“The default choice for production React today - server components, file-based routing, and first-class deployment story make it the fastest path from idea to shipped app.”
Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more
A fast, all-in-one vulnerability scanner - containers, filesystems, git repos, and Terraform/IaC misconfigurations all covered by one CLI tool.
Where trivy fits, based on its real tags and topics.
git clone https://github.com/aquasecurity/trivy.gitSee the repository's README for language-specific setup steps.
[![GitHub Release][release-img]][release] [![Test][test-img]][test] [![Go Report Card][go-report-img]][go-report] [![License: Apache-2.0][license-img]][license] [![GitHub Downloads][github-downloads-img]][release] ![Docker Pulls][docker-pulls]
Trivy ([pronunciation][pronunciation]) is a comprehensive and versatile security scanner. Trivy has *scanners* that look for security issues, and *targets* where it can find those issues.
- Container Image - Filesystem - Git Repository (remote) - Virtual Machine Image - Kubernetes
37.1K
Stars
551
Forks
216
Watchers
240
Open Issues
539
Contributors
15
Topics
Category: 🔒 Security
Difficulty: Beginner
Part of: Security Toolkit
“The default choice for production React today - server components, file-based routing, and first-class deployment story make it the fastest path from idea to shipped app.”
The Postgres development platform. Supabase gives you a dedicated Postgres database to build your web, mobile, and AI applications.
“A genuinely open-source Firebase alternative - real Postgres underneath, with auth, storage, and realtime built in rather than a proprietary database.”
“Utility-first CSS that's become the default styling approach for new projects - fast to write, easy to keep consistent, no dead CSS to prune later.”
“An all-in-one JavaScript runtime, bundler, test runner, and package manager - genuinely faster than the Node.js equivalents it replaces.”
“The most practical secure-coding reference that exists - concrete, actionable guidance per vulnerability class, not a wall of theory.”
“The standard penetration testing framework - essential for offensive security work, strictly for authorized testing on systems you own or have permission to test.”
“The most widely used free web app security scanner (OWASP ZAP) - a solid first line of defense for catching common web vulnerabilities pre-release.”
“Static analysis that's actually fast enough to run on every pull request - the rule syntax is simple enough that teams write their own custom checks instead of just accepting defaults.”
“Scans commits (and full git history) for leaked secrets - the cheapest insurance policy against an accidental key leak turning into an incident.”
“A genuinely full-featured open-source SIEM - threat detection, compliance, and log analysis without the licensing cost of commercial platforms.”
“The industry-standard container orchestrator - not always necessary at small scale, but the default assumption for any serious cloud-native platform team.”
“The most capable open-source relational database available - strong standards compliance, extensions for nearly everything (including full-text search and vectors), and a default choice for good reason.”
“Unifies dozens of LLM providers behind a single API, making model switching almost effortless in production.”
“The standard library for working with open-weight models - thousands of pretrained models are one line of code away.”
“The modern default frontend build tool - native ESM in dev means a dev server that starts and reloads almost instantly, even on large apps.”
“The open-source engine behind Docker - understanding containers here pays off no matter which orchestrator sits on top later.”