Security Scanning
Trivy
An open-source security scanner for container images, filesystems, Git repositories, Kubernetes configurations, and infrastructure code.
Problem it solves
Why it exists.
It finds known vulnerabilities, misconfigurations, secrets, and license issues before workloads are shipped.
Optimized for
Where it shines.
CI pipelines and registries that need fast, broad scanning across container and infrastructure artifacts.
Use with care
Where not to use it.
Do not treat scanner output as a complete threat model; prioritize findings and keep vulnerability databases current.
Components
What it is made of.
- Image scanner
- Filesystem scanner
- Config scanner
- Secret scanner
- CI integrations
Process
How it works.
- An artifact or repository is scanned
- Findings are matched against vulnerability and policy data
- Results are prioritized
- The pipeline reports or blocks the release