yamlguard
Check your YAML files before you commit or deploy them. yamlguard catches syntax errors and style issues, and can scan supported infrastructure files for security problems with Checkov.
Install the yamlguard CLI from PyPI, or use the Docker image pooyanazad/yaml-checker. Both run the same validator; Docker includes Checkov. The current Docker release uses the earlier image name; future releases will use pooyanazad/yamlguard.
Install and run
Python
Requires Python 3.9 or newer. Create a virtual environment so the installation stays separate from your system Python.
Linux / macOS:
python3 -m venv .venv
source .venv/bin/activate
python -m pip install yamlguard
Windows — Command Prompt:
py -m venv .venv
.venv\Scripts\activate
python -m pip install yamlguard
In PowerShell, activate the environment with .\.venv\Scripts\Activate.ps1 instead.
Then check a file:
yamlguard config.yaml
The base installation checks syntax with PyYAML and style with yamllint. To add security scanning, install the optional extra in the same environment:
python -m pip install "yamlguard[security]"
yamlguard deployment.yaml
Checkov checks supported infrastructure formats, such as Kubernetes manifests. Without Checkov, syntax and style checks still run, with a warning that security scanning was skipped.
Docker
With Docker installed, open a terminal in the folder containing your YAML files and run:
Linux / macOS:
docker run --rm -v "$(pwd):/data:ro" pooyanazad/yaml-checker:v3.5.0-20261011 config.yaml
Windows — PowerShell:
docker run --rm -v "${PWD}:/data:ro" pooyanazad/yaml-checker:v3.5.0-20261011 config.yaml
Windows — Command Prompt:
docker run --rm -v "%cd%:/data:ro" pooyanazad/yaml-checker:v3.5.0-20261011 config.yaml
These commands mount your current folder read-only at /data. Use paths within that folder, such as config.yaml or ./configs/. Files must be readable by the container's non-root user.
Images support linux/amd64 and linux/arm64. The examples use the published 3.5.0 image. Use the Docker image and versioned tag shown under Latest release when choosing another release.
Everyday examples
yamlguard config.yaml # Check one file
yamlguard config.yaml deployment.yml # Check several files
yamlguard ./configs/ # Check all .yaml and .yml files recursively
yamlguard "./configs/**/*.yaml" # Let yamlguard expand the pattern
yamlguard ./configs/ --no-security # Run syntax and style checks only
yamlguard deployment.yaml --timeout 60 # Limit each validator subprocess to 60 seconds
With Docker, pass these same arguments after the image name. For example, replace config.yaml in the Docker command with ./configs/ --no-security.
Run yamlguard --help for all options. You can also run the CLI as python -m yamlguard. Missing paths are skipped with a warning; the command fails if no files remain.
Reports and exit codes
Text output is the default. For CI or other tools, export a report:
yamlguard ./configs/ --format json > results.json
yamlguard ./configs/ --format junit > test-results.xml
yamlguard ./configs/ --format sarif > results.sarif
JSON returns one object for one file or an array for several files. JUnit XML works with test-report viewers; SARIF 2.1.0 works with compatible code-scanning tools. Upload reports through your CI configuration.
In version 3.5.0 and newer, machine-readable reports go to stdout and warnings go to stderr.
| Exit code | Meaning |
|---|---|
0 |
No findings, or only Medium / Low / Info findings. |
1 |
Critical / High findings, no matching files, or a required dependency is missing. |
2 |
Invalid command-line arguments. |
Syntax errors are Critical. Lint errors are Medium and warnings are Low, so lint findings alone do not fail the command. Checkov findings without a severity default to High.
Project links
Releases · Report an issue · Contributing · Maintainer release guide
Latest release
v3.5.1-20261011 — 2026-10-11
Changes since v3.5.0-20261011 (7 non-merge commits).
- Build and maintenance: 2 commit(s).
- Fixes: 3 commit(s).
- Documentation: 2 commit(s).
Docker image: pooyanazad/yamlguard:v3.5.1-20261011
Metadata
Release files for yamlguard 3.5.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| yamlguard-3.5.1.tar.gz | 161.9 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| yamlguard-3.5.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 179.9 kB
Release files / yamlguard-3.5.1.tar.gz
| Download URL | yamlguard-3.5.1.tar.gz |
|---|---|
| Size | 161.9 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
765fdbc4aa9594fe6987aa3185e94723742678bdac33bc48a776b1f4bdd69d19
|
|
BLAKE2b-256 checksum How to use checksums |
358d75b561f7defe84629212d676b747c84b7711ed860638368ed0eacdfe9290
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 11, 2026.
Transparency logRelease files / yamlguard-3.5.1-py3-none-any.whl
| Download URL | yamlguard-3.5.1-py3-none-any.whl |
|---|---|
| Size | 17.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
1e2078eeb9dc5a9ed24c5704e1caa57ff44b23f2ba7943a1ba7c122054d73154
|
|
BLAKE2b-256 checksum How to use checksums |
ce1c275a8f1480cf7e90e3ceb1627aed760fb57dfed5adce50c43fd2f8877c50
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 11, 2026.
Transparency log