Why we are featuring it
One scanner for many risk surfaces.
Trivy brings vulnerability, SBOM, configuration, secret, and license scanning into a CLI for images, repositories, and clusters. Integrations place it directly inside development and deployment workflows.
What is inside
- Scans images, filesystems, Git, VMs, and Kubernetes.
- Finds CVEs, dependencies, SBOM, IaC, secrets, and licenses.
- Installable through Homebrew, Docker, or binaries.
- GitHub Actions, Kubernetes operator, and VS Code integrations.