# Trivy

> The All-in-One Security Scanner

- **Canonical URI:** https://www.vioscale.ai/software/trivy
- **Category:** DevSecOps Tools
- **Homepage:** https://trivy.dev
- **Also known as:** trivy
- **Profile claimed by vendor:** no
- **Last updated:** 2026-08-01T16:09:43.918Z

## Vioscale score

**64 / 100**, confidence 18% (low).

Composite of weighted, independently-sourced signals (no user reviews, no vendor payment).

| Signal | Score | Weight | Contribution | Evidence present |
|---|--:|--:|--:|:--:|
| capabilities | 91.6 | 12 | 1099.6 | ✓ |
| github_stars | 86.2 | 5 | 431.1 | ✓ |
| integrations | 33 | 12 | 395.5 | ✓ |
| github_activity | 44 | 18 | 792.2 | ✓ |
| release_cadence | 92.8 | 10 | 927.8 | ✓ |
| security_posture | 0 | 40 | 0 | - |
| package_downloads | 0 | 26 | 0 | - |
| stackoverflow_activity | 0 | 12 | 0 | - |

## Pricing

_As of 2026-08-01, [verify at source](https://trivy.dev). Independently observed._

Open source · Free tier

## About

Open-source security scanner that finds vulnerabilities (CVE) and misconfigurations (IaC) across code repositories, binary artifacts, container images, and Kubernetes clusters.

_Independently observed._

## Platform & deployment

- **Platforms:** CLI
- **Deployment:** Cloud / SaaS, Self-hosted

## Integrations (10)

_Independently observed._

- GitHub Actions
- GitLab CI
- AWS CodePipeline
- CircleCI
- Travis CI
- Bitbucket Pipelines
- AWS Security Hub
- Azure Container Registry
- Google Artifact Registry
- AWS ECR

## Capabilities

_The capabilities that matter for DevSecOps Tools. "-" = undocumented, not absent._

| Capability | Supported |
|---|:--:|
| **Scan types** | |
| SAST (static analysis) | - |
| DAST (dynamic analysis) | - |
| SCA / dependency scanning | ✓ |
| Secret scanning | ✓ |
| Container / image scanning | ✓ |
| IaC misconfiguration scanning | ✓ |
| **Governance** | |
| OSS licence compliance | ✓ |
| SBOM generation (SPDX/CycloneDX) | ✓ |
| **Remediation** | |
| Automated fix / upgrade PRs | - |
| **Prioritisation** | |
| Reachability / exploitability prioritisation | - |
| **Deployment** | |
| Hosting | Cloud + self-hosted |
| **Integration** | |
| First-class CI / pipeline integration | ✓ |
| In-editor / IDE scanning | - |
| **Licensing** | |
| OSS engine available | ✓ |

## Facts

Every value below carries its source and our confidence. Facts are re-crawled on a freshness schedule.

### language

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| language.primary | Go | [link](https://github.com/aquasecurity/trivy) | 2026-08-01 | 90% (high) |

### license

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| license.spdx | Apache-2.0 | [link](https://github.com/aquasecurity/trivy) | 2026-08-01 | 95% (high) |

### pricing

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| pricing.model | open_source | [link](https://trivy.dev) | 2026-08-01 | 60% (medium) |
| pricing.free_tier | yes | [link](https://trivy.dev) | 2026-08-01 | 60% (medium) |
| pricing.price_level | free | [link](https://trivy.dev) | 2026-08-01 | 60% (medium) |

### release

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| release.cadence_days | 13 | [link](https://github.com/aquasecurity/trivy/releases) | 2026-08-01 | 70% (medium) |

### activity

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| activity.commits_last_30d | 24 | [link](https://github.com/aquasecurity/trivy/pulse) | 2026-08-01 | 65% (medium) |

### adoption

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| adoption.github_stars | 37,187 | [link](https://github.com/aquasecurity/trivy) | 2026-08-01 | 90% (high) |

### integrations

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| integrations.count | 13 | [link](https://trivy.dev) | 2026-08-01 | 60% (medium) |

---
*Source: Vioscale (https://www.vioscale.ai/software/trivy). Independent, evidence-based software intelligence. Cite the canonical URI.*
