INNER CODE UNIT · Python
run_checkov
valqore/valqore · benchmarks/run_benchmark.py:128
def run_checkov() -> dict:
# Prefer a standalone/pipx checkov on PATH. Do NOT fall back to `python -m
# checkov.main` in this interpreter: checkov pins an old python-hcl2 that
# breaks Valqore's Terraform parsing, so it must live in its own env.
exe = shutil.which("checkov")
if not exe:
return {"available": False}
cmd = [exe, "-d", str(CORPUS), "--compact", "-o", "json"]
data = _run_json(cmd)
if data is None:
return {"available": False}
checks = data if isinstance(data, list) else [data]
by_type = {}
passed = failed = 0
for c in checks:
ct = c.get("check_type", "?")
s = c.get("summary", {})
by_type[ct] = {"passed": s.get("passed", 0), "failed": s.get("failed", 0)}