Overview
Trivy is a security scanner for container images, filesystems, Git repositories, VM images, and Kubernetes. It combines checks for vulnerabilities, SBOM data, IaC misconfigurations, secrets, and software licenses behind one target-and-scanner CLI model.
Based on official documentation; not hands-on tested · Content checked:
Inspect multiple software-supply-chain layers with one CLI
Trivy finds SBOM information for operating-system packages and dependencies, known CVEs, IaC issues, secrets, and software licenses. It scans images, project filesystems, remote repositories, VM images, and Kubernetes clusters and integrates with GitHub Actions, a Kubernetes operator, and a VS Code extension.
Sources: [1]
For aligning checks across workstations, CI, and clusters
It fits DevSecOps workflows that apply a common scanner to working directories, built images, Git repositories, and running Kubernetes environments to reduce gaps across vulnerabilities, secrets, and misconfigurations. Installation options include binaries, Homebrew, and containers.
Sources: [1]
Select targets and scanners explicitly, and keep canaries out of production
Coverage and results depend on the chosen target, scanner, language, operating system, and platform support. Limit credentials and permissions for each target and define triage, update, and exception handling. Canary builds are generated on every main-branch push and may contain critical bugs, so the README does not recommend them for production.
Sources: [1]
Official sources
- [1]Trivy README(2026-09-13)
Supplemental curator note
Selected for moving from a Japanese developer's personal project into a company organization while using broad target and scanner metadata to improve discovery.
Growth trends
Last 30 days
37,887 Stars
Trend data is still being collected.
Built with
- Go
- Docker
Categories and tags
Categories
Tags
GitHub Topics
- security
- security-tools
- docker
- containers
- vulnerability-scanners
- vulnerability-detection
- vulnerability
- golang
- go
- kubernetes
- hacktoberfest
- devsecops
GitHub dataView detailed GitHub data
- Stars
- 37,887
- Forks
- 678
- Watchers
- 224
- Open issues
- 170
- Contributors
- 442
- Primary language
- Go
- License
- Apache-2.0
- Repository last updated
- Sep 11, 2026
Explore next
- Kubernetes127,382 Stars
A cloud-native platform for deploying, maintaining, and scaling containers across hosts.
Go - Sherlock91,396 Stars
A Python OSINT CLI that checks username-based account candidates across social networks.
Python - Moby72,090 Stars
Docker's upstream open-source project for assembling container platforms from replaceable components.
Go - Ansible70,666 Stars
An agentless SSH-based platform for configuration, deployment, cloud, and network automation using human-readable descriptions.
Python - Prometheus66,055 Stars
A monitoring platform that pulls labeled time-series metrics and combines PromQL, rules, alerts, and service discovery.
Go
Report incorrect information
Tell us if any listing information is incorrect or outdated.