Checkov
Checkov is a static code analysis tool for scanning Infrastructure as Code (IaC) files for misconfigurations.
Files
Checkov will run on files with the following files and extensions:
.tf.yml.yaml.json.template.bicep.hclbower.jsonbuild.gradlebuild.gradle.ktsgo.sumgradle.propertiesMETADATAnpm-shrinkwrap.jsonpackage.jsonpackage-lock.jsonpom.xmlrequirements.txtDockerfile.dockerfileDockerfile.*.csprojyarn.lockGemfileGemfile.lockgo.modpaket.dependenciespaket.lockpackages.configcomposer.jsoncomposer.lock
Configuration
CodeRabbit will include on the following severity levels based on the profile selected:
Chill
HIGHCRITICAL
Assertive
MEDIUMHIGHCRITICAL