What we still need to verify : 1 point in this profile is not yet confirmed against vendor documentation.
- Migration status into Trivy: tfsec has been folded into Trivy's misconfiguration scanning, confirm current guidance for new adopters
Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.
What it does
tfsec reads Terraform HCL directly and evaluates it against a set of provider-specific checks. Rather than working from a plan file, it builds its own model from source, resolving variable defaults, locals and module references where the code makes them available. That source-level approach is why it fits naturally into pre-commit and pull request workflows: it needs no credentials, no state file and no provider initialization to produce results.
Checks are organized by cloud provider and service, each carrying a stable identifier, a severity, an explanation of the risk and a documentation link. Findings point at the specific line and show the offending expression, which keeps remediation obvious. Custom checks can be written in JSON, YAML or Rego, and inline comments suppress a finding at the resource with a reason string.
An important structural note: Aqua has consolidated tfsec's engine and checks into Trivy's misconfiguration scanning. The tfsec name and standalone binary remain familiar in many pipelines, but new adoption is generally pointed at Trivy.
Where it fits
tfsec is a developer-facing, pre-apply check. It runs on a laptop, as a pre-commit hook, and in CI on every pull request touching Terraform. Developers usually encounter it before a security team ever sees the finding, which is the point. Nothing has to be deployed for it to work, but its view is limited to what the HCL states plainly.
Strengths
- Terraform-specific focus means its checks and its output are tuned to how Terraform is actually written, with clear line-level attribution.
- Fast enough on large repositories to sit in a pre-commit hook without irritating developers.
- Inline suppression with a required reason produces a documented trail of accepted risk in the code itself.
- No credentials or state access required, so it is easy to introduce into a pipeline without a security review of its own.
Limitations
- Terraform only. It has nothing to say about Kubernetes manifests, Dockerfiles, CloudFormation or any other format, so it rarely stands alone.
- Source-level analysis cannot see into remote modules or resolve values determined at apply time, which is the standard blind spot and a recurring source of both missed and spurious findings.
- The project's consolidation into Trivy means new work happens there. Teams adopting today should expect to migrate, and those with existing tfsec pipelines should plan for it.
Who it suits
Still reasonable for teams with an established tfsec step that works and no appetite to change it, and for anyone who wants a minimal, Terraform-only check with almost no setup. Teams starting fresh, or who need coverage beyond Terraform, should go to Trivy directly rather than adopting tfsec and migrating later.
Used tfsec? Recommend it under your own name and title.
Recommend this tool