Independent cybersecurity directory, built from public sources. Featured listings are paid placements and always labelled. How we work

Trivy

Open-source vulnerability scanner for containers, file systems, IaC, and Kubernetes with zero-config setup

ToolApplication SecuritySelf-hosted, Open source

Pricing: Free (open source) / Aqua Platform for enterprise features

Reviewed by the Cyber Vendor Guide editorial team against the public sources cited below · Last reviewed September 2026 · How we review listings

What is Trivy?

Trivy is an open-source, comprehensive vulnerability scanner developed by Aqua Security that covers container images, file systems, Git repositories, Kubernetes clusters, and infrastructure-as-code configurations. Trivy stands out for its simplicity, speed, and breadth of scanning targets, requiring zero configuration to get started. It has become a widely adopted open-source scanner for container images in CI/CD pipelines and is widely adopted in Kubernetes-native environments for runtime vulnerability assessment.

Best for: DevOps and platform engineering teams that need a fast, open-source vulnerability scanner for containers and Kubernetes environments with zero configuration overhead

Pros

  • Completely free and open source with no licensing costs
  • Zero-configuration setup with a single binary installation
  • Extremely fast scanning suitable for every CI/CD pipeline run
  • Broadest scanning target coverage of any open-source scanner
  • De facto standard for container image scanning in Kubernetes environments

Things to check

  • No web dashboard or centralized management in open-source version
  • Vulnerability database updates rely on community and Aqua research
  • Lacks automated fix PR generation and remediation workflow
  • No dedicated SAST engine for deep code-level vulnerability analysis
  • Enterprise features require paid Aqua Platform subscription

Reported in public reviews and vendor documentation. See sources below.

Key Features

Container image vulnerability scanning
File system and Git repository scanning
Infrastructure-as-code misconfiguration detection
Kubernetes cluster scanning
SBOM generation and scanning
Secret detection in code and configurations
License scanning for open-source dependencies
Integration with CI/CD platforms and container registries

Do you work at Trivy? to confirm the details or send us a correction.

Add the Cyber Vendor Guide badge to your site

Trivy Comparisons

Sources & references

Where the information on this listing comes from. Always verify pricing and capabilities against the vendor before a purchasing decision.

Spot an error, or do you represent Trivy? Request a correction.

Key facts

Pricing
Free (open source) / Aqua Platform for enterprise features
Model
Open source with commercial Aqua Platform
Founded
2019
Cloud
No
Self-hosted
Yes
Open source
Yes

Trivy Alternatives

  • SnykDeveloper-first application security platform for finding an...
  • SonarQubeOpen-source code quality and security analysis platform with...
  • CheckmarxEnterprise application security platform with deep SAST, SCA...
  • VeracodeCloud-based application security testing platform with SAST,...
  • SemgrepLightweight, open-source static analysis with intuitive patt...
View all alternatives

In the glossary

SCA