# Trivy

> Find vulnerabilities, misconfigurations and secrets

Scans containers, Kubernetes, code repos and clouds and generates SBOMs.

- Source: https://github.com/aquasecurity/trivy
- Homepage: https://trivy.dev
- License: Apache-2.0
- Language: Go
- Stars: 38227
- Forks: 726
- Contributors: 560
- Last commit: 2026-10-02
- Latest release: v0.75.0 (2026-10-01)
- Purpose: Security & identity
- Runs on: Docker / self-host, CLI
- For: Enterprise

## Worth score: 85/100

How much DigGitHub recommends it, from activity, adoption, docs, license and security signals.

- Popularity: 23/25
- Momentum: 10/20
- Maintenance: 25/25
- Community: 12/15
- Readiness: 15/15

## Alternatives

- [Shannon](https://diggithub.com/KeygraphHQ/shannon.md): AI pentester for your web apps and APIs
- [Gitleaks](https://diggithub.com/gitleaks/gitleaks.md): Find secrets in code
- [RustScan](https://diggithub.com/bee-san/RustScan.md): Modern, fast port scanner
- [Cilium](https://diggithub.com/cilium/cilium.md): eBPF-based networking and security
- [Codex Security](https://diggithub.com/openai/codex-security.md): OpenAI's security scanning CLI and SDK
- [Web Check](https://diggithub.com/lissy93/web-check.md): All-in-one website analysis
- [SafeLine](https://diggithub.com/chaitin/SafeLine.md): Self-hosted web application firewall and reverse proxy
- [Authelia](https://diggithub.com/authelia/authelia.md): Single sign-on and 2FA portal

---

Source page: https://diggithub.com/aquasecurity/trivy
Updated: 2026-10-05
