Trivy

Package

Open-source CLI for container and filesystem vulnerability scanning

Price
Free, open source
Access
None, runs locally

About

Local security scanner for container images, filesystems and repositories. It checks OS and language packages for vulnerabilities and can scan secrets and infrastructure misconfiguration. Scanners and database downloads are configurable; it does not dynamically attack running web applications.

What you can do with it

  • Scan container images for vulnerable OS packages and language dependencies
  • Check a repository or filesystem for known dependency vulnerabilities
  • Enable configuration scanning for Terraform and Kubernetes security issues

Get started

  1. Install the Trivy CLI for your operating system
  2. Allow it to download vulnerability databases or configure offline databases
  3. Run trivy image or trivy filesystem against your target

Example

trivy image --scanners vuln alpine:3.20
trivy filesystem --scanners vuln .

Details

Hosting
Runs locally, Self-hosted
Available in
Worldwide
MCP server
None

Tasks

Alternatives

Other tools for the same tasks.

Last checked on .