{"data":{"slug":"trivy","name":"Trivy","tagline":"Apache-2.0 all-in-one vuln/IaC/secret/SBOM scanner; no paid tier","category":"devops","categoryName":"DevOps","url":"https://trivy.dev","github":"https://github.com/aquasecurity/trivy","pricing":"open-source","hook":"Trivy is the single binary that scans images, repos, IaC, and K8s when stitching four scanners is the tax.","whatsGood":"Apache-2.0. CVE vuln scan, misconfig, secrets, licenses, SBOM. Targets: containers, filesystems, git, Terraform/CloudFormation/Dockerfiles, Kubernetes. Default scanner in GitLab/Harbor/Artifact Hub. No feature gate on the CLI.","theCatch":"CLI/CI scanner — not Aqua Platform management UI/RBAC/policy SaaS. Vs Grype/Snyk: Aqua OSS default with broad target surface; Aqua Inc monetizes a separate commercial platform. You still triage and patch.","verdict":"Apache-2.0 security scanner. Fully free CLI; Aqua Platform is the paid cousin.","addedAt":"2026-09-04","featured":false,"domain":"DevOps","subSpecialty":"Security","capabilities":["vuln","iac","sbom"],"surfaces":["Self-host"],"ecosystem":["Multi-platform","Go"],"licenseModel":"Apache-2.0","githubStars":37778},"related":[{"slug":"github-actions","name":"GitHub Actions","tagline":"CI/CD that lives where your code does"},{"slug":"docker","name":"Docker","tagline":"Container runtime that changed deployment"},{"slug":"kubernetes","name":"Kubernetes","tagline":"Container orchestration at scale"},{"slug":"terraform","name":"Terraform","tagline":"Infrastructure as code that actually works"},{"slug":"pulumi","name":"Pulumi","tagline":"Infrastructure as code in real languages"}],"links":{"self":"/api/gems/trivy","html":"/gems/trivy","markdown":"/gems/trivy.md","category":"/api/gems?category=devops","categoryPage":"/stacks/devops"}}