← Back to feed

trivy

GitHub Repo Pretty sure · backed by paying company
https://github.com/aquasecurity/trivy

Container security scanner that actually works and gets deployed everywhere. The rare open-source tool that solved a real problem before enterprise competitors existed.

10%
75%
15%
Slop 10%Signal 75%Science 15%

Trivy is the unglamorous workhorse of DevSecOps. It scans container images, filesystems, K8s clusters, and VMs for vulns/secrets/misconfig with minimal friction. The README is honest—no ML buzzwords, no «AI-powered detection»—just multi-target/multi-scanner coverage and real integrations (GitHub Actions, K8s operator, VS Code). High signal because it ships in production pipelines at scale. Low science because it's mostly vulnerability database lookups and pattern matching, not novel research....

33571 stars Go 2026-03-19 2537 days old

Become a MFer to rate — log in