OpenBSD Handbook

Current snapshot · amd64 · Generated 2026-09-09

tfsec-1.28.14

static analyzer for Terraform

Back to search · Project homepage

Description

tfsec uses static analysis of your Terraform code to spot potential misconfigurations. Features: * Checks for misconfigurations across all major (and some minor) cloud providers * Hundreds of built-in rules * Scans modules (local and remote) * Evaluates HCL expressions as well as literal values * Evaluates Terraform functions e.g. concat() * Evaluates relationships between Terraform resources * Compatible with the Terraform CDK * Applies (and embellishes) user-defined Rego policies * Supports multiple output formats: lovely (default), JSON, SARIF, CSV, CheckStyle, JUnit, text, Gif. * Configurable (via CLI flags and/or config file) * Very fast, capable of quickly scanning huge repositories * Plugins for popular IDEs available (JetBrains, VSCode and Vim) * Community-driven - come and chat with us on Slack!

Package information

Ports path
security/tfsec
Package architecture
amd64
Maintainer
Pavel Korovin <pvk@openbsd.org>
Categories
security, lang/go
Available flavors
None listed
Only for architectures
aarch64, amd64, arm, i386, riscv64

These are ports metadata. Binary availability depends on the release, architecture and mirror. Build and test dependencies are not an installation checklist.

Direct dependencies

Build

Installing and updating packages · Package details as JSON