trivy
Off-the-shelfDependency CVEs, secrets, and misconfiguration in one pass.
What it scans
Dependencies, files, and configuration in the acquired artifact, fully offline.
What it catches
- Dependency CVEs.
- Hardcoded secrets.
- Misconfiguration in the artifact's files.
Source and provenance
Nerlo pins and publishes each scanner's provenance so you can verify it yourself. Every scan surfaces the source, version, and install command in its report.
- Kind
- Off-the-shelf
- Source channel
- github releases (.deb)
- Pinned version
- 0.71.0
- License
- Apache-2.0
- Source URL
- https://github.com/aquasecurity/trivy