AppSecNews
IaC Security Open source Established Verified profile

Trivy

by Aqua Security

An open-source scanner that finds vulnerabilities, misconfigurations, secrets and license issues across container images, filesystems, repositories and IaC.

Visit trivy.dev (leaves AppSecNews, opens in a new tab) Leaves AppSecNews for the vendor's own site.

No endorsements yet

Run Trivy in production? A named recommendation helps the next team shortlisting it.

Recommend this tool

Endorsers verify their identity through LinkedIn. Titles and companies are self declared, shown as they were when each person signed, and reviewed by an editor before anything is published. Endorsements are never paid for.

What it does

Trivy is several analyzers behind one command. For vulnerability detection it unpacks a target, identifies the OS distribution and reads its package database, then walks the filesystem for language-specific lock files, matching what it finds against a vulnerability database it caches locally. Because the database ships as an OCI artifact and the binary has no runtime dependencies, an offline setup is practical, which is unusual in this space.

For misconfiguration it uses the engine consolidated from tfsec plus its own Rego checks, covering Terraform and plan files, CloudFormation, Kubernetes manifests, Helm charts, Dockerfiles and ARM templates. It also scans for embedded secrets, detects declared licenses, and generates SBOMs in CycloneDX and SPDX formats. The same scanner runs against a container image, a local directory, a Git repository, a running Kubernetes cluster or a VM image, which is the real reason it ends up everywhere.

Where it fits

Trivy runs in almost every stage. Developers invoke it locally, CI scans images after build and infrastructure code on pull requests, registries call it on push, and the Trivy Operator runs it continuously in a cluster. Ownership is usually shared, with platform teams wiring it into pipelines and application teams acting on results. The one prerequisite worth planning for is database distribution: pulling the vulnerability database on every CI run is wasteful and, in restricted environments, fragile, so cache it.

Strengths

  • One tool and one output format across images, filesystems, repositories, clusters and IaC, removing a lot of pipeline plumbing.
  • Single static binary with offline database support, viable in air-gapped and regulated environments where most scanners are not.
  • Terraform plan file scanning resolves values that source-only analysis cannot, improving accuracy on nontrivial configurations.
  • SARIF, JSON and SBOM output slots into code scanning surfaces and supply chain workflows without conversion scripts.

Limitations

  • Breadth comes at the expense of depth in places. Its vulnerability matching relies on package metadata, so it can miss vendored or statically linked components, and reachability analysis is not its focus.
  • Findings volume on a typical base image is high, and severity alone is a poor filter. Expect to invest in ignore files and base image hygiene.
  • Misconfiguration rule depth is not exhaustive across every format it parses, so coverage varies by target type.

Who it suits

A sensible default for most teams, particularly those who want one scanner rather than four and value running it identically on a laptop, in CI and in a cluster. Less suitable as the only tool where deep reachability analysis is needed to cut noise, or where the workflow and exception management of a commercial platform is required.

Used Trivy? Recommend it under your own name and title.

Recommend this tool