aquasecurity/tfsec

Tfsec is now part of Trivy

View on GitHub ↗Jump to charts ↓

Summary Information

Updated 53 minutes ago
Added to GitGenius on September 9th, 2026
Created on March 4th, 2019
Open Issues & Pull Requests: 18 (+0)
GitHub issues: Disabled - open counts may still include pull requests.
Number of forks: 559
Total Stargazers: 7,036 (+0)
Total Subscribers: 69 (+0)

Charts & Analytics

Fetching additional details & charts...

Issue Activity (beta)

GitHub issues are disabled for this repository, so issue analytics and the issue explorer are not available.

Detailed Description

Tfsec is a static analysis scanner for Terraform infrastructure-as-code that detects security misconfigurations across cloud providers.

Tfsec addresses the problem of identifying security risks in Terraform configurations before deployment. It uses static analysis to examine HCL code and spot potential misconfigurations. The tool evaluates both literal values and HCL expressions, including Terraform functions like concat(), and can trace relationships between resources. It applies hundreds of built-in rules covering major cloud providers and supports user-defined Rego policies for custom checks. The scanner handles local and remote modules and is compatible with Terraform CDK.

Tfsec suits teams using Terraform who want to integrate security scanning into CI pipelines. It offers multiple output formats including JSON, SARIF, CSV, CheckStyle, JUnit, and text, making it adaptable to different workflows. IDE plugins are available for JetBrains, VSCode, and Vim. The tool is fast and capable of scanning large repositories quickly. However, the project has transitioned to Trivy, which consolidates tfsec's Terraform scanning capabilities alongside support for additional languages and a broader ecosystem of integrations. While tfsec remains available, the maintainers direct engineering effort toward Trivy going forward.

The project maintains the tfsec repository as a stable tool while actively developing its successor. Development focus has shifted away from tfsec toward Trivy, where Terraform scanning continues as a native capability alongside expanded functionality for other infrastructure-as-code languages.