Skip to content

Trivy

Scanner for containers, filesystems, repos and cloud config

VerifiedCloud / DevSecOps· Containers & Supply ChainBeginnerApache-2.0Open sourceEntry revised 1 Jan 2026
  • Linux
  • macOS
  • Windows
  • Docker
  • Source

Overview

5 commands documented

Trivy reads an image or a directory and reports vulnerabilities, exposed secrets, misconfigurations and license issues in one pass, with SBOM output for supply-chain records. It is designed to run in CI with a fixed exit code, which is how it becomes a control rather than a report.

It is also the rare security tool with an explicitly readable codebase and a single binary, which makes it a good first scanner to add to a pipeline you own.

Supported platforms

5

Documented install or usage guidance

Learning curve

beginner

Difficulty of becoming productive, not of the underlying theory

Tags

sbom, supply chain, vulnerabilities, secrets, ci

Dataset entry

trivy.ts

Reviewed 2026-01-01

Installation

Grouped by platform. Elevation requirements are marked per method.

Homebrew

RecommendedHomebrew
brew install trivy

Package availability follows your distribution and enabled repositories. Entry revised 1 Jan 2026 — confirm the current release on the project's own download page.

Commands

5 entries

Every command carries its purpose, an example where useful, and the limitations that change how you should read the output.

01Scan an image

bash

Vulnerability scan with a severity threshold; exits non-zero on findings when asked.

trivy image --severity HIGH,CRITICAL --ignore-unfixed nginx:1.27

Notes

  • `--ignore-unfixed` removes findings you cannot act on today, which is what makes a gate tolerable.

02Scan a repository for secrets and dependencies

bash

Filesystem mode covers lockfiles, embedded secrets and IaC misconfiguration in one pass.

trivy fs --scanners vuln,secret,misconfig .

Notes

  • Secret findings are reported with the file and a redacted value; verify them before treating a hit as a leak.

03Fail a build on new issues

bash

The exit-code flag is what turns a scanner into a control.

trivy image --exit-code 1 --severity CRITICAL --ignorefile .trivyignore myapp:ci

Notes

  • Every entry in `.trivyignore` needs a reason and a review date, or it becomes an untracked risk acceptance.

04Produce an SBOM

bash

Emits a CycloneDX or SPDX document for provenance records and procurement questions.

trivy sbom ./sbom.cdx.json && trivy image --format cyclonedx --output sbom.cdx.json myapp:1.4

05Scan a cluster

bash

Mode that inspects workloads for misconfiguration and exposed secrets using read-only access.

trivy k8s --report all cluster
  • Needs a kubeconfig with get/list permissions only. Never grant a scanner write access.

What it is used for

  • Pipeline gate

    Block a release on fixable critical vulnerabilities.

  • Registry hygiene

    Scheduled scans of what is actually deployed.

  • Supply-chain records

    SBOMs attached to each build artifact.

Common errors

Symptoms you will actually hit, with the cause and the legitimate fix.

DB update fails behind a proxy or in CI without egressCause 1/3

Possible causes

  • Trivy downloads its vulnerability database on first run.

Usual fix

Cache the DB (`--download-db-only`, an artifact cache, or a mirror), or use `--skip-db-update` in an image that ships one.

Thousands of findings on a base imageCause 2/3

Possible causes

  • Scanning every severity of an old distroless/base layer.

Usual fix

Update the base image first, then gate on `CRITICAL` with `--ignore-unfixed`; the count is a maintenance story, not a report.

'no such image' inside a Docker-in-Docker runnerCause 3/3

Possible causes

  • The daemon socket is not mounted into the job.

Usual fix

Mount `/var/run/docker.sock` read-only into the step, or scan the tarball export instead of the daemon.

Tips

  • Add `--security-checks vuln,secret,config` explicitly so a future default change cannot silently disable a check.
  • Publish the JSON output as a build artifact; a gate that produces no record cannot be audited later.
  • Fix base images, not findings: most of the list disappears at the Dockerfile layer.

Alternatives & comparisons

Not documented yet: grype, snyk. Request an entry and it will link up automatically.Request a tool

Side-by-side

References

Where to verify anything on this page. External links open in a new tab.

Found something wrong?Suggest an editMore in Cloud / DevSecOps

Looking for alternatives?

Checkov cover adjacent parts of the same job.

Compare side by side