# checkov

Canonical URL: https://doramagic.ai/en/projects/checkov/

Source repository: https://github.com/bridgecrewio/checkov

## What it is

Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.

## Capability boundary

Portable AI capability asset

## First safe verification

Verify the smallest path in an isolated environment and keep a rollback path.

## Main risk

May increase setup, validation, or first-run risk for the user.

## Evidence base

https://github.com/bridgecrewio/checkov, https://github.com/bridgecrewio/checkov#readme, Human Manual, Pitfall Log
