Trivy

Security & Compliance Technologies
Trivy
Trivy is an open-source security scanner for containers, Infrastructure as Code, and cloud-native applications. It detects vulnerabilities, misconfigurations, secrets, and license issues across the software supply chain.
What is it?
Trivy is an open-source security scanning tool developed by Aqua Security. It is designed to provide fast and comprehensive vulnerability scanning for container images and cloud-native environments.
What does it do?
Trivy scans container images, file systems, Git repositories, Kubernetes manifests, and IaC files to identify vulnerabilities, exposed secrets, misconfigurations, and compliance issues. It integrates easily into CI/CD pipelines.
Where is it used?
Trivy is widely used in DevSecOps pipelines, Kubernetes environments, cloud-native applications, and enterprise systems where container security and supply chain protection are critical.
When & why it emerged
Trivy was introduced in 2019 as container adoption increased and security risks shifted left into development workflows. It emerged to provide a simple, fast, and developer-friendly security scanner for modern infrastructures.
Why we use it at Internative
We use Trivy to automate security scanning across containers and infrastructure code. Its speed and ease of integration allow us to enforce security controls early without slowing down delivery.
More in Security & Compliance Technologies
Other technologies from the same category of the library.

Datalust Seq
Datalust Seq is a centralized logging and observability platform designed for structured log analysis. It helps teams collect, search, and visualize application logs in real time to diagnose issues and monitor system health.

Sentry.io
Sentry.io is an application monitoring platform that helps teams detect, diagnose, and fix errors in real time. It provides deep visibility into application performance, crashes, and runtime issues across platforms.

Cloudflare
Cloudflare is a global web performance and security platform that accelerates websites, APIs, and applications. It provides CDN, DDoS protection, WAF, DNS, and edge computing to improve speed, reliability, and security.

Prometheus
Prometheus is an open-source monitoring and alerting system designed for cloud-native environments. It collects time-series metrics via a pull-based model and enables powerful querying and alerting for distributed systems.

Grafana
Grafana is an open-source observability and data visualization platform used to explore, analyze, and monitor metrics, logs, and traces. It enables real-time dashboards and alerts across cloud-native and enterprise systems.

Datadog
Datadog is a cloud-native monitoring, observability, and security platform for modern applications. It provides real-time visibility into infrastructure, applications, logs, and user experience across distributed systems.