Checkov

Description: A static code analysis tool for infrastructure-as-code. Scans Terraform, CloudFormation, Kubernetes, and other IaC files for security misconfigurations and compliance violations.

Subcategory: Infrastructure as Code Security

License: open-source

URL: Checkov