Available worldwide

What is Trivy?

A free, open-source tool that scans code repositories, container images, binary artifacts, and Kubernetes clusters to identify vulnerabilities, misconfigurations, secrets, and license compliance issues. Designed for cloud-native environments and integrates into CI/CD pipelines.

Independently observed

Trivy pricing

We don't have Trivy's full plan breakdown yet (its pricing page resisted automated reading). Here's what we could confirm. Always check live pricing for exact numbers.

What Trivy does

The capabilities that matter for devsecops tools, normalised so it lines up with every alternative. “-” means we haven't confirmed it, not that it's missing.

Scan types
SAST (static analysis)
DAST (dynamic analysis)
-
SCA / dependency scanning
Secret scanning
Container / image scanning
IaC misconfiguration scanning
Governance
OSS licence compliance
SBOM generation (SPDX/CycloneDX)
-
Remediation
Automated fix / upgrade PRs
-
Prioritisation
Reachability / exploitability prioritisation
-
Deployment
Hosting
Self-hosted only
Integration
First-class CI / pipeline integration
In-editor / IDE scanning
-
Licensing
OSS engine available
Independently observed

Platform & deployment

Independently observed
Platforms
  • CLI
Deployment
  • Self-hosted

Integrations (7)

Independently observed
  • Docker
  • GitHub
  • GitLab
  • Azure Container Registry
  • Kubernetes
  • Harbor
  • CloudNativePG

Security & compliance

Known vulnerabilities: 5 (4 in the last 12 months), max severity CRITICAL sourcea count reflects scale & disclosure, not quality

Trivy FAQ

Common questions about Trivy, answered from independent, dated evidence.

What is Trivy?

A free, open-source tool that scans code repositories, container images, binary artifacts, and Kubernetes clusters to identify vulnerabilities, misconfigurations, secrets, and license compliance issues. Designed for cloud-native environments and integrates into CI/CD pipelines. It is indexed under DevSecOps Tools.

Source: https://trivy.dev

Is Trivy free to use?

Trivy is open source, so it can be self-hosted and used at no licence cost. It is released under the Apache-2.0 licence. Pricing changes often, so verify at source before relying on it.

Source: https://trivy.dev

What platforms does Trivy support?

Trivy supports a command-line interface. Platforms we have not confirmed are simply not listed here rather than ruled out.

Source: https://trivy.dev

Can Trivy be self-hosted?

Yes. Trivy can be deployed self-hosted, so it does not have to run on the vendor's infrastructure.

Source: https://trivy.dev

What does Trivy integrate with?

We have confirmed 7 integrations for Trivy, including Docker, GitHub, GitLab, Azure Container Registry, Kubernetes, Harbor and CloudNativePG. This is what we could verify from public sources, so the vendor may support others we have not indexed.

Source: https://trivy.dev

Is Trivy open source?

Yes. Trivy is published under the Apache-2.0 licence, a permissive licence that generally allows commercial use and modification. Licence terms can change between releases, so verify against the repository for the version you intend to use.

Source: https://github.com/aquasecurity/trivy

Trivy alternatives

Other devsecops tools we track, ranked by the same independent score.

All Trivy alternatives, ranked →

Compare Trivy

Side by side against other devsecops tools, attribute by attribute, with a source on every value.

Independent · unbought · dated

The vioscaleAI score: one lens on the evidence

Not user reviews and not a paid placement: a confidence-weighted blend of the independent signals below (adoption, activity, security posture, and more), which you can sort and re-weight yourself. Vendors can correct their listing but can never move their rank, and stars are weighted low as a vanity metric. It is one way to read the evidence for Trivy, not the verdict.

Balanced composite 57 / 100
low · 41%
Signal contributions to the composite score
SignalScoreWeightContributionEvidence
Capabilities920.065.8
Release cadence970.055.1
Development activity530.095.0
Security score640.042.7
Stars860.032.2
Dependent projects360.062.2
Integrations260.061.6
Security posture00.210.0-
Package downloads00.140.0-
Developer Q&A activity00.060.0-

Computed . Re-weight it by intent, or see the full method.

All data & sourcesshow ↓

Every value we hold, with its source, retrieval date, and confidence. This is the evidence behind the score: don't trust it, verify it.

Activity

AttributeValueEvidence
Commits last 30d47mediumsource · 2026-09-11 · 65%

Adoption

AttributeValueEvidence
Github stars37,872highsource · 2026-09-11 · 90%
Dependent repos134highsource · 2026-09-11 · 85%

Content

AttributeValueEvidence
Faq6 itemsmediumsource · 2026-09-10 · 66%

Features

AttributeValueEvidence
CapabilitiesSca: Yes · Sast: Yes · Hosting: self · Ci native: Yes · Open source: Yes · Iac scanning: Yesmediumsource · 2026-08-14 · 60%

Integrations

AttributeValueEvidence
Count7mediumsource · 2026-08-14 · 60%

Language

AttributeValueEvidence
PrimaryGohighsource · 2026-09-11 · 90%

License

AttributeValueEvidence
SpdxApache-2.0highsource · 2026-09-11 · 95%

Market

AttributeValueEvidence
AvailabilityPrimaryMarkets: … · AvailabilityScope: global · AvailableCountries: … · NotAvailableCountries: …highsource · 2026-08-14 · 75%

Pricing

AttributeValueEvidence
Modelopen_sourcemediumsource · 2026-08-14 · 60%
Price levelfreemediumsource · 2026-08-14 · 60%
Free tierYesmediumsource · 2026-08-14 · 60%
TransparentYesmediumsource · 2026-08-14 · 60%

Release

AttributeValueEvidence
Cadence days5mediumsource · 2026-09-11 · 70%
History20 itemsmediumsource · 2026-09-11 · 70%

Security

AttributeValueEvidence
Scorecard6.4highsource · 2026-09-11 · 90%
VulnerabilitiesCount: 5 · Source: https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=go&package_name=github.com%2Faquasecurity%2Ftrivy&per_page=100 · Last 12m: 4 · Max severity: CRITICALhighsource · 2026-09-11 · 90%
Still deciding?

Is Trivy the right choice for you?

Tell us the job, the constraints and what you weigh most, and we will rank Trivy against the rest of the devsecops tools we index, using the same dated evidence weighted your way.

Free to run, no account needed to start. How the evaluation works

For the makers of Trivy

Is this your product?

This profile was built from public sources without asking you. You can take the badge below and use it anywhere, and you can claim the profile to correct anything we got wrong. Both are free, and neither moves Trivy up or down: nobody can buy rank here, including you.

Take the badge

Live, always current, and free to use on your own site. It shows Trivy's independent score and links back to this profile.

Trivy, verified on vioscaleAI
HTML
<a href="https://www.vioscale.ai/software/trivy" target="_blank" rel="noopener">
  <img src="https://www.vioscale.ai/badge/software/trivy.svg" alt="Trivy, verified on vioscaleAI" width="330" height="76" loading="lazy" />
</a>
Markdown, for a README →
Markdown
[![Trivy, verified on vioscaleAI](https://www.vioscale.ai/badge/software/trivy.svg)](https://www.vioscale.ai/software/trivy)

Claim the profile

Verify you control the domain and you can correct the facts, add the sources we should be reading, and see how AI assistants are describing Trivy. Free, and it does not change the score.

  • Correct anything wrong, with evidence
  • Point our crawler at the pages that matter
  • See which AI systems are reading this profile
Claim Trivy

Not the owner? How vendor profiles work