Trivy
softwareAbout
Open-source security scanner by Aqua Security for finding vulnerabilities, misconfigurations, and secrets in containers, filesystems, Git repos, and Kubernetes clusters.
Overview
Trivy has become the default open-source security scanner for containers and infrastructure, combining speed, ease of use, and comprehensive scanning that makes it essential in modern CI/CD pipelines.
Pros
- +Fast, comprehensive, and completely free
- +Easy to integrate into CI/CD pipelines
- +Actively maintained by Aqua Security
Cons
- -CLI-focused with no built-in dashboard
- -Can produce false positives in edge cases
- -Less enterprise features than commercial scanners
This may be an affiliate link — the creator and GuruStacks may earn a commission, at no extra cost to you. Learn more
Details
Pricing
Model
unknown
Platforms
Community
Listed in Stacks
Cybersecurity Analyst
Essential tools for cybersecurity analysts covering SIEM, vulnerability scanning, penetration testing, endpoint protection, network security, and incident response.
DevOps Engineer Stack
Comprehensive DevOps engineering tools and platforms for CI/CD, infrastructure automation, monitoring, and cloud operations
Related
Similar tools
View alternatives →Snyk
4.4Developer-first security platform that finds and fixes vulnerabilities in code, open-source dependencies, containers, and infrastructure as code. Integrates into the development workflow.
Harbor
4.4Open-source cloud-native container registry that provides vulnerability scanning, image signing, content trust, and role-based access control for container images.
Flux CD
4.4CNCF graduated GitOps toolkit for Kubernetes that keeps clusters in sync with configuration sources like Git repos and Helm charts using a pull-based approach.
OpenVAS
4.2Open-source vulnerability scanner providing comprehensive network security auditing and vulnerability assessment for detecting security issues across IT infrastructure.
Nessus
4.5Tenable's industry-leading vulnerability assessment scanner for identifying CVEs, misconfigurations, and compliance gaps across networks and systems.
Nuclei
4.2Open-source vulnerability scanner and security automation platform for exposure discovery, attack surface mapping, and custom security workflow execution.