Skip to content
hackingtools.ai
Trivy

Trivy

Aqua Security's open-source scanner for vulnerabilities, misconfigurations, secrets and SBOMs across containers, code, Kubernetes and cloud targets.

0

0 upvotes · 0 downvotes

Pricing
Free
Platforms
LinuxWindowsmacOS
Licence
Open source
Reviewed
Last reviewed 1 October 2026

What it is

Trivy is an open-source security scanner from Aqua Security. It finds vulnerabilities (CVEs), infrastructure-as-code misconfigurations, exposed secrets and software bill of materials (SBOM) data across container images, filesystems, repositories, Kubernetes clusters and related cloud-native targets, with an Apache-2.0 licence.

What it helps with

- Scanning container images and local filesystems for known package vulnerabilities.
- Checking Terraform, Kubernetes manifests and other IaC for misconfigurations.
- Detecting hardcoded secrets in code and artefacts.
- Generating SBOMs for supply-chain visibility and licence awareness.
- Integrating into CI/CD pipelines, local developer workflows and cluster scanning.
- Providing a free foundation that Aqua's commercial platform can extend for enterprise programmes.

Who it's for

DevOps, platform and AppSec engineers who need a free, easy-to-run scanner for containers and cloud-native estates, and teams standardising vulnerability and misconfiguration checks before production.

Worth knowing

Trivy itself is free and open source (Apache-2.0). Official docs and installs are at trivy.dev and github.com/aquasecurity/trivy. Brand assets in the repository are Creative Commons BY 4.0. Aqua Security offers commercial products that build on Trivy for broader platform management. This listing covers authorised security scanning only.

← Back to directory