Trivy icon
Trivy icon

Trivy

Scanner for vulnerabilities in container images, file systems, and Git repositories, as well as for configuration issues and hard-coded secrets.

Demo: Vulnerability detection

Cost / License

Application type

Platforms

  • Mac
  • Linux
  • Docker
2likes
0articles

Features

Properties

  1.  Security-focused

Features

  1. Docker icon  Support for Docker
  2.  Kubernetes
  3.  Golang

Trivy News & Activities

Highlights All activities

Recent activities

  • Vibgrate icon
    Maoholguin added Trivy as alternative to Vibgrate
  • eliasbuenosdias liked Trivy
  • CVE Lite CLI icon
    Sonu-Kapoor added Trivy as alternative to CVE Lite CLI
  • sbomify action icon
    vpetersson added Trivy as alternative to sbomify action
  • Keelscan icon
    craftripple added Trivy as alternative to Keelscan
  • sr00 updated Trivy
  • PackageFix icon
    metriclogic added Trivy as alternative to PackageFix
  • javyer liked Trivy

Trivy information

AlternativeTo Categories

Security & PrivacyDevelopment

GitHub repository

  •  37,961 Stars
  •  691 Forks
  •  272 Open Issues
  •   Updated  
View on GitHub

Popular alternatives

View all
Trivy was added to AlternativeTo by sr00 on and this page was last updated .
No comments or reviews, maybe you want to be first?

Featured in Lists

A list of open-source software containing slop (LLM generated) code or endorses the usage of LLMs in other ways. This...

List by Edgars with 139 apps, updated

A list with 13 apps by b4st1en without a description.

List by b4st1en with 13 apps, updated

Official Links

What is Trivy?

Trivy (tri pronounced like trigger, vy pronounced like envy) is a simple and comprehensive scanner for vulnerabilities in container images, file systems, and Git repositories, as well as for configuration issues. Trivy detects vulnerabilities of OS packages (Alpine, RHEL, CentOS, etc.) and language-specific packages (Bundler, Composer, npm, yarn, etc.). In addition, Trivy scans Infrastructure as Code (IaC) files such as Terraform, Dockerfile and Kubernetes, to detect potential configuration issues that expose your deployments to the risk of attack. Trivy also scans hardcoded secrets like passwords, API keys and tokens. Trivy is easy to use. Just install the binary and you're ready to scan.