Security and privacy · Edition No. 42 · 6 Oct 2026

aquasecurity/trivy

Lists the known security holes in a project's parts and in packaged programs.

← Security and privacyRead the whole edition →

38,100 stars · Apache-2.0 · v0.75.0 (2026-10-01) · Track this in Scout

Lists the known security holes in a project's parts and in packaged programs.

▶Repo detailsthe review · specs · pros & cons · install

What it is

Trivy is a single command-line program that scans container images, ordinary folders, code repositories and infrastructure settings files. It compares what it finds against public databases of reported security problems.

What it is good for. Anyone who ships software without a security team to check it, and anyone running programs somebody else packaged. Running it on a folder that already exists, before touching anything, is a ten-minute answer to "is there anything badly wrong in here".

Stars38,100
LicenceApache-2.0
Latestv0.75.0 (2026-10-01)
Good
  • It is read-only, so there is no risk in trying it, and the first useful answer arrives in one command.
  • It covers more than one kind of problem: known holes in code libraries, mistakes in settings files, and passwords left in the files by accident.
  • Apache licence 2.0 (a permissive licence that also grants patent rights), read from the file at main/LICENSE and plain and unmodified, with no commercial carve-out.
Watch for
  • The copyright holder in the licence file was never filled in. The line reads exactly Copyright [yyyy] [name of copyright owner] — the template Apache ships, left as it came. The licence terms themselves are standard; nobody is named as owning the work.
  • Output is a long wall of terminal text, with no interface. It tells you a problem exists and leaves the judgement about what matters to you.
  • The documented way to scan container images mounts /var/run/docker.sock into the scanner, which gives that container root-level control over the whole machine. It is one copied line and it is easy to run without understanding what was granted.
Similar repositories
Install
# Debian or Ubuntu. Needs: sudo, and an internet connection for the first scan.
sudo apt-get install -y wget gnupg
wget -qO - https://aquasecurity.github.io/trivy-repo/deb/public.key \
  | gpg --dearmor | sudo tee /usr/share/keyrings/trivy.gpg > /dev/null
echo "deb [signed-by=/usr/share/keyrings/trivy.gpg] https://aquasecurity.github.io/trivy-repo/deb generic main" \
  | sudo tee -a /etc/apt/sources.list.d/trivy.list
sudo apt-get update
sudo apt-get install -y trivy
# Scan a folder that already exists:
trivy fs .
Screenshots
aquasecurity/trivy: GitHub preview cardaquasecurity/trivy: Screenshot 1

Get the next edition in your inbox

A dozen repositories, opened and checked. The licence read, the last release dated, and the ones that did not make it named with the reason. It is the half most lists leave out.

No tracking pixels. One click to leave. The archive stays free either way.

We use your address to send the edition and nothing else. Confirm by email, leave in one click. How we handle it.