

Trivy
Scanner for vulnerabilities in container images, file systems, and Git repositories, as well as for configuration issues and hard-coded secrets.
Features
Properties
- Security-focused
Features
Support for Docker
- Kubernetes
- Golang
Trivy News & Activities
Recent activities
glatisant added Trivy as alternative to Exploit Observer
Sonu-Kapoor added Trivy as alternative to CVE Lite CLI- vpetersson added Trivy as alternative to sbomify action
- sr00 updated Trivy
metriclogic added Trivy as alternative to PackageFix- javyer liked Trivy
Trivy information
Featured in Lists
A list of open-source software containing slop (LLM generated) code or endorses the usage of LLMs in other ways. This …
A list with 13 apps by b4st1en without a description.
What is Trivy?
Trivy (tri pronounced like trigger, vy pronounced like envy) is a simple and comprehensive scanner for vulnerabilities in container images, file systems, and Git repositories, as well as for configuration issues. Trivy detects vulnerabilities of OS packages (Alpine, RHEL, CentOS, etc.) and language-specific packages (Bundler, Composer, npm, yarn, etc.). In addition, Trivy scans Infrastructure as Code (IaC) files such as Terraform, Dockerfile and Kubernetes, to detect potential configuration issues that expose your deployments to the risk of attack. Trivy also scans hardcoded secrets like passwords, API keys and tokens. Trivy is easy to use. Just install the binary and you're ready to scan.








