Trivy Security Scanner for Containers and IaC
Trivy is Aqua Security’s scanner for vulnerabilities, misconfigurations, secrets, SBOMs, and license issues. It fits security review, container hygiene, and infrastructure-as-code checks in one CLI.
Prerequisites
Docker, Kubernetes, Git, or a local filesystem target depending on scan mode
Installation
Requirements and caveats from upstream:
- ![Docker Pulls][docker-pulls]
- docker run aquasec/trivy
- There are canary builds (Docker Hub, GitHub, [ECR](https://gallery.ec...
Basic usage or getting-started notes:
Get Trivy
Trivy is available in most common distribution channels. The full list of installation options is available in the [Installation] page. Here are a few popular examples:
brew install trivy
Extracted from upstream docs: https://raw.githubusercontent.com/aquasecurity/trivy/HEAD/README.md