Trivy is the de-facto open-source security scanner for containers and cloud-native artifacts, detecting vulnerabilities in images and dependencies, exposed secrets, and misconfigurations in IaC such as Terraform and Kubernetes manifests. Maintained by Aqua Security, it is embedded in countless CI pipelines and is the default scanner in several registries, including Harbor. It is entirely free; Aqua's commercial platform builds on it. It suits any team that wants credible scanning in CI with a single fast binary.
open-sourcecontainer-scanningiac-scanningaquaci
Overview
- Founded
- 2019
- Pricing tier
- Low
- Startup-friendly
- Yes
- Enterprise-ready
- No
App & code security (SAST/SCA)
- SAST
- No
- SCA
- Yes
- Secret scanning
- Yes
- DAST
- No
- Container scanning
- Yes
- IaC scanning
- Yes
- CI/CD integration
- Yes
- Open-source
- Yes
- Self-hostable
- Yes
- Free tier
- Yes: Fully free OSS (Apache 2.0).
