Trivy
PackageOpen-source CLI for container and filesystem vulnerability scanning
- Price
- Free, open source
- Access
- None, runs locally
About
Local security scanner for container images, filesystems and repositories. It checks OS and language packages for vulnerabilities and can scan secrets and infrastructure misconfiguration. Scanners and database downloads are configurable; it does not dynamically attack running web applications.
What you can do with it
- Scan container images for vulnerable OS packages and language dependencies
- Check a repository or filesystem for known dependency vulnerabilities
- Enable configuration scanning for Terraform and Kubernetes security issues
Get started
- Install the Trivy CLI for your operating system
- Allow it to download vulnerability databases or configure offline databases
- Run trivy image or trivy filesystem against your target
Example
trivy image --scanners vuln alpine:3.20
trivy filesystem --scanners vuln .Details
- Hosting
- Runs locally, Self-hosted
- Available in
- Worldwide
- MCP server
- None