Trivy
Apache-2.0 all-in-one vuln/IaC/secret/SBOM scanner; no paid tier
DevOps / Security · Apache-2.0 · 37.8k
What's Good
Apache-2.0. CVE vuln scan, misconfig, secrets, licenses, SBOM. Targets: containers, filesystems, git, Terraform/CloudFormation/Dockerfiles, Kubernetes. Default scanner in GitLab/Harbor/Artifact Hub. No feature gate on the CLI.
The Catch
CLI/CI scanner — not Aqua Platform management UI/RBAC/policy SaaS. Vs Grype/Snyk: Aqua OSS default with broad target surface; Aqua Inc monetizes a separate commercial platform. You still triage and patch.
Verdict
Apache-2.0 security scanner. Fully free CLI; Aqua Platform is the paid cousin.
Embed
[](https://stackgems.com/gems/trivy)