Skip to content
/ kics Public
forked from Checkmarx/kics

Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.

License

Notifications You must be signed in to change notification settings

JulioSCX/kics

This branch is 454 commits behind Checkmarx/kics:master.

Folders and files

NameName
Last commit message
Last commit date
Jul 8, 2024
Jul 18, 2024
May 3, 2024
Jul 4, 2024
Jul 1, 2024
May 28, 2024
Jan 30, 2024
May 15, 2024
Apr 8, 2024
Jul 17, 2024
May 23, 2022
May 17, 2024
Aug 27, 2023
May 23, 2022
Jan 18, 2021
Feb 1, 2021
Jan 19, 2024
Jun 26, 2024
Apr 23, 2024
Mar 30, 2022
Jul 4, 2024
May 3, 2023
May 9, 2024
May 31, 2024
Apr 9, 2024
Aug 2, 2021
Jul 9, 2024
Jul 9, 2024
Mar 22, 2024
Apr 12, 2024
Oct 11, 2021
Mar 7, 2024
Mar 22, 2024
Mar 22, 2024
Mar 22, 2024

Repository files navigation

Latest Release License Queries Docker Pulls GitHub contributors Documentation GitHub Discussions

checkmarx Codacy Badge Quality Gate Status Go Report Card Go Coverage

KICS - Keep Infrastructure as Code Secure KICS - Keep Infrastructure as Code Secure


Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.

KICS stands for Keeping Infrastructure as Code Secure, it is open source and is a must-have for any cloud native project.

Supported Platforms


Terraform Kubernetes Docker
CloudFormation Ansible Helm
OpenAPI gRPC Azure Resource Manager Google Deployment Manager
Cloud Development Kit SAM Docker Compose Knative
Crossplane Pulumi ServerlessFW
Azure BluePrints GitHub Workflows OpenTofu Bicep

Beta Features

Databricks             NIFCloud              TencentCloud    

By default, Databricks, NIFCloud, and TencentCloud queries run when you scan Terraform files using KICS.

The Severity and Description of these queries are still under review.

Getting Started

Setting up and using KICS is super-easy.

Interested in more advanced stuff?

  • Deep dive into KICS queries.
  • Understand how to integrate KICS in your favourite CI/CD pipelines.

See KICS documentation for more details and topics.

How it Works

What makes KICS really powerful and popular is its built-in extensibility. This extensibility is achieved by:

  • Fully customizable and adjustable heuristics rules, called queries. These can be easily edited, extended and added.
  • Robust but yet simple architecture, which allows quick addition of support for new Infrastructure as Code solutions.

Community

You're welcome to join our community, talk with us on GitHub discussions or contact KICS core team at [email protected].

KICS Contributors

See our individual contributors in the community page. You're welcome to join them by contributing to KICS.

We also like to thank the following organizations for their ongoing contribution:

KICS Users

KICS is used by various companies and organizations, some are listed below. If you would like to be included here please open a PR.

Keeping Infrastructure as Code Secure!


© 2024 Checkmarx Ltd. All Rights Reserved.

About

Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.

Resources

License

Code of conduct

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages

  • Open Policy Agent 41.7%
  • HCL 26.8%
  • Go 23.9%
  • Bicep 3.3%
  • HTML 3.3%
  • Dockerfile 0.7%
  • Other 0.3%