Trivy
Comprehensive and versatile security scanner for containers, Git repos, and Kubernetes.
Why consider Trivy?
Trivy by Aqua Security is an open-source vulnerability and misconfiguration scanner. Written in Go, it scans container images, Git repositories, Kubernetes clusters, and SBOMs for CVEs, exposed secrets, and cloud infrastructure misconfigurations.
Learn Trivy by building
Practical setup notes, real use cases, and copy-ready examples in one focused guide.
In this guide2 sections
Overview of Trivy
Trivy integrates into CI/CD pipelines to detect operating system package and application dependency CVEs in seconds.
Quickstart
# Scan a container imagetrivy image alpine:3.18# Scan a local repository for secrets and vulnerabilitiestrivy fs ./my-projectTrivy is licensed under the Apache License Version 2.0.
Related tools
More options with a similar category or technology profile.
Dapr CLI
Command-line tool for managing Dapr distributed application runtime environments and sidecars.
bpytop
Python port of bashtop with game-like UI, responsive mouse support, and hardware sensors.
bashtop
Linux resource monitor showing usage and stats for processor, memory, disks, network, and processes.
SchemaHero
Kubernetes-native declarative database schema management and table migration operator.