Skip to content

Trivy

Vulnerability Scanning

Trivy is a comprehensive security scanner that detects vulnerabilities, misconfigurations, secrets, and software licenses across containers, filesystems, Git repos, VM images, and Kubernetes.

Go Latest v0.72.0 · 27d ago Security brief →

Features

  • Scans container images for OS package vulnerabilities and SBOM data
  • Audits local filesystems for CVEs, secrets, and misconfigurations
  • Analyzes Git repositories (remote) for IaC issues and sensitive information
  • Examines virtual machine images for security flaws
  • Inspects Kubernetes clusters for policy violations and vulnerabilities

Recent releases

View all 7 releases →
No immediate action
v0.71.1 Bug fix

Fixes for OCI, ospkg, VEX, errors

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

About

Stars
36,976
Forks
545
Languages
Go Go Template Shell

Install & Platforms

Install via
brew docker binary

Community & Support

Alternative to

Aqua

Beta — feedback welcome: [email protected]