StepSecurity Logo
StepSecurity
LoginStart free
step-security/checkov-action

step-security/checkov-action

This GitHub Action runs Checkov against infrastructure-as-code, open source packages, container images, and CI/CD configurations to identify misconfigurations, vulnerabilities, and license compliance issues.

GitHubGitHub Repository

0 stars

Composite

Maintained by StepSecurity

Score updated 24 hours ago

GitHub Actions security score comparison

step-security/checkov-actionbridgecrewio/checkov-action

Score

10/10

7/10

License

Apache License 2.0Apache License 2.0

Maintained

Maintained by StepSecurity18 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10

Vulnerabilities

0 existing vulnerabilities detected

0 existing vulnerabilities detected

Branch protection

Branch protection is maximal on development and all release branches

branch protection is not maximal on development and all release branches

Manual code review

Upstream changes are reviewed before merging-

Secure publishing

Reproducible builds with SBOM and provenance-

Signed commits

All commits are signed-

Automated security tools

Findings from tools are triaged and fixed before each change-

Popular

Used by StepSecurity enterprise customersUsed by 1392 open-source projects

Security Policy

security policy file detectedsecurity policy file not detected