Team-operated artifact scanning
Trivy OSS
Model CI and registry compute, database mirrors and updates, caching, policies, suppressions, reporting, support, upgrades, triage, and remediation.12
Open-source artifact scanning
An open-source scanner for supported container images, filesystems, repositories, virtual-machine images, Kubernetes targets, packages, IaC, secrets, and licenses.
Choose Trivy when open-source local and CI artifact scanning fits the target matrix and the team can own databases, configuration, policy, false positives, triage, upgrades, and remediation.12
Whether the team should operate Trivy in local and CI workflows for the exact artifacts and finding types it supports.
Trivy scans configured targets and finding classes; it is not complete SAST, runtime protection, a managed remediation program, or proof that an artifact or application is secure.12
For: Platform, DevOps, and application-security teams wanting an open-source artifact scanner they can run and govern
Trivy is open-source software with no separate software license fee; total cost is CI compute, caching, database updates, storage, policy, triage, support, upgrades, and remediation engineering.12
Team-operated artifact scanning
Model CI and registry compute, database mirrors and updates, caching, policies, suppressions, reporting, support, upgrades, triage, and remediation.12
Aqua Security · Accessed Official
Aqua Security · Accessed Official
Aqua Security · Accessed Official
Snyk · Accessed Official
Snyk · Accessed Official
GitHub · Accessed Official
GitHub · Accessed Official
Semgrep · Accessed Official
Semgrep · Accessed Official