Aqua Security Acquires TFsec
July 13, 2021

Aqua Security announced the acquisition of tfsec, an open source security scanner for Infrastructure as Code (IaC).

The acquisition brings an immediate integration of tfsec into Aqua Trivy, adding IaC security scanning capabilities, with additional Aqua platform integrations planned later this year. Tfsec’s co-founders will join Aqua following the acquisition.

Amir Jerbi, CTO and co-founder of Aqua Security, said: “Aqua is committed to investing in open source cloud security tools and to providing users a frictionless way to assimilate essential security capabilities into their cloud native applications where they need them most.”

IaC security scanning is a critical step in helping users secure the configurations of the environments in which they deploy their applications. The integration of Aqua Trivy and tfsec helps teams to shift left, combining the ease of use and scanning speed of Trivy with the enhanced IaC coverage with tfsec, without additional management overhead and as part of a unified workflow.

With its run anywhere design, tfsec provides a download and run scanning solution that is fast, accurate, and flexible. The approach tfsec takes to loading your code ensures that your IaC is interpreted exactly as Terraform does; meaning that regardless of complexity, you get the best possible view of any vulnerabilities before you deploy.

“We saw a need in the market for a more intelligent form of Terraform scanning,” said Liam Galvin, tfsec co-founder. “Building tfsec from community input, we were able to deliver on developers’ needs for a quicker, more efficient way to run security checks.”

“Aqua Trivy has become the industry standard for open source vulnerability scanning thanks to its simple user experience and rich functionality. Now Trivy brings the same superior experience into Infrastructure as Code scanning to provide even more value to container and code scanning,” says Itay Shakury, Director of Open Source at Aqua Security. “By integrating tfsec and Trivy, our users can scan code repositories and container images for vulnerabilities and IaC configuration issues – all using a single tool, that can integrate into their CI tool or even be used as a Github action.”

While tfsec will remain a standalone project, in addition to its integration into Trivy, it will also be added to Aqua Security’s suite of open source cloud security tools, including Tracee, Starboard, Kube-bench and Kube-hunter. With this portfolio, users can also perform penetration tests of Kubernetes clusters, integrate disparate Kubernetes security tools into an aggregate security dataset that is available natively in Kubernetes, view runtime and forensics data for Linux, and more.

Tfsec co-founders Liam Galvin and Owen Rumney will join the Aqua team as Cloud Engineers bringing deep experience in both software and open source.

Galvin is an experienced full stack engineer with more than 15 years of building software and contributing to the open source community. His most recent experience has been rooted in security, and he joins Aqua from FORM3 where he was a Lead Security Engineer. Galvin built tfsec having used Hashicorp’s Terraform to build cloud infrastructure for multiple startups after recognizing the security gap. He also maintains many other open source projects, such as traitor: a local privilege escalation framework for Linux which has recently garnered significant attention from the community.

Rumney is a seasoned software engineer with experience in building repeatable, consistent deployments in large-scale, ephemeral data processing environments. In addition to his work with tfsec, most recently he served as Senior Platform and Security Engineer at FORM3, and he has held prior roles as a Lead Data Engineer at BP and Holland & Barrett. He has combined his background in IaC with a focus on cloud security risks, working to help individuals and organizations to intercept potential issues before they make it to production.

Share this

Industry News

November 07, 2024

Broadcom announced the general availability of VMware Tanzu Platform 10 that establishes a new layer of abstraction across Cloud Foundry infrastructure foundations to make it easier, faster, and less expensive to bring new applications, including GenAI applications, to production.

November 07, 2024

Tricentis announced the expansion of its test management and analytics platform, Tricentis qTest, with the launch of Tricentis qTest Copilot.

November 07, 2024

Redgate is introducing two new machine learning (ML) and artificial intelligence (AI) powered capabilities in its test data management and database monitoring solutions.

November 07, 2024

Upbound announced significant advancements to its platform, targeting enterprises building self-service cloud environments for their developers and machine learning engineers.

November 07, 2024

Edera announced the availability of Am I Isolated, an open source container security benchmark that probes users runtime environments and tests for container isolation.

November 06, 2024

Progress announced 10 years of partnership with emt Distribution — a leading cybersecurity distributor in the Middle East and Africa.

November 06, 2024

Port announced $35 million in Series B funding, bringing its total funding to $58M to date.

November 05, 2024

Parasoft has made another step in strategically integrating AI and ML quality enhancements where development teams need them most, such as using natural language for troubleshooting or checking code in real time.

November 05, 2024

MuleSoft announced the general availability of full lifecycle AsyncAPI support, enabling organizations to power AI agents with real-time data through seamless integration with event-driven architectures (EDAs).

November 05, 2024

Numecent announced they have expanded their Microsoft collaboration with the launch of Cloudpager's new integration to App attach in Azure Virtual Desktop.

November 04, 2024

Progress announced the completion of the acquisition of ShareFile, a business unit of Cloud Software Group, providing a SaaS-native, AI-powered, document-centric collaboration platform, focusing on industry segments including business and professional services, financial services, industrial and healthcare.

November 04, 2024

Incredibuild announced the acquisition of Garden, a provider of DevOps pipeline acceleration solutions.

October 31, 2024

The Open Source Security Foundation (OpenSSF) announced an expansion of its free course “Developing Secure Software” (LFD121).

October 31, 2024

Redgate announced that its core solutions are listed in Amazon Web Services (AWS) Marketplace.

October 30, 2024

LambdaTest introduced a suite of new features to its AI-powered Test Manager, designed to simplify and enhance the test management experience for software development and QA teams.