head to head · open source

checkov vs dep-scan

checkov has 9,015 GitHub stars, 1,415 forks, 170 open issues and last shipped 3 days ago. dep-scan has 1,286 stars, 138 forks, 82 open issues and last shipped 2 days ago. checkov leads on adoption by 601% (9,015 vs 1,286 stars). checkov is written in Python under Apache-2.0; dep-scan is written in Python under MIT. checkov has attracted 16% as many forks as stars, dep-scan 11%. dep-scan was the more recently maintained of the two, and both are self-hostable with no licence fee. The two share 1 topic tag (compliance), so they are genuine substitutes rather than adjacent tools.

Two open source projects, one decision. Both are free and self-hostable — the differences are community size, license terms, language stack and release pace.

checkov ★ 9.0K dep-scan ★ 1.3K category Business Software

← all 20902 open source comparisons

Side by side

checkov dep-scan
GitHub stars ★ 9.0K ★ 1.3K
License Apache-2.0 MIT
Written in Python Python
Last push 2026-09-17 2026-09-18
Forks ⑂ 1.4K ⑂ 138
Self-hosting Yes Yes
Data ownership Your server Your server

pick checkov if

  • You weight community size — 9.0K stars and counting
  • You want the Apache-2.0 license terms
  • Your stack matches Python
  • You value the larger contributor base for long-term maintenance

full checkov profile →

pick dep-scan if

  • You want the dep-scan feature set and don't need the biggest community
  • You prefer the MIT license terms
  • Your stack matches Python
  • You evaluated both and dep-scan fits your workflow better

full dep-scan profile →

About checkov

Checkov is an open source static code analysis and software composition analysis tool that scans infrastructure as code, container images and open source packages for security and compliance misconfigurations during the build, and it is aimed at developers, DevOps engineers and security teams who want those checks to run before anything is deployed to AWS, Azure or Google Cloud.

read the full checkov overview →

About dep-scan

OWASP dep scan is a next generation security and risk audit tool that checks project dependencies for known vulnerabilities, advisories and license limitations, built for developers and security teams that audit local repositories or container images.

read the full dep-scan overview →

More in Business Software

Plane ★ 60K Twenty ★ 57K Odoo ★ 54K Cal.com ★ 49K Rocket.Chat ★ 46K cobalt ★ 44K

Related comparisons

lighthouse vs checkov lighthouse vs teleport lighthouse vs lynis lighthouse vs prowler lighthouse vs gs-quant lighthouse vs opa lighthouse vs amphion lighthouse vs kyverno opencode vs vibe-kanban conductor vs vibe-kanban vibe-kanban vs wekan vibe-kanban vs qinglong vibe-kanban vs edict vibe-kanban vs openproject vibe-kanban vs onedev wekan vs qinglong plane vs rocket-chat plane vs cobalt plane vs buzz rocket-chat vs cobalt plane vs jitsi plane vs srs plane vs huly plane vs zulip

More Compliance & Risk Management projects

Compare either of these against the rest of the Compliance & Risk Management field.

checkov vs lighthouse checkov vs teleport checkov vs lynis checkov vs prowler checkov vs gs-quant checkov vs opa checkov vs Amphion checkov vs kyverno checkov vs aircrack-ng checkov vs tfsec checkov vs rundeck checkov vs agent-governance-toolkit

Frequently asked questions

Is checkov or dep-scan more popular?

checkov has 9,015 GitHub stars and dep-scan has 1,286. checkov has the larger community by that measure.

Are checkov and dep-scan free?

Both are open source. checkov is licensed under Apache-2.0 and dep-scan under MIT. Neither carries a licence fee.

What is the difference between checkov and dep-scan?

checkov is written in Python and dep-scan in Python. The practical differences are community size, licence terms, language stack and release cadence — all compared in the table above.

Which should I choose, checkov or dep-scan?

Choose checkov if you want the larger community (9,015 stars) or its Apache-2.0 licence terms. Choose dep-scan if its feature set, stack or MIT licence fits better. Both are self-hostable.