TR

Trivy

Comprehensive security scanner for containers and code

Developer Tools & Git ★ 37.3k stars Easy setup Apache-2.0

Trivy is an open-source vulnerability and misconfiguration scanner for containers, file systems, Git repositories, and Kubernetes. It can run as a CLI or a long-running server for centralized scanning.

Key features

  • Scans containers and code
  • Misconfiguration detection
  • SBOM generation
  • Kubernetes integration

Strengths

  • Released under the Apache-2.0 license
  • Easy to set up — beginner-friendly
  • First-class Docker support for quick deployment
  • Kubernetes-ready with Helm charts available

Trivy replaces

Compare Trivy

29 head-to-head comparisons.

Similar developer tools & git apps