Skip to main content

Checkov, Trivy and tflint

Checkov, Trivy and tflint are static scanners: they read code and images and report misconfigurations, known vulnerabilities and mistakes before anything is deployed. The GCP Enterprise Baseline and the GCP blueprints run them on every commit through pre-commit and on every pull request in CI.

What it does​

tflint lints OpenTofu code: syntax, unused declarations and, with a provider ruleset, invalid values such as a machine type that does not exist. Checkov checks infrastructure code against security policies, for example a bucket without uniform access or a cluster without network policy. Trivy scans infrastructure code for misconfigurations and container images for known vulnerabilities (CVEs) in OS packages and libraries. Each tool accepts in-line suppressions, and a suppression should say why.

How BuiltForProd uses it​

ToolVersionRuns onWhere
tflint0.64.0, tflint-ruleset-google 0.40.0OpenTofu modulespre-commit; the lint-and-scan job of each infrastructure plan.yml
Checkov3.3.19 (infrastructure), 3.3.22 (code repositories)OpenTofu modules; workflows and Dockerfiles in the code repositoriespre-commit; the plan workflow through the pinned Checkov action
Trivytrivy-action v0.36.0 in CIOpenTofu modules (pre-commit); built images (CI)pre-commit terraform_trivy; the ci.yml image scan of the code repositories

Configuration. .tflint.hcl enables the terraform plugin with the recommended preset and the Google ruleset, and lints only the repository's own modules. .checkov.yaml scans the Terraform framework, skips .terragrunt-cache and .terragrunt-stack, and skips one check, CKV_TF_1, because every module is local. tflint is downloaded at a pinned version and checked against its release SHA-256 before it runs in CI.

Suppressions carry a reason. A finding that does not apply is skipped in the resource itself, with the reason on the same line, so a reviewer sees the exception where it is made. For example, the GKE cluster skips the Calico network-policy check because Dataplane V2 enforces NetworkPolicy itself, and the data lake skips legacy bucket access logs because Data Access audit logs record object access.

Image scans. The code repositories' ci.yml builds every image without pushing it and scans it with Trivy: fixable CRITICAL and HIGH findings in OS packages and libraries fail the pull request, and findings with no fix available are reported but do not block. Pushed images are scanned again by Artifact Analysis in the registry.

Terms you will see​

TermMeaning
RulesetA tflint plugin of provider-specific rules, here for Google Cloud.
Check IDThe identifier of a Checkov policy, such as CKV_GCP_12.
In-line skipA suppression comment on the resource, with its reason.
ignore-unfixedTrivy reports CVEs without a fix but does not fail on them.

Where to read more​