SaaSHub helps you find the best software and product alternatives Learn more →
Tfsec Alternatives
Similar projects and alternatives to tfsec
-
checkov
Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.
-
trivy
Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more
-
InfluxDB
Build time-series-based applications quickly and at scale.. InfluxDB is the Time Series Platform where developers build real-time applications for analytics, IoT and cloud-native services. Easy to start, it is available in the cloud or on-premises.
-
terraform-security-scan
Run a security scan on your terraform with the very nice https://github.com/aquasecurity/tfsec
-
terrascan
Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure. [Moved to: https://github.com/accurics/terrascan] (by cesar-rodriguez)
-
-
cli
a lightweight, security focused, BDD test framework against terraform. (by terraform-compliance)
-
-
SonarQube
Static code analysis for 29 languages.. Your projects are multi-language. So is SonarQube analysis. Find Bugs, Vulnerabilities, Security Hotspots, and Code Smells so you can release quality code every time. Get started analyzing your projects today for free.
-
terragrunt
Terragrunt is a thin wrapper for Terraform that provides extra tools for working with multiple Terraform modules.
-
-
-
terraform-docs
Generate documentation from Terraform modules in various output formats
-
pre-commit-terraform
pre-commit git hooks to take care of Terraform configurations 🇺🇦
-
kics
Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.
-
iam-policy-json-to-terraform
Small tool to convert an IAM Policy in JSON format into a Terraform aws_iam_policy_document
-
terraformer
CLI tool to generate terraform files from existing infrastructure (reverse Terraform). Infrastructure to Code
-
infracost
Cloud cost estimates for Terraform in pull requests💰📉 Love your cloud bill!
-
OPA (Open Policy Agent)
An open source, general-purpose policy engine.
-
terratest
Terratest is a Go library that makes it easier to write automated tests for your infrastructure code.
-
terrascan
Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure.
-
-
SaaSHub
SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives
tfsec reviews and mentions
-
What are the best static analysis security testing tools for Terraform and infrastructure as code?
Beyond Snyk and Checkov - I have also used https://github.com/aquasecurity/tfsec at a few organizations both for use locally and in CI (PR Review Checks)
- Breve guia de sobrevivência com Terraform
-
My Cloud Resume Challenge Journey
Once I completed the main steps of the challenge, I went back to do some security modificaions including enabled DNSSEC, deploying WAF (I ended up removing this as the costs were quite high and instead set up account level throttling for my API) and running IAM Access Analyser to flag anything I'd over permissioned. I also set up Git commit signing and added a new Git Action workflow to run Tfsec any time I updated my terraform config files
-
Atlantis vs. Terraform Cloud / Terraform Enterprise – Comparison
Flexibility is one of the core advantages of Atlantis, as it allows easy integration with other Terraform-helper tools(e.g., tfsec, checkov, Infracost, or Terratag). It can work with Terraform wrappers, such as Terragrunt, out of the box and even add some of Terragrunt’s features to vanilla Terraform – like before and after hooks for every execution stage (init, plan, apply, etc.).
-
List of most useful Terraform open-source tools
tfsec: https://github.com/aquasecurity/tfsec
-
Terraform Module Template
Static code analysis with TFLint, tfsec and checkov.
-
Newbie needs some guidance on new project
For your scanning, I would also check out tfsec and tflint. In you ci/cd, add them to the same step as terraform validate.
-
Trouble building a module to host a static website in S3 using Cloudfront
I recommend running tfsec against your module and taking a look at the suggestions.
-
Terraform - IaC Scanning with TFSEC for VsCode (Extension)
You can scan your Terraform configuration artifacts easily giving you the confidence that all is well with your configuration before committing your code to source control / deploying your Terraform (IaC) configurations. It is a free/open source tool by AquaSecurity. For more information go check out the Tfsec github page
-
A note from our sponsor - #<SponsorshipServiceOld:0x00007fea6196fa70>
www.saashub.com | 9 Feb 2023
Stats
aquasecurity/tfsec is an open source project licensed under MIT License which is an OSI approved license.