Trivy
Open-source scanner for vulnerabilities, misconfigs and secrets
FreeSecurityDevOpsOpen Source4 impressions
Trivy is a free alternative to Snyk.
Trivy is an open-source scanner that finds vulnerabilities, misconfigurations, secrets and generates SBOMs for code, containers and Kubernetes.
- for
- Developers and security teams needing fast, free scanning of code, images and infrastructure.
- pricing
- open source
- license
- Apache-2.0
Key features
- Vulnerability scanning — Detects CVEs in binaries, container images and source code repositories.
- Misconfiguration detection — Finds insecure settings in IaC templates and Kubernetes manifests.
- Secret scanning — Identifies hard-coded credentials and secrets in code and images.
- SBOM generation — Creates Software Bill of Materials for artifacts to track component licenses.
- Cloud and Kubernetes scanning — Scans cloud resources and Kubernetes clusters for security issues.
- Docker extension — Integrates as a Docker extension for easy image scanning in Docker workflows.
Use cases
- Scan container images for vulnerabilities before deployment
- Validate IaC templates for misconfigurations in CI pipelines
- Generate SBOMs for compliance and license tracking
- Detect hard-coded secrets in source repositories
- Monitor Kubernetes clusters for security drift
Trivy vs alternatives
Snyk | Semgrep | ||
|---|---|---|---|
| Best for | All-in-one open-source security scanner | Commercial vulnerability management | Static analysis of source code |
| Pricing | Open source | Subscription | Subscription |
| DevHunt upvotes | 0 | 0 | 0 |
| Launched | — | — | — |
- Trivy vs Snyk: Snyk offers a commercial SaaS platform with paid plans and broader ecosystem integrations
- Trivy vs Semgrep: Semgrep focuses on static code analysis for bugs and security, not container or IaC scanning
Trivy FAQ
Is Trivy free to use?+
Yes, Trivy is open-source and released under the Apache-2.0 license.
What types of artifacts can Trivy scan?+
It can scan source code repositories, binary artifacts, container images, IaC files and Kubernetes clusters.
Does Trivy support secret detection?+
Yes, Trivy includes secret scanning to find hard-coded credentials in code and images.
Can Trivy generate a Software Bill of Materials?+
Yes, Trivy can produce SBOMs for scanned artifacts.
How does Trivy integrate with CI/CD pipelines?+
Trivy can be run as a CLI tool or Docker extension and is commonly used in CI/CD workflows to scan images and IaC.
Summarized by DevHunt from trivy.dev · Oct 1, 2026. Details may change; check the official site.
About this listing
DevHunt lists Trivy because developers expect to find it next to the tools in its category. It did not launch on DevHunt. Work on Trivy? Message us to claim this listing.
Snyk
Semgrep



-(1).png?auto=compress&fit=max&w=64)

