OpenTofu
What’s scanned
- *.tf and OpenTofu-compatible configurations (treated as Terraform-equivalent where applicable)
Why it matters
- Most Terraform guardrails apply identically; your teams can adopt OpenTofu without losing security coverage.
Policy approach
- Keep the same rule taxonomy where possible (e.g., IAC-00XX), and document any format-specific differences in the rule page.