← DevOps tools
Security Scanning

Trivy

An open-source security scanner for container images, filesystems, Git repositories, Kubernetes configurations, and infrastructure code.

Why it exists.

It finds known vulnerabilities, misconfigurations, secrets, and license issues before workloads are shipped.

Where it shines.

CI pipelines and registries that need fast, broad scanning across container and infrastructure artifacts.

Where not to use it.

Do not treat scanner output as a complete threat model; prioritize findings and keep vulnerability databases current.

What it is made of.

  • Image scanner
  • Filesystem scanner
  • Config scanner
  • Secret scanner
  • CI integrations

How it works.

  1. An artifact or repository is scanned
  2. Findings are matched against vulnerability and policy data
  3. Results are prioritized
  4. The pipeline reports or blocks the release
Questions and answers.Open the interview practice set for Trivy.
Search