Trivy
Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more observed · 2026-08-28
Health v2 · maintenance only
98/100
- Activity 98
- Release rhythm 98
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 12.0
- age_days: 2702
- days_rel: 19
- days_push: 12
- n_releases_24m: 9
Adoption not part of the score
37636 stars · 635 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded
Trivy is an all-in-one open-source security scanner that finds vulnerabilities (CVEs), IaC misconfigurations, secrets, and software licenses across container images, filesystems, git repositories, VM images, and Kubernetes clusters. It is a Go-based CLI tool with integrations including a GitHub Action, a Kubernetes operator, and a VS Code extension.
Use cases
- scan container images for known CVEs before pushing to a registry
- find exposed secrets and API keys in a code repository
- detect Terraform and Kubernetes misconfigurations in IaC files
- generate an SBOM of OS packages and dependencies
- audit a Kubernetes cluster for security issues
- add vulnerability scanning to CI/CD pipelines with GitHub Actions
- check software license compliance across dependencies
When to choose
- you need a single free tool covering vulnerabilities, secrets, misconfigurations, and SBOM generation
- you want container, Kubernetes, filesystem, and git repo scanning in one CLI
- you need easy CI/CD integration via GitHub Actions or a Kubernetes operator
- you want a widely adopted, actively maintained scanner with permissive Apache-2.0 licensing
When to avoid
- you need full commercial security management with policy enforcement and reporting dashboards
- you require dynamic application security testing (DAST) or runtime threat detection
- you need SAST for deep code-flow analysis rather than dependency and config scanning
Facets
cli-tool · maturity stable
vulnerability-scanning security dependency-audit secrets-management infrastructure-as-code developer-tools ci-cd security cloud-computing developer-tools windows cli go sbom cve-scanning misconfiguration-detection secret-scanning container-security kubernetes-security iac-scanning devsecops license-compliance devops containers linux macos docker kubernetes
4 sources
- readme: https://github.com/aquasecurity/trivy · fetched 2026-08-28 · b04221382fc2
- homepage: https://trivy.dev · fetched 2026-08-29 · 4f7592ce3fab
- site_page: https://trivy.dev/docs/latest/getting-started · fetched 2026-08-29 · faea6d27bd87
- site_page: https://trivy.dev/docs · fetched 2026-08-29 · 0f971f3f3e2e
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| aquasecurity/trivy | main | 98 |
| aquasecurity/trivy-operator | backend | 99 |
| aquasecurity/trivy-action | plugin | 88 |
For agents
markdown · JSON · MCP: product_card(name="aquasecurity/trivy")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem