About Trivy
Trivy is a security scanner from Aquasec, written in Go and released under the Apache-2.0 license. It has scanners that look for different security issues and targets where those issues can be found. The README describes it as comprehensive and versatile, and it covers the major programming languages, operating systems and platforms.
Targets include container images, filesystems, remote Git repositories, virtual machine images and Kubernetes. Scanners look for OS packages and software dependencies in use, which produces an SBOM, known vulnerabilities (CVEs), infrastructure-as-code issues and misconfigurations, sensitive information and secrets, and software licenses. Its topics reference DevSecOps and vulnerability scanning.
Trivy is available through most common channels, including Homebrew, a Docker image and downloadable binaries, and integrates with platforms such as GitHub Actions, a Kubernetes operator and a VS Code plugin. Canary builds are produced with each push to the main branch. It suits developers, platform teams and security engineers who want to scan images and code in CI pipelines.
Key features
- Scans container images and filesystems
- Scans Git repositories and Kubernetes
- Known vulnerability (CVE) detection
- IaC misconfiguration and secret detection
- SBOM generation and license scanning
- GitHub Actions and VS Code integrations
Good fit for
- →Scanning container images in CI
- →Finding leaked secrets in repositories
- →Auditing Kubernetes and IaC configs
- Tags
- security-scanner
- vulnerability-scanning
- containers
- devsecops
- kubernetes
- sbom
- iac
- golang
Trivy: questions and answers
- What is Trivy used for?
- Trivy is a security scanner that finds vulnerabilities, misconfigurations, secrets and license issues in container images, filesystems, Git repositories and Kubernetes. It is a good fit for scanning container images in CI, finding leaked secrets in repositories, and auditing Kubernetes and IaC configs.
- Is Trivy open source?
- Yes. Trivy is open source under the Apache-2.0 licence. Its source code is on GitHub at aquasecurity/trivy and is written mainly in Go.
- Is Trivy free?
- Yes. Trivy is open source, so the software itself is free to use.
- What is Trivy an alternative to?
- Trivy is an open-source alternative to Snyk, Wiz, Aikido Security and Socket. Other open-source alternatives to Snyk include Grype, Dependency-Track and Semgrep.
- Is Trivy actively maintained?
- Yes. The most recent commit to Trivy was on 2 October 2026, and the latest release is v0.75.0, published on 1 October 2026. The project has 38k stars on GitHub.
Open-source alternatives to Trivy
See all
Grype
Security
A vulnerability scanner for container images and filesystems
Apache-2.0vs Snyk★ 13k
Dependency-Track
Security
Dependency-Track is an intelligent Component Analysis platform that allows organizations t
Apache-2.0vs Snyk★ 4.3k
Kubescape
Security
Kubescape is an open-source Kubernetes security platform for your IDE, CI/CD pipelines, an
Apache-2.0vs Wiz★ 12k
Semgrep
Security
Lightweight static analysis for many languages. Find bug variants with patterns that look
LGPL-2.1vs Snyk★ 17k
Horusec
Security
Horusec is an open source tool that improves identification of vulnerabilities in your pro
Apache-2.0vs Checkmarx★ 1.3k
tfsec
Security
Tfsec is now part of Trivy
MITvs Aikido Security★ 7k
SaaS alternatives to Trivy
See all
Snyk
Security
Developer security platform that scans code, dependencies, containers and IaC
SaaSWiz
Security
Agentless cloud security platform mapping risk across code, cloud and runtime
SaaS
Aikido Security
Security
All-in-one application security platform for code, cloud and runtime scanning
SaaS
Socket
Security
Supply chain security that detects risky open source packages before install
SaaS
GitGuardian
Security
Detects leaked secrets and credentials in code repositories and developer tools
SaaSVeracode
Security
Application security testing platform covering static, dynamic and software composition
SaaS

