Side-by-side IaC scan comparison made me switch teams at work
Last month I ran both tfsec and Checkov against the same Terraform repo, about 340 lines with a few S3 buckets and an IAM role. tfsec flagged maybe 4 things, all legit, and its CLI was dead simple. Checkov found 22 issues but half of them were false positives about stuff like tagging policies we don't even enforce. I spent 2 hours digging through Checkov's docs just to figure out which rules to skip, and at that point my teammate walked by and asked why I was still on the same ticket. The kicker is we had been paying for Checkov's enterprise tier for a year, and nobody realized the free tfsec caught the one actual misconfiguration, an open security group, way faster. Has anyone else ditched a fancy scanner for a simpler one and had to convince their security lead it wasn't a downgrade?