38,100 stars · Apache-2.0 · v0.75.0 (2026-10-01) · Track this in Scout
Lists the known security holes in a project's parts and in packaged programs.
▶Repo detailsthe review · specs · pros & cons · install
What it is
Trivy is a single command-line program that scans container images, ordinary folders, code repositories and infrastructure settings files. It compares what it finds against public databases of reported security problems.
What it is good for. Anyone who ships software without a security team to check it, and anyone running programs somebody else packaged. Running it on a folder that already exists, before touching anything, is a ten-minute answer to "is there anything badly wrong in here".
- It is read-only, so there is no risk in trying it, and the first useful answer arrives in one command.
- It covers more than one kind of problem: known holes in code libraries, mistakes in settings files, and passwords left in the files by accident.
- Apache licence 2.0 (a permissive licence that also grants patent rights), read from the file at
main/LICENSEand plain and unmodified, with no commercial carve-out.
- The copyright holder in the licence file was never filled in. The line reads exactly
Copyright [yyyy] [name of copyright owner]— the template Apache ships, left as it came. The licence terms themselves are standard; nobody is named as owning the work. - Output is a long wall of terminal text, with no interface. It tells you a problem exists and leaves the judgement about what matters to you.
- The documented way to scan container images mounts
/var/run/docker.sockinto the scanner, which gives that container root-level control over the whole machine. It is one copied line and it is easy to run without understanding what was granted.
anchore/grypeFinds the same known holes in images and file listings, covered in Edition 39, but with no settings-file or password checking.
Track this in Scout- quay/clair
Analyses container images for the same problems, but as a service you run and feed images into rather than a single command.
Track this in Scout - future-architect/vuls
Finds known holes in installed software, but scans whole machines over a remote login rather than images, and is GPL-3.0.
Track this in Scout
# Debian or Ubuntu. Needs: sudo, and an internet connection for the first scan. sudo apt-get install -y wget gnupg wget -qO - https://aquasecurity.github.io/trivy-repo/deb/public.key \ | gpg --dearmor | sudo tee /usr/share/keyrings/trivy.gpg > /dev/null echo "deb [signed-by=/usr/share/keyrings/trivy.gpg] https://aquasecurity.github.io/trivy-repo/deb generic main" \ | sudo tee -a /etc/apt/sources.list.d/trivy.list sudo apt-get update sudo apt-get install -y trivy # Scan a folder that already exists: trivy fs .

