Skip to main content

A meta-code checker written in Python.

Project description

Betterscan

Betterscan: The Open DevSecOps Orchestration Toolchain

Betterscan used checkmate5 to orchestrate, unify and de-duplicate SAST and scanning .

Here is the engine used by Betterscan

Checkmate5

Python-based meta static-analysis runner that orchestrates multiple language analyzers (Bandit, Brakeman, Kubescape, Trivy, OpenGrep, Staticcheck, etc.) and stores findings in a database backend.

Table of Contents


Fork notice & acknowledgements

This project is a modified version of the original Checkmate.


About

Checkmate5 is a cross-language (meta-)tool for static code analysis, written in Python. It orchestrates multiple scanners, normalizes findings into a single view, and de-duplicates overlapping results. This provides a global overview of code quality and security findings across a project—aiming to present clear, actionable insights.

Snapshots let you view findings at a specific point in time, while the issues view can also show the full history of findings across all scans for a project.

New features

  • OpenGrep runs via local CLI with auto-install and rules auto-refresh.
  • OpenGrep uses only Aikido and Amplify security rules (refreshed before each scan).
  • Trivy replaces tfsec for IaC checks.
  • Snapshots listing and snapshot-scoped issue filtering.
  • Issue report formats: HTML, JSON, SARIF.
  • Ignore file support via .checkmate/ignore-findings.json.
  • Severity filtering and CI-friendly exit codes.
  • Debug mode for tool output (--debug-tools).

Findings identity and ignore rules

Each finding is identified by a stable fingerprint. If two findings share the same fingerprint (with the same analyzer and code), they are treated as identical and deduplicated across scans.

The unique identity in the database is:

  • project + analyzer + code + fingerprint

The hash field is derived from analyzer, code, and fingerprint and is also unique per issue.

ignore-findings.json format

Place a file at .checkmate/ignore-findings.json. It can be either:

  • A list of ignore entries, or
  • { "ignore": [ ... ] }

Each ignore entry is a dict. If an entry specifies multiple keys, all of them must match to ignore a finding.

Supported keys:

  • snapshot (prefix match)
  • hash
  • fingerprint
  • project (project id)
  • analyzer (same as "Plugin" in checkmate issues output)
  • code
  • file
  • line (integer match)

Minimal example (ignore by fingerprint):

[
  { "fingerprint": "abc123" }
]

More specific example (ignore a single issue):

{
  "ignore": [
    {
      "project": "YOUR_PROJECT_ID",
      "analyzer": "opengrep",
      "code": "generic.security",
      "fingerprint": "abc123",
      "file": "src/app.py",
      "line": 42
    }
  ]
}

Use project, analyzer (plugin), code, and fingerprint for the most stable unique identification. hash is also unique if you have it from JSON output.


Licenses

  • The original Checkmate project is licensed under the MIT license: https://opensource.org/licenses/MIT
  • Original Checkmate parts remain released under the MIT License.
  • This fork’s modifications are released under the AGPL-3.0 license (previously LGPL 2.1 with Commons Clause). See LICENSE for details.

Requirements

  • Python 3.8+
  • Python dependencies (typical): blitzdb5, pyyaml, sqlalchemy, requests
  • OpenGrep CLI (local binary) for OpenGrep-based analyzers

Tools used

Checkmate5 orchestrates external tools. Availability, licensing, and usage terms are governed by each upstream project.

  • OpenGrep
  • Bandit
  • Brakeman
  • Trivy
  • Kubescape
  • Staticcheck

OpenGrep setup

Checkmate5 uses the local OpenGrep CLI for opengrep (generic).

Install OpenGrep (recommended):

curl -fsSL https://raw.githubusercontent.com/opengrep/opengrep/main/install.sh | bash

The CLI is expected at ~/.opengrep/cli/latest/opengrep or via OPENGREP_BIN.

It will be installed when missing.

Rules

Rules are automatically refreshed before each scan from:

Checkmate5 uses only Aikido and Amplify security rules and invokes OpenGrep with -f ./rules/aikido -f ./rules/amplify flags.

