Checkov
checkovA static code analysis tool for infrastructure as code (IaC), and a software composition analysis (SCA) tool for images and open source packages.
A static code analysis tool for infrastructure as code (IaC), and a software composition analysis (SCA) tool for images and open source packages.
Otty extracts these into your secret store instead of syncing the files. Every generated manager config below leaves them out too.
bc-api-keyThe rest of the file syncs. Only these values are lifted out and kept in your secret store.
bc-api-keyThe rest of the file syncs. Only these values are lifted out and kept in your secret store.
Nothing. Checkov writes no caches or state in your home directory.
bc-api-keyLifted into your secret store; the rest of the file syncs.
bc-api-keyLifted into your secret store; the rest of the file syncs.
Only what the catalog names. A directory that syncs brings everything inside it except what is listed as excluded here.
Opens otty://sync/add/checkov. Otty ships with this catalog, so the link only has to name the tool — nothing is downloaded.
Every one of these keeps the credential file out.