{"request_id":"req_01M45X2STTYSGAV8MF4YXXW1XW","technology":{"canonical_id":"tech_000000000000009YBMQKPCDG03","parent_canonical_id":"","parent_id_zoho":"","name":"Trivy","slug":"trivy","requires_context":false,"popularity":null,"description":"Security scanner for vulnerabilities, configuration errors, secrets and software inventories in development and deployment artifacts.","explanation":"Trivy inspects supported container images, filesystems, repositories, virtual-machine images and Kubernetes targets. Its scanners cover known vulnerabilities, infrastructure misconfigurations, exposed secrets, licenses and software-bill-of-materials data. Coverage depends on the selected scanner and target. This record describes the Trivy project; Aqua’s commercial security product has a separate scope.","official_website_url":"https://trivy.dev/","official_documentation_url":"https://trivy.dev/docs/latest/guide/","source_repository_url":"https://github.com/aquasecurity/trivy","use_cases":[{"statement":"Check application dependencies and OS packages for known vulnerabilities.","evidence_urls":["https://trivy.dev/docs/latest/guide/scanner/vulnerability/"]},{"statement":"Inspect infrastructure configuration and secrets before deployment.","evidence_urls":["https://github.com/aquasecurity/trivy"]},{"statement":"Produce software inventories and SBOM data for artifact review.","evidence_urls":["https://github.com/aquasecurity/trivy"]}],"strengths":[{"statement":"A single executable performs static checks without starting scanned container or VM images; scanning images stored in a container runtime still requires access to that runtime.","evidence_urls":["https://trivy.dev/docs/latest/community/principles/"]},{"statement":"OS-vendor advisories account for distribution-specific backported fixes.","evidence_urls":["https://trivy.dev/docs/latest/guide/scanner/vulnerability/"]}],"limitations":[{"statement":"Coverage depends on supported package formats and advisory sources; some third-party OS packages are skipped.","evidence_urls":["https://trivy.dev/docs/latest/guide/scanner/vulnerability/"]},{"statement":"Database and other external-resource downloads can encounter public-infrastructure rate limits; restricted networks require preparation.","evidence_urls":["https://trivy.dev/docs/latest/guide/advanced/air-gap/"]},{"statement":"Static analysis does not provide runtime protection or malware detection.","evidence_urls":["https://trivy.dev/docs/latest/community/principles/"]}],"pricing":{"access_model":"unknown","billing_models":[],"free_trial_availability":"unknown","evidence_urls":[]},"technology_license":{"name":"Apache License 2.0","scope":"Trivy project source code; does not assert terms for Aqua commercial services or all scanned dependencies.","spdx_id":"Apache-2.0","url":"https://raw.githubusercontent.com/aquasecurity/trivy/main/LICENSE","evidence_urls":["https://raw.githubusercontent.com/aquasecurity/trivy/main/LICENSE"]},"organizations":[{"name":"Aqua Security","role":"maintainer","evidence_urls":["https://trivy.dev/docs/latest/commercial/compare/"]}],"certifications":null,"deployment_options":[{"type":"self_hosted","scope":"Run the scanner binary or official container in user-controlled development or CI infrastructure.","evidence_urls":["https://www.trivy.dev/docs/latest/getting-started/installation/"]}],"lifecycle":"active","revision":1,"updated_at":"2026-10-04T17:19:30.595036Z","reviewed_at":"2026-10-04T17:19:30.595036Z","source_freshness_at":"2026-10-04T14:57:06Z","aliases":null,"category_ids":["cat_11MNQ7PJNS8D3T72QD5C0G1F6Y","cat_145M0N7ZW6M0TXSRVW454A2AJC"],"domain_ids":["dom_1D2B1EQWZC9G38JXH4C7REEMPK"],"classification_kind":"tool","sources":[{"url":"https://github.com/aquasecurity/trivy","type":"official","title":"Trivy source repository","claim":"Actual scanner source; target and scanner inventory, SBOM use and distinction from Aqua commercial offering.","retrieved_at":"2026-10-04T14:57:06Z"},{"url":"https://raw.githubusercontent.com/aquasecurity/trivy/main/LICENSE","type":"official","title":"Trivy LICENSE","claim":"Apache License 2.0 for project source.","retrieved_at":"2026-10-04T14:57:06Z"},{"url":"https://trivy.dev/","type":"official","title":"Trivy homepage","claim":"Project homepage and scanner purpose.","retrieved_at":"2026-10-04T14:57:06Z"},{"url":"https://trivy.dev/docs/latest/commercial/compare/","type":"official","title":"Trivy/Aqua comparison","claim":"Aqua Security maintains Trivy; commercial product has a distinct feature/support scope.","retrieved_at":"2026-10-04T14:57:06Z"},{"url":"https://trivy.dev/docs/latest/community/principles/","type":"official","title":"Trivy Project Principles","claim":"Single-binary static analysis; no runtime protection or intentional-attack detection.","retrieved_at":"2026-10-04T14:57:06Z"},{"url":"https://trivy.dev/docs/latest/guide/","type":"official","title":"Trivy User Guide","claim":"Official documentation entry point and target/scanner navigation.","retrieved_at":"2026-10-04T14:57:06Z"},{"url":"https://trivy.dev/docs/latest/guide/advanced/air-gap/","type":"official","title":"Trivy network considerations","claim":"External resource requirements, offline preparation and public-infrastructure rate limits.","retrieved_at":"2026-10-04T14:57:06Z"},{"url":"https://trivy.dev/docs/latest/guide/scanner/vulnerability/","type":"official","title":"Trivy vulnerability scanning","claim":"OS/language package checking, vendor advisory selection and third-party package coverage limits.","retrieved_at":"2026-10-04T14:57:06Z"},{"url":"https://www.trivy.dev/docs/latest/getting-started/installation/","type":"official","title":"Installing Trivy","claim":"Official binary and container distribution support user-controlled deployment.","retrieved_at":"2026-10-04T14:57:06Z"}],"external_ids":[{"system":"beast","value":"358446000127787011"}],"provenance":"Published taxonomy release 2026.10.7"},"release_version":"2026.10.7"}
