macOS
brew install terrascanlocal Homebrew formula metadata
sudo port install terrascanMacPorts ports tree · sysutils/terrascan/Portfile · 来源: api.github.com
安装
brew install terrascanlocal Homebrew formula metadata
sudo port install terrascanMacPorts ports tree · sysutils/terrascan/Portfile · 来源: api.github.com
nix profile install nixpkgs#terrascannixpkgs package indexes · pkgs/by-name/te/terrascan/package.nix · 来源: api.github.com
scoop install main/terrascanScoop official bucket manifest trees · bucket/terrascan.json · 来源: api.github.com
概览
Detect compliance and security violations across Infrastructure as Code
历史
Terrascan is an open-source static analyzer for Infrastructure as Code that checks cloud and Kubernetes configuration before deployment. Its official README describes scanning for misconfigurations, posture drift, security vulnerabilities, and compliance violations, with local CLI and CI/CD integration workflows.
The project originated under Accurics and later moved under Tenable ownership, as reflected by changelog links that compare older releases under github.com/accurics/terrascan and later releases under github.com/tenable/terrascan. The current official repository is archived and states that it is no longer maintained.
Terrascan became a package-manager-friendly IaC security tool because it distributed native release binaries, Docker images, and package recipes. The README documents Homebrew installation, AUR installation, and Docker usage, while the input metadata also lists MacPorts, Nix, and Scoop packages.
In the package-nerd niche, Terrascan was used as a local scanner in developer workstations and CI jobs before Terraform, Kubernetes, Helm, Kustomize, CloudFormation, ARM, Dockerfile, or GitHub infrastructure changes were applied. Its value was the ability to run policy checks from a normal shell command without adopting a hosted platform first.
Terrascan is significant as part of the early wave of IaC security CLIs that package managers made easy to slot into pre-commit hooks, CI images, and ephemeral developer machines. Its archived status is now part of its history: packages may remain useful for reproducing older pipelines, but new deployments need to account for maintenance risk.
安全态势
infrastructure mutation or orchestration signal.
orange 风险 · 中 置信度 · infrastructure
在无人值守的代理使用前,请检查该工具是否读取明文凭据、写入远程状态、发布制品或调用插件。
可执行文件
| 命令 | 类型 | 暴露范围 | 备注 |
|---|---|---|---|
terrascan | cli | 全局可执行文件 |
新鲜度
这些信号区分页生成时间、软件包管理器活动和上游发布比较。只有存在证据 URL 和可比较版本时,才会提示版本落后。
https://github.com/tenable/terrascan
安装元数据
| 软件包键 | brew:terrascan |
|---|---|
| 版本 | 1.19.9 |
| 软件包管理器 | Homebrew |
| 软件包管理器页面 | https://formulae.brew.sh/formula/terrascan |
| 主页 | https://runterrascan.io/ |
| 仓库 | https://github.com/tenable/terrascan |
| 上游文档 | https://github.com/tenable/terrascan#readme |
| 许可证 | Apache-2.0 |
| 源码归档 | https://github.com/tenable/terrascan/archive/refs/tags/v1.19.9.tar.gz |
| 最后更新 | 2026-05-24T01:41:05Z |
| Pulse | updated |
| 构建依赖 | go |
| Bottle | 可用 (于 arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux) |
| Homebrew post-install | 未定义 |
| 服务 | 未声明 |
注册表事实
| Source Database | Homebrew formula API |
|---|---|
| Tap | homebrew/core |
| Full Name | terrascan |
| Version Scheme | 0 |
| Revision | 0 |
| Head Version | HEAD |
| Bottle Stable Root URL | https://ghcr.io/v2/homebrew/core |
| Deprecated | yes |
| Disabled | no |
| Keg Only | no |
| URL Keys |
|
源数据库匹配
匹配项来自外部软件包管理器索引,并与本地 Automic Vault 软件包链接分开显示。
terrascan
nix profile install nixpkgs#terrascanterrascan
sudo port install terrascanmain/terrascan
scoop install main/terrascan来源线索
此页面由 av-web 从 scripts/generate-pkg-sqlite.py 生成的私有软件包 SQLite 工件提供。
View the package source record on GitHub.