checkov
« Back to VersTracker
Description:
Prevent cloud misconfigurations during build-time for IaC tools
Type: Formula  |  Latest Version: 3.2.490@1  |  Tracked Since: Dec 17, 2025
Links: Homepage  |  @bridgecrewio  |  formulae.brew.sh
Category: Security
Tags: security devops iac cloud scanning compliance
Install: brew install checkov
About:
Checkov is a static code analysis tool for infrastructure as code (IaC). It scans cloud formations and IaC frameworks like Terraform to detect security misconfigurations and compliance policy violations before deployment. The tool supports multiple cloud providers and helps shift security left in the development lifecycle.
Key Features:
  • Scans Terraform, CloudFormation, and Kubernetes manifests
  • Detects security misconfigurations and compliance violations
  • Provides fix suggestions and security ratings
  • Integrates with CI/CD pipelines and IDEs
Use Cases:
  • Preventing cloud security vulnerabilities in IaC before deployment
  • Enforcing compliance standards like CIS benchmarks in CI/CD
Alternatives:
  • tfsec – Terraform-specific scanner, while Checkov supports multiple IaC frameworks
  • Terrascan – Similar IaC scanning capabilities with different policy sets
License: Apache-2.0
Dependencies: certifi, libyaml, numpy, pydantic, python@3.14, rpds-py
Bottles available for: arm64_tahoe, arm64_sequoia, arm64_sonoma, sonoma, arm64_linux, x86_64_linux
Version History
Detected Version Rev Change Commit
Nov 4, 2025 8:42pm 0 VERSION_BUMP cf74e4c4
Oct 30, 2025 11:52am 0 VERSION_BUMP 0c19b0b1
Oct 22, 2025 9:55pm 0 VERSION_BUMP 4551eb20
Sep 14, 2025 6:35am 0 VERSION_BUMP a3f32378
Sep 13, 2025 7:16am 0 VERSION_BUMP 47ef4ab9
Dec 18, 2024 10:54am 0 VERSION_BUMP 42596019
Nov 12, 2024 4:33pm 0 VERSION_BUMP 36790bab
Nov 12, 2024 3:31pm 0 VERSION_BUMP bf52771b
Nov 10, 2024 3:04pm 0 VERSION_BUMP 3f96c80e
Oct 28, 2024 6:07pm 0 VERSION_BUMP 9785d025
Oct 12, 2024 8:12pm 0 VERSION_BUMP 57bc798e
Oct 12, 2024 3:00pm 0 VERSION_BUMP dc7f0ebb