featured · github
Trivy: One Scanner for Containers, Code, and Cloud Configs
Find vulnerabilities, secrets, and misconfigurations across your entire stack—without juggling five different tools.
aquasecurity/trivy ↗Trivy scans containers, Kubernetes clusters, source code repos, and cloud infrastructure for three things: known vulnerabilities (CVEs), leaked secrets (API keys, tokens), and dangerous misconfigurations (overpermissioned IAM, exposed databases). Run it in your CI/CD pipeline before you ship—it catches problems at build time, not production time. Most teams buy point tools for each layer. Trivy does all five in one binary. It's open-source, integrates with GitHub/GitLab Actions natively, and outputs an SBOM (software bill of materials) your compliance team actually wants. If you're shipping anything containerized and want to stop guessing whether you're exposing secrets or vulnerable dependencies, this is the 15-minute setup that pays for itself on day one.
Share kit
Trivy: Scan everything for vulns, secrets, misconfig in one pass
Containers. Code. Cloud configs. Kubernetes. Trivy finds vulnerabilities, leaked secrets, and dangerous misconfigurations across all five in a single binary. CI/CD native. Open-source. Outputs SBOM for compliance. If you're shipping containerized products and not scanning pre-deployment, this is the 15-minute setup that catches the problems that kill launches.
Your CI/CD pipeline is probably shipping secrets and CVEs without knowing it. Trivy finds them—vulnerabilities, misconfigs, API keys—across containers, code, clouds, and K8s in one scan. Open-source. Integrates with GitHub Actions in 5 minutes. https://github.com/aquasecurity/trivy
Security scanning doesn't need to be baroque. Trivy does what five specialized tools do—finds vulnerabilities, secrets, and misconfigurations in containers, Kubernetes, code, and cloud infrastructure—in a single binary. Open-source. Native GitHub/GitLab integration. Built for teams shipping fast without cutting corners on safety. https://github.com/aquasecurity/trivy
Just integrated Trivy into our CI/CD and caught 47 vulnerabilities we'd otherwise shipped. One tool scans containers, Kubernetes, code, clouds, and pulls secrets before they leave your repo. No plugin hell, no separate SCA tool. Run it once, see everything. GitHub Repo → https://github.com/aquasecurity/trivy
trivy does what usually takes 3 tools: finds CVEs in containers, misconfigs in k8s, secrets in code, SBOM in one scan. already at 60k+ stars. if you're shipping anything, this saves audit friction fast. https://github.com/aquasecurity/trivy