Trivy is a comprehensive and versatile security scanner that targets vulnerabilities in container images, file systems, and Git repositories, as well as configuration issues. It detects OS packages and language-specific dependencies with CVEs, IaC files and Kubernetes with misconfigurations, and secrets.
Features
β¦Detects vulnerabilities in OS packages (Alpine, RHEL, CentOS, etc.) and language-specific bundles (Bundler, Composer, npm, yarn)
β¦Identifies IaC issues in Terraform, CloudFormation, Kubernetes, and Dockerfiles
β¦Scans for sensitive data exposure: API keys, tokens, passwords, and private keys in repositories
β¦Detects container image vulnerabilities and misconfigurations in one unified scanner
β¦Generates reports in multiple formats: JSON, YAML, SARIF, CycloneDX, and plain text
β¦Easy to install and use: single binary with no dependencies, works in CI/CD pipelines
Pricing
basicFree (OSS)
proFree tier (unlimited scans)
enterpriseCustom
Get Started
Ready to get started? Contact us for a custom quote.