Skip to main content
šŸŽ¤ Luca Berton is speaking at Red Hat Summit & KubeCon EU 2026!Learn more →
Back to Blog

Trivy Container Vulnerability Scanner

Trivy scans container images, filesystems, and IaC for vulnerabilities and misconfigurations. Learn how to integrate Trivy into your CI/CD pipeline.

Luca BertonMarch 25, 20262 min read

Trivy is the most popular open-source vulnerability scanner for containers. It scans images, filesystems, Git repos, and Kubernetes clusters for CVEs, misconfigurations, and exposed secrets in a single tool.

Quick Start

bash
# Install
brew install trivy

# Scan a container image
trivy image nginx:latest

# Output
nginx:latest (debian 12.4)
Total: 142 (UNKNOWN: 0, LOW: 89, MEDIUM: 41, HIGH: 10, CRITICAL: 2)

ā”Œā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”¬ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”¬ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”¬ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”
│   Library    │ Vulnerability  │ Severity │   Status   │
ā”œā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”¼ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”¼ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”¼ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”¤
│ libssl3      │ CVE-2024-XXXX  │ CRITICAL │ fix: 3.0.14│
│ libcurl4     │ CVE-2024-YYYY  │ HIGH     │ fix: 8.5.0 │
ā””ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”“ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”“ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”“ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”˜

Scan Types

Container Images

bash
# Scan with severity filter
trivy image --severity HIGH,CRITICAL myorg/app:v1.2.3

# Scan and fail CI if critical vulnerabilities found
trivy image --exit-code 1 --severity CRITICAL myorg/app:v1.2.3

# Scan with SBOM output
trivy image --format spdx-json -o sbom.json myorg/app:v1.2.3

Filesystem and Code

bash
# Scan project dependencies
trivy fs --scanners vuln .

# Scan for exposed secrets
trivy fs --scanners secret .

# Scan IaC files (Terraform, CloudFormation, Kubernetes)
trivy config ./terraform/

Kubernetes Cluster

bash
# Scan running cluster
trivy k8s --report summary cluster

# Scan specific namespace
trivy k8s -n production --report all
Related Course

Master this topic with hands-on labs

Go beyond reading — build real projects in sandboxed environments with expert video guidance.

Browse Courses →

CI/CD Integration

GitHub Actions

yaml
jobs:
  security-scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4

      - name: Build image
        run: docker build -t myorg/app:${{ github.sha }} .

      - name: Trivy vulnerability scan
        uses: aquasecurity/trivy-action@master
        with:
          image-ref: myorg/app:${{ github.sha }}
          format: sarif
          output: trivy-results.sarif
          severity: CRITICAL,HIGH
          exit-code: 1

      - name: Upload SARIF
        uses: github/codeql-action/upload-sarif@v3
        with:
          sarif_file: trivy-results.sarif

SARIF output integrates with GitHub's Security tab, showing vulnerabilities alongside your code.

GitLab CI

yaml
container_scanning:
  stage: test
  image:
    name: aquasec/trivy:latest
    entrypoint: [""]
  script:
    - trivy image --exit-code 1 --severity HIGH,CRITICAL
        --format json -o trivy-report.json
        $CI_REGISTRY_IMAGE:$CI_COMMIT_SHA
  artifacts:
    reports:
      container_scanning: trivy-report.json

Ignoring False Positives

Not every CVE is exploitable in your context:

yaml
# .trivyignore.yaml
vulnerabilities:
  - id: CVE-2024-1234
    statement: "Not exploitable — feature not used"
    expires: 2026-06-01

  - id: CVE-2024-5678
    statement: "Mitigated by network policy — no external access"

Document why each ignore exists and set expiration dates for review.

Stay Updated

Get weekly IT automation tips

Docker, Ansible, Terraform, MLOps — curated insights delivered to your inbox. No spam.

Subscribe Free →

Trivy Operator for Kubernetes

Run continuous scanning inside your cluster:

bash
helm install trivy-operator aquasecurity/trivy-operator \
  --namespace trivy-system --create-namespace

The operator creates VulnerabilityReport CRDs for every workload:

bash
# View vulnerability reports
kubectl get vulnerabilityreports -A

# Check a specific workload
kubectl get vulnerabilityreport -n production \
  -l trivy-operator.resource.name=order-api -o yaml

IaC Scanning

Catch misconfigurations before deployment:

bash
trivy config ./terraform/

Failures: 3 (HIGH: 2, CRITICAL: 1)

CRITICAL: S3 bucket has public access enabled
  terraform/storage.tf:15-20

HIGH: Security group allows ingress from 0.0.0.0/0
  terraform/networking.tf:8-14

HIGH: RDS instance not encrypted
  terraform/database.tf:22-30

Trivy checks Terraform, CloudFormation, Kubernetes manifests, Dockerfiles, and Helm charts against hundreds of built-in rules.

Comparison with Other Scanners

FeatureTrivyGrypeSnyk
PriceFreeFreeFreemium
Imagesāœ“āœ“āœ“
IaC scanningāœ“āœ—āœ“
Secret scanningāœ“āœ—āœ“
K8s operatorāœ“āœ—āœ—
SBOM generationāœ“āœ“āœ“
SpeedFastFastSlower

Trivy's advantage is breadth — one tool covers images, code, IaC, secrets, and live clusters.

---

Ready to go deeper? Master container security with hands-on courses at CopyPasteLearn.

Ready to learn by doing?

Stop reading tutorials — start building. Expert video courses with hands-on labs in real sandboxed environments.

Share this article
LB
Luca Berton

Docker Captain, IT automation expert, Red Hat Summit & KubeCon speaker. Building hands-on education for DevOps engineers at CopyPasteLearn.

Related Articles

Explore topics

Browse more articles on the topics covered here.