Trivy is the most popular open-source vulnerability scanner for containers. It scans images, filesystems, Git repos, and Kubernetes clusters for CVEs, misconfigurations, and exposed secrets in a single tool.
Quick Start
# Install
brew install trivy
# Scan a container image
trivy image nginx:latest
# Output
nginx:latest (debian 12.4)
Total: 142 (UNKNOWN: 0, LOW: 89, MEDIUM: 41, HIGH: 10, CRITICAL: 2)
āāāāāāāāāāāāāāāā¬āāāāāāāāāāāāāāāāā¬āāāāāāāāāāā¬āāāāāāāāāāāāā
ā Library ā Vulnerability ā Severity ā Status ā
āāāāāāāāāāāāāāāā¼āāāāāāāāāāāāāāāāā¼āāāāāāāāāāā¼āāāāāāāāāāāāā¤
ā libssl3 ā CVE-2024-XXXX ā CRITICAL ā fix: 3.0.14ā
ā libcurl4 ā CVE-2024-YYYY ā HIGH ā fix: 8.5.0 ā
āāāāāāāāāāāāāāāā“āāāāāāāāāāāāāāāāā“āāāāāāāāāāā“āāāāāāāāāāāāāScan Types
Container Images
# Scan with severity filter
trivy image --severity HIGH,CRITICAL myorg/app:v1.2.3
# Scan and fail CI if critical vulnerabilities found
trivy image --exit-code 1 --severity CRITICAL myorg/app:v1.2.3
# Scan with SBOM output
trivy image --format spdx-json -o sbom.json myorg/app:v1.2.3Filesystem and Code
# Scan project dependencies
trivy fs --scanners vuln .
# Scan for exposed secrets
trivy fs --scanners secret .
# Scan IaC files (Terraform, CloudFormation, Kubernetes)
trivy config ./terraform/Kubernetes Cluster
# Scan running cluster
trivy k8s --report summary cluster
# Scan specific namespace
trivy k8s -n production --report allMaster this topic with hands-on labs
Go beyond reading ā build real projects in sandboxed environments with expert video guidance.
Browse Courses āCI/CD Integration
GitHub Actions
jobs:
security-scan:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Build image
run: docker build -t myorg/app:${{ github.sha }} .
- name: Trivy vulnerability scan
uses: aquasecurity/trivy-action@master
with:
image-ref: myorg/app:${{ github.sha }}
format: sarif
output: trivy-results.sarif
severity: CRITICAL,HIGH
exit-code: 1
- name: Upload SARIF
uses: github/codeql-action/upload-sarif@v3
with:
sarif_file: trivy-results.sarifSARIF output integrates with GitHub's Security tab, showing vulnerabilities alongside your code.
GitLab CI
container_scanning:
stage: test
image:
name: aquasec/trivy:latest
entrypoint: [""]
script:
- trivy image --exit-code 1 --severity HIGH,CRITICAL
--format json -o trivy-report.json
$CI_REGISTRY_IMAGE:$CI_COMMIT_SHA
artifacts:
reports:
container_scanning: trivy-report.jsonIgnoring False Positives
Not every CVE is exploitable in your context:
# .trivyignore.yaml
vulnerabilities:
- id: CVE-2024-1234
statement: "Not exploitable ā feature not used"
expires: 2026-06-01
- id: CVE-2024-5678
statement: "Mitigated by network policy ā no external access"Document why each ignore exists and set expiration dates for review.
Get weekly IT automation tips
Docker, Ansible, Terraform, MLOps ā curated insights delivered to your inbox. No spam.
Subscribe Free āTrivy Operator for Kubernetes
Run continuous scanning inside your cluster:
helm install trivy-operator aquasecurity/trivy-operator \
--namespace trivy-system --create-namespaceThe operator creates VulnerabilityReport CRDs for every workload:
# View vulnerability reports
kubectl get vulnerabilityreports -A
# Check a specific workload
kubectl get vulnerabilityreport -n production \
-l trivy-operator.resource.name=order-api -o yamlIaC Scanning
Catch misconfigurations before deployment:
trivy config ./terraform/
Failures: 3 (HIGH: 2, CRITICAL: 1)
CRITICAL: S3 bucket has public access enabled
terraform/storage.tf:15-20
HIGH: Security group allows ingress from 0.0.0.0/0
terraform/networking.tf:8-14
HIGH: RDS instance not encrypted
terraform/database.tf:22-30Trivy checks Terraform, CloudFormation, Kubernetes manifests, Dockerfiles, and Helm charts against hundreds of built-in rules.
Comparison with Other Scanners
| Feature | Trivy | Grype | Snyk |
|---|---|---|---|
| Price | Free | Free | Freemium |
| Images | ā | ā | ā |
| IaC scanning | ā | ā | ā |
| Secret scanning | ā | ā | ā |
| K8s operator | ā | ā | ā |
| SBOM generation | ā | ā | ā |
| Speed | Fast | Fast | Slower |
Trivy's advantage is breadth ā one tool covers images, code, IaC, secrets, and live clusters.
---
Ready to go deeper? Master container security with hands-on courses at CopyPasteLearn.
Ready to learn by doing?
Stop reading tutorials ā start building. Expert video courses with hands-on labs in real sandboxed environments.
Related Articles
Snyk Developer Security Platform
Snyk finds and fixes vulnerabilities in code, dependencies, containers, and infrastructure as code. Learn how to integrate Snyk into your development workflow.
Falco Runtime Security Kubernetes
Falco detects runtime threats in Kubernetes using eBPF. Learn how to set up Falco for container security monitoring, write custom rules, and integrate.
Tekton Cloud Native CI/CD
Tekton runs CI/CD pipelines as Kubernetes custom resources. Learn how Tekton works, how to build pipelines with Tasks and Pipelines, and when to choose it.
Troubleshoot OpenClaw Gateway Errors
Fix OpenClaw gateway errors: 401 unauthorized, connection refused, origin not allowed, and WebSocket failures with resolution guides.
Troubleshoot SELinux AVC Denials
Learn to read SELinux AVC denial logs, use ausearch and sealert, and follow a systematic troubleshooting workflow for RHEL systems.
TypeScript Express Tutorial 2026
Build a production REST API with TypeScript and Express. Complete tutorial covering project setup, routing, middleware, and deployment.
Explore topics
Browse more articles on the topics covered here.