Strictly avoided: --config auto and --config s/managed are not used.

Config overrides

  • CHECKMATE_OPENGREP_CONFIG

Debugging tool output

Run:

checkmate analyze --debug-tools

This prints the OpenGrep command, config paths, and raw JSON results.

Parallel execution

Speed up analysis with parallel jobs:

checkmate analyze --jobs 4
checkmate analyze --jobs 8

This passes the job count to analyzers like opengrep that support parallel execution.

Issues output formats

Generate reports from the latest snapshot:

checkmate issues --html-output
checkmate issues --json-output
checkmate issues --sarif-output

Legacy aliases still work:

checkmate issues html
checkmate issues json
checkmate issues sarif

CLI usage

Common flows:

checkmate init
checkmate analyze
checkmate issues

If you use the git plugin:

checkmate git init
checkmate analyze
checkmate issues

List snapshots and filter issues to a specific snapshot:

checkmate snapshots
checkmate issues --snapshot <snapshot_id_or_prefix>

checkmate init examples

Default (SQLite in .checkmate/database.db):

checkmate init

PostgreSQL:

checkmate init --backend sql --connection-string "postgresql+psycopg2://user:password@localhost:5432/checkmate"

MySQL:

checkmate init --backend sql --connection-string "mysql+pymysql://user:password@localhost:3306/checkmate"

Custom SQLite path:

checkmate init --backend sqlite --connection-string "sqlite:////absolute/path/to/my-checkmate.db"

Backend configuration

Projects are configured in .checkmate/config.json. A typical sqlite setup looks like:

{
  "project_id": "YOUR_PROJECT_ID",
  "project_class": "Project",
  "backend": {
    "driver": "sqlite",
    "connection_string": "sqlite:////absolute/path/to/.checkmate/database.db"
  }
}

PostgreSQL example:

{
  "project_id": "YOUR_PROJECT_ID",
  "project_class": "Project",
  "backend": {
    "driver": "sql",
    "connection_string": "postgresql+psycopg2://user:password@localhost:5432/checkmate"
  }
}

MySQL example:

{
  "project_id": "YOUR_PROJECT_ID",
  "project_class": "Project",
  "backend": {
    "driver": "sql",
    "connection_string": "mysql+pymysql://user:password@localhost:3306/checkmate"
  }
}

Notes:

  • For PostgreSQL, install psycopg2 (or psycopg).
  • For MySQL, install pymysql.
  • For SQLite, the file will be created if it does not exist.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

checkmate5-1.5.1.tar.gz (696.0 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

checkmate5-1.5.1-py3-none-any.whl (180.3 kB view details)

Uploaded Python 3

File details

Details for the file checkmate5-1.5.1.tar.gz.

File metadata

  • Download URL: checkmate5-1.5.1.tar.gz
  • Upload date:
  • Size: 696.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.14.2

File hashes

Hashes for checkmate5-1.5.1.tar.gz
Algorithm Hash digest
SHA256 20baa3dbbe21dbec4e92b03a2d943ab74d8305f6a4b4eec85b01d9cdc7d8d5b2
MD5 4ab47f20a24923116552435d851e1377
BLAKE2b-256 8a80b80d2ad610a2a1b06b5daea2d92445c7adaed3f6243aa2d8715bc91bd6d5

See more details on using hashes here.

File details

Details for the file checkmate5-1.5.1-py3-none-any.whl.

File metadata

  • Download URL: checkmate5-1.5.1-py3-none-any.whl
  • Upload date:
  • Size: 180.3 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.14.2

File hashes

Hashes for checkmate5-1.5.1-py3-none-any.whl
Algorithm Hash digest
SHA256 24305bb16f0b70959f103d4e881c0a733ba4fb297abe4e9e5560e11aab26f52c
MD5 8abdd6d4f5dfbbeae3484ecc5265cf3d
BLAKE2b-256 b84bdc383077420bdcf08ccdfea44c8a448b54f0b1f400a08bdefed8be9d9f71

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page