7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

tfsec

Open source

tfsec is a static analysis scanner for Terraform code that finds cloud misconfigurations, now being folded into Aqua Security's Trivy.

aquasecurity.github.io
tfsec homepage screenshot
GitHub stars
7k
Last commit
6 mo ago
Repository age
7 years
Version
v1.28.14
Licence
MIT
Self-hosted
Yes

About tfsec

tfsec is a security scanner that uses static analysis of Terraform code to spot potential misconfigurations. It checks infrastructure as code against hundreds of built-in rules for the major cloud providers, so problems such as open storage or weak settings can be caught in review or CI before resources are deployed.

It scans local and remote modules, evaluates HCL expressions, Terraform functions and relationships between resources, works with the Terraform CDK, and applies user-defined Rego policies. Output is available in several formats, including a readable default and JSON. The README announces that tfsec is now part of Trivy, the broader Aqua Security scanner, and encourages users to migrate, with a guide comparing the two tools.

tfsec stays available for the time being, but engineering attention goes to Trivy, which offers more languages and integrations and commercial support from Aqua. tfsec is written in Go and licensed under MIT, and runs locally or in CI with nothing to host. It suits DevSecOps teams with existing Terraform scanning who are planning their move to Trivy.

Key features

  • Static analysis of Terraform code
  • Hundreds of built-in misconfiguration rules
  • Scans local and remote modules
  • Custom Rego policy support
  • Multiple output formats
  • Migration path to Trivy

Good fit for

  • →Scanning Terraform in CI pipelines
  • →Finding cloud misconfigurations before deployment
  • →Planning a move from tfsec to Trivy
Built with
Go
Tags
terraform
security
static-analysis
iac
devsecops
misconfiguration
scanner
go
trivy

tfsec: questions and answers

What is tfsec used for?
tfsec is a static analysis scanner for Terraform code that finds cloud misconfigurations, now being folded into Aqua Security's Trivy. It is a good fit for scanning Terraform in CI pipelines, finding cloud misconfigurations before deployment and planning a move from tfsec to Trivy.
Is tfsec open source?
Yes. tfsec is open source under the MIT licence. Its source code is on GitHub at aquasecurity/tfsec and is written mainly in Go.
Is tfsec free?
Yes. tfsec is open source, so the software itself is free to use.
What is tfsec an alternative to?
tfsec is an open-source alternative to Aikido Security, Wiz, Orca Security and Aqua Security. Other open-source alternatives to Aikido Security include Grype, Kubescape and Trivy.
Is tfsec actively maintained?
The most recent commit to tfsec was on 25 March 2026, and the latest release is v1.28.14, published on 2 May 2025. The project has 7k stars on GitHub.

Open-source alternatives to tfsec

See all

SaaS alternatives to tfsec

See all