docs - #5768
checkov - 3.0.40

Published by github-actions[bot] 11 months ago

Bug Fix

  • terraform_plan: TF plan resources connection fix - #5767
checkov - 3.0.38

Published by github-actions[bot] 11 months ago

Feature

  • terraform: Adding YAML based build time policies for corresponding PC runtime policies - #5714
checkov - 3.0.37

Published by github-actions[bot] 11 months ago

Bug Fix

  • terraform: fix valid value for aws keyspaces_table encryption_specification type - #5756
checkov - 3.0.36

Published by github-actions[bot] 11 months ago

Bug Fix

  • terraform: check min TLS version also on azure app slots - #5753
checkov - 3.0.34

Published by github-actions[bot] 11 months ago

Feature

  • general: add possibility to change parallelization type - #5737

Bug Fix

  • cloudformation: ignore unresolved references in CKV_AWS_45 - #5747
checkov - 3.0.32

Published by github-actions[bot] 12 months ago

Feature

  • sast: Python cdk policies batch 2 - #5725

Bug Fix

  • general: add option to pass --skip-download with github-action - #5734

Platform

  • general: print the log upload location if the --support flag is used - #5738
checkov - 3.0.28

Published by github-actions[bot] 12 months ago

Bug Fix

  • terraform: Adding both azurerm_linux_web_app_slot & azurerm_windows_web_app_slot in scope of the test CKV_AZURE_153 - #5687

Documentation

  • general: Switch references to Bridgecrew with Prisma Cloud - #5704
checkov - 3.0.25

Published by github-actions[bot] 12 months ago

Bug Fix

  • general: do not require a repo ID when using an API key and --list - #5726
checkov - 3.0.24

Published by github-actions[bot] 12 months ago

Feature

  • sast: add new python CDK policies - #5706
  • terraform: Ensure that only critical system pods run on system nodes - #5665
Package Rankings
Top 9.86% on Proxy.golang.org
Top 0.86% on Pypi.org
Badges
Extracted from project README
checkov Maintained by Prisma Cloud build status security status code_coverage docs PyPI Python Version Terraform Version Downloads Docker Pulls slack-community Open in Gitpod