Back to browse
GitHub Repository

One deterministic gate for your two riskiest moments: the terraform apply that reshapes your cloud, and the dependency you're about to install.

1 starsGo

Bumper – block a destructive Terraform apply or a malicious dependency

by gnana097·Jun 9, 2026·2 points·0 comments

AI Analysis

●●SolidSolve My ProblemShip It

Single gate for Terraform and deps, but Checkov and Snyk already cover this.

Strengths
  • Reads terraform show -json diffs, not just end state snapshots
  • Single static Go binary with no API keys or external accounts required
  • Catches both destructive applies and known-malicious packages in one pass
Weaknesses
  • Terraform plan checking already solved by Checkov, tfsec, OPA
  • Dependency scanning overlaps heavily with Snyk and Dependabot
Target Audience

DevOps engineers, platform teams using Terraform

Similar To

Checkov · tfsec · Snyk

Similar Projects

Infrastructure●●●Banger

Evidra – a fail-closed MCP guardrail for AI infrastructure ops

Fail-closed guardrail for AI agent infrastructure access—kills unsafe ops before they ship.

Solve My ProblemWizardry
vitass
113mo ago
Security●●●Banger

IDEViewer – Security scanner for malicious IDE Extensions

Scans bundled node_modules inside extensions where standard SCA tools can't see.

Big BrainSolve My Problem
securient
3018d ago