Skip to content
CloudTweaks
App & Code Security (SAST/SCA)

Trivy

$ BudgetFree · Last reviewed July 2026

Trivy is the de-facto open-source security scanner for containers and cloud-native artifacts, detecting vulnerabilities in images and dependencies, exposed secrets, and misconfigurations in IaC such as Terraform and Kubernetes manifests. Maintained by Aqua Security, it is embedded in countless CI pipelines and is the default scanner in several registries, including Harbor. It is entirely free; Aqua's commercial platform builds on it. It suits any team that wants credible scanning in CI with a single fast binary.

open-sourcecontainer-scanningiac-scanningaquaci

Overview

Founded
2019
Pricing tier
Low
Startup-friendly
Yes
Enterprise-ready
No

App & code security (SAST/SCA)

SAST
No
SCA
Yes
Secret scanning
Yes
DAST
No
Container scanning
Yes
IaC scanning
Yes
CI/CD integration
Yes
Open-source
Yes
Self-hostable
Yes
Free tier
Yes: Fully free OSS (Apache 2.0).

Categories & compliance

Categories

Attributes are sourced facts; rankings are derived from them by a transparent scoring engine. “Verified” is a vendor-claimed badge and has no effect on ranking.