Listed by DevHunt
Trivy

Trivy

Open-source scanner for vulnerabilities, misconfigs and secrets

FreeSecurityDevOpsOpen Source4 impressions

Trivy is the most popular open source security scanner for Vulnerability &, IaC, SBOM discovery, cloud scanning and Kubernetes security

Trivy is a free alternative to Snyk.

Trivy is an open-source scanner that finds vulnerabilities, misconfigurations, secrets and generates SBOMs for code, containers and Kubernetes.

for
Developers and security teams needing fast, free scanning of code, images and infrastructure.
pricing
open source
license
Apache-2.0
aquasecurity/trivy 38k 721Goupdated 2 days ago
works withDockerKubernetesAzure Container Registry

Key features

6 features of Trivy
  • Vulnerability scanning — Detects CVEs in binaries, container images and source code repositories.
  • Misconfiguration detection — Finds insecure settings in IaC templates and Kubernetes manifests.
  • Secret scanning — Identifies hard-coded credentials and secrets in code and images.
  • SBOM generation — Creates Software Bill of Materials for artifacts to track component licenses.
  • Cloud and Kubernetes scanning — Scans cloud resources and Kubernetes clusters for security issues.
  • Docker extension — Integrates as a Docker extension for easy image scanning in Docker workflows.

Use cases

  • Scan container images for vulnerabilities before deployment
  • Validate IaC templates for misconfigurations in CI pipelines
  • Generate SBOMs for compliance and license tracking
  • Detect hard-coded secrets in source repositories
  • Monitor Kubernetes clusters for security drift

Trivy vs alternatives

TrivySnykSemgrep
Best forAll-in-one open-source security scannerCommercial vulnerability managementStatic analysis of source code
PricingOpen sourceSubscriptionSubscription
DevHunt upvotes000
Launched———
  • Trivy vs Snyk: Snyk offers a commercial SaaS platform with paid plans and broader ecosystem integrations
  • Trivy vs Semgrep: Semgrep focuses on static code analysis for bugs and security, not container or IaC scanning

Trivy FAQ

Is Trivy free to use?+

Yes, Trivy is open-source and released under the Apache-2.0 license.

What types of artifacts can Trivy scan?+

It can scan source code repositories, binary artifacts, container images, IaC files and Kubernetes clusters.

Does Trivy support secret detection?+

Yes, Trivy includes secret scanning to find hard-coded credentials in code and images.

Can Trivy generate a Software Bill of Materials?+

Yes, Trivy can produce SBOMs for scanned artifacts.

How does Trivy integrate with CI/CD pipelines?+

Trivy can be run as a CLI tool or Docker extension and is commonly used in CI/CD workflows to scan images and IaC.

Summarized by DevHunt from trivy.dev · Oct 1, 2026. Details may change; check the official site.

About this listing

DevHunt lists Trivy because developers expect to find it next to the tools in its category. It did not launch on DevHunt. Work on Trivy? Message us to claim this listing.