Consider adding Checkov. Checkov now has a documented pre-commit integration: https://bridgecrewio.github.io/checkov/4.Integrations/pre-commit.html pre-commit configuration is available at: https://github.com/bridgecrewio/checkov/blob/master/.pre-commit-hooks.yaml