https://www.sonarsource.com/zh/knowledge/languages/cloudformation/
SonarQube & SonarCloud use dozens of unique static code analysis rules to find CloudFormation bugs, code smells & vulnerabilities on the Sonar solution.
static code analysistool programming languagesonar