Trivy
A security scanner that finds vulnerabilities, misconfigurations, secrets and license issues in container images, filesystems, Git repositories and Kubernetes.
- GitHub stars
- 38k
- Last commit
- yesterday
- Latest release
- v0.75.0
- Licence
- Apache-2.0

Trivy is a security scanner from Aquasec, written in Go and released under the Apache-2.0 license. It has scanners that look for different security issues and targets where those issues can be found. The README describes it as comprehensive and versatile, and it covers the major programming languages, operating systems and platforms.
Targets include container images, filesystems, remote Git repositories, virtual machine images and Kubernetes. Scanners look for OS packages and software dependencies in use, which produces an SBOM, known vulnerabilities (CVEs), infrastructure-as-code issues and misconfigurations, sensitive information and secrets, and software licenses. Its topics reference DevSecOps and vulnerability scanning.
Trivy is available through most common channels, including Homebrew, a Docker image and downloadable binaries, and integrates with platforms such as GitHub Actions, a Kubernetes operator and a VS Code plugin. Canary builds are produced with each push to the main branch. It suits developers, platform teams and security engineers who want to scan images and code in CI pipelines.
Key features
- Scans container images and filesystems
- Scans Git repositories and Kubernetes
- Known vulnerability (CVE) detection
- IaC misconfiguration and secret detection
- SBOM generation and license scanning
- GitHub Actions and VS Code integrations
Pricing: Free and open source under the Apache-2.0 license.
