Trivy

The All-in-One Security Scanner

Also known as
trivy

What is Trivy?

Open-source security scanner that finds vulnerabilities (CVE) and misconfigurations (IaC) across code repositories, binary artifacts, container images, and Kubernetes clusters.

Independently observed

Trivy pricing

We don't have Trivy's full plan breakdown yet (its pricing page resisted automated reading). Here's what we could confirm. Always check live pricing for exact numbers.

What Trivy does

The capabilities that matter for devsecops tools, normalised so it lines up with every alternative. “-” means we haven't confirmed it, not that it's missing.

Scan types
SAST (static analysis)
-
DAST (dynamic analysis)
-
SCA / dependency scanning
Secret scanning
Container / image scanning
IaC misconfiguration scanning
Governance
OSS licence compliance
SBOM generation (SPDX/CycloneDX)
Remediation
Automated fix / upgrade PRs
-
Prioritisation
Reachability / exploitability prioritisation
-
Deployment
Hosting
Cloud + self-hosted
Integration
First-class CI / pipeline integration
In-editor / IDE scanning
-
Licensing
OSS engine available
Independently observed

Platform & deployment

Independently observed
Platforms
  • CLI
Deployment
  • Cloud / SaaS
  • Self-hosted

Integrations (10)

Independently observed
  • GitHub Actions
  • GitLab CI
  • AWS CodePipeline
  • CircleCI
  • Travis CI
  • Bitbucket Pipelines
  • AWS Security Hub
  • Azure Container Registry
  • Google Artifact Registry
  • AWS ECR

Trivy alternatives

Other devsecops tools we track, ranked by the same independent score.

Independent · unbought · dated

The Vioscale score: one lens on the evidence

Not user reviews and not a paid placement: a confidence-weighted blend of the independent signals below (adoption, activity, security posture, and more), which you can sort and re-weight yourself. Vendors can correct their listing but can never move their rank, and stars are weighted low as a vanity metric. It is one way to read the evidence for Trivy, not the verdict.

Balanced composite 64 / 100
low · 18%
Signal contributions to the composite score
SignalScoreWeightContributionEvidence
Capabilities9212.001099.6
Release Cadence9310.00927.8
Github Activity4418.00792.2
Github Stars865.00431.1
Integrations3312.00395.5
Security Posture040.000.0-
Package Downloads026.000.0-
Stackoverflow Activity012.000.0-

Computed . Re-weight it by intent, or see the full method.

All data & sourcesshow ↓

Every value we hold, with its source, retrieval date, and confidence. This is the evidence behind the score: don't trust it, verify it.

Activity

AttributeValueEvidence
Commits last 30d24mediumsource · 2026-08-01 · 65%

Adoption

AttributeValueEvidence
Github stars37,187highsource · 2026-08-01 · 90%

Features

AttributeValueEvidence
Capabilities{"sca":true,"sbom":true,"hosting":"both","ci_native":true,"open_source":true,"iac_scanning":true,"secret_scanning":true,"container_scanning":true,"license_compliance":true}mediumsource · 2026-08-01 · 60%

Integrations

AttributeValueEvidence
Count13mediumsource · 2026-08-01 · 60%

Language

AttributeValueEvidence
PrimaryGohighsource · 2026-08-01 · 90%

License

AttributeValueEvidence
SpdxApache-2.0highsource · 2026-08-01 · 95%

Pricing

AttributeValueEvidence
Modelopen_sourcemediumsource · 2026-08-01 · 60%
Free tierYesmediumsource · 2026-08-01 · 60%
Price levelfreemediumsource · 2026-08-01 · 60%

Release

AttributeValueEvidence
Cadence days13mediumsource · 2026-08-01 · 70%