S
26

Side-by-side IaC scan comparison made me switch teams at work

Last month I ran both tfsec and Checkov against the same Terraform repo, about 340 lines with a few S3 buckets and an IAM role. tfsec flagged maybe 4 things, all legit, and its CLI was dead simple. Checkov found 22 issues but half of them were false positives about stuff like tagging policies we don't even enforce. I spent 2 hours digging through Checkov's docs just to figure out which rules to skip, and at that point my teammate walked by and asked why I was still on the same ticket. The kicker is we had been paying for Checkov's enterprise tier for a year, and nobody realized the free tfsec caught the one actual misconfiguration, an open security group, way faster. Has anyone else ditched a fancy scanner for a simpler one and had to convince their security lead it wasn't a downgrade?
1 comments

Log in to join the discussion

Log In
1 Comment
the_tara
the_tara1mo ago
Ha! My buddy literally did this with SonarQube last year. He switched their whole pipeline to a free linter and the security lead only cared once he showed the paid tool missed a real flaw the free one caught.
8