Skip to content

NordCoderd/cloud-security-plugin

Repository files navigation

Cloud (IaC) Security Plugin for JetBrains IDEs

CI JetBrains Plugin Version JetBrains Plugin Downloads

Logo

Cloud (IaC) Security Linter for JetBrains IDEs (e.g., IntelliJ IDEA, PyCharm, WebStorm, and more).

Scan Docker (dockerfile and compose), Kubernetes files for security vulnerabilities and misconfigurations directly within your JetBrains IDE.

Why this plugin?

  • Seamless integration into the IDE without installing external tools.
  • Verifies your files on the fly and highlight problems earlier, and that make shift left happens.
  • Quick-fixes for problems are available for some inspections that could help fix problems faster.
  • Supports complicated verifications, such as tracking variables and arguments as sources of issues.
  • Pure Kotlin implementation, leveraging the power of IDEs.

What does the plugin offer?

  • Dockerfile Analysis: Detect security vulnerabilities and optimize Docker images with over 40 checks.
  • Docker Compose: Detect security vulnerabilities and misconfigurations.
  • Kubernetes: Detect security issues to align with the Pod Security Standards.
  • Quick Fixes: Resolve issues faster using built-in quick fixes.

What problems can the plugin detect?

You can find more information about detected problems:

Planned features

  • Kubernetes: Implementing more rules to align with the NSA and CISA Kubernetes Hardening Guide.

References

Thanks

  • My mother, who supported me every step of the way and who is no longer with us.