7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

Trivy

Open source

A security scanner that finds vulnerabilities, misconfigurations, secrets and license issues in container images, filesystems, Git repositories and Kubernetes.

trivy.dev
Trivy homepage screenshot
GitHub stars
38k
Last commit
today
Repository age
7 years
Version
v0.75.0
Licence
Apache-2.0
Self-hosted
Yes

About Trivy

Trivy is a security scanner from Aquasec, written in Go and released under the Apache-2.0 license. It has scanners that look for different security issues and targets where those issues can be found. The README describes it as comprehensive and versatile, and it covers the major programming languages, operating systems and platforms.

Targets include container images, filesystems, remote Git repositories, virtual machine images and Kubernetes. Scanners look for OS packages and software dependencies in use, which produces an SBOM, known vulnerabilities (CVEs), infrastructure-as-code issues and misconfigurations, sensitive information and secrets, and software licenses. Its topics reference DevSecOps and vulnerability scanning.

Trivy is available through most common channels, including Homebrew, a Docker image and downloadable binaries, and integrates with platforms such as GitHub Actions, a Kubernetes operator and a VS Code plugin. Canary builds are produced with each push to the main branch. It suits developers, platform teams and security engineers who want to scan images and code in CI pipelines.

Key features

  • Scans container images and filesystems
  • Scans Git repositories and Kubernetes
  • Known vulnerability (CVE) detection
  • IaC misconfiguration and secret detection
  • SBOM generation and license scanning
  • GitHub Actions and VS Code integrations

Good fit for

  • →Scanning container images in CI
  • →Finding leaked secrets in repositories
  • →Auditing Kubernetes and IaC configs
Tags
security-scanner
vulnerability-scanning
containers
devsecops
kubernetes
sbom
iac
golang

Trivy: questions and answers

What is Trivy used for?
Trivy is a security scanner that finds vulnerabilities, misconfigurations, secrets and license issues in container images, filesystems, Git repositories and Kubernetes. It is a good fit for scanning container images in CI, finding leaked secrets in repositories, and auditing Kubernetes and IaC configs.
Is Trivy open source?
Yes. Trivy is open source under the Apache-2.0 licence. Its source code is on GitHub at aquasecurity/trivy and is written mainly in Go.
Is Trivy free?
Yes. Trivy is open source, so the software itself is free to use.
What is Trivy an alternative to?
Trivy is an open-source alternative to Snyk, Wiz, Aikido Security and Socket. Other open-source alternatives to Snyk include Grype, Dependency-Track and Semgrep.
Is Trivy actively maintained?
Yes. The most recent commit to Trivy was on 2 October 2026, and the latest release is v0.75.0, published on 1 October 2026. The project has 38k stars on GitHub.

Open-source alternatives to Trivy

See all

SaaS alternatives to Trivy

See all