Skip to content
OpenCatalogcurated by FLOSSK
Security & Privacy

Trivy

All-in-one scanner for container images, IaC, Kubernetes manifests, SBOMs, and VM OS packages with CI integrations.

Why it is included

Single CLI covering vulnerabilities and misconfigs—common in supply-chain pipelines.

Best for

DevSecOps gates from registry scan to Terraform and K8s YAML review.

Strengths

  • Broad targets
  • SARIF
  • Operator and cache options

Limitations

  • Rule/db freshness depends on update cadence

Good alternatives

Grype · Checkov · Terrascan

Related tools