# Trivy

> Apache-2.0 all-in-one vuln/IaC/secret/SBOM scanner; no paid tier

**Category:** DevOps  
**Pricing:** open-source  
**URL:** https://trivy.dev  
**GitHub:** https://github.com/aquasecurity/trivy  
**Added:** 2026-09-04

---

## The Hook

Trivy is the single binary that scans images, repos, IaC, and K8s when stitching four scanners is the tax.

## What's Good

Apache-2.0. CVE vuln scan, misconfig, secrets, licenses, SBOM. Targets: containers, filesystems, git, Terraform/CloudFormation/Dockerfiles, Kubernetes. Default scanner in GitLab/Harbor/Artifact Hub. No feature gate on the CLI.

## The Catch

CLI/CI scanner — not Aqua Platform management UI/RBAC/policy SaaS. Vs Grype/Snyk: Aqua OSS default with broad target surface; Aqua Inc monetizes a separate commercial platform. You still triage and patch.

## Verdict

Apache-2.0 security scanner. Fully free CLI; Aqua Platform is the paid cousin.
