Skip to content
aicoolies logo
Trivy logo

Trivy

Comprehensive open-source vulnerability scanner

Trivy is an open-source vulnerability scanner with 24K+ GitHub stars by Aqua Security that scans container images, file systems, Git repositories, Kubernetes clusters, and IaC configurations for security issues. Detects OS package and language-specific vulnerabilities, misconfigurations, secrets, and license violations in a single tool. Runs as a simple CLI with zero configuration needed. Supports SBOM generation, VEX for vulnerability filtering, and CI/CD integration.

About Trivy

Trivy is a comprehensive open-source security scanner by Aqua Security that has become the de facto standard for container and infrastructure security scanning. With over 24,000 GitHub stars, it covers the broadest range of scanning targets in a single tool.

Trivy scans container images, file systems, Git repositories, Kubernetes clusters, and virtual machine images for known vulnerabilities in OS packages and language-specific dependencies. It also detects IaC misconfigurations in Terraform, CloudFormation, Kubernetes manifests, and Dockerfiles.

Additional capabilities include secrets detection for finding leaked credentials, license scanning for compliance, and SBOM generation in CycloneDX and SPDX formats. VEX support allows filtering out vulnerabilities that are not applicable to your specific deployment.

The tool runs as a standalone CLI with zero configuration needed — just point it at a target and get results. It integrates with CI/CD pipelines through GitHub Actions, GitLab CI, Jenkins, and other platforms. Enterprise features are available through Aqua Security's commercial platform.

Pricing & Platform Specs

Pricing Summary

Trivy is a 100% free and open-source comprehensive security and vulnerability scanner under the Apache-2.0 license ($0). It offers unlimited scanning across containers, Kubernetes, IaC, and source code repositories with zero licensing fees. Aqua Security provides commercial enterprise platforms for runtime eBPF protection and CSPM via custom quote.

full pricing breakdown →

Supported Platforms

CLI, Docker, GitHub Actions, CI/CD

Explore categories, tags & use cases

Open-source browser infrastructure for AI agents at scale

Steel is an open-source browser API purpose-built for AI agents, providing managed headless browser sessions with anti-bot bypass, proxy rotation, CAPTCHA solving, and session persistence. It handles the infrastructure layer that browser automation agents like Browser Use and Stagehand run on top of. Self-hostable or available as a cloud service. Over 6,000 GitHub stars.

freemiumOpen Source

Open-source background jobs and AI workflows for TypeScript

Trigger.dev is an open-source platform for building and deploying background jobs, AI agents, and long-running workflows in TypeScript. It eliminates serverless timeouts with durable task execution, automatic retries, queue-based concurrency control, and elastic scaling. Used by 30,000+ developers at companies like MagicSchool and Icon.com, it processes hundreds of millions of agent runs monthly. Backed by a $16M Series A led by Dalton Caldwell's Standard Capital fund.

freemiumOpen Source

Open-source PaaS alternative to Vercel, Heroku, and Netlify

Dokploy is a free open-source platform-as-a-service for self-hosting applications without cloud vendor lock-in. It provides automated deployments from Git repositories, built-in SSL certificates, database provisioning, Docker and Docker Compose support, and a clean web dashboard for managing multiple applications on your own servers. With 18,000+ GitHub stars, it fills the gap for teams wanting Vercel-like deployment simplicity on their own infrastructure.

freemiumOpen Source

Side-by-Side Comparisons

AccuKnox logo
AccuKnox
vs
Trivy logo
Trivy
vs
Falco logo
Falco

AccuKnox vs Trivy vs Falco — Kubernetes Security Tools for Runtime Protection & Vulnerability Scanning

Kubernetes security requires multiple layers of defense, from image scanning to runtime threat detection. This comparison examines three leading tools that address different aspects of the Kubernetes security stack: AccuKnox as a comprehensive Zero Trust CNAPP platform with eBPF-powered runtime enforcement, Trivy as a versatile open-source vulnerability scanner for containers and infrastructure, and Falco as the CNCF graduated standard for kernel-level runtime threat detection.

Community experience

Sources & verification

Sources checked
Content verified

Verification dates are editorial checks. Routine CMS saves and automatic updatedAt timestamps do not advance them.

FAQ

What is Trivy?

Trivy is an open-source vulnerability scanner with 24K+ GitHub stars by Aqua Security that scans container images, file systems, Git repositories, Kubernetes clusters, and IaC configurations for security issues. Detects OS package and language-specific vulnerabilities, misconfigurations, secrets, and license violations in a single tool. Runs as a simple CLI with zero configuration needed. Supports SBOM generation, VEX for vulnerability filtering, and CI/CD integration.

Is Trivy free?

Yes — Trivy is open source and free to use. Trivy is a 100% free and open-source comprehensive security and vulnerability scanner under the Apache-2.0 license ($0). It offers unlimited scanning across containers, Kubernetes, IaC, and source code repositories with zero licensing fees. Aqua Security provides commercial enterprise platforms for runtime eBPF protection and CSPM via custom quote.

Is Trivy open source?

Yes — Trivy is open source.

Is Trivy still maintained?

Yes — Trivy is active. Its listing was last verified on September 6, 2026.

What are the best Trivy alternatives?

The first editor-selected Trivy alternatives are Steel, Trigger.dev, Dokploy.