One open-source scanner for containers, filesystems, repos, IaC and Kubernetes.
Trivy scans container images, filesystems, git repositories, infrastructure-as-code and running Kubernetes clusters for vulnerabilities, misconfigurations, secrets and licence issues — all from a single fast binary with no server component. It has become the default scanner in container pipelines.
Best for
Free and open source
Open sourceFree tier: Everything, self-hosted
What drives the bill: Free and open source. You pay in engineering time and CI minutes.
Check current pricing on Aqua Security’s siteFigures are indicative and were last reviewed August 2026. Vendors change pricing often; confirm before you commit.
No reviews of Trivy yet. If you have used it in anger, yours would be the first.
If Trivy is not the right fit, these solve the same problem differently.
Security Testing
Developer-first security across dependencies, code, containers and infrastructure.
Security Testing
Software composition analysis with automated remediation and licence compliance.
Security Testing
Enterprise application security platform: SAST, SCA, DAST, IaC and API security.