# Checkov

> Checkov is an open source static analysis tool that scans Terraform, Kubernetes and Dockerfile code for security and compliance misconfigurations.

- Source: https://www.itwonderlab.com/checkov/
- Published: 2026-09-02
- Updated: 2026-09-02
- Author: Javier Ruiz Jiménez (https://www.javierruizjimenez.com/)
- Site: IT Wonder Lab (https://www.itwonderlab.com/)

---

**Checkov**, from Prisma Cloud, reads your IaC files before they are deployed and reports insecure settings, for example a public S3 bucket or an unencrypted volume, with the id of the policy that failed.

### Key concepts

- **Policy**: a rule such as `CKV_AWS_18`.
- **Skip**: suppress a rule with an inline comment and a reason.
- Runs in CI, next to [TFLint](https://www.itwonderlab.com/tflint/) and [Trivy](https://www.itwonderlab.com/trivy/).

### Learn it

See [Terraform security scanning with TFLint, Checkov and Trivy](https://www.itwonderlab.com/terraform-security-scanning-tflint-checkov-trivy/).
