Homebrew
RecommendedHomebrewbrew install trivy
Scanner for containers, filesystems, repos and cloud config
Trivy reads an image or a directory and reports vulnerabilities, exposed secrets, misconfigurations and license issues in one pass, with SBOM output for supply-chain records. It is designed to run in CI with a fixed exit code, which is how it becomes a control rather than a report.
It is also the rare security tool with an explicitly readable codebase and a single binary, which makes it a good first scanner to add to a pipeline you own.
Supported platforms
5
Documented install or usage guidance
Learning curve
beginner
Difficulty of becoming productive, not of the underlying theory
Tags
sbom, supply chain, vulnerabilities, secrets, ci
Dataset entry
trivy.ts
Reviewed 2026-01-01
Grouped by platform. Elevation requirements are marked per method.
brew install trivy
Needs elevated privileges (sudo / Administrator).
sudo apt install -y wget apt-transport-https gnupg lsb-release
wget -qO - https://aquasecurity.github.io/trivy-repo/deb/public.key | sudo apt-key add -
echo deb https://aquasecurity.github.io/trivy-repo/deb $(lsb_release -sc) main | sudo tee /etc/apt/sources.list.d/trivy.list
sudo apt update && sudo apt install trivy
sudo rpm -ivh https://github.com/aquasecurity/trivy/releases/latest/download/trivy_0.58.1_Linux-64bit.rpm
Package availability follows your distribution and enabled repositories. Entry revised 1 Jan 2026 — confirm the current release on the project's own download page.
Every command carries its purpose, an example where useful, and the limitations that change how you should read the output.
Vulnerability scan with a severity threshold; exits non-zero on findings when asked.
trivy image --severity HIGH,CRITICAL --ignore-unfixed nginx:1.27
Notes
Filesystem mode covers lockfiles, embedded secrets and IaC misconfiguration in one pass.
trivy fs --scanners vuln,secret,misconfig .
Notes
The exit-code flag is what turns a scanner into a control.
trivy image --exit-code 1 --severity CRITICAL --ignorefile .trivyignore myapp:ci
Notes
Emits a CycloneDX or SPDX document for provenance records and procurement questions.
trivy sbom ./sbom.cdx.json && trivy image --format cyclonedx --output sbom.cdx.json myapp:1.4
Mode that inspects workloads for misconfiguration and exposed secrets using read-only access.
trivy k8s --report all cluster
Block a release on fixable critical vulnerabilities.
Scheduled scans of what is actually deployed.
SBOMs attached to each build artifact.
Symptoms you will actually hit, with the cause and the legitimate fix.
Possible causes
Usual fix
Cache the DB (`--download-db-only`, an artifact cache, or a mirror), or use `--skip-db-update` in an image that ships one.
Possible causes
Usual fix
Update the base image first, then gate on `CRITICAL` with `--ignore-unfixed`; the count is a maintenance story, not a report.
Possible causes
Usual fix
Mount `/var/run/docker.sock` read-only into the step, or scan the tarball export instead of the daemon.
Not documented yet: grype, snyk. Request an entry and it will link up automatically.Request a tool
Side-by-side
Where to verify anything on this page. External links open in a new tab.
Checkov cover adjacent parts of the same job.