Softwr
Trivy logo

Trivy

Open-source vulnerability and misconfiguration scanner

Overview

What Trivy does

Trivy is an open-source security scanner from Aqua Security that finds vulnerabilities, misconfigurations, secrets and licence issues across container images, filesystems, Git repositories, Kubernetes clusters and infrastructure-as-code. Its adoption owes as much to packaging as detection: a single binary with no server to run, sensible defaults, and a scan that completes fast enough to sit in a pull request check. That is why it became a common default in CI pipelines rather than a security-team-only tool.

What people use it for

  • Failing a pull request when a container image introduces a known CVE
  • Scanning Terraform and Kubernetes manifests for misconfiguration before apply
  • Catching committed secrets as part of an existing CI step

The honest half

Where it falls short

Concrete and checkable, so you can decide whether any of them matter to you. This is the half of a review a vendor will not write about Trivy.

  • Reports what public advisory databases know, so coverage varies by ecosystem and unfixed CVEs create noise
  • No built-in triage or exception workflow, so suppressing accepted risk is managed in config files
  • Findings are point-in-time from CI, with no continuous runtime monitoring unless you add the commercial platform

Cross-shopped

What people choose instead of Trivy

Each pairing was judged by two reviewers asking whether a buyer would genuinely weigh the two against each other. The ones that failed were deleted rather than published.

  • Trivy logo
    Trivy
    vs
    Snyk logo
    Snyk

    Snyk: Commercial scanning with triage workflow, fix pull requests and reporting that Trivy leaves to you

Pricing

What Trivy costs

Taken from the vendor's own pricing page. Prices move, so check before you buy.

Trivy

Free

  • Full scanner
  • Unlimited scans
  • Community support

Capabilities

Features

  • Multi-target scanning

    Container images, filesystems, repositories, Kubernetes and IaC

  • Vulnerability detection

    OS packages and language dependencies against public advisory databases

  • Misconfiguration checks

    Terraform, Kubernetes and Dockerfile policy scanning

  • Secret detection

    Finds committed credentials during the same scan

Answered, with sources

Questions people ask

Each answer names the page it came from, so you can check it rather than take our word for it.

Is Trivy free?

Yes, open source from Aqua Security with no licence fee. Aqua sells a commercial platform around it.

What can Trivy scan?

Container images, filesystems, Git repositories, Kubernetes clusters and infrastructure-as-code, for vulnerabilities, misconfigurations, secrets and licences.

Does Trivy need a server?

No. It is a single binary, which is a large part of why it became a default in CI.

Share

Keep looking

Where to go from Trivy

Best Cybersecurity software for

Compare Trivy with

Other Cybersecurity software

  • The world's most-loved password manager

  • Powerful protection against evolving threats

  • Simplify online life with LastPass password manager

  • Developer-first security platform

  • Open source password management for everyone

  • Drop-in user authentication and management for developers

  • Privacy-first VPN with one flat price and no email required to sign up

  • Enterprise AI governance and data compliance platform.

  • Secure, green and ad-free. Email to feel good about.

  • Runtime identity security at agentic scale

  • Secrets management for humans and AI agents

  • Customer identity and access management platform for SaaS applications

Softwr does not host reviews and shows no star rating for Trivy, because a rating we did not collect is not ours to publish. What is here is the pricing and platform detail from the vendor’s own pages, limitations we could state concretely, and alternatives a reviewer confirmed people weigh against it. Tell us if any of it is wrong.

More on Trivy

Best Cybersecurity software alternatives

Open-source authentication and two-factor portal for reverse proxies

Vulnerability scanner for container images and filesystems

Headless identity and user management API

Open-source identity provider with flexible authentication flows

Secrets management for humans and AI agents

Security and AI agent governance for code and supply chain

Unified security platform automating vulnerability detection and fixing across development

Compare Trivy with alternatives