aquasecurity/trivy
# Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more
$ git clone https://github.com/aquasecurity/trivy.git
stars
37,005
forks
547
language
Go
license
Apache License 2.0
What is aquasecurity/trivy?
Trivy is an open-source security scanner that detects vulnerabilities, misconfigurations, secrets, and generates software bill of materials (SBOM) across containers, Kubernetes clusters, infrastructure-as-code files, and code repositories. Developers use it to identify security issues early in the development pipeline, from container images to cloud deployments. It integrates into CI/CD workflows and provides comprehensive coverage across multiple artifact types and cloud platforms.
Links
Topics
Activity
238 open issues · last updated Jul 21, 2026