Ross ROSS = Recommend OSS · open-source software intelligence for agents

Trivy

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more observed · 2026-08-28

github.com/aquasecurity/trivy · homepage · Go · Apache-2.0 (permissive) observed · 2026-08-28

Health v2 · maintenance only

98/100

  • Activity 98
  • Release rhythm 98
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 12.0
  • age_days: 2702
  • days_rel: 19
  • days_push: 12
  • n_releases_24m: 9

Full methodology

Adoption not part of the score

37636 stars · 635 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

Trivy is an all-in-one open-source security scanner that finds vulnerabilities (CVEs), IaC misconfigurations, secrets, and software licenses across container images, filesystems, git repositories, VM images, and Kubernetes clusters. It is a Go-based CLI tool with integrations including a GitHub Action, a Kubernetes operator, and a VS Code extension.

Use cases

  • scan container images for known CVEs before pushing to a registry
  • find exposed secrets and API keys in a code repository
  • detect Terraform and Kubernetes misconfigurations in IaC files
  • generate an SBOM of OS packages and dependencies
  • audit a Kubernetes cluster for security issues
  • add vulnerability scanning to CI/CD pipelines with GitHub Actions
  • check software license compliance across dependencies

When to choose

  • you need a single free tool covering vulnerabilities, secrets, misconfigurations, and SBOM generation
  • you want container, Kubernetes, filesystem, and git repo scanning in one CLI
  • you need easy CI/CD integration via GitHub Actions or a Kubernetes operator
  • you want a widely adopted, actively maintained scanner with permissive Apache-2.0 licensing

When to avoid

  • you need full commercial security management with policy enforcement and reporting dashboards
  • you require dynamic application security testing (DAST) or runtime threat detection
  • you need SAST for deep code-flow analysis rather than dependency and config scanning

Facets

cli-tool · maturity stable

vulnerability-scanning security dependency-audit secrets-management infrastructure-as-code developer-tools ci-cd security cloud-computing developer-tools windows cli go sbom cve-scanning misconfiguration-detection secret-scanning container-security kubernetes-security iac-scanning devsecops license-compliance devops containers linux macos docker kubernetes

4 sources

Member repositories

RepositoryRoleHealth v2
aquasecurity/trivymain98
aquasecurity/trivy-operatorbackend99
aquasecurity/trivy-actionplugin88

For agents

markdown · JSON · MCP: product_card(name="aquasecurity/trivy")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem