Skip to main content

yamlguard

CI PyPI License: MIT

Check your YAML files before you commit or deploy them. yamlguard catches syntax errors and style issues, and can scan supported infrastructure files for security problems with Checkov.

Install the yamlguard CLI from PyPI, or use the Docker image pooyanazad/yaml-checker. Both run the same validator; Docker includes Checkov. The current Docker release uses the earlier image name; future releases will use pooyanazad/yamlguard.

Install and run

Python

Requires Python 3.9 or newer. Create a virtual environment so the installation stays separate from your system Python.

Linux / macOS:

python3 -m venv .venv
source .venv/bin/activate
python -m pip install yamlguard

Windows — Command Prompt:

py -m venv .venv
.venv\Scripts\activate
python -m pip install yamlguard

In PowerShell, activate the environment with .\.venv\Scripts\Activate.ps1 instead.

Then check a file:

yamlguard config.yaml

The base installation checks syntax with PyYAML and style with yamllint. To add security scanning, install the optional extra in the same environment:

python -m pip install "yamlguard[security]"
yamlguard deployment.yaml

Checkov checks supported infrastructure formats, such as Kubernetes manifests. Without Checkov, syntax and style checks still run, with a warning that security scanning was skipped.

Docker

With Docker installed, open a terminal in the folder containing your YAML files and run:

Linux / macOS:

docker run --rm -v "$(pwd):/data:ro" pooyanazad/yaml-checker:v3.5.0-20261011 config.yaml

Windows — PowerShell:

docker run --rm -v "${PWD}:/data:ro" pooyanazad/yaml-checker:v3.5.0-20261011 config.yaml

Windows — Command Prompt:

docker run --rm -v "%cd%:/data:ro" pooyanazad/yaml-checker:v3.5.0-20261011 config.yaml

These commands mount your current folder read-only at /data. Use paths within that folder, such as config.yaml or ./configs/. Files must be readable by the container's non-root user.

Images support linux/amd64 and linux/arm64. The examples use the published 3.5.0 image. Use the Docker image and versioned tag shown under Latest release when choosing another release.

Everyday examples

yamlguard config.yaml                        # Check one file
yamlguard config.yaml deployment.yml         # Check several files
yamlguard ./configs/                         # Check all .yaml and .yml files recursively
yamlguard "./configs/**/*.yaml"              # Let yamlguard expand the pattern
yamlguard ./configs/ --no-security            # Run syntax and style checks only
yamlguard deployment.yaml --timeout 60       # Limit each validator subprocess to 60 seconds

With Docker, pass these same arguments after the image name. For example, replace config.yaml in the Docker command with ./configs/ --no-security.

Run yamlguard --help for all options. You can also run the CLI as python -m yamlguard. Missing paths are skipped with a warning; the command fails if no files remain.

Reports and exit codes

Text output is the default. For CI or other tools, export a report:

yamlguard ./configs/ --format json > results.json
yamlguard ./configs/ --format junit > test-results.xml
yamlguard ./configs/ --format sarif > results.sarif

JSON returns one object for one file or an array for several files. JUnit XML works with test-report viewers; SARIF 2.1.0 works with compatible code-scanning tools. Upload reports through your CI configuration.

In version 3.5.0 and newer, machine-readable reports go to stdout and warnings go to stderr.

Exit code Meaning
0 No findings, or only Medium / Low / Info findings.
1 Critical / High findings, no matching files, or a required dependency is missing.
2 Invalid command-line arguments.

Syntax errors are Critical. Lint errors are Medium and warnings are Low, so lint findings alone do not fail the command. Checkov findings without a severity default to High.

Releases · Report an issue · Contributing · Maintainer release guide

Latest release

v3.5.1-20261011 — 2026-10-11

Changes since v3.5.0-20261011 (7 non-merge commits).

  • Build and maintenance: 2 commit(s).
  • Fixes: 3 commit(s).
  • Documentation: 2 commit(s).

Full changelog

Docker image: pooyanazad/yamlguard:v3.5.1-20261011

Metadata

Release files for yamlguard 3.5.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for yamlguard 3.5.1
File Size Uploaded
yamlguard-3.5.1.tar.gz 161.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for yamlguard 3.5.1
File Interpreter ABI Platform
yamlguard-3.5.1-py3-none-any.whl Python 3 none any Details

Total release size: 179.9 kB

Release files / yamlguard-3.5.1.tar.gz

Download URL yamlguard-3.5.1.tar.gz
Size 161.9 kB
Tags Source
SHA-256 checksum
How to use checksums
765fdbc4aa9594fe6987aa3185e94723742678bdac33bc48a776b1f4bdd69d19
BLAKE2b-256 checksum
How to use checksums
358d75b561f7defe84629212d676b747c84b7711ed860638368ed0eacdfe9290
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 11, 2026.

Transparency log

Release files / yamlguard-3.5.1-py3-none-any.whl

Download URL yamlguard-3.5.1-py3-none-any.whl
Size 17.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
1e2078eeb9dc5a9ed24c5704e1caa57ff44b23f2ba7943a1ba7c122054d73154
BLAKE2b-256 checksum
How to use checksums
ce1c275a8f1480cf7e90e3ceb1627aed760fb57dfed5adce50c43fd2f8877c50
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 11, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

3.5.1 This release

2 release files

3.5.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page