OSS Tanbou

Trivy — security scanning across containers, Kubernetes, and repositories

Discovery score 289.5OSS health 96
About these scores

Discovery score is an unbounded weighted, log-compressed index of stars, watchers, forks, and contributors. Growth momentum is its change over the observed period; OSS health is a 0–100 score from available repository recency, Community Health, and release data.

Stars
37,887
Primary language
Go
License
Apache-2.0
Repository last updated
Sep 11, 2026

Overview

Trivy is a security scanner for container images, filesystems, Git repositories, VM images, and Kubernetes. It combines checks for vulnerabilities, SBOM data, IaC misconfigurations, secrets, and software licenses behind one target-and-scanner CLI model.

Based on official documentation; not hands-on tested · Content checked:

Inspect multiple software-supply-chain layers with one CLI

Trivy finds SBOM information for operating-system packages and dependencies, known CVEs, IaC issues, secrets, and software licenses. It scans images, project filesystems, remote repositories, VM images, and Kubernetes clusters and integrates with GitHub Actions, a Kubernetes operator, and a VS Code extension.

Sources: [1]

For aligning checks across workstations, CI, and clusters

It fits DevSecOps workflows that apply a common scanner to working directories, built images, Git repositories, and running Kubernetes environments to reduce gaps across vulnerabilities, secrets, and misconfigurations. Installation options include binaries, Homebrew, and containers.

Sources: [1]

Select targets and scanners explicitly, and keep canaries out of production

Coverage and results depend on the chosen target, scanner, language, operating system, and platform support. Limit credentials and permissions for each target and define triage, update, and exception handling. Canary builds are generated on every main-branch push and may contain critical bugs, so the README does not recommend them for production.

Sources: [1]

Official sources

  1. [1]Trivy README(2026-09-13)
Supplemental curator note

Selected for moving from a Japanese developer's personal project into a company organization while using broad target and scanner metadata to improve discovery.

Growth trends

Last 30 days

37,887 Stars

Trend data is still being collected.

Built with

  • Go
  • Docker

Categories and tags

GitHub Topics

  • security
  • security-tools
  • docker
  • containers
  • vulnerability-scanners
  • vulnerability-detection
  • vulnerability
  • golang
  • go
  • kubernetes
  • hacktoberfest
  • devsecops
GitHub dataView detailed GitHub data
Stars
37,887
Forks
678
Watchers
224
Open issues
170
Contributors
442
Primary language
Go
License
Apache-2.0
Repository last updated
Sep 11, 2026
Report incorrect information

Tell us if any listing information is incorrect or outdated.