OnCallReady

Commands

checkov - static analysis of infrastructure as code for security and compliance misconfigurations

checkov (-d DIR | -f FILE) [--framework terraform|terraform_plan] [-c IDS] [--skip-check IDS] [-o cli|json] [--compact] [--quiet] [--soft-fail]

Options you will use

-d, --directory DIR
scan every Terraform file under DIR
-f, --file FILE
scan one file; a plan in JSON (terraform show -json tfplan > tfplan.json) is scanned as terraform_plan
-c, --check IDS
run only these checks (comma separated)
--skip-check IDS
run everything except these
-o, --output FORMAT
cli (default), json, sarif, junitxml
--compact
do not print the code block of failed resources
--quiet
show failed checks only
--soft-fail
always exit 0 (report, but do not fail the pipeline)
--var-file FILE
Variable files to load in addition to the default files (terraform.tfvars, *.auto.tfvars). Only with --directory.
--framework LIST
Filter scan to run only on specific infrastructure as code frameworks: terraform, terraform_plan, kubernetes, helm, dockerfile, github_actions...
--skip-framework LIST
Filter scan to skip specific infrastructure as code frameworks.
-s, --soft-fail
Runs checks but always returns a 0 exit code.
--soft-fail-on LIST
Exits with a 0 exit code for the specified checks (IDs or severities).
--hard-fail-on LIST
Exits with a non-zero exit code for the specified checks.
--download-external-modules BOOL
Download external terraform modules from public git repositories and the registry.
--external-checks-dir DIR
Directory for custom checks to be loaded (repeatable).
--repo-root-for-plan-enrichment DIR
Directory containing the HCL code used to generate a given plan file (links plan findings back to the .tf lines).
--deep-analysis
Combine the plan file with the Terraform files for graph-based checks.
--config-file FILE
Path to a .checkov.yaml config file.
--create-config FILE
Write the current run's settings to a config file.
--baseline FILE
Use a .checkov.baseline file to report only results not in the baseline.
--create-baseline
Write a .checkov.baseline of the current failures (to adopt checkov on a legacy repo).
--output-file-path PATH
Name of the output folder to save the chosen output formats.
--list
List the IDs and titles of the checks.
--block-list-secret-scan LIST
List of files to filter out from the secret scanner.
--check IDS
Filter scan to run only on a specific check identifier (allowlist), comma separated.

Examples

$ checkov -d . --compact

scan the configuration

$ terraform show -json tfplan > tfplan.json && checkov -f tfplan.json

scan the planned values, with every variable resolved

Gotchas

Taught in

Try checkov in a real terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.