head to head · open source

checkov vs kyverno

checkov has 9,015 GitHub stars, 1,415 forks, 170 open issues and last shipped 3 days ago. kyverno has 8,168 stars, 1,602 forks, 703 open issues and last shipped today. checkov leads on adoption by 10% (9,015 vs 8,168 stars). checkov is written in Python under Apache-2.0; kyverno is written in Go under Apache-2.0. checkov has attracted 16% as many forks as stars, kyverno 20%. kyverno was the more recently maintained of the two, and both are self-hostable with no licence fee. The two share 2 topic tags (compliance, kubernetes), so they are genuine substitutes rather than adjacent tools.

Two open source projects, one decision. Both are free and self-hostable — the differences are community size, license terms, language stack and release pace.

checkov ★ 9.0K kyverno ★ 8.2K category Business Software

← all 20902 open source comparisons

Side by side

checkov kyverno
GitHub stars ★ 9.0K ★ 8.2K
License Apache-2.0 Apache-2.0
Written in Python Go
Last push 2026-09-17 2026-09-20
Forks ⑂ 1.4K ⑂ 1.6K
Self-hosting Yes Yes
Data ownership Your server Your server

pick checkov if

  • You weight community size — 9.0K stars and counting
  • You want the Apache-2.0 license terms
  • Your stack matches Python
  • You value the larger contributor base for long-term maintenance

full checkov profile →

pick kyverno if

  • You want the kyverno feature set and don't need the biggest community
  • You prefer the Apache-2.0 license terms
  • Your stack matches Go
  • You evaluated both and kyverno fits your workflow better

full kyverno profile →

About checkov

Checkov is an open source static code analysis and software composition analysis tool that scans infrastructure as code, container images and open source packages for security and compliance misconfigurations during the build, and it is aimed at developers, DevOps engineers and security teams who want those checks to run before anything is deployed to AWS, Azure or Google Cloud.

read the full checkov overview →

About kyverno

Kyverno is a Kubernetes native policy engine that lets platform engineering teams define security, compliance, automation, and governance rules as policy as code, using the Kubernetes tools they already run rather than a separate policy language.

read the full kyverno overview →

More in Business Software

Plane ★ 60K Twenty ★ 57K Odoo ★ 54K Cal.com ★ 49K Rocket.Chat ★ 46K cobalt ★ 44K

Related comparisons

lighthouse vs checkov lighthouse vs kyverno lighthouse vs teleport lighthouse vs lynis lighthouse vs prowler lighthouse vs gs-quant lighthouse vs opa lighthouse vs amphion opencode vs vibe-kanban conductor vs vibe-kanban vibe-kanban vs wekan vibe-kanban vs qinglong vibe-kanban vs edict vibe-kanban vs openproject vibe-kanban vs onedev wekan vs qinglong plane vs rocket-chat plane vs cobalt plane vs buzz rocket-chat vs cobalt plane vs jitsi plane vs srs plane vs huly plane vs zulip

More Compliance & Risk Management projects

Compare either of these against the rest of the Compliance & Risk Management field.

checkov vs lighthouse checkov vs teleport checkov vs lynis checkov vs prowler checkov vs gs-quant checkov vs opa checkov vs Amphion checkov vs aircrack-ng checkov vs tfsec checkov vs rundeck checkov vs agent-governance-toolkit checkov vs laravel-activitylog

Frequently asked questions

Is checkov or kyverno more popular?

checkov has 9,015 GitHub stars and kyverno has 8,168. checkov has the larger community by that measure.

Are checkov and kyverno free?

Both are open source. checkov is licensed under Apache-2.0 and kyverno under Apache-2.0. Neither carries a licence fee.

What is the difference between checkov and kyverno?

checkov is written in Python and kyverno in Go. The practical differences are community size, licence terms, language stack and release cadence — all compared in the table above.

Which should I choose, checkov or kyverno?

Choose checkov if you want the larger community (9,015 stars) or its Apache-2.0 licence terms. Choose kyverno if its feature set, stack or Apache-2.0 licence fits better. Both are self-hostable.