Checkov
Descripción
Checkov es un escáner de infraestructura como código (IaC) que detecta configuraciones inseguras en Terraform, CloudFormation, Kubernetes, etc.
Uso local
checkov -d . # Escanea el directorio actual
Reportes
-
CLI, JSON, JUnit, SARIF.
-
Puede integrarse con plataformas como Prisma Cloud o DefectDojo.
Integración en CI/CD
Esta acción de GitHub ejecuta Checkov en infraestructura como código, paquetes de código abierto, imágenes de contenedores y configuraciones de CI/CD para identificar configuraciones incorrectas, vulnerabilidades y problemas de cumplimiento de licencias.
- name: Run Checkov action
id: checkov
uses: bridgecrewio/checkov-action@master
with:
directory: .
soft_fail: true
download_external_modules: true
github_pat: ${{ secrets.GH_PAT }}
env:
GITHUB_OVERRIDE_URL: true # optional: this can be used to instruct the action to override the global GIT config to inject the PAT to the URL
Integraciones
GitHub, Jira (API), Slack.
VSCode: extensión oficial para resaltar problemas en tiempo real.
UI
Checkov OSS no tiene UI propia, pero Prisma Cloud (versión paga) sí.
Licencia
Open source (Apache 2.0).
Instalación simple en máquinas virtuales.
Facilidad de uso