Tech riderRev. 4 Oct 2026
KubeLinter
- 1Runs onLinux, Mac, self-hosted
- 2CostsFree plan
- 3Terraform analysisNo
- 4Kubernetes analysisYes
- 5CloudFormation analysisNo
- 6Custom policiesYes
- 7Secrets detectionYes
- 8Pull request scanningYes
8 lines stated Written from the maker's own pages: github.com

Overview
KubeLinter is ranked #16 of 27 in infrastructure testing tools on Specifiction. It runs on Linux, macOS, Self-hosted. There is a free plan.
KubeLinter plans and pricing
All plansCompared on infrastructure testing tools
- Terraform analysis
- Nogithub.com
- Kubernetes analysis
- Yesgithub.com
- CloudFormation analysis
- Nogithub.com
- Custom policies
- Yesgithub.com
- Secrets detection
- Yesgithub.com
- Pull request scanning
- Yesgithub.com
Facts
- Purpose
- KubeLinter statically analyzes Kubernetes YAML files, Helm charts, and Kustomize manifests against best practices for production readiness and security.github.com · 4 Oct 2026
- Default checks
- Default checks cover practices such as running containers as non-root, enforcing least privilege, and storing sensitive information only in secrets.github.com · 4 Oct 2026
- Custom checks
- Users can enable or disable checks and create custom checks to match organizational policies.github.com · 4 Oct 2026
- Lint feedback
- When a check fails, KubeLinter reports remediation recommendations and returns a non-zero exit code.github.com · 4 Oct 2026
- Install options
- The project documents installation through Go, release binaries, Homebrew or LinuxBrew, nix-shell, and Docker.github.com · 4 Oct 2026
- Output formats
- KubeLinter can generate multiple output formats in one run, including SARIF and JSON.github.com · 4 Oct 2026
- Signing
- KubeLinter container images are signed with cosign, and the project provides a public key for verification.github.com · 4 Oct 2026
- Keyless verification
- The README says keyless cosign signatures are not production ready.github.com · 4 Oct 2026
- Vulnerability reporting
- The security policy directs confidential vulnerability reports to Red Hat's Product Security team.github.com · 4 Oct 2026
- License
- KubeLinter is licensed under the Apache License 2.0.github.com · 4 Oct 2026
- Community support
- The project invites users to join its Slack workspace to engage with maintainers and other users.github.com · 4 Oct 2026
- Compatibility caveat
- The README warns that command usage, flags, and configuration file formats may change in the future.github.com · 4 Oct 2026
- Latest release
- The latest release page opened for this research identifies version v0.8.3.github.com · 4 Oct 2026
- Maker
- The README says KubeLinter was created by StackRox and is now powered by Red Hat.github.com · 4 Oct 2026
Best KubeLinter alternatives
See all 12 All accessCh 01 Chef InSpec Free planFree trialAPI Free to start7.5 All accessCh 02 Conftest Free planLinuxMac Free to start7.4 All accessCh 03 kubeconform Free planLinuxMac Free to start7.2 All accessCh 04 Test Kitchen Free planLinuxMac Free to start7.2 All accessCh 05 AWS CloudFormation Free planAPILinux Free to start7.1 All accessCh 06 Sonobuoy LinuxMac 7.1
Where it ranks on Specifiction
Is KubeLinter yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- github.com/stackrox/kube-linter· checked 4 Oct 2026
- github.com/stackrox/kube-linter/blob/main/SECURITY· checked 4 Oct 2026
- github.com/stackrox/kube-linter/releases/latest· checked 4 Oct 2026
